< Back to all clusters
[TECHNOLOGY] · United Kingdom · 2 sources

started · updated

Part of situation: (2 clusters)

UK power plant cyber attack highlights infrastructure reporting gaps

A cyber attack, reportedly linked to the Iranian regime, forced an unidentified small ‘peaker’ power generation facility in the United Kingdom offline for four days. Because the facility was a smaller reserve plant, the incident did not cause disruptions to the national grid or the broader energy supply.

The event has highlighted vulnerabilities in critical national infrastructure (CNI), specifically regarding regulatory reporting thresholds. Under current NIS Regulations, mandatory notification is not required if an incident does not meet specific criteria regarding the operator's size or the significant impact on service continuity. This incident fell below those legal thresholds, meaning it went largely unobserved at the time.

The National Cyber Security Centre (NCSC) and the Department for Energy Security and Net Zero are investigating the attack and have briefed energy sector CEOs. The incident has prompted discussions regarding the review of electricity generation thresholds, with the government potentially consulting on revised requirements following the Cyber Security and Resilience Bill.

Entities

Department for Energy Security and Net Zero · National Cyber Security Centre · Ofgem

Sources

about 5 hours ago