The Router Nobody Audits: When the State Walks Past Your Firewall
On 13 July 2026, nineteen national cyber agencies across thirteen countries put their names to a single warning. The United States National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation led it. The United Kingdom's National Cyber Security Centre co-signed, and so did New Zealand's own National Cyber Security Centre, alongside agencies from Australia, Canada, France, Estonia, Finland, Italy, Poland, Sweden, the Czech Republic, and Denmark. The advisory, catalogued as AA26-194A, carries a title that sounds almost mundane: improve router hygiene to protect against Russian state-sponsored targeting.
Read past the title and the mundane part disappears. The advisory attributes a years-long campaign against critical infrastructure to FSB Center 16, the signals-intelligence branch of Russia's Federal Security Service. The sectors it names are communications, the Defense Industrial Base, energy, financial services, government, and healthcare. And the way in was not a defeated firewall or a bypassed endpoint-detection platform. It was the edge router: the device that sits at the boundary of almost every network, that carries no dashboard any executive ever sees, and that almost no governance framework asks a single question about.
The last two instalments of this cycle asked what happens when a board under-governs a frontier artificial intelligence model. This one asks a plainer question, and a much older one. What happens when nobody has looked at the router in the server cupboard since the day it was installed?
A nineteen-agency warning about a fifteen-year-old door
The scale of the coalition is the first thing worth sitting with. Nineteen agencies across thirteen countries is among the broadest international cyber advisories this series has covered. That breadth is itself the signal. A coordinated, cross-continental statement is not issued about a niche technical curiosity. It is issued when a specific, well-understood technique is still working against critical infrastructure worldwide, and the agencies that watch that infrastructure have decided the quiet approach is no longer enough.
The National Cyber Security Centre of the United Kingdom put it plainly through its director of resilience and future technology, who described the joint advisory as decisive, actionable direction from the global security community that network defenders should implement. Note the word defenders. This is guidance aimed not at spies but at the people who run ordinary corporate and infrastructure networks, because that is where the exposed devices are.
FSB Center 16 is tracked across the security industry under a shelf of different names, depending on which vendor first mapped the activity: Berserk Bear, Energetic Bear, Dragonfly, Crouching Yeti, Ghost Blizzard, and, in Cisco's own naming, Static Tundra. The multiplicity of names matters less than the single fact underneath them. This is one long-running state intelligence operation, and it has been walking through the same door for years.
The technique nobody was watching
Here is the part that should stop a board in its tracks, because there is nothing exotic in it. The actors scan the open internet for routers running the Simple Network Management Protocol, known as SNMP, with default or common community strings. A community string is, in effect, a password for reading and writing a device's configuration, and on a great many routers it has never been changed from the value the manufacturer shipped. Once a reachable device is found, the actors send a spoofed instruction that tells the router to copy its own running configuration into a file. That file is then pulled off the device over the Trivial File Transfer Protocol, or TFTP, a transfer method that carries no encryption at all.
The advisory documents more than that one path. It describes exploitation of Cisco's Smart Install feature, a convenience function roughly fifteen years old that has been a known risk since at least 2018, and it names two specific vulnerabilities: CVE-2018-0171 and CVE-2008-4128. The second of those was assigned in 2008, seventeen years before this advisory was written. The recommended fixes are equally unglamorous. Move from the older SNMP versions to the authenticated SNMPv3, or switch SNMP off where it is not needed. Disable Cisco Smart Install where it is not actively required. Block TFTP, Smart Install, and SNMP at the network edge. Remove default and weak credentials.
None of this requires a frontier model. That contrast is the editorial point of this article, and it is deliberate. A state intelligence service reached critical infrastructure across a dozen countries using a protocol that predates most current board members' careers and a Cisco feature old enough to have a teenager's birth certificate. The threat that gets the headlines is the capable new model. The threat that gets in is the device that has worked quietly in the background for years, which is precisely why nobody has looked at it.
