The Kit You Forgot Was on the Internet, and How to Find It
At the end of August, the National Cyber Security Centre published a warning with a deliberately dry title, about the risk from internet-exposed systems and edge devices. Behind the title sits a simple observation. Attackers are increasingly going after the operational kit that businesses connect to their networks, they are finding some of it reachable from the public internet, and in a number of cases the owners never knew it was.
It would be easy to file that under “critical infrastructure, not my problem”. I would suggest reading it the other way. The NCSC notes this activity across multiple sectors, in the UK as well as abroad, and the pattern it describes is one I have seen inside ordinary businesses for years. This is a story about unglamorous kit and unowned lists, and that makes it very much a small business story.
Operational technology is more of your business than you think
Strip away the jargon and operational technology means the equipment that does physical work: the controllers on a production line, the chillers and compressors, the building management system, the CCTV recorder, the door entry panel, the heating controls, the pump house at the golf club.
Twenty years ago that kit lived on its own wiring and kept itself to itself. Today almost all of it ships with a network port and a web page for managing it, and almost all of it ends up plugged into the same network as your laptops and your accounts package. A 40-person food producer can easily have more devices with an IP address on the factory floor than in the office. Most firms that size could not produce a list of them.
How kit ends up on the internet without anyone deciding
Here is the detail in the NCSC’s warning that deserves the most attention. Exposure is usually not a decision anyone made. It arrives through a misconfiguration, or through a legacy connection nobody remembers, or through an asset nobody is managing.
The classic route is remote support. An installer fits a piece of equipment, needs to reach it from their office, and opens a path in from the internet. It works, everyone moves on, and the path stays open for years after the support contract ends. Add a default password that was never changed and firmware that has not been updated since installation, and you have the exact combination the NCSC is warning about. Nobody was careless on the day. The cause is that the device never made it onto a list, so no process ever touched it again.
That is the root of it. The symptom is a strange entry in a log or, for the unlucky, a line stopped and a Monday morning ruined. The cause is not knowing what you have and what can reach it.
The one-hour exercise: borrow the NCSC’s homework
The NCSC’s recommended measures are written for engineers, but they scale down honestly to a business of 20 plus staff as one exercise and three fixes.
The exercise is the list. Every device on your premises with a network connection goes on it: the obvious computers, then the printers, cameras, door controllers, machine controllers, meeting room screens and anything an installer ever plugged in. For each one, two questions. Can it be reached from outside the building, and who looks after it? An experienced IT provider can answer the first question for your whole network in well under a day, and the answers are usually a surprise.
Then the three fixes that close most of the gaps the NCSC describes:
Default and shared passwords. Anything still using the credentials it shipped with gets them changed, and administrator access gets multi-factor authentication wherever the device supports it.
Unsupported kit. Every device on the list should be within vendor support and receiving updates. The ones that cannot be updated should be replaced or walled off as a minimum, so they cannot be reached from anywhere they do not need to be.
One flat network. The building kit, the production kit and the business IT should not sit on one undivided network where a problem in any of them can reach all of them. Separating them is routine work, and it is the difference between an incident and an inconvenience.
Backups round it out, tested by actually restoring something, because the NCSC’s guidance ends where every honest security conversation ends: assume something will eventually go wrong and rehearse the recovery.
None of this is a product purchase. It is a list, a schedule and ownership, which is why it tends not to happen on its own. For a proportionate baseline to measure against, the government-backed Cyber Essentials scheme covers much of the same ground and exists precisely so smaller firms do not have to invent this from scratch.
The short version
The NCSC is telling everyone, calmly and in public, that attackers are finding the kit nobody remembers connecting. The fix is not fear and it is not a gadget. It is knowing what you have, what can reach it and who owns it, reviewed on a schedule, so exposure stops being something that happens to you and becomes something you decided. Fix the cause, not the symptom, and this whole category of problem quietly disappears. That is what IT that stays fixed looks like.
I spent years as CIO of an industrial services business with more than 100 sites across 14 countries, where kit on the network vastly outnumbered people at desks and an asset list you could trust was the foundation everything else stood on. Net Tech IT brings that same discipline to businesses of 20 plus staff across Sussex, Surrey and London as part of managed IT support, and we install and look after Paxton access control ourselves, so we treat door entry and CCTV as IT because it is. Specialist security work, where it is genuinely needed, is delivered through vetted partners and coordinated by us. If you could not put your hand on a list of everything connected to your network, that is a one-hour conversation worth having. Get in touch or book a call whenever it suits.
Pat | Net Tech IT, Horsham
Sources
- National Cyber Security Centre, Disruptive cyber activity highlights risk from internet-exposed systems and edge devices (27 August 2026)
- National Cyber Security Centre, Cyber Essentials