Operational Technology Cyber Risk: What UK CISOs Must Secure Now | INFORMD Executive Briefing

Operational Technology Cyber Risk: What UK CISOs Must Secure Now

Operational technology cyber attacks on UK infrastructure are escalating: 80% of UK manufacturers have suffered at least one cyber attack in the past year, and pro-Russia threat groups are actively targeting critical infrastructure with disruption — not just espionage — as the explicit objective for 2026.

Why Is OT Cyber Security Now a Board-Level Risk in 2026?

Operational technology (OT) — the software and hardware that controls physical systems, from manufacturing lines and energy infrastructure to water treatment and logistics — was long considered a separate discipline from enterprise IT security. Air-gapped networks, proprietary protocols, and specialist vendors created a managed separation that kept most enterprise security frameworks focused on information systems.

That separation no longer holds. According to Dragos’s 2026 OT Cybersecurity Year in Review, Dragos now tracks 26 active OT threat groups globally, with three new groups — AZURITE, PYROXENE, and SYLVANITE — identified in 2025. These groups have shifted their operational objectives from intelligence collection and long-term persistence to active disruption: targeting the ability to shut down or damage physical systems, not merely to observe them.

In the UK context, the National Cyber Security Centre (NCSC) has issued specific warnings about pro-Russia hacktivist groups targeting critical national infrastructure providers and local government, with attacks linked to perceived UK support for Ukraine. The NCSC’s guidance identifies energy, water, transport, and manufacturing as high-risk sectors. For CISOs in these sectors — or those with supply chains that touch them — OT security is no longer a specialist backwater: it is a primary risk management responsibility.

The UK Cyber Security and Resilience Bill, currently progressing through Parliament, will expand mandatory incident reporting obligations to cover a broader range of OT-dependent sectors and will introduce new baseline security requirements for operators of essential services. CISOs must build their OT security programmes now to meet these obligations before they become enforceable.

Executive Action:

  • Map your organisation’s OT environment: identify every industrial control system, SCADA system, and connected physical asset within scope of your CISO accountability.
  • Review your threat intelligence against the Dragos 2026 OT threat group profiles — determine whether any are known to target your sector or your supply chain.
  • Brief your board’s Risk Committee on OT cyber risk as a distinct and escalating threat category, separate from enterprise IT risk.

What Are the Core Components of an Effective OT Security Framework?

Securing operational technology requires a different architectural approach from enterprise IT security. OT systems prioritise availability and safety above confidentiality — the inverse of most IT security frameworks. A network outage that disrupts a manufacturing line or disables a safety control system carries immediate physical consequences that have no equivalent in enterprise IT.

The joint NCSC/CISA guidance on securing industrial control systems identifies five foundational controls that CISOs should implement as a baseline. Network segmentation is the first and most critical: OT environments should be isolated from enterprise IT networks, with strictly controlled and monitored crossing points. According to PwC’s geopolitical risk analysis (2026), many UK organisations still operate with partial or informal network segmentation that provides inadequate protection against lateral movement from IT breaches into OT environments.

Asset inventory and vulnerability management is the second foundational control. OT environments characteristically contain legacy systems — some running operating systems that are decades old — which cannot be patched using standard enterprise patch management processes. CISOs must maintain a current asset inventory and develop a risk-based approach to legacy system vulnerability management that accounts for the operational constraints of OT environments.

Identity and access management in OT contexts requires particular attention to privileged access: many OT systems were designed without strong authentication and rely on shared credentials, local accounts, or vendor-managed access paths that are invisible to enterprise IAM systems. The NCSC has specifically highlighted vendor remote access as a primary attack vector in OT breaches — third-party access to OT environments must be subject to the same rigour as direct employee access.

Executive Action:

  • Conduct an OT network segmentation audit: document every connection between your OT and IT environments and assess whether each connection is necessary, monitored, and controlled.
  • Commission an OT asset inventory if one does not exist: identify all legacy systems, their patch status, and the mitigating controls in place for unpatchable vulnerabilities.
  • Review all vendor remote access arrangements for OT systems: enforce multi-factor authentication, session recording, and time-limited access for all third-party connections.

How Does the UK Cyber Security and Resilience Bill Change CISO Obligations?

The UK Cyber Security and Resilience Bill, introduced following the government’s 2023 consultation and now expected to receive Royal Assent in late 2026, represents the most significant expansion of UK cyber security regulation since the NIS Regulations 2018. For CISOs, the key changes are three: expanded scope, mandatory reporting timelines, and new incident classification requirements.

Expanded scope: The Bill extends the NIS Regulations framework to a broader set of sectors and digital service providers, including managed service providers (MSPs) and data centre operators. Organisations currently outside the NIS scope that provide services to critical national infrastructure sectors will fall within the new framework, creating supply chain compliance obligations that many CISOs have not yet mapped.

Mandatory reporting: The Bill shortens the timeframe for reporting significant cyber incidents to the competent authority to 24 hours for initial notification — down from 72 hours under the current NIS Regulations. CISOs must ensure their incident detection, classification, and reporting processes can meet this tighter timeline for OT incidents, which often require physical investigation and are inherently more complex to classify than IT incidents.

Incident classification: The Bill introduces a tiered classification system for OT incidents based on operational impact, requiring escalated reporting for incidents that affect physical systems or safety controls. This is a new obligation for many OT-reliant organisations that currently report IT and OT incidents through a single unified process.

Our Cybersecurity and Resilience briefings contain detailed analysis of the Cyber Security and Resilience Bill and its implications for your sector. Use our Executive Assessment tools to benchmark your OT security maturity against NCSC baseline requirements.

Executive Action:

  • Map your organisation’s scope under the Cyber Security and Resilience Bill: identify whether you are an operator of essential services, a digital service provider, or a supply chain partner of either — and assess whether MSP or data centre relationships bring you into scope indirectly.
  • Redesign your incident response playbook to include OT-specific scenarios with 24-hour initial notification timelines and tiered operational impact classification.
  • Conduct a tabletop exercise simulating a state-sponsored OT attack on a critical system — test your detection, isolation, and notification capabilities against the new Bill’s requirements before it takes effect.

INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.

What is operational technology (OT) and why is it a cyber security concern in 2026?

Operational technology refers to hardware and software controlling physical systems — manufacturing, energy, water, logistics. Historically air-gapped from IT networks, OT environments are now increasingly connected. In 2026, pro-Russia threat groups are actively targeting UK critical infrastructure OT systems for disruption, with 80% of UK manufacturers hit in the past year.

How is OT cyber security different from enterprise IT security?

OT systems prioritise availability and safety over confidentiality — the opposite of IT security. Legacy systems cannot be patched using standard enterprise tools. Network segmentation, asset inventory, and vendor access management require OT-specific approaches. A security failure in OT can cause physical damage, not just data loss.

What does the UK Cyber Security and Resilience Bill require from CISOs?

The Bill, expected to receive Royal Assent in late 2026, shortens mandatory incident reporting to 24 hours, expands scope to managed service providers and data centre operators, and introduces tiered OT incident classification. CISOs must redesign incident response playbooks and reporting processes before the Bill takes effect.

Which sectors are most at risk from OT cyber attacks in the UK?

The NCSC specifically identifies energy, water, transport, and manufacturing as high-risk sectors for state-sponsored OT attacks. Dragos’s 2026 report shows 80% of UK manufacturers experienced at least one cyber attack in the past year. Professional services and logistics firms with OT dependencies in their supply chains also face elevated risk.

Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.

Similar Posts