Decoding the world of cybersecurity

Small generators face years-long cyber gap

Hundreds of smaller UK power generators may remain outside stronger baseline cyber requirements until 2030 despite a recent attack that disrupted an unnamed gas plant for four days.

Small generators face years-long cyber gap
Summary
  • Government plans aim to introduce baseline cyber resilience across all parts of downstream gas and electricity by the end of 2030.
  • The timetable follows a reported cyberattack that shut an unnamed small gas generator for four days without disrupting the wider electricity system.
  • Smaller distributed assets create a regulatory challenge as the power system becomes more decentralised, digital, and remotely managed.

Hundreds of smaller UK electricity generators could remain outside stronger baseline cyber requirements for several more years even after a cyberattack disrupted an unnamed gas-fired plant, putting the timetable for energy-sector resilience under greater scrutiny.

The UK government’s Energy Sector Cyber Security Strategy sets a goal of introducing baseline cyber resilience across all parts of the downstream gas and electricity system by the end of 2030.

Before then, officials intend to assess Network and Information Systems regulatory thresholds and develop proposals for baseline requirements covering Ofgem licensees by the end of 2027.

The timetable has gained greater attention following a reported attack on a small gas generator that shut the facility for four days. Cyber Insider covered the incident earlier this week. The outage did not disrupt the wider electricity system, and public reporting has not identified the plant.

The latest policy question extends beyond that individual incident. Britain has hundreds of smaller generation assets, including facilities that may operate intermittently and increase output when electricity supply is tight.

Those sites do not necessarily fall under the same regulatory thresholds as the largest power stations and other nationally significant infrastructure. The government’s current programme is intended to close more of that gap, but its sector-wide baseline is not due until the end of the decade.

The energy strategy says the government will assess existing NIS thresholds by the end of 2027, including whether new critical subsectors need to be captured. It also plans to shape proposals for baseline cyber requirements for all Ofgem licensees over the same period.

By the end of 2030, the government says it intends to have raised resilience across the whole downstream gas and electricity system through a baseline level applying to all relevant parts.

The policy problem is partly one of scale. A small generator may not be systemically important in isolation, making it difficult to justify imposing every control used for the largest operators. A power system containing many similar distributed assets creates a different form of aggregate exposure.

Sites can share suppliers, remote-access technologies, industrial equipment, operating practices, or management platforms. Common dependencies can therefore produce concentration even where generation assets are geographically dispersed and owned by separate companies.

The NCSC’s warning this week about increased targeting of internet-exposed operational technology adds to that concern. Industrial equipment can acquire unintended external exposure through legacy connectivity, remote maintenance, misconfiguration, or unmanaged devices, particularly at sites without large permanent technical teams.

The energy system itself is also changing. Distributed generation, storage, smart equipment, remote operation, and digital balancing are adding new technology dependencies around infrastructure that was historically regulated through more concentrated models of generation and transmission.

The government’s strategy acknowledges those changes by calling for improved understanding of sector risk, stronger supply-chain resilience, reassessment of NIS thresholds, and broader baseline requirements.

The attack on the unnamed generator does not demonstrate that smaller plants collectively threaten electricity-system stability. The reported four-day outage did not cause wider disruption. It does show that cyber activity can reach the availability of generation assets below the most heavily regulated tier.

The gap between that present exposure and the 2030 baseline leaves the sector relying on existing regulation, voluntary improvements, supplier controls, and the interim measures government and Ofgem develop during the next four years.

The recent incident has not produced a publicly announced acceleration of the 2030 target. The question now is how quickly the intermediate regulatory work reduces exposure before the sector-wide baseline is fully in place.

×