If you're an SMB, you'd be forgiven for skipping the NCSC's latest alert. Don't.

A Defense.com mug and a laptop on a desk beside a window, with a power station across the water at sunset A Defense.com mug and a laptop on a desk beside a window, with a power station across the water at sunset A Defense.com mug and a laptop on a desk beside a window, with a power station across the water at sunset
Photo of Tim Anderson

Tim Anderson

Chief Commercial Officer

3rd Sep 2026

Written for critical national infrastructure, ignored by nearly everyone else. If your business has a firewall, a remote access system or a customer portal facing the internet, here are five things worth doing this month.

On 27 August the NCSC published an alert about increased targeting of operational technology (OT) systems across multiple sectors globally, including in the UK, carried out by a range of threat actors and resulting in some limited real-world disruption. It is tagged for cybersecurity professionals, large organizations and the public sector. Most owners of smaller UK businesses will never open it, and on the face of it they have no reason to.

There is one paragraph at the very bottom, though, that almost nobody will reach. Alongside the OT targeting, it states:

"...there continues to be a broader pattern of disruptive cyber activity targeting internet exposed systems and edge devices affecting all sectors." National Cyber Security Centre, 27 August 2026

For organizations without OT, the actions it lists are unglamorous security best practices, and the good news is that they are entirely achievable:

  1. keep an accurate inventory of internet-facing systems
  2. understand what your edge devices do and apply vendor updates promptly
  3. retire end-of-life equipment
  4. disable insecure management protocols such as Telnet and SNMP v1 and v2
  5. monitor for unexpected configuration changes or outbound connections

None of that is particularly complicated. The challenge is having someone with the time and expertise to do it, and to keep doing it.

What "internet-exposed" means in a normal UK business

Most smaller organizations assume this is not their problem, because they do not run a power station, or at best that their MSP has it covered. But the phrase internet-exposed covers a lot of ordinary systems:

  • The firewall or router the ISP installed, still running the password it shipped with
  • A VPN or remote access appliance bought in a hurry during 2020 and never revisited or hardened
  • A NAS box holding the file share, reachable from outside so the team can get at critical files
  • Remote Desktop Protocol (RDP) or remote control software left open on a server after a migration that was supposed to be temporary
  • CCTV, door entry, alarm panels, heating and building management, all increasingly IP connected
  • EPOS terminals, digital signage, a warehouse scanner controller
  • A web application or customer portal built by an agency that no longer exists

The NCSC makes a point here that applies to a serviced office just as much as to a substation. Organizations should not assume their systems are inaccessible from the internet without verifying it, because exposure can arise through misconfiguration, legacy connections or unmanaged assets. Almost nobody exposes something deliberately. It happens because a supplier needed access, or a device shipped with a feature enabled by default, or nobody switched something off after a project ended.

Why this lands harder on smaller organizations

Three reasons, none of them about budget.

Nobody owns the list. In a business without dedicated IT, the asset inventory lives in the head of whoever set things up, and that person may have left in 2022. You cannot patch, retire or monitor what nobody has written down.

Edge devices sit outside your existing tools. Antivirus and Microsoft Intune do not know about a firewall, a NAS or a camera recorder. The systems most likely to be found by an attacker are often the ones that no tooling tracks automatically.

Attacks do not respect office hours. Automated scanning for exposed and unpatched systems runs continuously, and our tests show that a system made available to the internet will be scanned within 32 milliseconds. The window between a vulnerability being published and being exploited at scale is now measured in days, sometimes hours due to AI vulnerability discovery.

Five things worth doing this month, most of them free

  1. Write down what faces the internet. Every public IP, every open port, every device, every web application, every supplier with remote access. Then challenge each one: does it still need to be reachable?
  2. Remove default and shared credentials, and turn on MFA everywhere it is supported. The NCSC lists this second in its actions for OT operators, ahead of almost everything else.
  3. Check support status. Anything past end of life or out of vendor support needs a replacement date in the diary, no excuses.
  4. Register for the NCSC's Early Warning service. It is free, and it exists to help identify publicly exposed vulnerabilities and other potential security issues affecting internet-facing systems, so risks can be addressed before they are exploited.
  5. Test a restore, not just a backup. The NCSC's guidance on tested recovery and ransomware-resistant backups applies to any organization.

If you want a structured baseline rather than a checklist, Cyber Essentials remains the sensible starting point. The NCSC describes it as the minimum standard of cybersecurity recommended by the Government for organizations of all sizes. Its five controls map closely onto what this alert is asking for.

Where Defense.com™ fits

We are not going to pretend a security platform alone solves an OT problem. Network segmentation, secure industrial protocols and controller write protection are engineering work, and the NCSC's own guidance is the right reference for it.

Most businesses globally have no security team. What they are missing is visibility and expertise, and that is the gap our platform is built to close. It gives you one place to see what an attacker can reach, whether that is OT or an ordinary internet-facing system.

Threat Recon identifies your external attack surface and shows you what you expose that an attacker will target, which is most of the work in building an inventory of internet-facing systems. Vulnerability scanning covers external, internal and web application surfaces, ranks findings by severity, gives remediation guidance and re-scans continuously to confirm the fix worked. Our agent Orbital maps devices and assets and keeps them measured against standards such as Cyber Essentials. Watchtower delivers threat intelligence, including NCSC and CISA advisories, filtered to your sector, so you are told about what matters to your industry instead of being bombarded with everything.

Finally, we provide a guided Cyber Essentials and CE+ readiness assessment that surfaces control gaps before you sit an assessment.

For organizations that need eyes on it around the clock, our higher tiers include a 24/7 UK-based security operations center that investigates and acts. That takes the security management burden off a small internal team, which is the real constraint for most of the businesses reading this.

We sell entirely through partners, so if you already work with an IT provider or a security consultancy, the best next step is to send them this alert and ask what it means for you. If nobody is having that conversation with you, we can introduce you to someone who will.

The point

Strip out the OT specifics and the NCSC's message is simple. Know what you have exposed. Keep it supported. Watch it. Be able to recover from it. That is sound advice for any organization.

See what you have exposed

Get in touch today to start your free trial of Defense.com™ and find out what an attacker can already reach.