
Disruptive cyber activity highlights risk from internet-exposed systems and edge devices
While we have observed targeting of OT, there continues to be a broader pattern of disruptive cyber activity targeting internet-exposed systems and edge devices affecting all sectors.
We have previously highlighted other activity such as that against poorly configured routers, published in July 2026 with international partners.
For non-OT organizations, such activity highlights the importance of maintaining visibility of internet-exposed assets and edge network devices. Key actions include maintaining an accurate inventory of internet-facing systems, understanding the function and data flows of edge devices, applying vendor security updates promptly, retiring end-of-life equipment, disabling insecure management protocols such as SNMP v1, SNMP v2, and Telnet, and monitoring for unexpected configuration changes or outbound connections.
Source: UK NCSC (Cyber) (27 August 2026)






