NCSC statement following exploitation of Unitronics programmable logic controllers

Update: 19/12/2024
An updated advisory – co-sealed by the NCSC alongside international partners – has been released which includes new information about the activity referenced below and the latest mitigation advice to help protect infrastructure.
Organisations are encouraged to follow the advice in this latest advisory to help reduce their risk of compromise.
The advisory can be read on CISA’s website.
The National Cyber Security Centre (NCSC), which is a part of GCHQ, is recommending organisations follow the guidance published by US agencies and the Israel National Cyber Directorate (INCD), regarding the active exploitation of Unitronics programmable logic controllers (PLCs) used in a range of industries including the water, energy, food and beverage manufacturing, and healthcare sectors.
The exploitation is of limited sophistication, and is highly unlikely to cause any disruption to the routine operations of affected organisations. There is a very low potential risk, if the threat is unmitigated, to some small suppliers. As such, the NCSC is encouraging organisations using Unitronics PLCs to follow the steps outlined in the cyber security advisory.
The NCSC has previously highlighted the 'significant and enduring' threat faced by operators of the UK’s critical national infrastructure, including the water sector.
Jonathon Ellison, NCSC Director for National Resilience and Future Technology, said:
“The NCSC has warned for some time of the enduring threat to the UK’s critical national infrastructure.
“Our international counterparts have issued an advisory outlining a threat against a range of industries, including the water sector.
“We are notifying UK providers of this threat, and recommend they protect consumers by following the mitigation advice set out in the advisory.”
The NCSC works closely with all areas of critical national infrastructure and is engaging with organisations to highlight this issue and support with mitigation activities.
It is vital that critical service providers ensure they have robust security measures in place. The NCSC has published range of guidance on its website to help improve resilience and keep the UK safe online. This includes the Cyber Assessment Framework and 10 Steps to Cyber Security.