NCSC assesses threat to enterprise connected devices
NCSC warns that the growing adoption of Enterprise Connected Devices (ECDs) expands organisations' attack surface, enabling espionage, lateral movement, ransomware and botnet abuse.
This NCSC assessment, produced with DCMS, evaluates the cyber security threat posed by Enterprise Connected Devices (ECDs) — a broad category spanning end-user devices, enterprise IoT, and distinct enterprise devices such as printers, cameras, VoIP systems and video conferencing equipment. The paper judges it highly likely that ECDs represent an expanding attack surface due to weak vendor security, internet exposure, and their use as pivot points for accessing corporate networks. It draws on multiple case studies to illustrate real-world impact, including exploitation of an unauthenticated VoIP vulnerability (CVE-2019-19006) against ~1,200 organisations, a casino breach via a compromised smart fish tank, the VPNFilter router/NAS botnet, Mirai-based DDoS botnets, LG smart TV ransomware (FLocker), and the Ripple20 supply-chain vulnerabilities affecting the Treck IP stack used across millions of devices.
The report highlights three main threat-actor categories: nation-state actors conducting espionage (citing Russian APT28/STRONTIUM compromising IoT devices like VOIP phones, printers and video decoders across multiple sectors), cybercriminals seeking financial gain via ransomware and DDoS-for-hire, and hacktivist/state-linked groups such as the Russian collective 'Digital Revolution', which leaked documents describing an FSB-linked project to build a Mirai-inspired IoT botnet targeting CCTV and NVR devices. Supply-chain risk is also flagged, referencing NotPetya and SolarWinds as precedent nation-state supply-chain compromises relevant to the ECD ecosystem.
Overall, this is a strategic threat-landscape and awareness paper rather than an incident report — it aggregates known case studies and vulnerabilities to inform organisational risk assessment and supports NCSC/DCMS's Device Security Principles framework. No new indicators of compromise or previously unreported incidents are disclosed; the value is in synthesis and guidance for enterprises deploying IoT/ECD technology.
Mentioned in this report
Source reporting: https://www.ncsc.gov.uk/report/organisational-use-of-enterprise-connected-devices
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free