On 22 August 2026 The Telegraph reported that a cyberattack had forced a British power-generating facility offline for four consecutive days in July 2026, and that British intelligence assessments linked the activity to hackers associated with the Iranian regime, most likely the IRGC. Wider coverage followed on 23 and 24 August. It has been described as the first successful attack of its kind to take UK energy generation offline.
The government’s response was narrow and precise. Michael Shanks, Minister of State at the Department for Energy Security and Net Zero, confirmed that the incident affected a “small-scale energy generator”, that there was no threat to the wider grid, and that nobody lost power. The incident was reported to the NCSC. The facility has not been named. Neither the government nor the NCSC has issued a formal attribution to Iran or to any named threat group; the Iranian link rests on press reporting of intelligence assessments, and should be read that way.
Two qualifiers in the ministerial statement are doing a great deal of work, and they point in opposite directions.
“No threat to the wider grid” is a statement about consequence, and it appears to be accurate.
“Small-scale energy generator” is a statement about the victim — and in UK cyber regulation, size is not a description. It is a jurisdictional test. It determines whether a generator has any statutory cyber security duties at all.
That is the compliance story. Not that a power plant went down, but that the plant most likely went down while sitting outside the perimeter of the regulation written to prevent exactly this.
How the NIS Regulations 2018 decide who is regulated
The Network and Information Systems Regulations 2018 (SI 2018/506) do not apply to the energy sector at large. They apply to specific entities that have been identified as operators of essential services (OES) under Regulation 8, and identification runs through Schedule 2.
Schedule 2 is a table. For each sector and subsector it names the essential service, the type of entity, and — critically — a threshold requirement. An entity that provides the essential service but does not meet the threshold is not an OES. It is not partially regulated, or lightly regulated. It is outside the regime.
For electricity in Great Britain, the Schedule 2 thresholds are:
- Supply: electricity undertakings carrying out the function of supply to more than 250,000 final customers.
- Supply and generation: electricity undertakings carrying out the function of supply, and generation via generators which, cumulated with generators operated by affiliated undertakings, would have a total capacity, in terms of input to a transmission system, greater than or equal to 2 gigawatts.
- Transmission: transmission system operators whose disruption would affect more than 250,000 final customers; offshore transmission licence holders at 2GW or more cumulative capacity; interconnector licence holders at 1GW or more.
- Distribution: distribution system operators whose disruption would affect more than 250,000 final customers.
In Northern Ireland, which operates a separate and materially lower set of tests, the thresholds are supply licence holders serving more than 8,000 consumers and generation licence holders with capacity of 350 megawatts or more.
The 2GW figure is the one that matters here, and it is worth being exact about what it does and does not say. It is cumulative across affiliated undertakings, so a portfolio operator cannot decompose itself into sub-threshold subsidiaries. It is expressed in terms of input to a transmission system, which by construction excludes a great deal of generation that connects at distribution level. And it attaches, in the GB entry, to undertakings carrying out supply as well as generation.
The competent authority for downstream gas and electricity is a joint one: Ofgem and DESNZ.
A four-day outage at a “small-scale energy generator” is, on the face of the ministerial description, an outage at something well below 2GW. Whether the specific operator was designated is not public. But the structural point holds regardless of this one facility: a large fraction of UK generating capacity sits, entity by entity, below the Schedule 2 line.
What being outside the perimeter actually means
For an operator that is not an OES, the following do not apply.
Regulation 10 — the security duties. OES must take appropriate and proportionate technical and organisational measures to manage risks to the network and information systems on which their essential service relies, and to prevent and minimise the impact of incidents. This is the duty that the NCSC Cyber Assessment Framework operationalises, and that Ofgem and DESNZ supervise. A sub-threshold generator owes none of it as a matter of NIS law.
Regulation 11 — the duty to notify incidents. An OES must notify its competent authority of any incident with a significant impact on continuity of the essential service without undue delay and in any event no later than 72 hours after becoming aware of it, with prescribed content: the operator and services affected, time and duration, nature and impact, and cross-border implications. A sub-threshold generator has no statutory reporting duty. Reporting to the NCSC — as happened here — is voluntary.
Regulations 15 to 17 — information notices, powers of inspection, and enforcement notices. No regulator can compel a sub-threshold generator to produce evidence of its controls, inspect its OT estate, or serve an enforcement notice requiring remediation.
