All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to Geopolitics & Global Risk

UK small power plants face continued cyber risk after Iran-linked hack

Created at 27 Aug · 9:06 AM1 source↑ Market-relevant
IN SHORT

Hundreds of Britain's smallest power plants could remain at higher risk to state-sponsored cyber-attacks until the 2030s, despite a recent Iran-linked hack that shut down an unnamed gas plant for four days. The government's plan to toughen cybersecurity standards for these generators is not required until the end of 2030.

Key Numbers

2030scontinued cyber risk until
four dayspower plant outage duration
2027Ofgem proposals deadline
2030new standards implementation deadline
fournationally significant cyber-attacks per week

Who's Involved

Calum Miller
Lib Dems’ foreign affairs spokesperson
Michael Shanks
Energy minister
Rafael Narezzi
Chief executive of Centrii, an energy cybersecurity specialist
Ofgem
Industry regulator

↳ Why This Matters

The prolonged vulnerability of small power plants to cyber-attacks, particularly after a successful breach, poses a significant risk to national security and energy infrastructure resilience, especially at a time of heightened global threats.

Key facts

  • Hundreds of Britain's smallest power plants could face cyber risks until the 2030s.
  • An Iran-linked hack recently shut down an unnamed small gas power plant for four days.
  • New baseline cybersecurity standards for small power generators are not required until the end of 2030.
  • Ofgem must propose new cyber resilience requirements by the end of 2027.
  • The government is aware of growing cybersecurity threats and is working to improve standards.

Hundreds of Britain's smallest power plants may remain vulnerable to state-sponsored cyber-attacks until the 2030s, despite a recent successful hack linked to Iran that reportedly shut down an unnamed gas plant for four days. Officials have briefed energy sector leaders on the breach and the escalating cyber threat to critical infrastructure.

The government's timeline for implementing tougher baseline cybersecurity standards for these smaller generators extends to the end of 2030. This has raised concerns about national security, with critics calling it an "unacceptable gamble." Official documents indicate that the industry regulator, Ofgem, is expected to present proposals for new cyber resilience requirements for gas and electricity infrastructure by the end of 2027, with implementation following by the end of 2030. The recent hack has not altered this schedule.

These new requirements would apply to the type of small-scale gas plant that was reportedly targeted. The attack emerged as the Cabinet Office prepares to advise UK citizens on stocking up on essentials for extreme weather and potential hostile state actions. Calum Miller, the Lib Dems’ foreign affairs spokesperson, criticized the delay in bolstering security, stating that the government should not wait for a major incident to act.

Britain possesses numerous small, often unmanned, gas plants connected to local grids. While typically idle, they can quickly increase power generation when needed. Although last month's outage did not affect the overall electricity system, the attack highlights vulnerabilities in locally connected power infrastructure, which faces less stringent security standards than large-scale plants.

Michael Shanks, the energy minister, acknowledged in a consultation that the UK must "keep pace with the current threat landscape." An industry source confirmed the attack, noting it was one of the most successful on UK energy infrastructure. Rafael Narezzi, CEO of energy cybersecurity specialist Centrii, warned that while this incident may not have impacted the wider grid, future attacks could. He emphasized that attackers target vulnerabilities, not just plant size, and that the collective resilience of thousands of distributed assets is crucial.

A government spokesperson affirmed the UK's highly resilient energy system and ongoing collaboration with the sector to protect infrastructure and maintain high security standards. They added that the government is committed to reviewing and improving cyber resilience requirements for the downstream gas and electricity sector.

Frequently asked questions

An Iran-linked cyber-attack reportedly shut down an unnamed small gas power plant in the UK for four days last month.

The government's plan to toughen baseline cybersecurity standards for Britain's smallest power generators is not required until the end of 2030.

Ofgem, the industry regulator, is tasked with proposing new baseline cyber resilience requirements for gas and electricity infrastructure by the end of 2027.

These plants are often unmanned and connected to local grids, not required to meet the same security standards as large-scale power plants, making them potential targets for vulnerabilities.

What Happens Next

01Ofgem to lay out proposals for new baseline cyber resilience requirements by the end of 2027.
02New cybersecurity standards for small power generators to be implemented by the end of 2030.

How It Developed

An Iran-linked cyber-attack shut down a small gas power plant for four days last month.
Officials briefed energy bosses on the breach and the growing cyber threat to energy infrastructure.
The government's plan to toughen cybersecurity standards for small power generators is not required until the end of 2030.
Ofgem is to propose new baseline cyber resilience requirements for gas and electricity infrastructure by the end of 2027.
The Cabinet Office is preparing to urge citizens to stock up on essentials for extreme weather and potential state attacks.
A government spokesperson stated that the UK has a resilient energy system and is working to protect infrastructure.
The energy minister acknowledged the need to keep pace with the current threat landscape.

Sources

T1
UK’s small power plants face continued cyber risk after Iran-linked hackThe Guardian

Related Stories

CISA confirms over 100 US water systems targeted by hackers
26 Aug · 2:46 PM
Iran: IAEA cannot inspect attacked nuclear sites without new security protocols
26 Aug · 3:51 PM
Russia threatens UK military targets over missile tech sharing
27 Aug · 9:08 AM
Greek air defence system downs drones over Saudi Arabia
27 Aug · 8:14 AM
OPEC+ loses oil market sway as China's imports dictate prices
27 Aug · 6:10 AM