Skip to main content
Advertisement

UK's smallest power plants face cyber risk until 2030 despite Iran-linked hack

Hundreds of Britain's smallest power plants could remain vulnerable to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack in July. The government's plan to strengthen cybersecurity standards won't take effect until 2030, drawing criticism over delayed implementation.

By The UK Pulse Editorial Team··6 min read·How we work
A power plant with chimneys and electrical pylons under cloudy skies

Hundreds of Britain's smallest power generators could remain exposed to state-sponsored cyber-attacks until the 2030s despite a successful breach attributed to Iran-linked hackers last month, according to government timelines that have not been altered by the incident.

Energy industry leaders received briefings this week on the July attack, which disabled an unnamed small gas power plant for approximately four days. The incident has prompted heightened concern about vulnerabilities in energy infrastructure, particularly among smaller facilities that operate with less stringent security requirements than their larger counterparts.

The government's strategy to strengthen baseline cybersecurity standards for Britain's smallest power generators will not take effect until the end of 2030. According to , the Department for Energy Security and Net Zero has briefed power companies that there was no risk to the wider energy system from the incident. However, the delayed implementation timeline has drawn criticism from opposition politicians who argue it leaves critical infrastructure unnecessarily exposed.

Published government documents outline a two-stage process: the industry regulator Ofgem will develop proposals for new baseline cyber resilience requirements for gas and electricity infrastructure by the end of 2027, with mandatory implementation following by the end of 2030. According to the government consultation on cyber resilience requirements, this regulatory design phase will precede the full rollout of new standards across the decade.

The targeted facilities are small-scale, unmanned gas plants connected to local power grids. These installations typically remain idle for most of the year but can be activated to increase electricity generation during periods of high demand or supply constraints. Unlike large-scale power plants and transmission assets, these smaller generators are not currently required to meet the same cybersecurity standards, creating what security experts describe as a significant vulnerability.

Energy minister Michael Shanks emphasised in the government consultation that the UK "needs to keep pace with the current threat landscape." According to reporting on the incident, Shanks stated that "nobody lost power" and characterised the affected generator as "tiny" compared with conventional power plants.

Why the delay concerns security experts

Calum Miller, the Liberal Democrats' foreign affairs spokesperson, characterised the timeline as an unacceptable risk to national security.

"Leaving hundreds of small power generators exposed to cyber threats until the 2030s is simply an unacceptable gamble with our national security,"
Miller said.
"The government should not have to wait for the lights to go out before taking the security of our energy infrastructure seriously. They must immediately fast-track these regulations, not leave them until the 2030s. We mustn't leave an open goal to hostile states at a time of heightened global threats."

Advertisement

Rafael Narezzi, chief executive of Centrii, an energy cybersecurity specialist, warned that the incident should serve as a cautionary signal rather than a reason for complacency.

"We should use it as a warning rather than wait for an incident,"
Narezzi said.
"Across the UK energy system we have small, medium and large generation assets, increasingly connected through digital systems, remote access, third parties and operational technology. This particular incident may not have had consequences for the wider grid, but the next one could be different."

Narezzi highlighted a broader concern about the scale of potential vulnerability.

"What concerns me about this incident is not necessarily the size of the power generator that was affected, but how many others may be out there,"
he explained.
"Attackers do not necessarily select their targets according to how many megawatts they generate. They look for vulnerabilities, trusted access and opportunities. The UK has thousands of distributed assets increasingly contributing to how our energy system operates. Individually, many may appear insignificant. Collectively, their resilience matters enormously."

What is the government's response?

A government spokesperson defended the department's approach, stating:

"The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards. We are alive to growing cybersecurity threats, which is why we also committed to reviewing the cyber resilience requirement for the downstream gas and electricity sector and are driving this work forward through parliament."

The government opened its formal consultation into cyber resilience for power generators in March 2026, following the introduction of the Cyber Security and Resilience Bill to parliament in late 2025. The consultation warned that the UK now faces four nationally significant cyber-attacks every week, underscoring the scale of the threat landscape.

Context: The July incident and broader vulnerabilities

The July attack represents one of the most successful cyber-strikes against UK energy infrastructure in recent years. An industry source with knowledge of the post-attack briefing confirmed that the plant remained offline for approximately four days, though the outage produced no measurable impact on the electricity system as a whole. The incident occurred as the Cabinet Office was preparing to launch a public campaign urging UK citizens to prepare for extreme weather events and potential attacks from hostile states.

Britain operates hundreds of small-scale, unmanned gas plants distributed across local power grids. These facilities are designed to provide flexible generation capacity when the electricity system faces strain, but their distributed nature and lighter regulatory burden have created security gaps. The attack has exposed the risk that coordinated strikes against multiple small generators could potentially have cascading effects on grid stability, even if individual facilities appear insignificant.

Implementation timeline and next steps

According to the wider energy-sector cyber strategy, the government will assess the regulatory threshold for cyber requirements by 2027, with a full resilience uplift across distributed generation and energy targeted for completion by 2030. The regulatory design phase will run through the remainder of the decade before new standards become mandatory.

The consultation process is expected to move into the regulatory design phase before implementation of the new standards takes place later in the decade. Industry stakeholders will have the opportunity to provide input during this period, though the core timeline remains unchanged despite the July incident.

Key Facts

  • A small gas power plant was shut down for four days in July 2026 in an attack attributed to Iran-linked hackers, with no impact on the wider electricity system.
  • The government will not require new baseline cybersecurity standards for small power generators until the end of 2030, with Ofgem to develop proposals by the end of 2027.
  • Britain operates hundreds of small, unmanned gas plants connected to local grids that are typically idle but can be activated during periods of high electricity demand.
  • The UK faces approximately four nationally significant cyber-attacks every week, according to government warnings issued during the consultation process.
  • Security experts warn that while individual small generators may appear insignificant, their collective resilience matters enormously to overall grid stability.

This article was sourced from theguardian

Advertisement

Related News