Regulation 18 — penalties. The NIS penalty structure is banded, and the bands are calibrated to consequence rather than to conduct:
| Band | Maximum | Applies to |
|---|---|---|
| 1 | £1,000,000 | Contravention that could not cause a NIS incident |
| 2 | £3,400,000 | Material contravention causing or capable of causing reduction of service provision for a significant period |
| 3 | £8,500,000 | Material contravention causing or capable of causing disruption of service provision for a significant period |
| 4 | £17,000,000 | Material contravention causing or capable of causing an immediate threat to life or significant adverse impact on the UK economy |
A four-day generation outage caused by a state-linked intrusion is, in the abstract, squarely Band 2 or Band 3 conduct. For an entity outside the regime, the applicable maximum is nil.
None of this is an accusation against the operator. It describes the incentive structure the regulation creates. The threshold model asks how much capacity you have. The attacker asks what you have left exposed. Reporting indicates the entry route involved internet-reachable industrial equipment — PLCs and HMIs — though the government has not confirmed the vector, the vendors, or the facility, and that detail should be treated as unconfirmed. What is not in doubt is that internet-exposed control equipment is the most consistently observed initial access route in the Iranian-linked infrastructure campaigns of the past two years, and that exposure is independent of installed capacity.
The threshold was already under review
DESNZ had already reached the same conclusion, in writing, months before the attack became public.
Between 27 March 2026 and 22 May 2026, DESNZ ran the consultation “Whole energy cyber resilience requirements: reshaping cyber regulation in downstream gas and electricity.” It preserves the existing 2GW cumulative generation threshold as the current position, but it explicitly puts the question of whether that threshold “remains fit for purpose” on the table, on the basis that the energy system it was drafted for no longer exists. The consultation cites a projected six-fold increase in battery storage capacity and renewable capacity almost tripling by 2030.
It also proposes a mechanism rather than a number: that Ofgem and DESNZ, as joint competent authority, commission the National Energy System Operator (NESO) to provide independent advice on which services are essential and what the appropriate thresholds should be. The outcome is tied to both that advice and to the enactment of the Cyber Security and Resilience Bill.
No new threshold figures were proposed in that document. Any assertion that the line is about to move to a specific number is, at the time of writing, speculation.
The aggregation problem
A threshold expressed per-entity and per-connection measures individual criticality. What has changed is that criticality has migrated from individual assets to populations of assets. Distributed generation, battery storage, small CHP, solar farms and behind-the-meter assets are now a material share of national capacity. Each is trivially sub-threshold. Collectively they are not trivial at all, and increasingly they are:
- Connected at distribution rather than transmission level, so they fall outside a test phrased around input to a transmission system.
- Aggregated commercially — through flexibility markets, virtual power plants and aggregators — which means many nominally independent assets can share one control platform, one remote-access path, and one vendor.
- Operated unmanned, with monitoring and control performed remotely as the normal operating mode rather than an exception.
The third point turns a scope question into a threat-modelling question. An attacker who compromises one aggregator’s remote-access platform is not attacking a sub-threshold asset. They are attacking a correlated portfolio whose aggregate exceeds any threshold anyone would care to draw — while every constituent asset remains individually out of scope.
This is recognisably the same defect that NIS2 produces from the opposite direction with its size-cap rule, under which entities below the medium-enterprise headcount and turnover thresholds fall outside the essential and important entity tiers unless a Member State designates them specifically. Both regimes chose a proxy — capacity in one case, organisational size in the other — for a property they actually care about, which is systemic consequence. Both proxies fail in the same place: at scale, in aggregate, where the individually insignificant becomes collectively decisive. The Polish district heating attack this site covered in the private APN case made the identical point through a different mechanism — a wind farm that was nobody’s idea of critical infrastructure functioning as the route into a plant serving 50,000 people.
What the Cyber Security and Resilience Bill does, and does not, fix
The Cyber Security and Resilience (Network and Information Systems) Bill is the intended structural fix, and this site has set out its architecture and timetable in the Lords Committee stage analysis. Committee Stage began on 1 September 2026, Royal Assent is expected in late 2026, and substantive effect through secondary legislation is expected around 2028.
Four features of the Bill bear directly on the sub-threshold problem.
Scope expansion by category. The Bill brings relevant managed service providers and data centres into direct regulation. Neither category resolves the generation threshold, but the RMSP category is materially relevant to distributed generation, because a great many unmanned sites are monitored and maintained under contract by third parties with privileged remote access. If your remote-access provider becomes a regulated RMSP, part of your exposure becomes somebody else’s statutory duty.
Designated critical suppliers. The Bill creates a power for regulators to designate specific suppliers to regulated entities as themselves subject to duties, where their failure would have a significant disruptive effect. This is the provision that can pull an organisation into statutory regulation by reference to who its customers are rather than what sector it is in. For a control system vendor, an aggregator, or an operations platform serving many small generators, designation is a live possibility.
