Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What should critical infrastructure teams do first when…
Cyber Security

What should critical infrastructure teams do first when legacy internet-facing devices cannot be fully secured?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Cyber Security

Start with a complete inventory of exposed routers, cameras, and other embedded devices, then identify which ones are past end of life or no longer receive security updates. Prioritise removal, replacement, or isolation of those assets because they create persistent footholds. If they must remain temporarily, restrict access, segment them tightly, and monitor for unusual remote administration activity.

Why the First Move Is Inventory, Not Hardening

When a legacy device cannot be fully secured, the first question is not how to harden it further, but whether you know exactly what is exposed. A complete inventory of internet-facing routers, cameras, and embedded systems gives teams the scope to sort devices by business function, support status, and exposure before they spend effort on controls that may not meaningfully reduce risk.

An inventory also distinguishes manageable risk from structural risk. Devices that are still supported can sometimes be tightened, while those that are past end of life usually need removal, replacement, or strict isolation because there is no realistic path to full remediation.

How to Decide Which Legacy Devices Can Stay Temporarily

The practical test is whether the device can be reduced to a bounded exception with a clear expiry date. If it can, isolate it from general access, limit remote administration to known paths, and place it on tightly segmented network zones so it cannot become a broad foothold.

If a device cannot be segmented, monitored, or controlled in a way that aligns with its exposure, treat it as a replacement or retirement candidate rather than an accepted exception. In critical infrastructure, “temporary” support for exposed legacy assets tends to become permanent unless ownership, timelines, and replacement funding are explicit.

For teams that need a real-world reminder of why exposed remote access and dormant legacy assets matter, the Colonial Pipeline ransomware attack shows how a single stale access path can create outsized operational impact.

What Good Containment Looks Like in Practice

Good containment is not just “put it behind a firewall.” It means the device is discoverable, owner-assigned, and limited to the smallest viable trust zone. Remote administration should be constrained to approved management hosts, with logging strong enough to spot unusual login times, failed attempts, configuration changes, or traffic patterns that suggest misuse.

Teams should also separate devices by criticality. A vulnerable camera on a low-value segment is not the same problem as a remotely reachable controller, modem, or router sitting on a path to operational systems. The containment choice should match the blast radius of the device, not the convenience of the administrator.

Risk and Threat Considerations

Legacy internet-facing devices are attractive because they are often unmanaged, unsupported, and reachable from outside the trust boundary. Attackers look for exactly this mix when they want a persistent foothold, especially in environments where remote administration is old, weakly monitored, or shared across multiple assets.

Failure mechanism: The device remains exposed after support has ended, or remains reachable through broad access paths, so compromise can persist even after perimeter controls are added elsewhere.

Impact: The device can become a stable entry point for intrusion, lateral movement, or operational disruption, and in critical infrastructure that can translate into service outage or wider safety consequences.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.AM-01 — Physical devices and systems inventoryExposed legacy devices must first be inventoried to understand scope and exposure.
PR.AA-05 — Least privilegeTemporary containment depends on limiting who can administer exposed devices.
Recommendation — Maintain a current inventory of exposed devices and classify unsupported assets for removal or isolation. Restrict remote administration to the minimum set of approved management paths and users.
CIS Controls v8CIS-12 — Network Infrastructure ManagementLegacy routers and other internet-facing devices are governed through network-device management and segmentation.
Recommendation — Segment legacy network devices and track their configuration, ownership, and exposure.
ISO/IEC 27001:2022A.8.9 — Configuration managementUnsupported devices require controlled configuration and isolation to reduce attack surface.
Recommendation — Apply controlled configuration baselines and isolate devices that cannot be fully secured.

Practitioner Guidance

What to prioritise: Start with a verified inventory of every exposed device, then flag anything past end of life or missing vendor support as a high-priority removal or isolation candidate. If the team cannot name the owner and the exposure path, it is not ready to be trusted.

Decision rule: If the device can be replaced quickly, replace it; if not, isolate it so tightly that compromise cannot spread and remote administration is limited to a known management path. If neither is possible, treat the device as an urgent risk exception that needs executive ownership.

What to verify: Confirm that monitoring is actually alerting on remote admin activity, not just collecting logs, and check that the segment boundaries still block direct access from user networks and the public internet.

Practitioner takeaway: The right first move is not to “secure the insecure device,” but to reduce uncertainty, shrink exposure, and decide quickly whether the asset deserves continued life at all.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org