Key facts
- Hundreds of Britain's smallest power plants could face cyber risks until the 2030s.
- An Iran-linked hack recently shut down an unnamed small gas power plant for four days.
- New baseline cybersecurity standards for small power generators are not required until the end of 2030.
- Ofgem must propose new cyber resilience requirements by the end of 2027.
- The government is aware of growing cybersecurity threats and is working to improve standards.
Hundreds of Britain's smallest power plants may remain vulnerable to state-sponsored cyber-attacks until the 2030s, despite a recent successful hack linked to Iran that reportedly shut down an unnamed gas plant for four days. Officials have briefed energy sector leaders on the breach and the escalating cyber threat to critical infrastructure.
The government's timeline for implementing tougher baseline cybersecurity standards for these smaller generators extends to the end of 2030. This has raised concerns about national security, with critics calling it an "unacceptable gamble." Official documents indicate that the industry regulator, Ofgem, is expected to present proposals for new cyber resilience requirements for gas and electricity infrastructure by the end of 2027, with implementation following by the end of 2030. The recent hack has not altered this schedule.
These new requirements would apply to the type of small-scale gas plant that was reportedly targeted. The attack emerged as the Cabinet Office prepares to advise UK citizens on stocking up on essentials for extreme weather and potential hostile state actions. Calum Miller, the Lib Dems’ foreign affairs spokesperson, criticized the delay in bolstering security, stating that the government should not wait for a major incident to act.
Britain possesses numerous small, often unmanned, gas plants connected to local grids. While typically idle, they can quickly increase power generation when needed. Although last month's outage did not affect the overall electricity system, the attack highlights vulnerabilities in locally connected power infrastructure, which faces less stringent security standards than large-scale plants.
Michael Shanks, the energy minister, acknowledged in a consultation that the UK must "keep pace with the current threat landscape." An industry source confirmed the attack, noting it was one of the most successful on UK energy infrastructure. Rafael Narezzi, CEO of energy cybersecurity specialist Centrii, warned that while this incident may not have impacted the wider grid, future attacks could. He emphasized that attackers target vulnerabilities, not just plant size, and that the collective resilience of thousands of distributed assets is crucial.
A government spokesperson affirmed the UK's highly resilient energy system and ongoing collaboration with the sector to protect infrastructure and maintain high security standards. They added that the government is committed to reviewing and improving cyber resilience requirements for the downstream gas and electricity sector.