Iran-linked hack leaves UK small power plants exposed to cyber risk until 2030s
Iran-linked hack shut a UK gas plant for 4 days; small power plants face risk until 2030 as Cyber Essentials rules tightened.
Officials briefed energy bosses this week on the breach, which is understood to have shut an unnamed small gas power plant for four days last month. The incident was first reported by the Sunday Telegraph and confirmed by an industry source familiar with the attack. The Guardian understands the hack has not altered the government’s timeline. Official documents published this month call on the industry regulator Ofgem to lay out proposals for new baseline cyber resilience requirements by the end of 2027, ahead of implementing standards by the end of 2030.
Britain has hundreds of small, unmanned gas plants connected to local power grids. They are typically idle for most of the year but can be used to ramp up generation when electricity supplies are squeezed. Although the outage had no impact on the electricity system, it has raised concerns about vulnerabilities in locally connected infrastructure that is not required to meet the same security standards as large-scale plants and transmission assets.
Calum Miller, the Liberal Democrats’ foreign affairs spokesperson, said: “Leaving hundreds of small power generators exposed to cyber threats until the 2030s is simply an unacceptable gamble with our national security.” He added that the government “should not have to wait for the lights to go out before taking the security of our energy infrastructure seriously”.
Rafael Narezzi, chief executive of energy cybersecurity specialist Centrii, said the incident should be used as a warning. “This particular incident may not have had consequences for the wider grid, but the next one could be different,” he said. “What concerns me is not necessarily the size of the power generator affected, but how many others may be out there.”
A government spokesperson said the UK has a highly resilient energy system and works closely with the energy sector to protect infrastructure. “We are alive to growing cybersecurity threats, which is why we also committed to reviewing the cyber resilience requirement for the downstream gas and electricity sector and are driving this work forward through parliament,” the spokesperson added.
Separately, the government has overhauled its Cyber Essentials framework, which provides baseline security controls for businesses of all sizes. According to TechRadar, the move comes against a backdrop of rising cyber breaches and high-profile attacks on companies including M&S and JLR. The latest changes include stricter patch management timelines, mandatory multi-factor authentication on all cloud services that support it, and bringing cloud services fully into scope. The new “Denzel” framework signals a shift from a once-a-year compliance exercise towards continuous cyber resilience, TechRadar reported, citing the UK Government Cyber Security Breaches Survey that found 4 in 10 businesses were compromised in the past 12 months.
Under the revised rules, critical patches must be deployed within a 14-day window, and businesses get two chances to prove compliance through a “double sampling” process before failing certification. If a cloud service supports MFA, it must be enabled for all users, otherwise it is an automatic certification failure. Cloud services previously could be excluded from assessment, but now they must be accounted for. TechRadar said businesses that have not yet reviewed their systems should do so now.