Jessica Entwistle
August 28 2026
The National Cyber Security Centre has published new guidance highlighting the risk from internet-exposed systems and edge devices following recent disruptive cyber activity. The NCSC reports that attackers are continuing to exploit vulnerabilities in perimeter infrastructure, including VPNs, firewalls, routers and other edge devices that sit at the boundary of organisational networks. The advisory does not name specific incidents but emphasises that many compromises begin with unpatched or misconfigured devices that are directly accessible from the internet. The NCSC is urging organisations to review their external attack surface, ensure edge devices are patched promptly, and consider whether systems need to be internet-facing at all.
Edge devices are often managed separately from core IT infrastructure, patched less frequently, and may run firmware that organisations are unaware is outdated or vulnerable. Attackers routinely scan the internet for exposed management interfaces, unpatched VPN appliances and misconfigured remote access tools. Once an edge device is compromised, it provides a foothold into the internal network, often with privileged access. The operational risk is that these devices are easy to overlook during routine security reviews, yet they represent one of the most common initial access vectors in serious incidents. Many organisations discover during incident response that edge infrastructure was not included in their patch management process, that default credentials were never changed, or that devices were left internet-accessible when they did not need to be.
Organisations should audit their external attack surface and identify all internet-exposed edge devices, including VPNs, firewalls, routers and remote access appliances. Review who is responsible for patching these devices and ensure they are included in your patch management process with the same discipline as servers and endpoints. Consider whether each device genuinely needs to be accessible from the internet or whether access can be restricted to specific IP ranges or removed entirely. Check that default credentials have been changed, that management interfaces are not publicly accessible, and that logging is enabled so that suspicious activity can be detected. This is also a sensible time to review your external vulnerability scanning processes and ensure that edge devices are included in regular security assessments.
Source: NCSC UK