Operational Technology
Pages
Page 12 of 37
Principle 2: Limit the exposure of your connectivity
Exposure refers to where an asset sits within the wider system architecture, and how accessible it is to external or adjacent networks, taking into account defence in depth controls. Ultimately, the more assets exposed at the network edge, the broader your attack surface becomes.
To manage this risk, organisations should adopt an exposure management approach. This involves proactively identifying, assessing, and mitigating risks associated with digital assets and their connectivity. This includes evaluating the asset’s placement in the network, the type of connectivity implemented, and the strength of cyber security controls. The NCSC Netherlands exposure management guidance defines categories such as ‘internet or external facing’ and ‘adjacent network-facing’ assets, helping organisations assess exposure levels systematically.
It is especially critical to ensure that you are managing the exposure of your admin interfaces. Where possible limit administration of devices or systems to only be achievable through privileged access workstations (PAW), which provide secure and trusted endpoints for system management. When administering critical security controls or obsolete systems via a PAW it may be appropriate to limit administration to only be achievable via local physical access to further reduce the exposure of these interfaces.
| Note: Network edges in OT can be hard to identify. For example, an unsecured radio link inside an OT network may not appear on network diagrams but still forms part of the network edge. Ensure you identify all data flows within the OT network and the components that facilitate this connectivity. |
Reduce time of exposure
Not all connections need to be continuously active. Where possible, use just-in-time access, enabling connectivity only when required and disabling it otherwise. This significantly reduces the window of opportunity for attackers.
Remove inbound port exposure
All connections with the OT environment should be initiated as outbound connections from within the OT environment. This principle helps avoid exposing inbound ports on the OT network perimeter or between internal zones, which can significantly increase security risk.
In scenarios where systems outside the OT environment require access to OT assets (for example remote vendor support), use brokered connections through a secure gateway located in a separate, security-controlled segment such as a demilitarised zone (DMZ). A brokered connection is a method where the external party connects to an intermediary system (the broker), which then securely relays the connection to the OT asset. This ensures that the OT system is never directly exposed to the internet or external networks, and that all access is mediated, monitored, and controlled.
| Note: The security of the brokered connection is critical. It must be actively updated and use modern authentication methods. |
Manage obsolescence risks
Obsolete devices pose a known and increasing security risk, making them unsuitable for direct external connectivity beyond the OT network boundary.
However, operational constraints often mean that migrating away from obsolete devices takes time. During this transition period, these devices may still need to communicate with other systems or receive vendor support.
To manage the associated risks, organisations should enable indirect access to external networks through compensating controls, including:
Network segmentation: isolate the obsolete device from the wider OT network using logical or physical segmentation to limit lateral movement and reduce exposure.
Trusted boundary controls: place up-to-date, security-hardened components between the obsolete device and external systems. Examples include:
a protocol gateway to translate and inspect traffic before it reaches the device
a hardened jump host to facilitate vendor support, ensuring access is controlled and monitored
Access restrictions: limit connectivity to only what is operationally necessary.
Monitoring and Logging: ensure all interactions with the obsolete device are logged and monitored for anomalous behaviour.
Manage unique connectivity bearer risks
The risk associated with a connection depends on the network type and transmission medium. For example:
public internet links carry higher exposure than private fibre
wireless technologies, even within private networks, may introduce risks of unauthorised access
Security controls should be tailored to the connectivity type to ensure adequate protection.
External attack surface management
Your public visibility can be monitored actively by using external attack surface management (EASM) tools or other internet-facing asset discovery tools, to identify accidental or unmanaged exposure before attackers do. These discovery tools index internet-connected assets and protocols, allowing anyone to find exposed web servers, remote access portals, or industrial devices. EASM tools can be used to reduce your attack surface and the likelihood of being targeted.
If your systems are visible to these scanning services then they are highly likely to be found and targeted by malicious actors, significantly increasing the risk to these systems. There are several things you should consider before using tools to manage your exposure:
-
Static public IP address space:
you must maintain a thorough and current list of all public IP addresses alongside exposed network ports in use. This task can be particularly challenging, especially for organisations that operate across vast geographical areas or use multiple ISPs, or have several infrastructure teams.
-
Dynamic public IP addressing:
particularly where your organisation uses cloud services, you may use dynamic addressing. This can increase the challenge of automated scanning. It is critical that you establish a process to maintain an accurate record of these addresses.
-
Continual monitoring:
you should establish ongoing processes to automate exposure management within your organisation. This should include scanning the full public IPv4 and IPv6 ranges belonging to your organisation, not just the IPs currently in use.
-
Third parties:
if connectivity to your environment is provided by a third party then it may be proportionate to include these endpoints in your exposure management program. This would require establishing processes with the third party for sharing IP addresses of endpoints within or directly supporting your OT systems.
Any device found through a EASM, or other internet-facing asset discovery tool should be deemed at risk and promptly investigated. This should include establishing:
- Was the system originally designed to be connected for direct internet access?
- Was this system designed to be exposed temporarily or permanently, and how long has it been exposed for?
- Are there any additional services/ports/protocols exposed by the system to those expected?
- Does the system have security controls implemented that are appropriate to its exposure?
- Is the system is updated and hardened?
- Does this systems exposure cause additional risk to other connected OT systems?
- Does the system need to be exposed directly to the public internet, or can connectivity be restricted to only those who need it?
- Is the asset and/or its internet connectivity critical to the delivery of your OT process?
Where these factors highlight that an asset is not designed or lacks sufficient security controls to operate in the threat context of the public internet, remediation actions should be immediately taken. Depending on your operational constraints this could include:
- disconnecting the asset
- reconfiguring/Updating the asset
- adding compensating controls to manage the exposure risk
Further reading International partners have published a range of resources on this topic: |
Managing wireless networks exposure
It is easy to think of exposure only at a device level, but the communication medium also needs to be considered. Devices that use wireless communications or send traffic using wireless signals can be exposed to a greater level of risk.
A wireless network is not constrained by the boundary of your site. This means physical controls can't be relied on to protect this network. If a wireless network is not configured with security in mind, it is trivial for an attacker to intercept and capture signals, as well as to potentially inject traffic into these networks.
Understanding the factors that impact security of your signals is critical to enabling you to build appropriate and proportionate controls.


