A cyber attack that reportedly forced a UK power generator offline for four days has highlighted the growing security challenge posed by increasingly connected energy infrastructure.
The UK Government confirmed that a small-scale generator was affected by a cyber incident last month, while stressing that at no point was there a risk to the wider energy system. The site has not been identified for security reasons, although The Telegraph reported that the attackers were affiliated with the Iranian regime.
In an official statement the Department for Energy Security and Net Zero said: “This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system. The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.”
The incident comes as the UK’s energy system becomes increasingly distributed, with smaller generators, batteries and other assets playing a growing role alongside traditional power stations. Many of these assets depend on connected technologies for monitoring, management and remote access, creating a much broader operational technology (OT) environment that needs to be secured.
For Rob Demain, CEO of e2e-assure, a UK cybersecurity company specialising in Security Operations Centre (SOC)-as-a-Service, the significance of the incident is not necessarily the impact of taking one small generator offline, but the possibility that the same weakness could exist across multiple connected assets.
“The electricity system is becoming increasingly distributed and, while one asset is of little consequence, a weakness that is repeated across hundreds of similar assets could compound to a significant problem due to the technology and suppliers the grid relies on,” he says.
He warns that relatively basic vulnerabilities could leave critical national infrastructure (CNI) exposed.
“How they got into the power plant isn’t currently clear, but it doesn’t necessarily have to have been a sophisticated attack,” says Demain. “CNI is vulnerable to all sorts of basic security challenges: exposed internet-facing devices, compromised remote access credentials, vulnerable gateways, or compromised third-party accounts.”
Similar concerns have emerged from attacks targeting critical infrastructure elsewhere.
Earlier this year, US authorities warned that Iran-affiliated threat actors had targeted critical infrastructure through internet-facing OT systems, including systems used to control physical processes in sectors such as energy and water.
Aras Nazarovas, Senior Information Security Researcher at Cybernews, says the attacks demonstrate that attackers do not necessarily need advanced techniques when connected OT is inadvertently exposed.
“Attackers didn’t rely on anything particularly advanced. They took advantage of OT systems that were supposed to be isolated but ended up exposed to the internet,” he says. “This is a very common issue in OT systems, and the same kind of attack can be repeated again and again, until the systems are properly secured.”
OT systems are often designed to operate continuously and may depend on legacy hardware and software that cannot simply be patched or replaced without careful consideration. An apparently straightforward security intervention can have operational or even safety implications.
“OT environments often don’t have the same security controls as IT systems,” Nazarovas says. “These systems are built to stay active 24/7, so a lot of standard protections like encryption or strong authentication aren’t always in place.”