Tighter reporting. The Bill replaces the current 72-hour NIS position with a two-stage duty: an initial notification within 24 hours of becoming aware of a significant incident, followed by a fuller report within 72 hours, to the relevant regulator and to the NCSC. The reportability threshold broadens beyond service continuity to cover confidentiality, integrity and availability.
Penalties. Up to £17 million or 4% of global annual turnover for serious contraventions, £10 million or 2% for less serious ones, and daily penalties up to £100,000 for continuing non-compliance.
What the Bill does not do is publish a new electricity generation threshold. That work sits with the DESNZ consultation, the NESO advice, and the secondary legislation and implementation consultation that follow assent. The scope question is being decided in the consultation, not in the Bill, and operators near any plausible line should be reading it accordingly.
The threat model this incident confirms
The UK generator incident did not occur in isolation. It was roughly contemporaneous with a coordinated campaign against more than 30 US community water utilities — small, under-resourced, and, in US terms, largely outside the scope of federal cyber mandates. The pattern is consistent enough to be planning-grade:
- Target selection is driven by exposure, not by importance. Iranian-linked activity documented in CISA advisory AA26-097A and its July 2026 update — covered here in the Schneider and Siemens scope expansion — has centred on internet-reachable PLCs and HMIs at facilities selected because they were findable, not because they were consequential.
- The initial access is unsophisticated. Default credentials, unauthenticated protocols, and management interfaces reachable from the public internet. The CyberAv3ngers water and wastewater advisory documented the same pattern in the US water sector.
- The intended effect is signalling. Disruption below the threshold of armed conflict, at a facility where the consequence is bounded, is a deliberate choice rather than an operational failure to hit something bigger.
The volume context comes from the NCSC. In his RUSI Annual Security Lecture on 17 June 2026, chief executive Richard Horne stated that the NCSC managed more than 200 incidents affecting UK critical national infrastructure and its supporting ecosystem in the year to May 2026, with around 75% believed to be linked to state actors — principally Russia, China and Iran. Horne has separately warned that the NCSC is now handling at least four “nationally significant” cyberattacks every week, and that this could rise sharply if the UK becomes further entangled in the wider Iran conflict.
A regulatory perimeter drawn in 2018 around a small number of very large assets is not a sensible fit for a threat that generates four nationally significant events a week and selects targets by search engine.
Mapping to the Cyber Assessment Framework
The NCSC Cyber Assessment Framework is the assessment instrument Ofgem and DESNZ use for NIS-designated energy operators, supplemented by the Ofgem CAF overlay for the downstream gas and electricity sector. It is also the single most useful thing a sub-threshold operator can adopt voluntarily, because it is the framework a regulator would use if the perimeter moved.
The outcomes this incident class exercises, by objective:
Objective A — Managing security risk. Governance and board ownership (A1), risk management that models a state-linked adversary rather than only opportunistic ransomware (A2), asset management extending to every internet-reachable OT device including those installed by contractors (A3), and supply chain (A4) covering remote-access providers, O&M contractors, aggregators and control-platform vendors.
Objective B — Protecting against cyber attack. Identity and access control (B2), specifically privileged and third-party remote access to unmanned sites; data and system security (B3); resilient networks and systems (B5), meaning IT/OT segmentation that is enforced and tested rather than documented; and vulnerability management (B4) for equipment that is frequently unpatchable and therefore must be isolated instead.
Objective C — Detecting cyber security events. Security monitoring (C1) with coverage that actually extends to the OT network, and proactive attack discovery (C2). The recurring finding in OT incidents — the Polish heat plant sat undetected for eleven days and misclassified for three months — is that nobody was watching the control network at all.
Objective D — Minimising the impact. Response and recovery planning (D1) exercised for a scenario in which the control system is unavailable or untrusted for days, and lessons learned (D2). Four days offline is a recovery-capability finding as much as a prevention finding.
OT control expectations, threshold or no threshold
IEC 62443 remains the reference standard and is threshold-agnostic. The relevant expectations for small and unmanned generation:
Zones and conduits. Define them formally (62443-3-2), and make the OT environment a zone with enumerated, authenticated conduits. The most common real-world failure is not the absence of segmentation but the presence of an undocumented conduit — a vendor’s cellular router, a legacy modem, a shared carrier network segment.
No direct internet exposure of control equipment. PLCs, HMIs, RTUs and engineering workstations should have no route from the public internet, including via a service provider’s network. Shodan-class exposure of a site’s HMI is the single highest-value finding available from an afternoon’s work.
