London Daily

Focus on the big picture.
Friday, Mar 06, 2026

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

The threshold to determine whether an incident affecting energy companies is reportable has prevented any reports being made.

A cyber security law introduced three years ago was meant to boost the resilience of the UK's energy sector by obliging gas and electricity firms to report when they were hacked.

But since then not a single report has been made, Sky News can reveal, despite numerous successful hacks of British energy firms attributed to hostile states as well as criminal groups.

Ofgem, the authority that is meant to receive these reports, told Sky News that only one company has ever tried to file a report informing the regulator that it had been hacked, but they were dismissed as the incident did not meet the threshold for being reported.

Ofcom's incident thresholds are based on the impact of an attack on customers


Last year, staff at a little-known company called Elexon - a firm that plays a critical role in balancing and settling payments between power plants and electricity suppliers - was left locked out of its internal systems due to a ransomware attack.

The British government has confirmed that Russian state-sponsored hackers have successfully penetrated the computer networks of the UK's energy grids, without disrupting them.

Former defence secretary Gavin Williamson warned that "thousands and thousands and thousands" of people could be killed if an attempt at disruption was made.

But the high thresholds for companies working across the gas and electricity sectors to report cyber security incidents to Ofgem risks leaving the regulator blind to how the sector is actually coping in the face of these threats.

These thresholds are based on the impact of hacks to the continuity of the companies' services, a metric that does not record the sector's security capabilities, just the intentions of the attackers.

Dr Jamie Collier, a threat intelligence consultant at FireEye, told Sky News that the thresholds could be useful considering the varying levels of sophistication across attacks on critical infrastructure organisations, allowing defenders to "focus on what really matters".

But the cyber security expert added: "Despite this, essential service providers and regulators should be careful not to neglect the threat posed from less sophisticated attacks."

FireEye has detected an increase in critical infrastructure incidents caused by novice hackers due to the growing availability of tools enabling these hackers to interact with industrial control systems.

The company also warns that multiple, highly-prolific criminal organisations with a financial motivation are currently "active inside essential service provider networks with the intent of profiting from a ransom of stolen information and disrupted services".

FireEye warns that novice hackers are now targeting industrial control systems.


"Most of the concern around cyber security has been focused on operational technology (OT) networks that interact with physical processes and machinery, such as power plant equipment or water treatment facilities," Dr Collier explained.

"Yet the traditional information technology (IT) networks that involve the flow of data - such as file storage or email - should not be neglected. This is because whilst the impact of malicious activity can be far more severe against OT systems, these attacks typically start out on IT networks. It is therefore vital to consider security across an entire service provider's infrastructure."

Dr Collier stressed that critical infrastructure providers "deserve credit for their use of fail-safe mechanisms that can mitigate the destructive impacts of many attacks".

Responding to Sky News, a government spokesperson said: "The UK's critical infrastructure is extremely well protected and over the past five years we have invested £1.9bn in the National Cyber Security Strategy to ensure our systems remain secure and reliable."

They added that a formal review of the impact of the cyber security law, the Network & Information Systems Regulations, will take place within the next 12 months.

