UK Small Power Plants Face Cyber Threat Until 2030s
Authorities warned the energy sector following an Iran-linked cyberattack, but concerns are raised as new security standards planned for small power plants will not come into force until 2030.
Following an Iran-linked cyberattack last month that knocked out a small gas power plant in the UK, it has emerged that the country's smallest power facilities could remain vulnerable to state-backed cyber threats into the 2030s.
Cyber Attack and Sector Warning
Officials briefed energy executives this week on the cyber breach that shut down an unnamed small gas plant for four days last month. The incident has put the sector on high alert against cyber threats facing energy infrastructure.
Across the UK, there are hundreds of small-scale, unmanned gas facilities connected to local electricity grids. Although the outage had no adverse impact on the electrical system, it highlighted vulnerabilities in local infrastructure that lack the stringent security standards of larger-scale facilities.
Delayed Security Standards and Timeline
The government's own plan to toughen baseline cybersecurity standards for the smallest electricity generators in the UK will not be made mandatory until the end of 2030, which is considered an unacceptable gamble for national security.
Official government documents outline that Ofgem is to draft new baseline cyber resilience requirements for gas and electricity infrastructure by the end of 2027, with the new standards implemented by the end of 2030.
Political Reactions and Assessments
Liberal Democrat foreign affairs spokesperson Calum Miller criticized the prolonged timeline for implementing cybersecurity standards, describing the situation as an unacceptable risk. Experts and politicians argue that the process must be accelerated to protect local infrastructure.