Commodities
Home›Commodities›Energy›UK delays tougher cybersecurity rules for small power…
UK delays tougher cybersecurity rules for small power plants until 2030
A July Iran-linked hack reportedly shut an unnamed small gas power plant for four days, but the government says the baseline cybersecurity standards rollout still runs through the end of 2030.
Britain faces continued cyber risk for hundreds of smaller power plants connected to the wider grid, even after an Iran-linked hack last month, according to The Guardian Business. Officials briefed energy bosses on the breach and alerted the industry to escalating threats targeting energy infrastructure.
The hack is understood to have shut an unnamed small gas power plant for four days in July, and experts warn such smaller, often locally connected sites could be targeted if they appear vulnerable. The outage did not affect the overall electricity system, but it raised concerns about security gaps in local power infrastructure.
The government’s plan to strengthen baseline cybersecurity standards for Britain’s smallest power generators is not due until the end of 2030. Government documents published this month call for Ofgem, the industry regulator, to outline proposals for new baseline cyber resilience requirements for gas and electricity infrastructure by the end of 2027, ahead of implementing the new standards by the end of 2030.
The reporting also notes the Cabinet Office is preparing to urge the public to stock up on tinned food and bottled water amid extreme weather concerns and potential attacks from hostile states. The Guardian Business adds that it understands the July hack has not changed the government’s timeline.