Cyber Essentials

A joint advisory from the National Cyber Security Centre and international partners, published on 13 July 2026, describes state-backed hackers exploiting poorly configured routers and firewalls, the third such warning in four months. Jonathan Krause, founder of Forensic Control and a former New Scotland Yard investigator, explains what is going wrong on these devices and what the Cyber Essentials Firewalls control requires to close the gap.
By Jonathan Krause | Founder, Forensic Control | 24 July 2026
On 13 July 2026, the National Cyber Security Centre (NCSC) and the United States’ Cybersecurity and Infrastructure Security Agency (CISA) issued a joint advisory warning that state-sponsored hackers are actively exploiting routers, firewalls and Virtual Private Network (VPN) gateways left with weak credentials, outdated firmware and thin logging. If your organisation has an internet-facing firewall or router, and nearly every organisation does, this advisory is describing your equipment, not just someone else’s. The Cyber Essentials Firewalls control exists precisely to close the gaps these attackers are exploiting, and it is worth checking your own setup against it before you read any further.
The 13 July advisory attributes this activity to FSB Centre 16, the Russian intelligence unit also tracked as Static Tundra, Berserk Bear and Energetic Bear, and names communications, defence, energy, financial services, government and healthcare organisations as particular targets. That sector list describes who NCSC is warning loudest, not the limit of who is exposed. A compromised router is valuable to an attacker chiefly as infrastructure, somewhere to route traffic through or a base from which to reach the next target, and infrastructure of that kind does not care what sector its host organisation sits in.
The advisory is specific about the mechanism. FSB Centre 16 has been exploiting default or weak Simple Network Management Protocol (SNMP) passwords and community strings, legacy SNMP versions left switched on, and Cisco’s Smart Install feature, often left enabled long after initial setup. The same advisory recommends organisations obtain Cyber Essentials certification and use NCSC’s Cyber Assessment Framework to check their own security maturity, the agency issuing the warning pointing readers at a certification your business may already hold.
This is not an isolated warning either. In June, the NCSC issued a separate alert after a database of credentials taken from FortiGate firewalls and VPN gateways was leaked online, the result of brute-force, dictionary and credential stuffing attempts against internet-facing management portals. In April, the NCSC and CISA jointly flagged Firestarter, a backdoor embedded in Cisco Firepower, Secure Firewall and Adaptive Security Appliance (ASA) devices, built to survive reboots and firmware updates. Three advisories inside four months, against three different vendors, is the shape of a trend rather than a single incident. We covered state-linked router hijacking in more detail after an earlier NCSC advisory on APT28; this year’s advisories describe the same class of target, different attackers and vendors.
In the external vulnerability scans I run as part of Cyber Essentials Plus assessments (the version of the certification that adds hands-on technical verification to the standard self-assessment), the router or firewall sitting at the edge of the network is, in the majority of cases, running firmware at least one release behind current, and SNMP or a management interface is often still reachable from the open internet. The organisations this turns up in rarely think of themselves as a target, which is exactly what makes them useful to the kind of activity the 13 July advisory describes.
The advisories differ in the specific mechanism, SNMP misconfiguration, leaked VPN credentials, embedded malware, but not in the underlying pattern. The administrative password or SNMP community string on the device is often still the one it shipped with, or was changed once, years ago, and left untouched since.
The device’s management interface, or a legacy protocol like SNMP, is reachable from the public internet rather than restricted to an internal network or a specific allow-listed address. The firmware, the software running the device itself, has a security update sitting unapplied because nobody owns the job of checking for one.
These three failures do not need a sophisticated attacker to exploit, only someone who knows where to look, and the advisories from April, June and July between them confirm that state-sponsored groups and opportunistic credential-stuffing operations know where to find it.
Cyber Essentials is built around five technical controls, and Firewalls is one of the two most directly relevant to what these advisories describe, the other being Security Update Management, the patching control. The Firewalls control requires a boundary firewall, or an equivalent device, on every internet connection into your network, with the default administrative password changed to something unique, unauthenticated inbound connections blocked by default, and any opened inbound rule documented, justified and reviewed regularly rather than left in place indefinitely.
