OT Security
Enterprise Connected Devices
Enterprise connected devices now underpin physical security, operational technology and digital infrastructure across UK organisations. This briefing examines how government policy from DSIT aligns with technical guidance from NCSC, NPSA and NACE, highlighting overlaps, tensions and practical implications for DFIR teams responsible for investigation, resilience and evidence preservation across increasingly converged cyber-physical environments within modern enterprise security and incident response.
NEWS ROUNDUP – 8th April 2026
CISA, FBI and NSA warned that Iranian-linked actors are targeting internet-connected PLCs in U.S. critical infrastructure, while a Massachusetts hospital diverted ambulances after a cyberattack. Investigators tracked cloud data theft to abused authentication tokens after a SaaS integrator breach, and the DOJ disrupted a GRU-linked DNS hijacking botnet as NIST advanced an AI risk profile for critical infrastructure operators broadly.
NEWS ROUNDUP – 20th February 2026
Attackers are cutting response windows: Unit 42 cites cases reaching data exfiltration in 72 minutes. Figure Technology Solutions confirmed a breach tied to leaked user records, while Meriden, Connecticut reported ransomware disruption. Mandiant warned of active exploitation of a Dell RecoverPoint for VMs zero-day, and the UK ICO prevailed in the DSG Retail appeal, sharpening expectations for “appropriate security” practice.
NEWS ROUNDUP – 18th February 2026
China-linked actors exploited a Dell RecoverPoint zero-day for 18 months, while CISA added an actively exploited Chrome flaw to its KEV catalog. Australia’s YouX faced a major data-leak claim, and passport scans from Abu Dhabi Finance Week were exposed via a vendor server. Police arrested a Phobos ransomware suspect in Poland, as the UK launched a business cyber-hygiene campaign nationwide.
NEWS ROUNDUP – 13th February 2026
Over the past 48 hours, CISA added four exploited vulnerabilities to the KEV catalog and issued an ICS advisory on Siemens SINEC NMS. Odido confirmed a customer data leak, while SmarterTools disclosed ransomware after an auth-bypass on an unpatched VM. Researchers flagged active exploitation of a critical BeyondTrust RCE and reported nation-state use of Google Gemini for campaigns this week.

