Summary
- The UK’s energy cyber strategy expands resilience expectations across electricity, gas, oil, and Ofgem-licensed operators.
- Energy operators face growing risk as renewable assets, storage, substations, and digital platforms become more connected.
- Leadership, governance, asset visibility, and tested recovery plans now sit alongside safety and financial risk.
In May, the UK government, under Keir Starmer, announced a four-year strategy aimed at strengthening cyber security across the country’s energy system. The Energy Sector Cyber Security Strategy sets out priorities and timelines for 2026–2030 to protect the electricity, gas and oil sectors from an increasing range of cyber threats.
The NCSC has noted a stark increase in the threat to the UK’s critical national infrastructure (CNI), “as adversaries seek to compromise these systems to achieve a range of outcomes, from financial gain and economic advantage, to pre-positioning, espionage and disruptive and destructive attacks.”
The four-year plan aims to ensure that:
- cyber security risks to the energy sector are identified, assessed, understood and managed
- resilience is increased at pace across the sector
- response and recovery plans are in place and tested for cyber incidents
- cyber requirements are expanded in scope and depth to keep up with the evolving threat and system landscape
The Government’s message to the energy sector is unmistakable; cyber resilience can no longer be treated as a compliance exercise or deferred until regulatory deadlines arrive. As the UK accelerates its transition to a smarter, more connected and increasingly decentralised energy system, cyber security has become fundamental to keeping the lights on, protecting critical infrastructure and maintaining public confidence. The Energy Sector Cyber Security Strategy may set milestones for the years ahead, but the organisations that will be best prepared are those that act now.
The time is now
While many of the strategy’s requirements will be phased in over the coming years, energy operators cannot afford to wait until ministerial deadlines are looming before taking action.
For too long, many organisations have relied on a reactive approach, detecting threats only after an attack has occurred. For example, in May 2025, a Southeast Asian energy provider was hit by ransomware threats from the NightSpire group. The threat actors disabled control systems for 18 days while demanding an $8 million ransom. Similarly, in 2023, nearly two dozen Danish energy companies were attacked in three successive waves. This was the largest cyberattack in Danish history and resulted in several of the power companies shutting off their connection to the internet to limit the damage.
That mindset is no longer fit for purpose. Today’s threat landscape demands continuous visibility of critical assets and the ability to identify malicious activity before it disrupts operations.
Equally, every new substation, renewable energy asset, battery storage facility or digital platform should be designed with cyber security embedded from day one. Retrofitting security is invariably more complex, more expensive and more disruptive than building it in from the outset. Organisations that invest now in governance, real-time visibility and proactive threat detection won’t simply be better placed to meet evolving regulatory expectations, they will gain a strategic advantage. This means strengthening operational resilience while protecting the services that millions of businesses and households rely on every day.
The opportunity for the sector is to move beyond asking, “what do we need to do to comply?” and instead ask, “what do we need to do to remain operational when, not if, a cyber attack occurs?” Those that make cyber resilience a priority today will be far better positioned to respond to emerging threats with confidence and navigate an increasingly demanding regulatory landscape with the Energy Sector Cyber Security Strategy coming into effect, NIS regulations being expanded and baseline cyber requirements applying to all Ofgem licensees.
Delaying this may mean implementing changes under greater regulatory scrutiny, increased operational pressure and, potentially, after vulnerabilities have already been exposed. Organisations should use this window to identify and prioritise their most critical assets, strengthen governance and embed resilience into day-to-day operations before compliance becomes a race against the clock.
Not just an IT ticket
The Energy Sector Cyber Security Strategy also means this is a board and CEO problem and not just an IT ticket, with cyber risk now sitting on the same line as safety and financial risk. If you own or operate renewable generation, storage or grid-connected assets, this now lands firmly on your desk. You are now in scope, even if you weren’t before.
The strategy explicitly extends baseline cyber resilience to operators not currently under NIS, with proposals for all Ofgem licensees regardless of size by the end of 2027. The idea that you are “too small to regulate” is now over.
It remains to be seen whether new Prime Minister, Andy Burnham, will make changes to this strategy. Either way, cyber resilience should be seen as a core operational requirement for the energy sector. As digitalisation and decentralised energy systems continue to expand, those who treat cyber security as a strategic business priority rather than a technical afterthought will be best placed to maintain trust, resilience and long-term operational success.