The 13 July advisory points organisations toward Cyber Essentials Plus and NCSC’s Cyber Assessment Framework as ways to check their own maturity against this. Cyber Essentials Plus adds independent technical verification, including external vulnerability scanning of your internet-facing systems, on top of the self-assessment questionnaire that base certification relies on, which is why an external scan catches a firmware version six months out of date or an exposed management interface that a self-assessment answer of ‘yes, configured correctly’ does not.
Three things are worth checking against your own estate this week. First, log into the administrative interface of your boundary firewall or router, commonly a FortiGate, Cisco or SonicWall unit, and confirm the admin password or SNMP community string is not the manufacturer default and has been changed within the last twelve months. Second, check whether that interface, or SNMP itself if still switched on, is reachable from the public internet; most vendors publish a guide to testing this, or ask whoever manages the device to confirm it today. Third, compare the device’s firmware version against the vendor’s current release notes. More than two versions behind is an unpatched gap of the kind these advisories describe attackers exploiting.
How common is this at the point of first certification? I do not need my own caseload to make the point here; the government’s own figures do it for me. The most recent Cyber Security Breaches Survey, run by the Department for Science, Innovation and Technology (DSIT) working with NCSC, found that 74 per cent of UK businesses currently have a firewall in place. That leaves roughly a quarter without one, and it is a reasonable bet that most first-time Cyber Essentials applicants sit in that gap rather than outside it. Certification is often the first point at which anyone has systematically checked the configuration at all.
What ties this year’s three advisories together is not a new attack technique but old equipment that nobody has checked in a long time, which is a far more ordinary problem to fix than the sophistication of the attackers might suggest. If your firewall or router has not had its firmware, its credentials and its exposed interfaces checked in the last twelve months, that is the gap worth closing before your next Cyber Essentials renewal, not after.
The Firewalls control is one of five technical requirements in the UK’s Cyber Essentials certification scheme. It requires every internet connection into an organisation’s network to sit behind a boundary firewall or equivalent device, with the default administrative password changed, unauthenticated inbound connections blocked by default, and any opened inbound rule documented and reviewed regularly. It applies to office networks, cloud services with their own firewall settings, and increasingly to home working setups, wherever the boundary between the internet and the organisation’s systems actually sits.
Three separate advisories from the National Cyber Security Centre (NCSC), working with international partners, between April and July 2026 describe routers, firewalls and Virtual Private Network (VPN) gateways being targeted through weak credentials, legacy management protocols such as the Simple Network Management Protocol (SNMP), and outdated firmware. These devices sit at the edge of an organisation’s network, so a successful compromise gives an attacker a foothold, a route for traffic, or infrastructure for wider activity, without needing to break through anything else first.
Base Cyber Essentials certification relies on a self-assessment questionnaire, so an organisation answers questions about its own firewall configuration. Cyber Essentials Plus adds independent technical verification, including external vulnerability scanning of internet-facing systems such as the boundary firewall, so an assessor rather than the organisation confirms the configuration and firmware are actually as described.
Log into the firewall or router’s administrative interface using the credentials currently in use and check them against the manufacturer’s documented defaults, which most vendors publish, and which older devices sometimes still display on a label on the unit itself. If nobody can confirm with certainty when the password was last changed, or by whom, treat that as a sign it needs changing now, along with a record of who holds it and when it was last rotated.
Yes. The Firestarter malware identified by the Cybersecurity and Infrastructure Security Agency (CISA) and the NCSC in April 2026 was specifically built to survive firmware updates and device reboots once it had already gained access, which is why the advisory recommends checking for indicators of existing compromise rather than assuming a current firmware version rules one out. Firmware currency closes the door an attacker would otherwise walk through; it does not automatically evict one who is already inside.
Start with the three checks that need no specialist tooling: confirm the administrative password or management protocol credentials on your boundary firewall or router are not a manufacturer default, confirm the administrative interface is not reachable from the public internet, and compare your firmware version against the vendor’s current release. An IT support provider or managed service provider can usually confirm all three within an hour if asked directly, and a Cyber Essentials assessment tests for these same three things.
Safeguard your business with our expert cyber security solutions. Whether you require digital forensics, penetration testing or proactive security assessments, our team is ready to assist. Contact us today to discuss your security needs and take the first step towards a more secure future.