Three NCSC warnings about internet-exposed edge devices have landed in five months. That should have moved the needle. It probably has not. The latest, published on 27 August, describes the same pattern as the last two. Routers, firewalls and industrial control interfaces sit open to the internet, often on default settings. Attackers walk straight in. At some point this stops being a technical problem. It becomes an accountability one.

Table of Contents
Internet-exposed edge devices: a pattern that is not subtle
Start with September 2025. The NCSC warned that a threat actor was targeting Cisco ASA 5500-X appliances. It used new malware, RayInitiator and LINE VIPER, and some of the affected devices were approaching end of support. The advice was simple: patch, and where a device could not be patched, replace it.
Then came July 2026. The NCSC and eighteen partner agencies from twelve countries named a culprit: the Russian FSB’s Centre 16, also known as Berserk Bear and Static Tundra. The group had sustained a campaign of router exploitation. It relied on default or weak SNMP credentials, legacy protocol versions, and unpatched Cisco Smart Install flaws. NCSC director Jonathon Ellison urged organisations to act “immediately”. A UK assurance firm’s own scans, published shortly after, found the same failures again and again: default passwords, exposed management interfaces, stale firmware.
Now the August advisory arrives. It warns that operational technology and other internet-facing systems keep getting exposed through misconfiguration and neglect, not sophisticated attack techniques. The NCSC’s own words are worth sitting with: organisations should not assume their OT is inaccessible from the internet without checking.
None of this needs a nation-state to exploit
What stands out across all three advisories is how unglamorous the failures are. Nobody needed a zero-day. They needed a router still running its factory password. Or a management port left open because closing it might break something nobody could explain. Or a firewall two firmware versions behind, because the maintenance window kept getting pushed back.
This is precisely the kind of finding a penetration test surfaces on day one of external reconnaissance. It is also the kind of finding that keeps recurring on repeat engagements, because the fix gets logged as a ticket and the ticket gets deprioritised. The attackers are not outsmarting anyone. They are checking the same things testers check, and finding them unfixed.
Why the advice on internet-exposed edge devices keeps not landing
The NCSC’s recommendations amount to basic vulnerability management, not novel defence. Inventory what faces the internet. Kill default credentials. Retire unsupported hardware. Disable legacy management protocols. Segment OT from business networks. None of it needs new budget so much as it needs ownership. Somebody has to know what the business exposes to the internet. Somebody has to act when a scan or a test flags a default password six months running.
That ownership gap is where these warnings keep landing and bouncing off. A board can read “install multi-factor authentication” and nod along, and nobody actually does it, because no single person owns the outcome. The organisations that stop appearing in these advisories tend to be the ones that assigned that ownership explicitly. Then they checked the work with an independent test, rather than trusting the ticket got closed.
There is a budget argument hiding in plain sight too. Chasing default credentials and unpatched firmware costs far less than the incident response, regulatory notification and reputational cleanup that follow a breach through an exposed edge device. Treating this as a hygiene task rather than a security project might be exactly why it keeps sliding down the list. Nobody budgets for hygiene the way they budget for a new firewall.
What should actually change
If your business has not had an external attack surface review in the past year, that is the gap these three advisories describe. This is not a lack of awareness, and it is not a lack of guidance. It is a lack of anyone checking whether last year’s fix on internet-exposed edge devices is still in place. Devices drift back to defaults. Firmware falls behind again. New kit gets added to the network, and nobody updates the inventory.
The NCSC will likely publish a fourth version of this same warning before the year is out, naming a different vendor but describing the same causes. Businesses that want to avoid the affected group next time should treat that as the prediction it is. Go and check what is actually exposed, rather than waiting for the next advisory to say so.
That check does not need to wait for a formal audit cycle. A short, scoped external test against the public-facing estate answers the question directly. What is reachable, and what still runs on default settings? More to the point, what would an attacker find in the first hour? Businesses that run that check regularly are the ones who read the next advisory about internet-exposed edge devices and can say, honestly, that they are already covered.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.