Small UK generator cyber attack exposes system-wide security gap

Facebook
Twitter
LinkedIn
Pinterest
Pocket
WhatsApp
  • A reported cyber attack forced a small British generator offline for four days in July, although no customers lost power and the wider grid was not threatened.
  • Media reports have linked the attackers to Iran, but the UK government has not publicly confirmed that attribution.
  • The more consequential issue is whether regulation adequately covers the growing number of small, remotely controlled energy assets.

The UK government has briefed energy company executives and circulated additional security advice after a cyber incident reportedly linked to Iran forced a small electricity generator offline for four days.

The incident occurred in July and affected a facility that was reportedly a gas-fired peaking plant with a capacity of about 15 MW. The plant’s identity, owner and location have not been disclosed.

Although the Telegraph and FT attributed the attack to Iran-linked hackers, ministers and the National Cyber Security Centre have not publicly confirmed who was responsible. The distinction is important because technical evidence that an attacker used tools or infrastructure associated with an Iranian group would not necessarily establish that the Iranian state directed the operation.

Energy minister Michael Shanks confirmed that a cyber incident had affected a small generator but sought to counter suggestions that electricity supplies had been endangered.

“To be clear: there was no threat to the wider grid and nobody lost power,” he said in a statement on X.

The Department for Energy Security and Net Zero said Britain had a highly resilient energy network. Officials have nevertheless briefed energy chief executives and are continuing to work with regulators and the NCSC to assess the threat and strengthen protections, according to Reuters.

Decentralised threats

The facility’s limited importance to national electricity supply explains why the incident had no wider operational effect. It also points towards the more significant vulnerability.

Small peaking plants are frequently unmanned and operated remotely. Facilities of this type commonly use programmable logic controllers to manage physical equipment, although neither the affected system nor the attackers’ route into it has been disclosed.

Britain’s electricity system is becoming more decentralised as batteries, flexible generators, electric vehicle chargers and other controllable assets connect to distribution networks. Individually, many sit below the capacity thresholds traditionally used to identify critical infrastructure. Collectively, they can represent a material volume of controllable power and may share technology suppliers, communications systems or remote management services.

The government had identified that regulatory gap before the latest incident. Its Energy Sector Cyber Security Strategy, published in May, assigns DESNZ, Ofgem, the National Energy System Operator and the NCSC responsibility for strengthening cyber assurance across the energy system.

An August consultation response committed the government to reviewing the thresholds under the Network and Information Systems Regulations and developing baseline cyber requirements for all Ofgem licensees by the end of 2027. A whole-system baseline is intended by 2030.

The incident gives that work greater urgency. The relevant controls include accurate asset inventories, separation between business and operational networks, tightly controlled remote access, prompt security updates and incident reporting that captures smaller operators before problems can spread.

NCSC chief executive Richard Horne warned in April that “cyber operations are now integral to conflict, as much a reality of modern warfare as drones and missiles”.

The July attack caused limited physical disruption. And although the plant was not considered nationally critical infrastructure, it remains to be seen whether the incident accelerates protection of the distributed assets on which the clean power system will increasingly depend.

Author

Facebook
Twitter
LinkedIn
Pinterest
Pocket
WhatsApp

Never miss any important news. Subscribe to our newsletter.

Recent News

Editor's Picks