Tec Nikan
فارسی
Talk to us
All news

The NCSC Names the Secure Replacement for Each Legacy Protocol

DNP3 to DNP3-SAv5, CIP to CIP Security, Modbus to Modbus Security, OPC DA to OPC UA. The UK agency's OT guidance is unusually specific, and doubles as an equipment replacement schedule.

OT securityindustrial protocolsNCSCnetwork segmentationasset management

The UK's National Cyber Security Centre has warned of increased targeting of operational technology across multiple sectors globally, including in the UK, by a range of threat actors — activity it says has "resulted in some limited real-world disruption." The accompanying guidance is more useful than the warning, because it names specific substitutions rather than talking in principles.

The protocol migration list is the centrepiece: DNP3 to DNP3-SAv5, CIP to CIP Security, Modbus to Modbus Security, and OPC DA to OPC UA. For management protocols it calls for removing Telnet and SNMP versions 1 and 2 outright, and for confining anything insecure with no secure alternative to isolated network segments. That is the same substitution list a zone-and-conduit assessment ends up producing, arrived at from the other direction.

The practical difficulty is that support for the secure variants is uneven across installed equipment, which means the migration list is also a replacement schedule. A controller that will never speak CIP Security is a controller with a defined end date, and pretending otherwise turns the isolation clause from a temporary measure into the permanent architecture.

Several other points carry more weight than their length suggests. Do not assume OT is inaccessible from the internet without verifying it — exposure arises from misconfigurations, legacy connections and unmanaged assets, and the assumption is doing a lot of load-bearing work in most plants. PLCs and HMIs must not be directly exposed to the public internet. Controllers should not be left in PROGRAM or maintenance modes, and logic needs password-based write protection or an equivalent so that reaching a device is not the same as being allowed to change it.

The guidance is equally direct about edge equipment. Industrial gateways, firewalls, routers and remote access appliances must stay within vendor support, receive routine updates, be replaced before end of life, and be managed only from segregated management networks that are not connected to the internet. Default credentials must go, shared passwords on web, management and protocol interfaces must be eliminated in favour of unique administrator accounts, multi-factor authentication wherever supported, and key-based authentication instead of passwords where protocols such as SSH allow it.

Finally it asks for logging and monitoring of all connectivity to and within OT networks, with particular attention to communication attempts from unexpected devices, networks or routes — noting that static, predictable OT environments benefit disproportionately from baseline monitoring, because anything new is by definition worth a look. The NCSC linked the warning to its July 2026 publication with international partners on activity against poorly configured routers.

Source: Industrial Cyber

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.