Poland, and the near-miss that proves the point
An advisory describing a technique is one thing. A recent, near-catastrophic instance of that technique is another, and this story has one. On 29 December 2025, coordinated attacks in Polish cyberspace struck more than thirty wind and photovoltaic farms, a manufacturing company, and a large combined heat and power plant that serves close to half a million customers. At the renewable-energy sites, the attack severed communication with the distribution system operators and stripped away remote supervisory control at the grid-connection layer. It did not stop the turbines and panels generating electricity. At the heat and power plant, the attackers tried to deploy wiper malware, custom-built destructive software, and it was blocked by the endpoint-detection platform the plant already had in place before it could execute.
One distinction has to be stated exactly, because getting it wrong would be both a factual error and an overstatement. The figure of close to half a million customers is the heat plant's customer base, not a count of people who lost power or heat. No source confirms an actual loss of supply to anyone. Poland's Prime Minister said the attack had been thwarted and that the system was never at risk. This was a near-miss, not a realised blackout, and it should be described as one.
The near-miss carries a governance lesson that outlasts the incident. The plant's defence did not hold because the initial access route was secure. It held because a later stage of the attack, the destructive payload, ran into detection software downstream of wherever the attackers first got in. A tested control at the point of execution contained a failure that had already occurred earlier, upstream, and invisibly. That is the Hour-Zero Protocol from the Cyber Guide working as designed: preparation that pays off not for the incident you expected, but for the one that begins somewhere you were not watching.
There is a second lesson in how the attribution unfolded, and it is one boards routinely misread. Poland's own national computer emergency response team, CERT Polska, published its incident report on 30 January 2026. That report identified the attacker only by the overlap of its infrastructure and technique with previously documented clusters, the Static Tundra and Berserk Bear and Ghost Blizzard and Dragonfly names. It did not name Russia, and it did not name the FSB. The formal, government-to-government attribution to FSB Center 16 came almost six months later, on 13 July 2026. Technical confidence about who did something and public willingness to say so on the record run on two different clocks. A board that expects a fast, public naming of an attacker, even where private technical certainty exists early, is planning against the wrong timeline.
Sanctions, and a campaign measured in years
The router advisory did not surface alone. On the same day, the United Kingdom and the European Union imposed their first coordinated joint cyber-sanctions package, designating more than thirty individuals and entities in total connected to Russian cyber operations, and formally attributing the December 2025 Poland attack to FSB Center 16. The two actions are two halves of one story: the technique, described in the advisory, and its named, sanctioned consequence.
The reporting around the sanctions places this campaign in its proper time frame. FSB Center 16's attributed targeting reaches back more than fifteen years and across multiple European states. This is not an isolated intrusion or an opportunistic smash-and-grab. It is a sustained, patient programme of access to critical infrastructure, run by a national intelligence service, using techniques cheap and durable enough to keep working for a decade and a half. For a director, the sanctions are not the reassurance they might first appear to be. They confirm that the activity was real, serious, and long-running, and that the exposed device class the advisory describes is the same one sitting in your own network.
New Zealand: co-signed, and warned already
New Zealand's place in this story is precise, and it is important to state it precisely rather than let an overseas incident imply a domestic one. No source ties any specific New Zealand organisation, network, or breach to FSB Center 16 activity. There is no confirmed New Zealand incident here. What there is, is exposure of exactly the same kind, and a national agency that has already said so.
Start with the co-signature. New Zealand's National Cyber Security Centre is named, by name, as one of the nineteen agencies behind AA26-194A. That the country appears through a single agency, rather than a separate computer emergency response team, is itself a recent structural fact: the National Cyber Security Centre and the former CERT NZ completed their integration on 23 July 2025, consolidating incident reporting for individuals, businesses, government, and critical-infrastructure operators into one point of contact. So when New Zealand signs an international advisory, it now signs with one voice.
The current threat picture gives that signature weight. The National Cyber Security Centre's Cyber Security Insights for the first quarter of 2026 recorded 5.6 million New Zealand dollars in direct financial losses across 1,164 incidents, a rise of seventy-six per cent on the previous quarter. Phishing and credential harvesting remained the most-reported attack method. None of that is router-specific, and it would be wrong to imply otherwise; it is the backdrop against which any edge-device exposure in this country should be read. It says the losses are real and climbing, and the boundary devices the advisory describes are present in every sector that suffered them.
