Arab Press

بالشعب و للشعب
Thursday, Mar 05, 2026

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

The threshold to determine whether an incident affecting energy companies is reportable has prevented any reports being made.

A cyber security law introduced three years ago was meant to boost the resilience of the UK's energy sector by obliging gas and electricity firms to report when they were hacked.

But since then not a single report has been made, Sky News can reveal, despite numerous successful hacks of British energy firms attributed to hostile states as well as criminal groups.

Ofgem, the authority that is meant to receive these reports, told Sky News that only one company has ever tried to file a report informing the regulator that it had been hacked, but they were dismissed as the incident did not meet the threshold for being reported.

Ofcom's incident thresholds are based on the impact of an attack on customers


Last year, staff at a little-known company called Elexon - a firm that plays a critical role in balancing and settling payments between power plants and electricity suppliers - was left locked out of its internal systems due to a ransomware attack.

The British government has confirmed that Russian state-sponsored hackers have successfully penetrated the computer networks of the UK's energy grids, without disrupting them.

Former defence secretary Gavin Williamson warned that "thousands and thousands and thousands" of people could be killed if an attempt at disruption was made.

But the high thresholds for companies working across the gas and electricity sectors to report cyber security incidents to Ofgem risks leaving the regulator blind to how the sector is actually coping in the face of these threats.

These thresholds are based on the impact of hacks to the continuity of the companies' services, a metric that does not record the sector's security capabilities, just the intentions of the attackers.

Dr Jamie Collier, a threat intelligence consultant at FireEye, told Sky News that the thresholds could be useful considering the varying levels of sophistication across attacks on critical infrastructure organisations, allowing defenders to "focus on what really matters".

But the cyber security expert added: "Despite this, essential service providers and regulators should be careful not to neglect the threat posed from less sophisticated attacks."

FireEye has detected an increase in critical infrastructure incidents caused by novice hackers due to the growing availability of tools enabling these hackers to interact with industrial control systems.

The company also warns that multiple, highly-prolific criminal organisations with a financial motivation are currently "active inside essential service provider networks with the intent of profiting from a ransom of stolen information and disrupted services".

FireEye warns that novice hackers are now targeting industrial control systems.


"Most of the concern around cyber security has been focused on operational technology (OT) networks that interact with physical processes and machinery, such as power plant equipment or water treatment facilities," Dr Collier explained.

"Yet the traditional information technology (IT) networks that involve the flow of data - such as file storage or email - should not be neglected. This is because whilst the impact of malicious activity can be far more severe against OT systems, these attacks typically start out on IT networks. It is therefore vital to consider security across an entire service provider's infrastructure."

Dr Collier stressed that critical infrastructure providers "deserve credit for their use of fail-safe mechanisms that can mitigate the destructive impacts of many attacks".

Responding to Sky News, a government spokesperson said: "The UK's critical infrastructure is extremely well protected and over the past five years we have invested £1.9bn in the National Cyber Security Strategy to ensure our systems remain secure and reliable."

They added that a formal review of the impact of the cyber security law, the Network & Information Systems Regulations, will take place within the next 12 months.

