
Recent attacks highlight an increase in targeting of critical national infrastructure (CNI) by state-sponsored actors.
This risk advisory aims to provide clarity on the current threat landscape and the increasing cyber risks facing organisations within the CNI sector.
What is the context?
High-profile incidents, such as state-sponsored attacks on US water systems and activity targeting UK power infrastructure, demonstrate a shift from theoretical risk to active disruption. In the UK, a cyber attack by suspected Iranian-affiliated actors shut down a small power plant for four days. Meanwhile, in July 2026, a coordinated attack linked to Iranian-affiliated threat groups compromised water utilities across at least 12 US states. Recent advisories from CISA and NCSC corroborate this trend by detailing persistent threats to operational technology (OT) and providing guidance on preparing for severe cyber threats and implementing secure connectivity.
The recurring factor in these events is the exploitation of insecure connectivity within OT environments, which are increasingly vulnerable to external compromise. Threat actors scan for publicly exposed industrial control equipment and cellular modems. Once compromised, threat actors modify operational programs, allowing them to turn off automatic safety shutdowns and alarms, forcing physical processes into unsafe states and manipulating monitoring dashboards to make everything appear normal to operators.
What is the risk?
This risk involves the compromise of OT and Industrial Control Systems (ICS), which are critical for the reliable delivery of essential services. Threat actors are pivoting from espionage to active sabotage, targeting the physical processes that underpin national infrastructure.
Source:
Risk events:
- System Intrusion (Control system bypass)
- Information Breach (Unauthorised access to systems)
Consequences:
- Operations (Business Disruption and Slow Recovery)
- Strategic (Damaged Reputation & Embarrassing Reporting)
- Financial (Unplanned Costs & Increased Inefficiency)
What factors drive the consequences?
- Use of legacy systems designed for reliability and uptime rather than security
- Limited visibility and monitoring of systems, often masking malicious activity until a physical fault occurs
What factors drive the frequency?
- IT/OT convergence expands the attack surface, creating pathways for threat actors to compromise physical controls
- Inadequate security controls, such as default credentials and absence of multi-factor authentication (MFA)
- Off-the-shelf exploit tools enabling opportunistic actors to target exposed infrastructure at scale
How may it evolve?
Geopolitical events may increase focus on attacking critical national infrastructure. We anticipate attacks on OT may become highly automated, with increasingly state-sponsored threat actors routinely mass-scanning for exposed endpoints during initial reconnaissance. As the industry digitises, the expanding attack surface likely invites more frequent, small-scale disruptions. Attackers will use these to test organisational resilience before attempting larger, more destructive campaigns that could lead to large scale environmental impacts and medical harm.
Source:
Risk events:
- Availability Interruption (Sabotage)
- Information Breach (Unauthorised modification of information)
Consequences:
- Operations (Business disruption, safety failure and medical harm)
- Compliance (Regulatory fines)
- Financial (Unplanned response costs)
- Strategic (Embarrassing reporting)
As these attacks evolve into larger OT campaigns, the threat transitions from minor disruptions to critical failures that could cause safety incidents or medical harm. Consequently, major incidents trigger regulatory fines under frameworks like NIS2, alongside significant response costs.
What action is required?
Carry out these actions as a priority to reduce immediate exposure:
- Audit infrastructure to identify and disconnect all internet-facing programmable logic controllers (PLCs), human-machine interfaces (HMIs) and other critical control devices.
- Mandate changing all default passwords across the OT environment and enforce MFA for all remote access to management systems.
- Maintain offline backups of critical OT configurations, including PLCs and HMIs, and deploy continuous monitoring to detect unauthorised traffic or configuration changes.
To build long-term resilience, the following actions should also be considered:
- Isolate critical industrial processes from corporate networks by deploying a demilitarised zone (DMZ) architecture between IT and OT systems.
- Prioritise OT vulnerability management using a risk-based approach, focusing on critical exposures and legacy systems that cannot be routinely patched.
- Govern and audit third party and vendor remote access, implementing “just-in-time” access rather than permanent access permissions.
- Develop and exercise incident response playbooks tailored for OT environments to ensure safe containment and recovery during a cyber incident.
For further information or assistance in understanding or measuring this risk to your organisation please contact us for a session with one of our cyber risk consultants.
Cydea uses the Open Information Security Risk Universe (OISRU) as a framework and taxonomy for describing information security risks independently of models or methods of analysing risks. Find out more about our contribution to the project on our cydea.tools site.
Photo by Roland Larsson on Unsplash