Closing the Perimeter

Industrial automation has long operated under a comforting assumption: the air gap. The belief was that as long as production lines, programmable logic controllers (PLCs) and supervisory control and data acquisition (SCADA) systems remained physically segregated from corporate IT, plants were inherently safe from external disruption.
Modern manufacturing and utility networks have evolved rapidly. Pushing operational data into cloud platforms for maintenance and process optimisation has dissolved traditional boundaries. The theoretical air gap has quietly vanished across many facilities, giving way to external connectivity routes that link the plant floor directly to the outside world.
The risks associated with this convergence were brought into sharp relief by the UK National Cyber Security Centre (NCSC). In their recent alert, Disruptive cyber activity highlights risk from internet-exposed systems and edge devices, the authority warned that both state-sponsored and criminal actors are actively targeting critical national infrastructure and commercial sectors. Most alarmingly, this malicious activity has moved beyond corporate IT networks to exploit operational technology (OT) systems directly, causing real-world operational impact.
For plant directors, OT engineers and operations leaders, this advisory serves as an urgent wake-up call. Protecting industrial processes requires moving past assumptions and addressing the practical vulnerabilities that leave critical shop-floor devices exposed to the public internet.
The Edge Device Dilemma
Edge devices sit at the exact perimeter where enterprise IT meets operational networks. These components include perimeter firewalls, cellular routers, remote access boxes, industrial VPN gateways, and building management interfaces.
Because these units frequently operate without requiring constant human intervention, they are often treated as invisible utility hardware. A technician installs a router in an electrical cabinet during a system commissioning, configures remote access so an overseas vendor can support a piece of machinery, and then leaves the device untouched for years.
This “fit and forget” mentality turns edge devices into prime targets for threat actors. Attackers do not necessarily need bespoke zero-day exploits to breach a facility. Instead, they scan the internet for known vulnerabilities in unpatched firmware, outdated hardware that has passed its end-of-life support date or devices that still run on factory-default passwords. Once an attacker gains a foothold in an edge device, they often inherit administrative privileges that grant direct access to internal subnets, bypassing outward-facing perimeter security completely.
Inadvertent Exposure on the Plant Floor
The NCSC alert highlights a crucial reality for industrial organisations: unintended internet exposure is far more prevalent than most engineering teams realise. Facilities often assume their PLCs, variable speed drives, and human-machine interfaces (HMIs) are completely isolated, only to discover that network changes have compromised their posture.
Several common scenarios introduce unintended exposure:
- Dual-Homed Workstations: Maintenance laptops or engineering workstations plugged simultaneously into a corporate Wi-Fi network and a machine subnet can act as unmonitored bridges for external malware.
- Misconfigured Perimeter Routing: Small configuration errors during network expansions can route public IP traffic straight down to industrial controllers, exposing management interfaces directly to search engines that index connected devices.
- Legacy Industrial Protocols: Protocols such as Modbus TCP, Profinet, and EtherNet/IP were originally engineered for performance and real-time reliability, lacking intrinsic encryption or authentication. When these protocols are exposed across boundary devices, any actor who discovers them can issue read and write commands directly to physical processes.
Critical Actions to Secure Industrial Operations
Addressing the risks outlined by the NCSC requires a pragmatic, defence-in-depth approach tailored to the unique demands of operational environments, where process uptime and safety remain paramount.
1. Establish Complete Asset and Perimeter Visibility
You cannot protect what you cannot see. Industrial enterprises must build and maintain a comprehensive, living inventory of every connected asset on the plant floor. This includes identifying all edge gateways, firewalls, network switches and industrial controllers. Teams should conduct regular external attack surface audits to verify whether any internal IP addresses, management portals or industrial ports are accidentally visible from the public internet.
2. Enforce Strict Network Segmentation
Organisations must implement robust zoning in accordance with recognised industrial security standards. Operational technology networks, engineering management subnets and corporate enterprise networks must be strictly separated by managed, industrial-grade boundary firewalls. Traffic moving between these layers should follow a zero-trust model, permitting only explicitly authorised, logged and monitored data flows.
3. Eliminate Insecure Remote Access and Default Credentials
Remote engineering access must be tightly controlled. Default factory credentials must be replaced immediately upon deployment with complex, unique administrative passwords. Wherever edge devices or remote access gateways support it, multi-factor authentication (MFA) must be enforced. Crucially, direct public management access to routers and VPNs should be disabled. Remote sessions should be brokered through secured jump hosts and monitored in real time.
4. Lock Down Remote Controller Logic
As recommended by the NCSC, OT devices must be operated in a state that prevents unauthorised remote programming during normal operations. Wherever feasible, physical keyswitches on PLCs should be set to “Run” rather than “Remote Run” or “Program” to stop threat actors from remotely altering control logic or downloading malicious firmware over the network.
5. Retire Legacy Protocols and Obsolete Equipment
Edge devices and network equipment that have reached vendor end-of-life status must be replaced. Unsupported hardware no longer receives essential security patches, leaving perimeter vulnerabilities permanently open. Furthermore, unencrypted management protocols such as Telnet and older versions of SNMP should be decommissioned in favour of modern, encrypted alternatives such as SSH, HTTPS, and SNMPv3.
Building True Resilience
Preventative perimeter security is vital, but true operational resilience demands the ability to detect unauthorised modifications and recover rapidly should an incident occur.
At Novotek, we help industrial organisations bridge the divide between robust cyber security requirements and daily production needs. Through modern industrial automation solutions and dedicated change management platforms such as Octoplant, we enable manufacturers and utility providers to:
- Maintain Automatic Asset Inventories: Continuously identify connected automation hardware, firmware versions, and communication paths across heterogeneous production environments.
- Track Configuration Changes: Automatically monitor and compare running PLC logic, SCADA configurations, and drive parameters against approved baselines, alerting engineering teams instantly to unplanned or suspicious alterations.
- Match Vulnerabilities (CVE Management): Proactively correlate installed hardware and firmware versions with global vulnerability databases, highlighting which devices require urgent attention.
- Ensure Rapid Disaster Recovery: Safeguard plant uptime with automated, version-controlled backups of all automation code. If a cyber event or corruption occurs, engineers can restore the exact, verified operating state within minutes, dramatically cutting recovery time.
The Time to Act Is Now
The warnings from the NCSC demonstrate that attacks against industrial perimeters are no longer hypothetical edge cases. As geopolitical instability rises and cyber tools become increasingly sophisticated, industrial operators cannot afford to leave their perimeters unexamined.
By auditing external connectivity, securing edge devices, and deploying robust operational change management, businesses can protect their critical infrastructure without compromising operational flexibility.
To review your OT security posture, assess internet-facing dependencies, or implement automated disaster recovery across your plant floor, contact the specialists at Novotek today.