Then there is the detail that sharpens the whole governance argument. AA26-194A is not the first time New Zealand's own cyber agency has warned about this exact class of device. On 5 February 2025, seventeen months earlier, the National Cyber Security Centre co-authored joint guidance with Australia, Canada, and the United Kingdom specifically on securing edge devices: routers, firewalls, virtual private network gateways, and internet-facing servers. The guidance was written for executives, managers, and practitioners alike, with vendor-agnostic hardening advice. Which means the governance failure this article describes is not the absence of a warning. The warning existed, in plain language, endorsed by New Zealand's own agency, for well over a year. The audit still did not happen.
The regulation that is coming, not here
There is a regulatory backdrop, and it needs to be handled with care about its status. The New Zealand Cyber Security Strategy 2026 to 2030, released by the Department of the Prime Minister and Cabinet in March 2026, proposes a tiered mandatory regime for critical infrastructure across seven essential services, including telecommunications and energy, the two sectors most directly in the frame of a router-hygiene advisory. At the most serious end of the proposed penalty regime, directors could face personal criminal liability of up to 100,000 New Zealand dollars for a serious breach and up to 500,000 for a critical one.
Every word of that is proposed, not enacted. Public consultation closed on 19 April 2026, and Cabinet is reviewing the feedback. I describe the proposal and its status; I make no forecast about whether or how quickly it becomes law, and I offer no view on whether the proposed penalties or scope are set at the right level. Those are decisions for the policy process, not for this article. The point that is safe to make, and worth making, is narrower: the direction of travel is towards personal director accountability for critical-infrastructure cyber resilience, and the edge router is a resilience question that sits squarely inside it.
What a board actually does with this
Strip the geopolitics away and a board is left with an unusually clean instrument. An international advisory, co-signed by its own national agency, has named a specific and cheap technique, named the sectors at risk, and published the exact fixes. In the language of the Cyber Guide, that is a Crisis Compass: a reading that tells a board which way the landscape has moved and what the next governance decision should be. Here the next decision is bounded, low-cost, and already within reach of an existing team.
The framework that does the real work is the Audit of Intent. Its claim is simple and unforgiving: governance failure lives in the gap between a control existing and that control having been tested against what it is actually supposed to do. Nearly every organisation in scope for this advisory has a firewall policy, an endpoint-detection platform, and an identity and access programme. Very few can say when the edge router's SNMP community string was last changed, or whether Cisco Smart Install is still switched on from a factory default that nobody revisited after installation. The router is not missing from the risk register because it is unimportant. It is missing because nobody was ever assigned to look at it. A device that has run without complaint for years is not evidence of good governance. It may only be evidence that nobody has checked.
Fiduciary Risk Exposure carries the same argument into the boardroom's own language. The Cyber Guide's position is that inadequate cyber governance can amount to a breach of a director's duty of care under section 137 of the Companies Act 1993. Across this cycle that argument has been applied to frontier artificial intelligence dependency. This article returns it to its plainest form. A director's duty of care extends to the infrastructure that is old, quiet, and easy to forget precisely because it works. Fiduciary Risk Exposure does not distinguish between a risk that is dramatic and a risk that is merely un-inspected.
There is a guardianship dimension too, and it is not decoration. The Kaitiakitanga Checklist in the Cyber Guide frames governance as active stewardship of the infrastructure and data an organisation holds in trust, not passive assumption that someone is looking after it. An edge router is exactly the kind of thing that checklist asks a board to steward deliberately. It sits at the boundary between the organisation and the wider network. It is the literal device through which every other digital asset held in trust must pass. Guardianship of that boundary is guardianship of everything behind it.
The advisory is also a clean case of what the Cyber Guide calls the Heaven Vector and the Skynet Vector, the same dynamic pointed in opposite directions. On the Skynet side, a state intelligence service achieves infrastructure access with a fifteen-year-old feature and a protocol most engineers assumed had been retired. On the Heaven side, nineteen agencies coordinate in the open, name the actor, publish exact indicators, and hand free, actionable mitigation to defenders everywhere. Collective, transparent disclosure can counter even the least sophisticated attack surface. But only if the organisations it reaches act on what it tells them.
