London Daily

Focus on the big picture.
Thursday, Jan 15, 2026

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

The threshold to determine whether an incident affecting energy companies is reportable has prevented any reports being made.

A cyber security law introduced three years ago was meant to boost the resilience of the UK's energy sector by obliging gas and electricity firms to report when they were hacked.

But since then not a single report has been made, Sky News can reveal, despite numerous successful hacks of British energy firms attributed to hostile states as well as criminal groups.

Ofgem, the authority that is meant to receive these reports, told Sky News that only one company has ever tried to file a report informing the regulator that it had been hacked, but they were dismissed as the incident did not meet the threshold for being reported.

Ofcom's incident thresholds are based on the impact of an attack on customers


Last year, staff at a little-known company called Elexon - a firm that plays a critical role in balancing and settling payments between power plants and electricity suppliers - was left locked out of its internal systems due to a ransomware attack.

The British government has confirmed that Russian state-sponsored hackers have successfully penetrated the computer networks of the UK's energy grids, without disrupting them.

Former defence secretary Gavin Williamson warned that "thousands and thousands and thousands" of people could be killed if an attempt at disruption was made.

But the high thresholds for companies working across the gas and electricity sectors to report cyber security incidents to Ofgem risks leaving the regulator blind to how the sector is actually coping in the face of these threats.

These thresholds are based on the impact of hacks to the continuity of the companies' services, a metric that does not record the sector's security capabilities, just the intentions of the attackers.

Dr Jamie Collier, a threat intelligence consultant at FireEye, told Sky News that the thresholds could be useful considering the varying levels of sophistication across attacks on critical infrastructure organisations, allowing defenders to "focus on what really matters".

But the cyber security expert added: "Despite this, essential service providers and regulators should be careful not to neglect the threat posed from less sophisticated attacks."

FireEye has detected an increase in critical infrastructure incidents caused by novice hackers due to the growing availability of tools enabling these hackers to interact with industrial control systems.

The company also warns that multiple, highly-prolific criminal organisations with a financial motivation are currently "active inside essential service provider networks with the intent of profiting from a ransom of stolen information and disrupted services".

FireEye warns that novice hackers are now targeting industrial control systems.


"Most of the concern around cyber security has been focused on operational technology (OT) networks that interact with physical processes and machinery, such as power plant equipment or water treatment facilities," Dr Collier explained.

"Yet the traditional information technology (IT) networks that involve the flow of data - such as file storage or email - should not be neglected. This is because whilst the impact of malicious activity can be far more severe against OT systems, these attacks typically start out on IT networks. It is therefore vital to consider security across an entire service provider's infrastructure."

Dr Collier stressed that critical infrastructure providers "deserve credit for their use of fail-safe mechanisms that can mitigate the destructive impacts of many attacks".

Responding to Sky News, a government spokesperson said: "The UK's critical infrastructure is extremely well protected and over the past five years we have invested £1.9bn in the National Cyber Security Strategy to ensure our systems remain secure and reliable."

They added that a formal review of the impact of the cyber security law, the Network & Information Systems Regulations, will take place within the next 12 months.

