Cookie Consent by Free Privacy Policy Generator

NCSC Publishes Water Sector Guidance on Secure Connectivity

The NCSC has added a water sector example to its Secure Connectivity Principles guidance, providing practical advice on securing operational technology networks in water and wastewater environments. Published on 11 August 2026, this is the first content authored by the Industrial Control System Community of Interest to appear on ncsc.gov.uk, reflecting ongoing collaboration between the NCSC and critical infrastructure operators to develop sector-specific security guidance that organisations can apply directly to their operational environments.

Why this matters for UK organisations

Water sector organisations face particular challenges around legacy systems, remote monitoring requirements and the operational impact of connectivity decisions. The NCSC's sector-specific approach helps translate broader security principles into practical steps that reflect the realities of operational technology environments, including the need to balance security, safety and operational continuity. The guidance addresses connectivity between corporate IT systems, industrial control systems and third-party remote access, areas where security decisions have direct operational consequences. For UK water companies and other critical infrastructure operators, this provides a clear reference point for reviewing how operational networks are segmented, monitored and connected to external systems.

What to review

For UK organisations operating industrial control systems, particularly in water, energy, manufacturing or transport, this is a prompt to review how secure connectivity principles are applied across operational networks. Consider whether network segmentation, remote access controls and monitoring capabilities reflect current NCSC guidance. Review whether operational technology security responsibilities are clearly assigned and understood across IT, engineering and operational teams, and whether security decisions account for the operational, safety and regulatory context of industrial control systems. Ensure that third-party remote access to operational networks is governed, monitored and regularly reviewed, and that connectivity decisions are documented and understood by those responsible for operational resilience.

Source: NCSC UK

News and blog posts
The North Korean threat actor known as Lazarus Group has exploited a Windows...
Israeli cybersecurity firm Dream has reported observing what appears to be the...
Today's brief highlights practical developments across governance,...
The NCSC has added a water sector example to its Secure Connectivity Principles...