UK’s small power plants face continued cyber risk after Iran-linked hack
Government measures to improve resilience are not due until 2030 and July’s hack has not altered this timeline Hundreds of Britain’s smallest power plants could remain at a higher risk to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack last month, it has emerged. Officials this week briefed energy bosses on the breach, which is understood to have shut an…
The UK government has decided not to enhance cybersecurity measures for small power plants sooner, with officials describing it as an "unacceptable gamble with our national security." Hundreds of Britain's smallest power plants, such as gas plants, could remain at higher risk from state-sponsored cyber-attacks until the 2030s. This follows a recent Iran-linked hack that shut down an unnamed small gas power plant for four days.
Despite the successful attack, the government's plan to strengthen baseline cybersecurity standards for these smaller generators will not be implemented until the end of 2030. The government's plan requires the industry regulator, Ofgem, to propose new baseline cyber resilience requirements for gas and electricity infrastructure by the end of 2027, with implementation by the end of 2030.
This timeline has raised concerns among experts and politicians about the potential vulnerabilities in the UK's energy infrastructure. Calum Miller, the Lib Dems’ foreign affairs spokesperson, criticized the decision as an "unacceptable gamble with our national security," warning that the government should fast-track the regulations.
The government acknowledges the growing cyber threats and has opened a consultation into the cyber resilience of power generators, but critics argue that leaving the issue until the 2030s leaves the energy sector exposed to potential attacks from hostile states.
Written by urgent.news from Guardian Business's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.