Arab Press

بالشعب و للشعب
Sunday, Mar 22, 2026

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

The threshold to determine whether an incident affecting energy companies is reportable has prevented any reports being made.

A cyber security law introduced three years ago was meant to boost the resilience of the UK's energy sector by obliging gas and electricity firms to report when they were hacked.

But since then not a single report has been made, Sky News can reveal, despite numerous successful hacks of British energy firms attributed to hostile states as well as criminal groups.

Ofgem, the authority that is meant to receive these reports, told Sky News that only one company has ever tried to file a report informing the regulator that it had been hacked, but they were dismissed as the incident did not meet the threshold for being reported.

Ofcom's incident thresholds are based on the impact of an attack on customers


Last year, staff at a little-known company called Elexon - a firm that plays a critical role in balancing and settling payments between power plants and electricity suppliers - was left locked out of its internal systems due to a ransomware attack.

The British government has confirmed that Russian state-sponsored hackers have successfully penetrated the computer networks of the UK's energy grids, without disrupting them.

Former defence secretary Gavin Williamson warned that "thousands and thousands and thousands" of people could be killed if an attempt at disruption was made.

But the high thresholds for companies working across the gas and electricity sectors to report cyber security incidents to Ofgem risks leaving the regulator blind to how the sector is actually coping in the face of these threats.

These thresholds are based on the impact of hacks to the continuity of the companies' services, a metric that does not record the sector's security capabilities, just the intentions of the attackers.

Dr Jamie Collier, a threat intelligence consultant at FireEye, told Sky News that the thresholds could be useful considering the varying levels of sophistication across attacks on critical infrastructure organisations, allowing defenders to "focus on what really matters".

But the cyber security expert added: "Despite this, essential service providers and regulators should be careful not to neglect the threat posed from less sophisticated attacks."

FireEye has detected an increase in critical infrastructure incidents caused by novice hackers due to the growing availability of tools enabling these hackers to interact with industrial control systems.

The company also warns that multiple, highly-prolific criminal organisations with a financial motivation are currently "active inside essential service provider networks with the intent of profiting from a ransom of stolen information and disrupted services".

FireEye warns that novice hackers are now targeting industrial control systems.


"Most of the concern around cyber security has been focused on operational technology (OT) networks that interact with physical processes and machinery, such as power plant equipment or water treatment facilities," Dr Collier explained.

"Yet the traditional information technology (IT) networks that involve the flow of data - such as file storage or email - should not be neglected. This is because whilst the impact of malicious activity can be far more severe against OT systems, these attacks typically start out on IT networks. It is therefore vital to consider security across an entire service provider's infrastructure."

Dr Collier stressed that critical infrastructure providers "deserve credit for their use of fail-safe mechanisms that can mitigate the destructive impacts of many attacks".

Responding to Sky News, a government spokesperson said: "The UK's critical infrastructure is extremely well protected and over the past five years we have invested £1.9bn in the National Cyber Security Strategy to ensure our systems remain secure and reliable."

They added that a formal review of the impact of the cyber security law, the Network & Information Systems Regulations, will take place within the next 12 months.

