SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
Iranian-linked cyber attack exposes UK energy flaws

Iranian-linked cyber attack exposes UK energy flaws

Tue, 25th Aug 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Cybersecurity specialists have warned that an Iranian-linked cyber attack that forced a small UK power plant offline highlights systemic weaknesses in the country's increasingly digital energy infrastructure. The UK government has attributed the incident to a state-aligned group accused of targeting critical infrastructure organisations.

The attack forced the privately owned generator to shut down for several days. The outage did not disrupt the wider grid, but security experts said it showed how relatively modest assets can pose broader systemic risks as the electricity system becomes more decentralised and more reliant on remote-access technologies.

Rafael Narezzi, Chief Executive Officer of Centrii, said focusing on the size of the site risked missing the broader problem of distributed vulnerability across the sector.

"Attackers do not necessarily select their targets according to how many megawatts they generate. They look for vulnerabilities, trusted access and opportunities.

"What concerns me about this incident is not necessarily the size of the power generator that was affected, but how many others may be out there," Narezzi said.

He pointed to the complex mix of operators and technologies that now underpin the UK's generation fleet.

"Across the UK energy system we have small, medium and large generation assets, increasingly connected through digital systems, remote access, third parties and operational technology. This particular incident may not have had consequences for the wider grid, but the next one could be different," he said.

Investigators are still assessing the exact route of intrusion, but security companies said the case fits a broader pattern of state-linked actors probing industrial systems and looking for repeatable weaknesses in operational technology.

Rob Demain, Chief Executive Officer of e2e-assure, said the industry should avoid drawing sweeping conclusions about grid-level risk while still treating the incident as a serious warning.

"At this time, we don't know much about the attack beyond that the power plant experienced downtime, which could have been a direct effect of the attack, part of the defensive response, or a combination of both. What it does demonstrate is that state-linked actors have both the intent and capability to target relatively ordinary industrial technology and are establishing access within the technology underpinning CNI that could potentially be used to cause disruption in future conflicts.

"The conclusion, however, should not be that Iranian hackers have demonstrated an ability to switch off Britain's whole electrical grid. But it does highlight the challenges the industry is facing. The electricity system is becoming increasingly distributed and, while one asset is of little consequence, a weakness repeated across hundreds of similar assets could compound into a significant problem because of the technology and suppliers the grid relies on," Demain said.

Narezzi said the incident showed how quickly a cyber event inside a single facility can lead to operational disruption.

"A small generator being taken offline for four days demonstrates something important: a cyber incident can move beyond IT and have a direct physical and operational consequence on energy infrastructure," he said.

He also argued that a narrow focus on large utilities leaves gaps that well-resourced attackers can exploit.

"Cybersecurity in critical infrastructure therefore cannot focus only on the very largest power stations or organisations. Attackers do not necessarily select their targets according to how many megawatts they generate. They look for vulnerabilities, trusted access and opportunities," Narezzi said.

Experts said many industrial networks still rely on older software and control systems, complicating patching and incident response.

"How they got into the power plant isn't currently clear, but it doesn't necessarily have to have been a sophisticated attack. CNI is vulnerable to all sorts of basic security challenges: exposed internet-facing devices, compromised remote-access credentials, vulnerable gateways or compromised third-party accounts.

"The challenge with securing operational technology is that it runs on legacy software that can't be easily patched remotely, and operators always have to weigh the operational and safety consequences of intervening, as an outage or downtime could threaten safety," Demain said.

Narezzi said the shift towards a more distributed grid means the resilience of many small units now carries system-level importance.

"The UK has thousands of distributed assets increasingly contributing to how our energy system operates. Individually, many may appear insignificant. Collectively, their resilience matters enormously," he said.

The government has set out new measures in the Cyber Security and Resilience Bill to update rules for critical infrastructure operators and their suppliers. Narezzi said any framework must cover smaller operators and complex supply chains, not just major utilities.

"That is why the Cyber Security and Resilience Bill is so important. We need to ensure that the legislation evolves to provide appropriate protection across the ecosystem of organisations and technologies on which our vital services depend, including the supply chain and smaller operators where compromise could ultimately have consequences far beyond an individual site," he said.

Beyond the UK incident, security specialists said recent activity targeting utilities in Europe and North America points to longer-term strategic campaigns by hostile states.

Simon Hodgkinson, Strategic Advisor at Semperis and former Chief Information Security Officer at bp, said many operations appear designed to test defences or establish persistence rather than cause immediate disruption.

"Many of the cyberattacks on electricity and water utilities are opening salvos, carried out either to gauge the effectiveness of a nation's cybersecurity defences or to plant backdoors for future attacks. It isn't surprising that Semperis found in a recent research report that 62% of electricity and water utilities in the UK and US were victimised by cyberattacks.

"These attacks are likely a precursor to future disruption. Utilities should adopt an assume-breach mindset and prepare to respond to and securely recover from attacks that target and hide in critical parts of the infrastructure. All critical infrastructure operators need attack-detection capabilities that provide visibility into both sophisticated and stealthy intrusions.

"Overall, embracing an assume-breach mindset is crucial for rapid recovery from cyberattacks. At the same time, implementing identity forensics and incident response capabilities enhances operational resilience, ensuring that identity systems remain secure against evolving threats. In an environment where regulations like DORA, GDPR and NIST mandate robust identity protection and swift breach response, IFIR provides a proactive, structured framework that helps minimise business disruptions and safeguard critical infrastructure from compromise," Hodgkinson said.

Demain said operators can still take immediate, low-cost steps while longer-term upgrades proceed.

"Replacing legacy systems takes time and has to be done with a lot of thought and care, but operators can't accept exposure in the meantime. They must balance moving carefully when changing the plant with moving quickly to reduce the risk around it.

"Immediate steps can be as simple as identifying what is internet-facing, removing unnecessary remote-access paths, disabling dormant supplier accounts, rotating weak or compromised credentials and restricting who can reach operational systems. The question to take from this incident is not how to protect one small generator, but whether the same route into that generator exists across 50 others and, while we work carefully on the permanent fix, whether we are moving fast enough to stop somebody using it first," he said.

Narezzi said the attack did not endanger national supply but should prompt faster action across the sector.

"This incident did not threaten the grid. We should use it as a warning rather than wait for one that does," he said.