Why this needs attention now

On 27 August 2026, the National Cyber Security Centre warned organisations about increased targeting of internet-exposed systems and network-edge devices.

The warning followed disruptive activity affecting operational technology, but the NCSC also highlighted a wider risk for ordinary businesses, schools and other organisations. Its advice includes maintaining an accurate list of internet-facing systems, applying vendor security updates promptly and retiring unsupported equipment.

This does not mean every internet-connected device is unsafe. Some services must be accessible remotely. The risk arises when an organisation does not know a device is exposed, no longer needs the connection or has not kept the equipment securely configured and supported.

What is an internet-exposed or edge device?

An edge device sits between your internal network and the outside world or provides a service that can be reached remotely.

Older connections can easily be forgotten. A port may have been opened temporarily for an engineer, a previous supplier may still have remote access or equipment may continue operating long after the person who installed it has left.

The NCSC specifically advises organisations not to assume their systems are inaccessible from the internet without checking. Unintended exposure can result from configuration mistakes, legacy connections and unmanaged devices.

  • Internet routers and firewalls
  • VPN and remote-access systems
  • Network-attached storage devices
  • CCTV recorders and camera-management systems
  • Door-access and alarm systems
  • Remote Desktop gateways
  • Telephone systems
  • Web servers and externally accessible applications
  • Building-management, heating or manufacturing equipment

Start with a clear inventory

The first step is to record what your organisation has and why it is accessible. Do not limit this check to computers and servers. Include equipment managed by CCTV, telecoms, alarm, facilities, heating and machinery suppliers.

The NCSC's vulnerability-management guidance recommends identifying assets, assigning responsibility and applying updates by default. It also makes clear that decisions to leave known risks unresolved should be owned at an appropriate senior level.

  • The device or service and its location
  • Its purpose, make, model and software or firmware version
  • The public IP address, domain or port used
  • Who manages it and which supplier supports it
  • Whether remote access is still required
  • When it was last updated
  • Its vendor support or end-of-life date

Remove exposure that is no longer needed

Every external connection should have a clear business reason. Remove old port-forwarding rules, unused supplier access and remote-management services that are no longer required. Internet-facing administration pages should be disabled where possible or restricted to approved secure connections.

Remote access should also be removed promptly when an employee, contractor or supplier no longer needs it.

  • Use a supported VPN or properly secured remote-access service.
  • Enable multi-factor authentication where the product supports it.
  • Give administrators individual accounts rather than shared logins.
  • Replace all default usernames and passwords.
  • Limit access to the people and locations that genuinely require it.
  • Avoid outdated management methods such as Telnet and SNMP versions 1 and 2.

Keep boundary equipment supported and updated

Routers, firewalls and VPN appliances are security products, but they are also computers running software. They can contain vulnerabilities and require regular updates.

If a device has reached the end of its supported life, installing the latest update available may not be enough. The manufacturer may no longer produce fixes for newly discovered vulnerabilities, so replacement should be planned.

  • Enable automatic security updates where appropriate.
  • Send vendor security notices to a monitored email address.
  • Review and install critical updates promptly.
  • Store configuration backups securely.
  • Plan replacement before vendor support ends.
  • Disable unused services and management features.
  • Retain and review logs for unexpected access or configuration changes.

Consider what happens behind the firewall

Securing the internet connection is important, but organisations should also limit what an affected device could reach. Where practical, separate systems according to their purpose. CCTV cameras, guest Wi-Fi, building controls, manufacturing equipment and ordinary office computers do not normally need unrestricted access to one another.

This separation can reduce the impact of a compromised or incorrectly configured device. It can also make unusual traffic easier to identify.

Maintain tested backups of important configurations and data. A configuration backup is only useful if somebody knows where it is stored, it is protected from unauthorised changes and the organisation knows how to restore it.

Practical internet-exposure checklist

UK organisations can also register for the NCSC's free Early Warning service. It provides notifications about potential malware, vulnerable services and open ports associated with registered public IP addresses and domains. It is a useful additional check, although it should complement rather than replace other security controls.

  • Record your public IP addresses and internet-facing domain names.
  • List every router, firewall, VPN, remote-access service and published application.
  • Include CCTV, alarms, telephone systems, building controls and machinery.
  • Confirm why each external connection is required.
  • Remove obsolete port forwarding and supplier access.
  • Change default credentials and eliminate shared administrator accounts.
  • Enable multi-factor authentication wherever supported.
  • Confirm every device is receiving security updates.
  • Record vendor support and end-of-life dates.
  • Disable outdated services such as Telnet and SNMP v1 or v2.
  • Review logs for unexpected access, connections or configuration changes.
  • Back up important configurations and test the recovery process.
  • Repeat the review after network changes and at least quarterly.

Official sources and further reading

These primary sources were checked when this article was last reviewed.

Written by

Christopher Lomax

Director of Bury I.T. Support Ltd, with more than 20 years of hands-on experience supporting business IT, Microsoft 365, networks, servers and cyber security.

About the team