Arab Press

بالشعب و للشعب
Wednesday, Apr 01, 2026

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

The threshold to determine whether an incident affecting energy companies is reportable has prevented any reports being made.

A cyber security law introduced three years ago was meant to boost the resilience of the UK's energy sector by obliging gas and electricity firms to report when they were hacked.

But since then not a single report has been made, Sky News can reveal, despite numerous successful hacks of British energy firms attributed to hostile states as well as criminal groups.

Ofgem, the authority that is meant to receive these reports, told Sky News that only one company has ever tried to file a report informing the regulator that it had been hacked, but they were dismissed as the incident did not meet the threshold for being reported.

Ofcom's incident thresholds are based on the impact of an attack on customers


Last year, staff at a little-known company called Elexon - a firm that plays a critical role in balancing and settling payments between power plants and electricity suppliers - was left locked out of its internal systems due to a ransomware attack.

The British government has confirmed that Russian state-sponsored hackers have successfully penetrated the computer networks of the UK's energy grids, without disrupting them.

Former defence secretary Gavin Williamson warned that "thousands and thousands and thousands" of people could be killed if an attempt at disruption was made.

But the high thresholds for companies working across the gas and electricity sectors to report cyber security incidents to Ofgem risks leaving the regulator blind to how the sector is actually coping in the face of these threats.

These thresholds are based on the impact of hacks to the continuity of the companies' services, a metric that does not record the sector's security capabilities, just the intentions of the attackers.

Dr Jamie Collier, a threat intelligence consultant at FireEye, told Sky News that the thresholds could be useful considering the varying levels of sophistication across attacks on critical infrastructure organisations, allowing defenders to "focus on what really matters".

But the cyber security expert added: "Despite this, essential service providers and regulators should be careful not to neglect the threat posed from less sophisticated attacks."

FireEye has detected an increase in critical infrastructure incidents caused by novice hackers due to the growing availability of tools enabling these hackers to interact with industrial control systems.

The company also warns that multiple, highly-prolific criminal organisations with a financial motivation are currently "active inside essential service provider networks with the intent of profiting from a ransom of stolen information and disrupted services".

FireEye warns that novice hackers are now targeting industrial control systems.


"Most of the concern around cyber security has been focused on operational technology (OT) networks that interact with physical processes and machinery, such as power plant equipment or water treatment facilities," Dr Collier explained.

"Yet the traditional information technology (IT) networks that involve the flow of data - such as file storage or email - should not be neglected. This is because whilst the impact of malicious activity can be far more severe against OT systems, these attacks typically start out on IT networks. It is therefore vital to consider security across an entire service provider's infrastructure."

Dr Collier stressed that critical infrastructure providers "deserve credit for their use of fail-safe mechanisms that can mitigate the destructive impacts of many attacks".

Responding to Sky News, a government spokesperson said: "The UK's critical infrastructure is extremely well protected and over the past five years we have invested £1.9bn in the National Cyber Security Strategy to ensure our systems remain secure and reliable."

They added that a formal review of the impact of the cyber security law, the Network & Information Systems Regulations, will take place within the next 12 months.