Newsletter

Related Articles

0:00
0:00
Close
UK Launches First-Ever ‘Town of Culture’ Competition to Celebrate Local Stories and Boost Communities
Planned Sale of Shell and Exxon’s UK Gas Assets to Viaro Energy Collapses Amid Regulatory and Market Hurdles
UK Intensifies Arctic Security Engagement as Trump’s Greenland Rhetoric Fuels Allied Concern
Meghan Markle Could Return to the UK for the First Time in Nearly Four Years If Security Is Secured
Meghan Markle Likely to Return to UK Only if Harry Secures Official Security Cover
UAE Restricts Funding for Emiratis to Study in UK Amid Fears Over Muslim Brotherhood Influence
EU Seeks ‘Farage Clause’ in Brexit Reset Talks to Safeguard Long-Term Agreement Stability
Starmer’s Push to Rally Support for Action Against Elon Musk’s X Faces Setback as Canada Shuns Ban
UK Free School Meals Expansion Faces Political and Budgetary Delays
EU Seeks ‘Farage Clause’ in Brexit Reset Talks With Britain
Germany Hit by Major Airport Strikes Disrupting European Travel
Prince Harry Seeks King Charles’ Support to Open Invictus Games on UK Return
Washington Holds Back as Britain and France Signal Willingness to Deploy Troops in Postwar Ukraine
Elon Musk Accuses UK Government of Suppressing Free Speech as X Faces Potential Ban Over AI-Generated Content
Russia Deploys Hypersonic Missile in Strike on Ukraine
OpenAI and SoftBank Commit One Billion Dollars to Energy and Data Centre Supplier
UK Prime Minister Starmer Reaffirms Support for Danish Sovereignty Over Greenland Amid U.S. Pressure
UK Support Bolsters U.S. Seizure of Russian-Flagged Tanker Marinera in Atlantic Strike on Sanctions Evasion
The Claim That Maduro’s Capture and Trial Violate International Law Is Either Legally Illiterate—or Deliberately Deceptive
UK Data Watchdog Probes Elon Musk’s X Over AI-Generated Grok Images Amid Surge in Non-Consensual Outputs
Prince Harry to Return to UK for Court Hearing Without Plans to Meet King Charles III
UK Confirms Support for US Seizure of Russian-Flagged Oil Tanker in North Atlantic
Béla Tarr, Visionary Hungarian Filmmaker, Dies at Seventy After Long Illness
UK and France Pledge Military Hubs Across Ukraine in Post-Ceasefire Security Plan
Prince Harry Poised to Regain UK Security Cover, Clearing Way for Family Visits
UK Junk Food Advertising Ban Faces Major Loophole Allowing Brand-Only Promotions
Maduro’s Arrest Without The Hague Tests International Law—and Trump’s Willingness to Break It
German Intelligence Secretly Intercepted Obama’s Air Force One Communications
The U.S. State Department’s account in Persian: “President Trump is a man of action. If you didn’t know it until now, now you do—do not play games with President Trump.”
Fake Mainstream Media Double Standard: Elon Musk Versus Mamdani
HSBC Leads 2026 Mortgage Rate Cuts as UK Lending Costs Ease
US Joint Chiefs Chairman Outlines How Operation Absolute Resolve Was Carried Out in Venezuela
Starmer Welcomes End of Maduro Era While Stressing International Law and UK Non-Involvement
Korean Beauty Turns Viral Skincare Into a Global Export Engine
UK Confirms Non-Involvement in U.S. Military Action Against Venezuela
UK Terror Watchdog Calls for Australian-Style Social Media Ban to Protect Teenagers
Iranian Protests Intensify as Another Revolutionary Guard Member Is Killed and Khamenei Blames the West
Delta Force Identified as Unit Behind U.S. Operation That Captured Venezuela’s President
Europe’s Luxury Sanctions Punish Russian Consumers While a Sanctions-Circumvention Industry Thrives
Berkshire’s Buffett-to-Abel Transition Tests Whether a One-Man Trust Model Can Survive as a System
Fraud in European Central Bank: Lagarde’s Hidden Pay Premium Exposes a Transparency Crisis at the European Central Bank
Trump Announces U.S. Large-Scale Strike on Venezuela, Declares President Maduro and Wife Captured
Tesla Loses EV Crown to China’s BYD After Annual Deliveries Decline in 2025
UK Manufacturing Growth Reaches 15-Month Peak as Output and Orders Improve in December
Beijing Threatened to Scrap UK–China Trade Talks After British Minister’s Taiwan Visit
Newly Released Files Reveal Tony Blair Pressured Officials Over Iraq Death Case Involving UK Soldiers
Top Stocks and Themes to Watch in 2026 as Markets Enter New Year with Fresh Momentum
No UK Curfew Ordered as Deepfake TikTok Falsely Attributes Decree to Prime Minister Starmer
Europe’s Largest Defence Groups Set to Return Nearly Five Billion Dollars to Shareholders in Twenty Twenty-Five
Abu Dhabi ‘Capital of Capital’: How Abu Dhabi Rose as a Sovereign Wealth Power
×