London Daily

Focus on the big picture.
Thursday, Sep 03, 2026

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

The threshold to determine whether an incident affecting energy companies is reportable has prevented any reports being made.

A cyber security law introduced three years ago was meant to boost the resilience of the UK's energy sector by obliging gas and electricity firms to report when they were hacked.

But since then not a single report has been made, Sky News can reveal, despite numerous successful hacks of British energy firms attributed to hostile states as well as criminal groups.

Ofgem, the authority that is meant to receive these reports, told Sky News that only one company has ever tried to file a report informing the regulator that it had been hacked, but they were dismissed as the incident did not meet the threshold for being reported.

Ofcom's incident thresholds are based on the impact of an attack on customers


Last year, staff at a little-known company called Elexon - a firm that plays a critical role in balancing and settling payments between power plants and electricity suppliers - was left locked out of its internal systems due to a ransomware attack.

The British government has confirmed that Russian state-sponsored hackers have successfully penetrated the computer networks of the UK's energy grids, without disrupting them.

Former defence secretary Gavin Williamson warned that "thousands and thousands and thousands" of people could be killed if an attempt at disruption was made.

But the high thresholds for companies working across the gas and electricity sectors to report cyber security incidents to Ofgem risks leaving the regulator blind to how the sector is actually coping in the face of these threats.

These thresholds are based on the impact of hacks to the continuity of the companies' services, a metric that does not record the sector's security capabilities, just the intentions of the attackers.

Dr Jamie Collier, a threat intelligence consultant at FireEye, told Sky News that the thresholds could be useful considering the varying levels of sophistication across attacks on critical infrastructure organisations, allowing defenders to "focus on what really matters".

But the cyber security expert added: "Despite this, essential service providers and regulators should be careful not to neglect the threat posed from less sophisticated attacks."

FireEye has detected an increase in critical infrastructure incidents caused by novice hackers due to the growing availability of tools enabling these hackers to interact with industrial control systems.

The company also warns that multiple, highly-prolific criminal organisations with a financial motivation are currently "active inside essential service provider networks with the intent of profiting from a ransom of stolen information and disrupted services".

FireEye warns that novice hackers are now targeting industrial control systems.


"Most of the concern around cyber security has been focused on operational technology (OT) networks that interact with physical processes and machinery, such as power plant equipment or water treatment facilities," Dr Collier explained.

"Yet the traditional information technology (IT) networks that involve the flow of data - such as file storage or email - should not be neglected. This is because whilst the impact of malicious activity can be far more severe against OT systems, these attacks typically start out on IT networks. It is therefore vital to consider security across an entire service provider's infrastructure."

Dr Collier stressed that critical infrastructure providers "deserve credit for their use of fail-safe mechanisms that can mitigate the destructive impacts of many attacks".

Responding to Sky News, a government spokesperson said: "The UK's critical infrastructure is extremely well protected and over the past five years we have invested £1.9bn in the National Cyber Security Strategy to ensure our systems remain secure and reliable."

They added that a formal review of the impact of the cyber security law, the Network & Information Systems Regulations, will take place within the next 12 months.

Newsletter

Related Articles

0:00
0:00
Close
UK Marks Merchant Navy Day With Tribute to Civilian Seafarers
Burnham Pays Tribute to Two Police Officers Killed on Duty in Northern England
Booking.com Left Fake Downing Street Listing Online for Two Months, Which Says
Burnham and Macron to Review UK-France Cooperation on Channel Crossings
UK Business Confidence Improves Slightly but Investment Concerns Persist
Burnham Faces Pressure Over Future North Sea Oil and Gas Licences
Burnham Pushes Wider English Devolution Through ‘Number Ten North’
British Chambers of Commerce Raises 2026 UK Growth Forecast to 1%
Keir Starmer Resigns as Holborn and St Pancras MP, Triggering By-Election
UK Chancellor Faces Tighter Budget Headroom as Long-Term Borrowing Costs Rise
UK Government Weighs Thames Water Nationalisation as Financial Crisis Deepens
Prime Minister Andy Burnham Faces First Commons Questions Over Tax and Spending Plans
Eleven British Seafarers Receive Merchant Navy Medal
Which? Creates Fake 10 Downing Street Rental Listing to Expose Booking.com Vetting Weaknesses
BP Appoints New Chairman in Effort to Stabilise Leadership
Aberdeen Sells Hydrogen Bus Fleet at Heavy Loss After Green Transport Experiment
UK Records Hottest Summer on Record as Climate Change Intensifies Extreme Heat
Scotland Pledges to End Temporary Accommodation for Children and Build 111,000 Affordable Homes
DNO Agrees $396 Million Deal to Acquire Capricorn Energy
Uber and Wayve Launch UK’s First Supervised Autonomous Ride-Hailing Service in London
Britain Expected to Avoid New US Tariffs Targeting European Union
Middle East Conflict Pushes UK Energy Costs Higher and Revives Inflation Concerns
UK Growth Forecast Cut to 1% Through 2027 as Youth Unemployment Is Projected to Rise
Andy Burnham Links Weak UK Growth to Brexit in First Full Commons Session as Prime Minister
Keir Starmer Resigns as MP, Triggering Holborn and St Pancras By-Election
UK Business Confidence Improves but Remains Deeply Negative
Aberdeen Hydrogen Bus Sale Recovers Just Six Pence for Every Pound Invested
Which? Exposes Booking.com Verification Failures With Fake 10 Downing Street Listing
British Business Bank Invests Up to £46 Million in Deep-Tech Startup Fund
Scottish Government Puts Violence Against Women at Center of Legislative Program
FCA Eases UK IPO Rules to Strengthen London’s Listing Market
UK Likely to Avoid Next US Tariff Measures as Washington Targets EU
Macron Visits UK for Bayeux Tapestry Exhibition and Border Security Talks
British Chambers of Commerce Cuts UK Growth Outlook to 1% for 2026 and 2027
Keir Starmer Resigns as MP for Holborn and St Pancras, Triggering By-Election
Prime Minister Andy Burnham Unveils Devolution and Cost-of-Living Agenda
UK Borrowing Costs Surge as 30-Year Gilt Yield Reaches 5.88%
Cleveland Police Receive £2 Million to Tackle Serious Crime in Middlesbrough
Number of Young People in England Without a Close Friend Reaches Record Level
Five Arrested After Newborn Baby Dies From Stab Wounds in Sheffield
Nigel Farage Faces Questions Over Reported Second Parliamentary Standards Investigation
UK Retirement Funding Requirement Rises by £64,000 Compared With 2021
UK House Prices Rise for First Time Since April, Nationwide Says
FCA Chief Faces Allegations of Intimidating Consumer Group Over £9 Billion Car Loan Inquiry
Scottish Government Presses Ahead With Cap on Essential Food Prices
Burnham Government Moves to Overhaul Early Prison Release Scheme
UK Records Hottest Summer on Record in 2026, Met Office Says
UK Government Announces Major Reset of Diplomatic Policy Towards Israel
UK Pushes Back After Trump Reopens Falkland Islands Sovereignty Dispute
Keir Starmer Resigns as MP, Triggering Holborn and St Pancras By-Election
×