Newsletter

Related Articles

0:00
0:00
Close
Iceland Supermarket Drops Trademark Challenge Against Icelandic Government in Long-Running Naming Dispute
UK Defence Secretary Visits Cyprus Following Scrutiny of Britain’s Response to Drone Attacks
Questions Grow Over Britain’s Military Readiness as Response to Iran Conflict Draws Scrutiny
UK Offers Failed Asylum Seeker Families Up to Forty Thousand Pounds to Leave Voluntarily
Saharan Dust Could Bring ‘Blood Rain’ to Parts of the UK as Weather Systems Shift
UK Deploys Additional Typhoon Fighter Jets to Qatar and Helicopters to Cyprus Amid Rising Middle East Tensions
Experts Urge Britain to Accelerate Renewable Energy Push as Global Conflicts Drive Up Costs
British Public Shows Strong Reluctance to Join Wider War in Iran
First UK Evacuation Flight Departs Middle East After Lengthy Delay
United Kingdom Imposes New Visa Requirements on Travelers from St. Lucia and Nicaragua
Iran Conflict Strains U.S.–U.K. Alliance as Trump and Starmer Clash Over Military Strategy
UK Interest Rates Could Rise Above Four Percent Again if Energy Shock Continues, Think Tank Warns
Starmer Defends Britain’s Iran Strategy as Badenoch Urges Stronger Military Support
Labour MP Says She Saw No Sign Husband Broke Law After Arrest in China Espionage Investigation
UK Jobless Rate Overtakes Italy’s for First Time in Years as Labour Market Weakens
United Kingdom Suspends Student Visas for Four Countries in Unprecedented Immigration Move
Campaigners Warn UK Student Visa Ban Could Push Migrants Toward Dangerous Channel Crossings
First U.K. Charter Flight for Stranded Nationals Set to Depart Oman Amid Middle East Crisis
France and United Kingdom Deploy Warships to Eastern Mediterranean as Middle East Conflict Escalates
U.K. Arrests Three Men Including Lawmaker’s Partner in Suspected China Espionage Investigation
Trump Says UK–US ‘Special Relationship’ Is Diminished Amid Middle East Dispute
UK Economic Forecasts Face Fresh Strain from Middle East Conflict and Rising Energy Costs
UK Reaffirms Close US Ties After Trump’s Public Criticism
Reeves Stresses Stability and Fiscal Discipline in UK Budget Update as Growth Outlook Shifts
UK Deploys Royal Navy Destroyer HMS Dragon to Cyprus After Drone Strike on RAF Base
Green Party Surges Past Labour in New UK Poll as Traditional Party Support Crumbles
Majority of Britons Oppose U.S. Use of UK Military Bases in Iran Conflict
UK Intensifies Evacuation Efforts from Oman, Working with Airlines to Boost Flight Capacity
Trump Condemns UK and Spain in Unusually Sharp Rift Over Iran Military Action
Trump Repeats UK Claims That Diverge from Verified Facts Amid Diplomatic Strain
UK Arrests Prominent Figures Linked to Epstein Network as Questions Mount Over US Action
Trump Says UK ‘Took Far Too Long’ to Approve Use of Airbases for Iran Strikes
Scope of Britain’s Role in the Expanding Middle East Conflict Comes Under Scrutiny
Trump Says He Is ‘Very Disappointed’ in Starmer Over Iran Comments
U.S. Embassy in Riyadh Struck by Drones Amid Escalating Iran Conflict
Starmer Confronts Strategic Test After Drone Strike Near British Base in Cyprus
Rolls-Royce Chief Signals Openness to Germany Joining UK-Led Fighter Jet Programme
UK Stocks Slip as Escalating Iran Conflict Triggers Global Market Selloff
UK Overhauls Asylum System to Make Refugee Status Temporary
Starmer Warns of ‘Reckless’ Iranian Strikes Amid Escalating Regional Tensions
British Base in Cyprus Targeted as Drones Intercepted Amid Expanding Iran Conflict
Starmer Diverges from Trump on Iran Strategy, Rejects ‘Regime Change from the Skies’
U.S. and Israel Intensify Strikes on Iran as Conflict Expands to Lebanon and Gulf States
Violent Pro-Iranian Protesters Storm U.S. Consulate in Karachi
Missile Debris Sparks Fires at Dubai’s Jebel Ali Port Near Palm Jumeirah
Iran Strikes U.S. Fifth Fleet Headquarters in Bahrain Amid Wider Gulf Retaliation
When the State Replaces the Parent: How Gender Policy Is Redefining Custody and Coercion
Bill Clinton Denies Knowing Woman in Hot Tub Photo During Closed-Door Epstein Deposition
Former U.S. President Bill Clinton Testifies on Ties to Jeffrey Epstein Before Congressional Oversight Committee
Dyson Reaches Settlement in Landmark UK Forced Labour Case
×