Where open source sits
There is an open-source dimension here that boards tend to miss, and it is the reason the defensive knowledge is not the scarce part. The vulnerabilities the advisory names carry public identifiers, CVE-2018-0171 and CVE-2008-4128, catalogued in the open through the Common Vulnerabilities and Exposures programme, the shared naming system the whole industry reads. The protocols involved, the Simple Network Management Protocol and the Trivial File Transfer Protocol, are open published standards anyone can study. The weakness is documented in public, freely, for defender and attacker alike. The harder open-source lesson sits one layer down, in provenance. A software bill of materials, the SBOM, records what is actually inside the firmware on a device, and the XZ Utils backdoor of 2024 showed how a single under-resourced open-source component can carry a compromise into everything downstream of it. Transparency is available. Someone still has to read it.
What this means for sovereign capacity
The sovereignty reading follows directly. A device that copies its own configuration into an unauthenticated file and ships it over a protocol with no encryption is not only a corporate risk; it is the access layer of national infrastructure, and the advisory names the Defense Industrial Base alongside energy and communications among the sectors in scope. The reason a seventeen-year-old flaw still matters is institutional. The United States Cybersecurity and Infrastructure Security Agency, the CISA, keeps it in the Known Exploited Vulnerabilities catalogue, a public register of the flaws that state actors are actually using, so that a known weakness cannot be quietly forgotten. Nineteen agencies across thirteen countries co-signed one advisory naming a single state intelligence unit, with New Zealand's agency among them. Collective disclosure is the defence. It works only when the organisations it warns act on it.
The Cyber Guide's argument has always been that the least dramatic risk is the one most likely to be ungoverned. The edge router is the sharpest current proof of it. A nineteen-agency coalition, a fifteen-year-old feature, a seventeen-year-old flaw, and a technique that needs no artificial intelligence at all. The advisory has done the hard part. What it asks of a board is not alarm. It is an audit.
If someone asked your board this week when the edge router in your server cupboard last had its configuration reviewed, and who owns that answer, what would come back?
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance.
I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.
References
[1] National Cyber Security Centre (UK). "UK and allies urge critical sectors to improve defences against Russian intelligence targeting." 13 July 2026. https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting
[2] Cybersecurity and Infrastructure Security Agency. "Joint Cybersecurity Advisory AA26-194A: Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting." 13 July 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a
[3] Forbes. "FBI Issues Warning As Russia's FSB Center 16 Hackers Target Routers." 14 July 2026.
[4] TechTimes. "FSB Center 16 Exploited Default Router Passwords to Map Critical Infrastructure for Years." 13 July 2026.
[5] Nextgov/FCW. "CISA adds long-standing router flaw to Known Exploited Vulnerabilities catalogue as allies warn on Russian targeting." July 2026.
[6] CERT Polska. "Incident report: coordinated attacks on the energy sector, December 2025." 30 January 2026. https://www.cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/
[7] The Hacker News. "CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms." January 2026.
[8] The Record. "Russia blamed for Poland grid cyberattack in joint UK-EU sanctions package." 12 July 2026.
[9] National Cyber Security Centre (NZ). "Quarter One sees significant cyber incidents (Cyber Security Insights, Q1 2026)." 22 June 2026. https://www.ncsc.govt.nz/news/quarter-one-sees-significant-cyber-incidents/
[10] National Cyber Security Centre (NZ), Australian Cyber Security Centre, Canadian Centre for Cyber Security, and National Cyber Security Centre (UK). "Joint guidance: security for edge devices." 5 February 2025. https://www.ncsc.govt.nz/protect-your-organisation/joint-guidance-security-for-edge-devices/
[11] National Cyber Security Centre (NZ). "NCSC and CERT NZ integration now complete." 23 July 2025. https://www.ncsc.govt.nz/news/ncsc-and-cert-nz-integration-now-complete/
[12] Department of the Prime Minister and Cabinet. "New Zealand's Cyber Security Strategy 2026-2030 (discussion document; proposed critical-infrastructure regime)." Released March 2026; consultation closed 19 April 2026. https://www.dpmc.govt.nz/sites/default/files/2026-03/nz-cyber-security-discussion-doc-feb-2026-v2.pdf

