Daily Weird News
Technology

Small UK power plants may remain exposed after Iran-linked cyberattack

A cyberattack reportedly shut an unnamed small gas power plant in Britain for about four days, without affecting the wider electricity system. Despite the incident, proposed cybersecurity standards for hundreds of similar facilities are not expected to take effect until the end of 2030.

Small UK power plants may remain exposed after Iran-linked cyberattack

Daily Weird News Report

Hundreds of small power plants in Britain could remain vulnerable to state-sponsored cyberattacks for years after an Iran-linked operation reportedly shut one of the facilities last month. The affected plant, whose name has not been disclosed, was taken offline for approximately four days, according to an industry source familiar with a government briefing for energy companies. The incident did not disrupt the wider electricity system, but it has drawn attention to the security of smaller generators connected to local grids. Many of Britain’s small gas plants are unmanned and spend most of the year idle. They can be brought into service when electricity supplies are under pressure. Unlike large power stations and transmission infrastructure, however, they are not currently required to meet the same cybersecurity standards. Government documents published this month call for Ofgem to develop proposals for baseline cyber-resilience requirements by the end of 2027. The new standards are expected to be implemented by the end of 2030. The Guardian reported that the recent attack has not changed that timetable. Calum Miller, the Liberal Democrats’ foreign affairs spokesperson, described the decision to wait as an unacceptable national-security risk and urged the government to accelerate the regulations. He said authorities should not wait for a larger disruption before strengthening protections. The government launched a consultation on the cyber resilience of power generators in March, after introducing the Cyber Security and Resilience Bill to Parliament late last year. In the consultation, energy minister Michael Shanks said Britain needed to keep up with the current threat environment. The government has also warned that the UK faces four nationally significant cyberattacks each week. Rafael Narezzi, chief executive of energy cybersecurity company Centrii, said the incident should serve as a warning. He noted that energy assets are increasingly connected through digital systems, remote access, third parties and operational technology. In his view, attackers may focus on weak points and trusted access rather than the amount of electricity a facility can generate. A government spokesperson said the UK’s energy system was highly resilient and that officials were working with the industry to protect infrastructure. The spokesperson also said the government was reviewing cyber-resilience requirements for downstream gas and electricity facilities.

Reporting

Sources

This story was assembled from reporting published by the following sources.