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
Egypt Reaffirms Strong Support for Saudi Arabia as Sisi Condemns Iran’s Gulf Attacks
Saudi Stocks Close Higher as Tadawul Index Gains 0.55% on Broad Sector Strength
Iran Fires Ballistic Missiles Toward Riyadh as Gulf Conflict Intensifies
Barcelona Midfielder Marc Casadó Attracts €40 Million Interest from Saudi Clubs
Strait of Hormuz Tensions Rise as Saudi Arabia Opens Key Air Base to US Forces
Saudi Arabia Confronts Strategic Turning Point as Iran Conflict Redefines Regional Alliances
Saudi Arabia Intercepts Missile as Two Others Land in Remote Area Without Casualties
Saudi Expulsion of Iranian Military Attaché Raises Doubts Over Fragile Riyadh–Tehran Rapprochement
Saudi Arabia’s Strategic East–West Pipeline Gains Global Attention as Energy Routes Face Growing Risks
Iran Reportedly Reduces Strikes on Saudi Arabia Amid Concerns Over Strong Retaliation
Saudi Arabia Criticises Israeli Strikes in Southern Syria Amid Rising Regional Tensions
Egypt and Saudi Arabia Warn Iran’s Actions Threaten Stability Across the Gulf
Egypt and Saudi Arabia Warn Iran’s Actions Threaten Stability Across the Gulf
Saudi Arabia Unveils Comprehensive 2026 Roadmap to Streamline Company Formation
Saudi-UAE Tensions Reveal Emerging Rivalry at the Heart of Gulf Power Dynamics
Saudi Arabia Launches Gulf Maritime Support Initiative to Safeguard Shipping
Saudi Arabia Expands US Military Access as UAE Braces for Prolonged Iran Conflict
Saudi Arabia Expels Iranian Diplomats Amid Escalating Regional Tensions
Saudi Arabia’s Edarat Wins Major Data Centre Deal with Regional Bank
Iran Intensifies Gulf Offensive as Saudi Arabia Intercepts Dozens of Drones
Regional Powers Hold Security Talks as Turkey Seeks New Strategic Pact
Asian Refiners Urge Saudi Arabia to Revise Oil Pricing Mechanism Amid War-Driven Volatility
Gulf States Weigh US Base Access and Military Alignment as Iran War Intensifies
IRGC Claims Strikes on Israel, Kuwait and Saudi Arabia as Conflict Widens
Saudi Arabia Intercepts Multiple Drones Amid Continued Iranian-Linked Attacks
Remains of Fallen Soldier Repatriated Following Death in Saudi Arabia
Iran Tensions Challenge Saudi Arabia’s Strategic Shift to Red Sea Oil Exports
Saudi Arabia Turns to Alternative Export Routes as Hormuz Disruption Strains Oil Flows
Saudi Arabia and UAE Move Closer to Backing US-Israeli Campaign Against Iran
Saudi Arabia Signals Readiness for Military Response as Iran Tensions Escalate
Saudi Arabia Warns Oil Could Surge Beyond $180 as Iran Conflict Disrupts Global Supply
Saudi Arabia Reports Drone Strike on Key Red Sea Refinery in Yanbu
United States Urges Citizens to Leave Saudi Arabia Amid Escalating Regional Conflict
Former Media Executive Chronicles Rise of Saudi Crown Prince in New Book
Saudi Aramco–Exxon Refinery in Yanbu Targeted in Latest Wave of Iranian Attacks
Greek-Operated Patriot System Intercepts Iranian Missiles Over Saudi Arabia
Asian Refiners Urge Saudi Arabia to Revise Oil Pricing as War Upends Markets
Arab and Muslim Ministers Convene in Riyadh to Coordinate Response to Iran Crisis
Saudi Arabia Expands Global Partnerships to Accelerate Vision 2030 Transformation
Europe and Japan Signal Readiness to Help Secure Strait of Hormuz Amid Escalating Crisis
Saudi Arabia Signals Firm Stance as Iranian-Linked Attacks Intensify
U.S. Lawmakers Press Rubio to Enforce Strong Safeguards in Saudi Nuclear Deal
Iran Issues Evacuation Warning to Gulf States After Strike on Major Gas Field
Saudi Arabia to Convene Arab and Islamic Ministers for Urgent Talks on Regional Conflict
Saudi Arabia Confirms Eid al-Fitr as Moon Sighting Determines End of Ramadan
Saudi Arabia Boosts Crude Exports to Highest Levels Since 2023, Data Shows
Iran Issues Warning to Gulf Energy Infrastructure Following Strike on Major Gas Field
Saudi Arabia Restarts Ras Tanura Refinery Following Drone Strike, Reinforcing Energy Resilience
Saudi Arabia Restarts Ras Tanura Refinery Following Drone Strike, Reinforcing Energy Resilience
Saudi Arabia Intercepts Ballistic Missiles Targeting Riyadh Amid Escalating Regional Tensions
×