Full Report
New guidance is the first content authored by the Industrial Control System COI to appear on ncsc.gov.uk.
Analysis Summary
# Regulation/Compliance: NCSC Secure Connectivity Principles (Water Sector Implementation)
## Overview
This guidance provides a practical application of the NCSC’s **Secure Connectivity Principles for Operational Technology (OT)**. It uses a fictional water utility ("Admin Corp Water") to demonstrate how Critical National Infrastructure (CNI) providers should design, secure, and operate the boundaries between OT and external networks. The focus is on standardizing digital connectivity while maintaining safety and reliability in legacy environments.
## Key Details
- **Issuing Authority:** National Cyber Security Centre (NCSC) in collaboration with the Industrial Control Systems Community of Interest (ICS-COI).
- **Effective Date:** Published August 11, 2026.
- **Jurisdiction:** United Kingdom; Critical National Infrastructure (CNI).
- **Status:** Final Guidance / Best Practice Framework.
## Requirements
### Mandatory Requirements
*Note: As this is NCSC guidance, it supports statutory obligations under the NIS (Network and Information Systems) Regulations but serves as a framework rather than a standalone law.*
1. **Risk-Informed Decision Making:** Organizations must align architectural choices with their specific threat landscape and regulatory obligations.
2. **Boundary Protection:** Implementation of secure gateways between OT and external/corporate networks.
3. **Asset Management:** Understanding the OT environment as a prerequisite for secure connectivity.
### Recommended Practices
1. **Principle-Based Design:** Use the eight secure connectivity principles as a "target state" for architecture.
2. **Centralized Connectivity:** Consolidate external connections to reduce the attack surface.
3. **Legacy Protocol Management:** Implement specific controls to wrap or tunnel insecure legacy protocols.
4. **Exposure Reduction:** Minimize the visibility of OT systems to the public internet.
## Affected Organizations
- **Industries:** Water and Wastewater, Energy, Transportation, and other OT-heavy CNI sectors.
- **Organization Size:** Primarily Large Organizations and Public Sector entities.
- **Geographic Scope:** United Kingdom (applicable globally as a best-practice framework).
## Compliance Timeline
- **April 2026:** NCSC publishes guidance on OT environment visibility.
- **August 11, 2026:** Publication of the Water Sector worked example for Secure Connectivity.
- **Ongoing:** Organizations are encouraged to adopt these principles immediately to build long-term cyber resilience against increasing edge-device threats.
## Implementation Guidance
### Assessment Phase
- **Inventory Audit:** Identify all internet-exposed systems and edge devices.
- **Gap Analysis:** Compare current OT boundary architectures against the eight NCSC Secure Connectivity Principles.
### Implementation Phase
- **Architectural Design:** Define a "target state" architecture based on the Admin Corp Water example.
- **Legacy Mitigation:** Apply security overlays to legacy infrastructure that cannot support modern protocols.
- **Governance:** Establish operational practices for managing third-party access and remote connectivity.
### Validation Phase
- **Technical Validation:** Use the ICS-COI Boundary Expert Group’s model to validate technical approaches against the principles.
- **Incident Preparedness:** Test the ability to maintain safety and reliability during a simulated connectivity breach.
## Technical Requirements
- **Secure Boundary Controls:** Use of unidirectional gateways or highly restricted firewalls.
- **Protocol Filtering:** Inspecting and filtering OT-specific traffic.
- **Standardized Digital Connectivity:** Moving away from ad-hoc remote access toward centralized, monitored gateways.
## Penalties & Enforcement
- **Fines:** While this guidance is not a law, failure to secure OT systems can lead to fines under **NIS Regulations** (up to £17 million in the UK for serious domestic disruption).
- **Other Consequences:** Operational downtime, loss of public trust, and potential safety hazards in water treatment/distribution.
- **Enforcement:** Monitored by relevant sector regulators (e.g., Ofwat) using the **Cyber Assessment Framework (CAF)**.
## Related Standards
- **NCSC Cyber Assessment Framework (CAF):** The principles map directly to CAF objectives regarding network security.
- **NIS Regulations:** This guidance serves as a pathway to meeting legal requirements for "Operators of Essential Services."
- **NIST 800-82:** Aligning with international standards for ICS security.
## Resources
- **Official Documentation:** [https://www.ncsc.gov.uk/collection/operational-technology/secure-connectivity]
- **Water Sector Example:** [https://www.ncsc.gov.uk/collection/operational-technology/worked-examples/secure-connectivity-water-sector-example]
- **PDF Version:** [https://www.ncsc.gov.uk/sites/default/files/2026-08/Water-sector-example-added-to-the-NCSC%E2%80%99s-Secure-connectivity-principles.pdf]
## Practical Recommendations
- **Immediate Action:** Review all internet-facing OT edge devices for avoidable vulnerabilities.
- **Cross-Functional Collaboration:** Ensure OT engineers and IT security architects jointly review the "Admin Corp Water" example.
- **Phased Migration:** Do not attempt to re-architect all legacy systems at once; prioritize boundaries with the highest risk exposure.