Remote access governance. For unmanned sites, remote access is the plant. It should be brokered through a jump host, require MFA that cannot be bypassed by locally configured accounts on the appliance, be session-recorded, be time-bound rather than standing, and be revocable per individual and per contractor. Local accounts on edge devices bypass identity-provider MFA entirely and must be tested for explicitly.
Authentication on industrial protocols. Where the protocol offers none, compensate at the network layer and monitor for engineering-mode commands, logic downloads and password changes on controllers.
Recovery from the controller up. Offline, tested copies of PLC logic, HMI projects, and device configurations, plus a documented procedure for regaining control of a device whose credentials an attacker has changed. This is what turns four days into four hours.
Checklist: what energy operators should do now
Determine your status accurately, and write it down.
- Calculate your generation capacity cumulated across affiliated undertakings, on an input-to-transmission-system basis, and compare it to 2GW (GB) or, for Northern Ireland generation licence holders, 350MW.
- Separately test the supply limb: more than 250,000 final customers.
- Confirm whether you have ever been identified as an OES under Regulation 8 and notified by Ofgem or DESNZ. Assumption is not evidence; find the correspondence.
- Record the determination with its date, inputs and reasoning. It is a live document, not a one-off — capacity changes, acquisitions change affiliated-undertaking maths, and the threshold itself is under review.
Prepare for the perimeter to move.
- Read the DESNZ “reshaping cyber regulation in downstream gas and electricity” consultation and track the NESO advice it proposes. If you are within a factor of two of any current threshold, treat in-scope as the planning assumption.
- Model the designated critical supplier exposure: do you supply, operate, monitor or maintain systems for an OES such that your failure would disrupt their essential service? If so, plan on being regulated regardless of your own capacity.
- Build the 24-hour initial notification capability now, ahead of the Bill. It needs a defined awareness trigger, a named out-of-hours decision-maker with authority to file without legal sign-off, a pre-drafted template, and a rehearsed path. Test it with a timed exercise starting outside business hours.
Adopt the framework voluntarily.
- Run a CAF self-assessment against the Ofgem downstream gas and electricity overlay, even if unregulated. Where you would fail, record the gap and a remediation date.
- Report significant incidents to the NCSC voluntarily, as the July 2026 operator did. It is the correct thing to do irrespective of duty, and a voluntary reporting history is the best available evidence of good faith if designation later arrives.
Fix remote access to unmanned sites.
- Enumerate every inbound path to every unmanned site, including contractor-installed cellular routers, vendor support tunnels, private APNs and carrier-managed segments. Verify against the physical estate, not against the network diagram.
- Search externally for your own exposed assets. Confirm no HMI, PLC, RTU or engineering workstation answers from the public internet.
- Enforce MFA on every remote-access path and test the local-account bypass on each edge appliance individually.
- Deploy monitoring that covers the OT network, with alerting on controller logic changes, engineering-mode transitions and credential changes.
- Hold offline, tested backups of controller logic and device configurations, and rehearse regaining control of a locked-out PLC.
Governance.
- Put the threshold determination, the CAF gap position, and the sub-threshold exposure in front of the board. In a NIS2 context, management-body accountability is explicit; in the UK it is less prescriptive on the face of the legislation, and the practical expectation is unchanged.
Conclusion
The most important sentence in the government’s response to this incident was the one intended to be reassuring. “Small-scale energy generator” was offered as a statement about impact. It reads, to anyone holding the NIS Regulations, as a statement about jurisdiction.
The threshold model was defensible in 2018, when it drew a perimeter around a manageable number of very large assets and gave a joint competent authority the resources to supervise them. It is a poor fit for an electricity system in which capacity is fragmenting into thousands of small, unmanned, remotely operated, commercially aggregated units — and a very poor fit for an adversary whose target selection is driven by what is reachable rather than by what is significant.
The Cyber Security and Resilience Bill will widen the perimeter, but not until roughly 2028, and not by resolving the generation threshold, which sits with a consultation and a piece of NESO advice. That leaves a window of at least two years in which a substantial share of UK generation has no statutory security duty, no reporting duty, and no regulator that can inspect it — during a period in which the NCSC is handling four nationally significant attacks a week.
Operators in that window have a straightforward decision to make. They can wait to be regulated, or they can adopt the framework they will eventually be measured against and start closing the gaps while doing so is voluntary, unhurried, and cheap. The attacker has already demonstrated that it is not waiting for the threshold to move.
This article is provided for informational purposes only and does not constitute legal advice.