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
Iran Says Its Strikes Target Only U.S. Military Assets and Denies Attacking Saudi Arabia
Drone Strike Hits U.S. Embassy in Riyadh as Middle East Conflict Escalates
Tom Brady’s Saudi Flag Football Event May Shift to U.S. as Middle East Conflict Disrupts Plans
Iran War Strikes Saudi Arabia at a Critical Moment for Its Economic Transformation
Saudi Cabinet Declares Kingdom Will Take All Necessary Measures to Defend National Security
United States Urges Citizens to Leave Fourteen Middle Eastern Countries as Iran War Escalates
Saudi Aramco’s Ras Tanura Refinery Targeted Again in Second Drone Attack Within Two Days
Saudi Pro League Orders Clubs to Continue Fixtures Despite Rising Middle East Conflict
Trump Pursues Major Civil Nuclear Agreement With Saudi Arabia Amid Regional Turmoil
Mass Drone Attacks Strike Gulf States as Iran Conflict Spreads Across Region
No Verified Confirmation of Ronaldo Departure Linked to Iran Conflict or AFC Suspension
No Verified Evidence of Israeli Intelligence Arrests in Qatar or Saudi Arabia
Drone Attack Forces Temporary Shutdown of Saudi Arabia’s Largest Oil Refinery
Israel Intensifies Air Campaign in Tehran as Iran Expands Regional Retaliation
Iranian Strikes Escalate Middle East Conflict, Drawing Saudi Arabia Closer to Wider War
No Verified Confirmation of Drone Strike on King Fahd Causeway Amid Regional Tensions
No Verified Evidence Saudi Crown Prince Is Seeking to Weaken Israel Amid Regional Tensions
Reports Emerge of Drone Strike Near US Embassy in Saudi Arabia as Americans Told to Shelter
Saudi Arabia Weighs Strategic Options as Tensions With Iran Intensify
Iran Expands Strikes on Saudi and Qatari Infrastructure, Opening a New Front in Gulf Conflict
Western Navies Sound Alarm as Russian Shadow Tankers Transit NATO Waters in Defiance of Sanctions
U.S. Embassy in Riyadh Struck by Drones Amid Escalating Iran Conflict
Imola Emerges as Standby Venue if Bahrain or Saudi Arabia Grands Prix Are Cancelled
Uncertainty Clouds $24 Billion Gulf Investment Linked to Paramount–WBD Deal
Middle East Strikes Disrupt Qatar LNG, Saudi Refining and Israeli Energy Fields
Gulf States Signal Possible Collective Action Over Iran’s Escalating Strikes
Saudi Arabia Summons Iranian Ambassador After Cross-Border Attacks
Saudi Arabia Intercepts Drones Targeting Ras Tanura Oil Refinery as Conflict Escalates
Saudi Arabia Clarifies It Supported Diplomacy With Iran, Not Military Escalation
Putin and Saudi Crown Prince Confer on Escalating Iran Crisis
Drone Strike Forces Shutdown of Saudi Arabia’s Largest Oil Refinery
Saudi Arabia Signals Harder Line on Iran as Regional Conflict Deepens
Strikes in Qatar and Saudi Arabia Pull Energy Infrastructure Deeper Into Expanding Middle East Conflict
U.S. and Israel Intensify Strikes on Iran as Conflict Expands to Lebanon and Gulf States
Violent Pro-Iranian Protesters Storm U.S. Consulate in Karachi
Missile Debris Sparks Fires at Dubai’s Jebel Ali Port Near Palm Jumeirah
Iran Strikes U.S. Fifth Fleet Headquarters in Bahrain Amid Wider Gulf Retaliation
Emerging Saudi–Turkish Alignment Draws Attention as Potential Strategic Challenge for Israel
Saudi Arabia Unveils $100 Billion Technology Investment Fund to Accelerate Post-Oil Diversification
Saudi Arabia Reaffirms Firm Commitment to Two-State Solution in Renewed Diplomatic Push
Saudi Arabia Launches Central Kitchen in Gaza to Deliver 24,000 Meals a Day
Saudi Arabia Announces $346 Million Support Package for Yemen in Renewed Humanitarian Push
Saudi Investors Increase US Equity Exposure Amid Domestic Market Weakness
Saudi Arabia Unveils Major Desert Gas Development in Strategic Shift Toward Diversified Energy Growth
Satellite Images Indicate Increased Aircraft Presence at Saudi Airbase Hosting US Forces
Telephone Diplomacy Sparks Tensions Between Two Key US Allies After Trump Intervention
Asian LPG Prices Surge After Damage Forces Saudi Aramco Export Disruptions
Saudi Arabia Unveils $100 Billion AI Infrastructure Fund to Challenge US and China
Saudi Stocks Close Lower as Tadawul All Share Index Falls 1.28 Percent
Saudi Arabia Launches Smart Mapping System to Enhance Pilgrim Experience at Holy Sites
×