The National Cyber Security Centre has issued a fresh warning about attackers targeting internet-exposed systems and “edge devices” — the routers, VPN gateways and firewalls that sit at the boundary between your business and the internet. The advisory follows international guidance published in July flagging poorly configured routers as an active attack route, and the NCSC is clear that this isn’t just a problem for critical infrastructure and industrial operators. Ordinary businesses are being caught by the same pattern.

The core issue is unintended exposure. Many organisations assume their internal systems and management interfaces aren’t reachable from the internet — until someone checks. Misconfigurations, forgotten remote-access connections, and devices nobody has audited in years quietly open a door that attackers are actively scanning for. If you’ve never asked “what does our network actually expose to the internet?”, now is a good time to ask it.

Why this matters even if you’re not “critical infrastructure”

It’s easy to read NCSC advisories and assume they’re written for power companies and hospitals. But the edge devices being exploited here — off-the-shelf routers, VPN appliances, firewall management interfaces — are exactly what a typical UK SME runs its internet connection through. Attackers don’t need to know who you are; automated scanning finds exposed, unpatched, or default-configured devices regardless of company size, and a compromised edge device gives an attacker a foothold straight past your other defences.

What the NCSC recommends — and how to actually do it

The advisory sets out a practical checklist, and most of it is achievable without specialist tools:

  • Build a real inventory. List every device with an internet-facing interface — routers, VPN gateways, firewalls, remote access tools. If your IT provider can’t produce this list in an afternoon, that’s itself a warning sign.
  • Kill unnecessary public access. Management interfaces for these devices should never be reachable from the open internet. If a supplier set one up for convenience years ago, close it.
  • Replace default credentials. Still the single most common way these devices get compromised. Check every device, not just the ones you remember setting up.
  • Patch and segment. Keep firmware current, and make sure a compromised edge device can’t reach your core systems — a flat network turns one weak router into a breach of everything.

For most SMEs, this is exactly the kind of audit that’s easy to postpone indefinitely because nothing has gone wrong yet. That’s the trap. If you don’t have the in-house expertise to run this check properly, CoolCoding can help with the technical implementation side — auditing what’s exposed and locking it down — while a service like KeepSafe gives you ongoing monitoring so you’re not relying on noticing a breach yourself weeks after it happens.

The takeaway

You don’t need to be a critical infrastructure operator to be a target — you just need an exposed, unpatched, or default-configured device sitting on the internet. Spend an hour this week finding out exactly what your business exposes to the outside world, close what doesn’t need to be open, and change any credentials that have never been touched. It’s a small task next to the cost of finding out the hard way.