London Daily

Focus on the big picture.
Wednesday, Sep 23, 2026

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

The threshold to determine whether an incident affecting energy companies is reportable has prevented any reports being made.

A cyber security law introduced three years ago was meant to boost the resilience of the UK's energy sector by obliging gas and electricity firms to report when they were hacked.

But since then not a single report has been made, Sky News can reveal, despite numerous successful hacks of British energy firms attributed to hostile states as well as criminal groups.

Ofgem, the authority that is meant to receive these reports, told Sky News that only one company has ever tried to file a report informing the regulator that it had been hacked, but they were dismissed as the incident did not meet the threshold for being reported.

Ofcom's incident thresholds are based on the impact of an attack on customers


Last year, staff at a little-known company called Elexon - a firm that plays a critical role in balancing and settling payments between power plants and electricity suppliers - was left locked out of its internal systems due to a ransomware attack.

The British government has confirmed that Russian state-sponsored hackers have successfully penetrated the computer networks of the UK's energy grids, without disrupting them.

Former defence secretary Gavin Williamson warned that "thousands and thousands and thousands" of people could be killed if an attempt at disruption was made.

But the high thresholds for companies working across the gas and electricity sectors to report cyber security incidents to Ofgem risks leaving the regulator blind to how the sector is actually coping in the face of these threats.

These thresholds are based on the impact of hacks to the continuity of the companies' services, a metric that does not record the sector's security capabilities, just the intentions of the attackers.

Dr Jamie Collier, a threat intelligence consultant at FireEye, told Sky News that the thresholds could be useful considering the varying levels of sophistication across attacks on critical infrastructure organisations, allowing defenders to "focus on what really matters".

But the cyber security expert added: "Despite this, essential service providers and regulators should be careful not to neglect the threat posed from less sophisticated attacks."

FireEye has detected an increase in critical infrastructure incidents caused by novice hackers due to the growing availability of tools enabling these hackers to interact with industrial control systems.

The company also warns that multiple, highly-prolific criminal organisations with a financial motivation are currently "active inside essential service provider networks with the intent of profiting from a ransom of stolen information and disrupted services".

FireEye warns that novice hackers are now targeting industrial control systems.


"Most of the concern around cyber security has been focused on operational technology (OT) networks that interact with physical processes and machinery, such as power plant equipment or water treatment facilities," Dr Collier explained.

"Yet the traditional information technology (IT) networks that involve the flow of data - such as file storage or email - should not be neglected. This is because whilst the impact of malicious activity can be far more severe against OT systems, these attacks typically start out on IT networks. It is therefore vital to consider security across an entire service provider's infrastructure."

Dr Collier stressed that critical infrastructure providers "deserve credit for their use of fail-safe mechanisms that can mitigate the destructive impacts of many attacks".

Responding to Sky News, a government spokesperson said: "The UK's critical infrastructure is extremely well protected and over the past five years we have invested £1.9bn in the National Cyber Security Strategy to ensure our systems remain secure and reliable."

They added that a formal review of the impact of the cyber security law, the Network & Information Systems Regulations, will take place within the next 12 months.

Newsletter

Related Articles

0:00
0:00
Close
Piddington Residents Back Symbolic Independence Vote Over Asylum Accommodation Plan
Reform UK Names Helen Jenner as New Leader in Wales
England Expands Devolution of Transport, Skills and Economic Development Powers
Liberal Democrats Call for Temporary Fuel Duty Cut to Ease Cost-of-Living Pressure
UK Farmers Warn Drought Has Caused Crop Failures and Reduced Harvests
UK Fixed Mortgage Rates Approach 6% as Lenders Raise Borrowing Costs
YouGov Poll Puts Labour at 23% With Conservatives and Reform UK on 21%
Badenoch Presses Burnham to Increase Defence Spending and Cut Welfare Costs
UK Military Figures Warn of Growing Threats to Undersea Infrastructure and National Readiness
BP Moves Ahead With Sale of UK North Sea Oil and Gas Business
UK and ASEAN Endorse New Framework for Trade and Economic Cooperation
UK Consumer Confidence Falls to Three-Year Low as Borrowing Costs and Job Concerns Rise
UK Inflation Rises to 3.1% as Motor Fuel Costs Push Prices Higher
Bank of England Sets Multi-Year Plan to Wind Down Quantitative Easing Holdings
UK Borrowing Rises to £18.3 Billion in August Ahead of October Budget
Michelin Guide Faces Industry Questions Over Restaurant Inspection Coverage
English Woodlands Face Renewed Weather Stress From Dry Conditions and Strong Winds
Research Finds Extensive Alcohol, Gambling and Unhealthy Food Branding During 2026 World Cup
Five Charged After Newborn Baby Dies From Stab Wounds in Sheffield
BT Could Reap £2 Billion From Recycling Copper as Full-Fibre Network Expands
FCA Urges Young Adults to Trace £1.5 Billion in Unclaimed Child Trust Funds
Reform UK Names Helen Jenner as New Leader in Wales After Dan Thomas Steps Down
Resolution Foundation Calls for Broad-Based Tax Rises to Fund Higher UK Defence Spending
Ed Davey Calls for Global Treaty to Halt Development of Super-Intelligent AI
Scotland Consults on Legal Price Caps for Essential Foods
NHS Productivity Reforms Could Prevent More Than 20,000 Early Deaths a Year, Report Says
United Kingdom and ASEAN Deepen Trade and Investment Cooperation
United Kingdom Deploys RAF Refuelling Support to Saudi Arabia After Houthi Attacks
UK Fiscal Headroom Shrinks as Higher Borrowing Costs Complicate Autumn Budget
UK Public Borrowing Jumps to £18.3 Billion in August, Raising Pressure Before Budget
Andy Burnham Reaffirms UK Net-Zero Target With £30 Million Community Energy Fund
Scottish Labour Leader Backs Rosebank and Jackdaw North Sea Projects
UK Consumer Confidence Falls to Three-Year Low
UK Diesel Prices Approach £2 a Litre as Global Supply Shortages Intensify
Chiltern Railways Returns to Public Ownership as UK Rail Nationalisation Advances
British Museum Faces Questions Over Peter Thiel’s Private Bayeux Tapestry Viewing
Earl Spencer Memoir Excerpts Renew Public Debate Over Diana’s Death
Liberal Democrats Gather in Brighton for Autumn Conference
Mothercare Shares Plunge as Middle East Store Closures Threaten Long-Term Solvency
Kent Police Treat Folkestone Hotel Fire as Suspicious
Caribbean Governments Advance Reparations Campaign Seeking Engagement With Britain
Scottish Labour Leader Backs Rosebank and Jackdaw North Sea Projects
FCA Urges Young Adults to Trace £1.5 Billion in Unclaimed Child Trust Funds
UK Competition Regulator Opens Inquiry Into McCormick-Unilever Foods Deal
Public Inquiry Into Tees, Esk and Wear Valleys Mental Health Failings Set to Begin
Nigel Farage Looks to US Immigration Enforcement Model for UK Border Policy
Chiltern Railways Moves Into Public Ownership
Security Review Raises Concerns Over Sensitive UK Police Data Stored on Microsoft Cloud
Burnham Government Warns of Difficult Autumn Budget as Fiscal Headroom Narrows
Bank of England Holds Rates at 3.75% as Inflation Rises to 3.1%
×