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
Saudi Arabia Updates Travel Advisory as Regional Conflict Intensifies
Saudi Arabia’s Sadara Suspends Petrochemical Production as Conflict Disrupts Operations
Iran Urges Saudi Arabia to Remove US Forces Amid Escalating Regional Tensions
Gulf Allies Urge Trump to Sustain Campaign Until Iran Is Fully Defeated
Saudi Arabia Unveils Strategic Rail Freight Corridors Connecting Gulf Ports to Jordan
Saudi Arabia Intercepts Drones and Ballistic Missiles in Major Defensive Operation
Houthi Escalation Opens New Front in Expanding Iran-Linked Conflict
Major Saudi Chemical Plant Halts Operations Amid Regional Conflict Disruptions
Strike on US Radar Aircraft in Saudi Arabia Signals Escalating Threat Capabilities
US Citizens in Saudi Arabia Advised to Shelter Indoors Amid Rising Regional Tensions
How Britain’s Prime Minister Controls U.S. Bomber Access in Escalating Iran Conflict
Saudi Arabia Urges Trump to Lead Strategic Reset in Middle East as UAE Weighs Ground Role
Reed Smith Expands Saudi Presence with Senior Corporate Appointments
Trump Announces Approval of F-35 Fighter Jet Sale to Saudi Arabia
BBC Faces Scrutiny Over Allegations of Paid Content Linked to Saudi Arabia
Ukraine Secures Defense Agreements with Qatar and Saudi Arabia as UAE Talks Advance
Oil Prices Surge as Saudi Arabia Adjusts Supply Amid Escalating Iran Tensions
Saudi Arabia Condemns Attacks on Kurdistan Leaders and Reaffirms Backing for Iraq’s Stability
Saudi Arabia Weighs Strategic Interests as Iran Conflict Raises Regional Stakes
Severe Thunderstorms Sweep Across UAE and Saudi Arabia Bringing Heavy Rainfall
Trump’s Strategic Alignment with Saudi Arabia Reflects Expanding Economic and Diplomatic Synergy
Saudi Arabia Strongly Condemns Attacks on Presidential Residences in Hawler
Saudi Stocks Edge Lower as Tadawul Index Closes Slightly Down
Houthis Enter Expanding Iran Conflict as US Deploys Additional Troops
Iran Seeks Assurances for Regional Allies as Saudi Arabia Presses for Firm Security Guarantees
Iranian Strike Reportedly Destroys $270 Million US E-3 Sentry Aircraft at Saudi Air Base
Iranian Strike on Saudi Base Leaves Ten American Personnel Injured
Ukraine Claims Russia Shared Satellite Intelligence with Iran Ahead of Saudi Base Strike
Pakistan Engages Regional Powers in Diplomatic Talks Over Iran Conflict
Escalating Iran Conflict Brings Renewed Focus to US Military Presence in Saudi Arabia
Iranian Strike Targets Saudi Airbase, Damaging Key US Military Assets
Modi and Saudi Crown Prince Emphasise Secure Shipping Routes in Talks on West Asia Conflict
Dallas-Based Company Secures One Billion Dollar Hotel Development Deal in Saudi Arabia
Zelensky Secures Defence Cooperation Deals with Gulf States During Strategic Regional Tour
Trump Calls on Saudi Arabia to Join Abraham Accords in Push for Expanded Middle East Cooperation
Trump Balances Humor and Praise in Remarks on Saudi Crown Prince
Saudi Arabia’s Strategic Pipeline Reaches Seven Million Barrel Capacity to Bypass Hormuz
Rubio Signals U.S. Could Conclude Iran Conflict Within Weeks as Air Campaign Intensifies
More Than a Dozen U.S. Soldiers Injured in Saudi Base Attack as Iran-Backed Houthis Expand Conflict
Iranian Strike on US Base in Saudi Arabia Injures Troops and Damages Aircraft
Pakistan to Convene Regional Talks with Saudi Arabia, Turkey and Egypt Amid Iran War Diplomacy
Ukraine and Saudi Arabia Reach ‘Mutually Beneficial’ Defence Agreement
Ukraine to Share Battlefield Expertise with Saudi Arabia Under New Defence Agreement
Trump Takes Center Stage at Saudi Arabia’s FII Miami Amid Escalating Iran Conflict
Gulf States Explore Pipeline Routes to Bypass Strait of Hormuz Amid Rising Tensions
Iran Conflict Drives Saudi Arabia to Deepen Security Ties with Ukraine
Saudi Arabia Reviews Desert Ski Resort Plans with Cancellation of Key Building Contracts
Saudi Arabia Targets Business Hotel Shortfall with $1 Billion Development Push
Iran and Allied Forces Intensify Strikes on Energy Sites and Urban Areas Across Region
Ukraine and Saudi Arabia Formalise Defence Cooperation Agreement, Zelenskiy Announces
×