Britain’s hundreds of small power plants face elevated cyber risk into the 2030s despite a recent Iran-linked attack that shut a plant for four days.
Government plans call for the regulator Ofgem to set out proposals by the end of 2027 and for baseline requirements to be implemented by the end of 2030, a timeline industry briefings have not been reported as changing has not altered this timeline.
The government opened a consultation into generator cyber resilience in March and has put a cyber security and resilience bill before parliament, reflecting warnings that the UK now faces four nationally significant cyber-attacks every week.
Calum Miller, the Lib Dems’ foreign affairs spokesperson, said: “Leaving hundreds of small power generators exposed to cyber threats until the 2030s is simply an unacceptable gamble with our national security.”
Industry specialists warned the incident exposed how many distributed, often unmanned gas plants contribute to the system and that attackers do not necessarily select targets by size, instead seeking vulnerabilities and trusted access.
A government spokesperson said the UK has a highly resilient energy system and is working with the sector to raise standards.