Arab Press

بالشعب و للشعب
Thursday, Mar 12, 2026

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

The threshold to determine whether an incident affecting energy companies is reportable has prevented any reports being made.

A cyber security law introduced three years ago was meant to boost the resilience of the UK's energy sector by obliging gas and electricity firms to report when they were hacked.

But since then not a single report has been made, Sky News can reveal, despite numerous successful hacks of British energy firms attributed to hostile states as well as criminal groups.

Ofgem, the authority that is meant to receive these reports, told Sky News that only one company has ever tried to file a report informing the regulator that it had been hacked, but they were dismissed as the incident did not meet the threshold for being reported.

Ofcom's incident thresholds are based on the impact of an attack on customers


Last year, staff at a little-known company called Elexon - a firm that plays a critical role in balancing and settling payments between power plants and electricity suppliers - was left locked out of its internal systems due to a ransomware attack.

The British government has confirmed that Russian state-sponsored hackers have successfully penetrated the computer networks of the UK's energy grids, without disrupting them.

Former defence secretary Gavin Williamson warned that "thousands and thousands and thousands" of people could be killed if an attempt at disruption was made.

But the high thresholds for companies working across the gas and electricity sectors to report cyber security incidents to Ofgem risks leaving the regulator blind to how the sector is actually coping in the face of these threats.

These thresholds are based on the impact of hacks to the continuity of the companies' services, a metric that does not record the sector's security capabilities, just the intentions of the attackers.

Dr Jamie Collier, a threat intelligence consultant at FireEye, told Sky News that the thresholds could be useful considering the varying levels of sophistication across attacks on critical infrastructure organisations, allowing defenders to "focus on what really matters".

But the cyber security expert added: "Despite this, essential service providers and regulators should be careful not to neglect the threat posed from less sophisticated attacks."

FireEye has detected an increase in critical infrastructure incidents caused by novice hackers due to the growing availability of tools enabling these hackers to interact with industrial control systems.

The company also warns that multiple, highly-prolific criminal organisations with a financial motivation are currently "active inside essential service provider networks with the intent of profiting from a ransom of stolen information and disrupted services".

FireEye warns that novice hackers are now targeting industrial control systems.


"Most of the concern around cyber security has been focused on operational technology (OT) networks that interact with physical processes and machinery, such as power plant equipment or water treatment facilities," Dr Collier explained.

"Yet the traditional information technology (IT) networks that involve the flow of data - such as file storage or email - should not be neglected. This is because whilst the impact of malicious activity can be far more severe against OT systems, these attacks typically start out on IT networks. It is therefore vital to consider security across an entire service provider's infrastructure."

Dr Collier stressed that critical infrastructure providers "deserve credit for their use of fail-safe mechanisms that can mitigate the destructive impacts of many attacks".

Responding to Sky News, a government spokesperson said: "The UK's critical infrastructure is extremely well protected and over the past five years we have invested £1.9bn in the National Cyber Security Strategy to ensure our systems remain secure and reliable."

They added that a formal review of the impact of the cyber security law, the Network & Information Systems Regulations, will take place within the next 12 months.

