Hundreds of Britain’s smallest power plants remain vulnerable to state-sponsored cyber-attacks despite a recent successful breach linked to actors from Iran, raising concerns about the country’s energy infrastructure security. The attack, which reportedly disabled a small gas power facility for approximately four days last month, has prompted government officials to alert energy sector leaders to the increasing cyber threat facing local generation assets.

The hack targeted a small-scale, unmanned gas plant connected to a local power grid. While the outage did not disrupt the broader electricity system, it exposed vulnerabilities in smaller energy installations that currently operate under less stringent cybersecurity regulations compared to larger power plants and transmission networks.

Government documents released this month reveal that proposals for new baseline cybersecurity standards, overseen by the energy regulator Ofgem, are expected to be set out by the end of 2027, with implementation planned by 2030. The timeline remains unchanged despite the recent attack, prompting criticism from opposition politicians and energy security experts who argue the delay poses unacceptable risks.

Calum Miller, the Liberal Democrats’ foreign affairs spokesperson, described the situation as “an unacceptable gamble with our national security,” calling for the government to accelerate the introduction of tougher cyber resilience measures rather than waiting until the next decade to act.

The UK operates hundreds of small gas-fired power stations, often unmanned and typically idle for much of the year, but capable of rapidly increasing electricity supply during periods of high demand. These distributed assets, many connected through digital and remote-access systems, are becoming integral to the country’s energy framework, making their cybersecurity increasingly critical.

Rafael Narezzi, chief executive of energy cybersecurity firm Centrii, emphasized the risks posed by the multitude of small and medium generators. He noted that state-backed attackers do not necessarily target facilities based on their output but seek vulnerabilities and opportunities for access. “The UK has thousands of distributed assets increasingly contributing to how our energy system operates. Individually, many may appear insignificant. Collectively, their resilience matters enormously,” Narezzi said.

The government began a consultation in March focused on enhancing cyber resilience for power generators, following the introduction of the Cyber Security and Resilience Bill to Parliament late last year. Energy Minister Michael Shanks highlighted the need for the UK “to keep pace with the current threat landscape,” amid an environment where four nationally significant cyber-attacks occur weekly.

A government spokesperson reaffirmed that the UK’s energy system remains highly resilient and emphasized ongoing collaboration with the sector to maintain and improve security standards. “We are alive to growing cybersecurity threats, which is why we also committed to reviewing the cyber resilience requirement for the downstream gas and electricity sector and are driving this work forward through parliament,” the spokesperson added.

Ofgem has yet to comment publicly on the incident or the forthcoming regulatory proposals.