London Daily

Focus on the big picture.
Tuesday, Aug 04, 2026

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

The threshold to determine whether an incident affecting energy companies is reportable has prevented any reports being made.

A cyber security law introduced three years ago was meant to boost the resilience of the UK's energy sector by obliging gas and electricity firms to report when they were hacked.

But since then not a single report has been made, Sky News can reveal, despite numerous successful hacks of British energy firms attributed to hostile states as well as criminal groups.

Ofgem, the authority that is meant to receive these reports, told Sky News that only one company has ever tried to file a report informing the regulator that it had been hacked, but they were dismissed as the incident did not meet the threshold for being reported.

Ofcom's incident thresholds are based on the impact of an attack on customers


Last year, staff at a little-known company called Elexon - a firm that plays a critical role in balancing and settling payments between power plants and electricity suppliers - was left locked out of its internal systems due to a ransomware attack.

The British government has confirmed that Russian state-sponsored hackers have successfully penetrated the computer networks of the UK's energy grids, without disrupting them.

Former defence secretary Gavin Williamson warned that "thousands and thousands and thousands" of people could be killed if an attempt at disruption was made.

But the high thresholds for companies working across the gas and electricity sectors to report cyber security incidents to Ofgem risks leaving the regulator blind to how the sector is actually coping in the face of these threats.

These thresholds are based on the impact of hacks to the continuity of the companies' services, a metric that does not record the sector's security capabilities, just the intentions of the attackers.

Dr Jamie Collier, a threat intelligence consultant at FireEye, told Sky News that the thresholds could be useful considering the varying levels of sophistication across attacks on critical infrastructure organisations, allowing defenders to "focus on what really matters".

But the cyber security expert added: "Despite this, essential service providers and regulators should be careful not to neglect the threat posed from less sophisticated attacks."

FireEye has detected an increase in critical infrastructure incidents caused by novice hackers due to the growing availability of tools enabling these hackers to interact with industrial control systems.

The company also warns that multiple, highly-prolific criminal organisations with a financial motivation are currently "active inside essential service provider networks with the intent of profiting from a ransom of stolen information and disrupted services".

FireEye warns that novice hackers are now targeting industrial control systems.


"Most of the concern around cyber security has been focused on operational technology (OT) networks that interact with physical processes and machinery, such as power plant equipment or water treatment facilities," Dr Collier explained.

"Yet the traditional information technology (IT) networks that involve the flow of data - such as file storage or email - should not be neglected. This is because whilst the impact of malicious activity can be far more severe against OT systems, these attacks typically start out on IT networks. It is therefore vital to consider security across an entire service provider's infrastructure."

Dr Collier stressed that critical infrastructure providers "deserve credit for their use of fail-safe mechanisms that can mitigate the destructive impacts of many attacks".

Responding to Sky News, a government spokesperson said: "The UK's critical infrastructure is extremely well protected and over the past five years we have invested £1.9bn in the National Cyber Security Strategy to ensure our systems remain secure and reliable."

They added that a formal review of the impact of the cyber security law, the Network & Information Systems Regulations, will take place within the next 12 months.

Newsletter

Related Articles

0:00
0:00
Close
Reform UK Wants the Royal Navy to Return Channel Boats to France
US and Japan Step In to Support the Yen in Rare Joint Intervention
The AI Pricing Problem: Companies Cannot Predict Their Own Bills
Europe’s Heat and Drought Are Now Disrupting Power, Shipping and Tourism
Apple’s OpenAI Lawsuit Becomes a Public Fight Over AI Hardware
UK Man Jailed After Keeping His Mother’s Body in a Freezer and Claiming £78,000
A SpaceX Rocket Is About to Crash Into the Moon — and Scientists Hope to Watch
World War II munitions discovered after wildfires in southern France
BP profits reach four-year high amid Middle East conflict
Europe’s Drying Rivers Trigger Power Cuts, Factory Shutdowns and Wildfire Emergencies
UK Driver Sentenced to Four Years for Staged Electric Vehicle Brake Failure Fraud
Conservative Party and Reform UK Face Scrutiny During Clacton By-Election Campaign
Ministry of Justice Reviews Early Release Rules After Public Anger Over Police Killer Cases
NHS Radiographers Report Rising Racist Abuse From Patients Across UK Hospitals
UK Banking Regulators Face Pressure After Customer Loses Fourteen Thousand Pounds in AI Voice Scam
Research Challenges Treasury Control Over UK Public Spending and Calls for Greater Local Decision-Making
Home Office Begins Four-Week Weapons Surrender Campaign Across Major English Cities
Southern England Records Driest July in Nearly Two Centuries as Drought Concerns Grow
Apple Challenges UK Government Request for Access to Encrypted User Data in Legal Fight
BP Reports Sharp Profit Increase as Middle East Conflict Drives Global Oil Prices Higher
Nigel Farage Expresses Openness to Potential Alliance with Restore Britain
AstraZeneca Merger Talks Reflect Intensifying Pharmaceutical Consolidation
University Merger May Set Template for Higher Education Reform
Apple's Legal Challenge Highlights Growing Tension Over Encryption and Surveillance
Prime Minister Andy Burnham's Agenda Signals Shift Toward Greater Regional Devolution
Mental Health Trust Faces Criticism Over Planned £25 Million Budget Cuts
Scientists and Cultural Leaders Call for Funding to Save Jodrell Bank Observatory
UK Manufacturing Output Reaches Highest Level in Nearly Two Years
University of Greenwich and University of Kent Complete Landmark Merger
Nigel Farage Unveils Naval Border Proposal Amid Questions Over £5 Million Donation
Prime Minister Andy Burnham Pledges Tougher Action on Small Boat Crossings
Apple Challenges UK Government Over Encrypted Data Access Demands
AstraZeneca Shares Fall After Reports of $400 Billion Bristol Myers Squibb Merger Talks
Triple Lock Lifts UK State Pension but Leaves a Wider Retirement Gap
Danube Drought Forces Hungary’s Paks Nuclear Plant Into Full Shutdown
Ceuta Death Toll Rises as Spain and Europe Clash Over Border Response
Cuba’s Grid Fails Again as Fuel Crisis Deepens
Nazca Lines Flight Crash Kills Thirteen as Peru Suspends Aerodiana
Modern Slavery Decisions Broaden the Al Fayed Inquiry’s Frame
FIFA’s Retreat Leaves a Larger Question Over Who Guards the Game
Two Firefighting Crew Members Die in Helicopter Collision West of Athens
Public Sector Automation Through Artificial Intelligence
Regional Investment Beyond London
Protection of Strategic Technology Assets
UK Competition Regulator Blocks Major Foreign Takeover of British Quantum Computing Firm
UK Government Commits Two Billion Pounds to Modernise Northern Rail Network
UK Parliament Approves Planning Reforms to Accelerate Housing Construction on Green Belt Land
Scotland Approves Major Floating Offshore Wind Expansion in the North Sea
United Kingdom and European Union Sign Defence and Critical Minerals Cooperation Agreement
NHS Invests Five Hundred Million Pounds in Artificial Intelligence Diagnostics to Reduce Waiting Lists
×