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
Three Commercial Vessels Attacked Near Strait of Hormuz, Thai-Flagged Ship Damaged and Crew Evacuated
Saudi Red Sea Oil Exports Set for Record in March as Kingdom Reroutes Crude Amid Hormuz Crisis
Saudi Arabia Seeks Belgian Military Support After Iranian Missile Attacks
Saudi Arabia Welcomes US Decision to Designate Sudan’s Muslim Brotherhood as Terrorist Organisation
Saudi Aramco Plans Dual Gulf and Red Sea Export Routes as Iran Crisis Disrupts Oil Shipments
Saudi Cabinet Condemns Iranian Attacks and Reaffirms Kingdom’s Right to Defend Its Sovereignty
Ukraine Deploys Counter-Drone Teams to Gulf States as Iranian Drone Threat Expands
Bahrain Grand Prix Faces Uncertainty as Saudi Arabia Works to Keep Formula One Race on Track
Saudi Arabia Faces New Strategic Dilemma in Yemen as Regional War Reshapes Calculations
OPEC Confirms Saudi-Led Oil Output Increase as Iran War Disrupts Global Energy Markets
Pakistan Pledges Rapid Support for Saudi Arabia Amid Escalating Middle East Tensions
Global Energy Agency Announces Record Release of 400 Million Barrels to Stabilize Oil Markets Amid Hormuz Disruption
Aramco Warns Global Oil Market Faces ‘Catastrophic’ Shock if Strait of Hormuz Remains Closed
Iran Launches Drone and Missile Attacks Across Gulf Targets Including Saudi Arabia, Kuwait and Bahrain
Saudi Arabia Elevates Fahad Al-Saif as Vision 2030 Enters Crucial Implementation Phase
Saudi Aramco Expands Routes to Move Oil Without Reliance on the Strait of Hormuz
Saudi Arabia and Pakistan Reaffirm Mutual Defense Cooperation Following Iran Strike
Saudi Arabia Plans Major Ukrainian Arms Deal to Counter Iranian Drone Threat
Pentagon Signals Intensification of U.S. Air Campaign as Iran Conflict Escalates
U.S. Senator Lindsey Graham Raises Prospect of Mutual Defense Pact With Saudi Arabia Amid Iran Conflict
Why Saudi Arabia Is Unlikely to Have Wanted U.S. Airstrikes on Iran
Saudi Arabia’s Red Sea Oil Exports Set to Reach Record High as Gulf Routes Face Disruption
Saudi Arabia Pushes East–West Oil Pipeline Toward Full Capacity as Hormuz Crisis Disrupts Global Energy Flows
Oil Prices Retreat From Peak as G7 Weighs Release of Strategic Reserves
Pentagon Identifies U.S. Soldier Who Died After Iranian Strike on Saudi Air Base
Why Saudi Arabia’s $50 Billion ‘The Line’ Megacity Slowed — and How Artificial Intelligence Is Reshaping the Plan
United States Withdraws Diplomatic Staff from Saudi Arabia and Southeast Turkey as Regional Conflict Escalates
Fanatics Moves Tom Brady Flag Football Showcase from Saudi Arabia to Los Angeles Amid Regional War
Saudi Arabia Seeks Strategic Support from Pakistan After Iranian Missile and Drone Attacks
Saudi Arabia Begins Oil Output Cuts as Hormuz Disruption Forces Storage Limits
Saudi Arabia Travel Advisory Tightened as Middle East War Triggers Regional Security Alerts
Saudi Arabia Warns Iran It Will Be ‘Biggest Loser’ as Drone Strikes Spread Across Gulf States
Lindsey Graham Urges Saudi Arabia to Join US Effort Against Iran as War Expands
Saudi Crown Prince Holds Strategic Calls With Spanish and Ukrainian Leaders Amid Regional Tensions
Kuwait’s Jazeera Airways Shifts Operations to Saudi Arabia Amid Regional Airspace Disruptions
Saudi Arabian Grand Prix: Why Jeddah’s Night Race Has Become One of Formula One’s Most Distinctive Events
F1 Leadership Addresses Bahrain and Saudi Arabia Races as Middle East Conflict Raises Safety Concerns
Zelenskyy Offers Saudi Crown Prince Assistance to Counter Iranian Drone Threat
Seventh U.S. Service Member Dies from Injuries After Iranian Strike in Saudi Arabia
Civilian Infrastructure Increasingly Hit as Iran Conflict Expands and Saudi Arabia Reports First Fatalities
Saudi Arabia Warns Iran to Halt Attacks and Signals Potential Retaliation
US Embassy in Riyadh Issues Security Alert Urging Americans to Shelter in Place Amid Regional Attacks
Projectile Strike on Saudi Residential Building Kills Two as Regional Conflict Expands
Saudi Arabia Warns Iran While Expanding Diplomatic Efforts to Contain Widening Middle East War
Iran’s President Rejects U.S. Surrender Demand as Drone and Missile Strikes Hit Gulf States
Saudi Arabia Intercepts Drone Swarm Targeting Strategic Shaybah Oil Field
Pakistan Faces Growing Pressure to Balance Ties With Iran and Saudi Arabia as Regional War Intensifies
Middle East Conflict Tests Mohammed bin Salman’s Vision to Transform Saudi Arabia Into a Global Hub
Proposed U.S.–Saudi Nuclear Deal Could Ease Traditional Nonproliferation Requirements
Iran Claims Strike on U.S.-Linked Oil Tanker Near Saudi Waters as Maritime Tensions Escalate
×