Budapest Post

Cum Deo pro Patria et Libertate
Budapest, Europe and world news

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

UK cyber security law forcing energy companies to report hacks has led to no reports, despite numerous hacks

The threshold to determine whether an incident affecting energy companies is reportable has prevented any reports being made.

A cyber security law introduced three years ago was meant to boost the resilience of the UK's energy sector by obliging gas and electricity firms to report when they were hacked.

But since then not a single report has been made, Sky News can reveal, despite numerous successful hacks of British energy firms attributed to hostile states as well as criminal groups.

Ofgem, the authority that is meant to receive these reports, told Sky News that only one company has ever tried to file a report informing the regulator that it had been hacked, but they were dismissed as the incident did not meet the threshold for being reported.

Ofcom's incident thresholds are based on the impact of an attack on customers


Last year, staff at a little-known company called Elexon - a firm that plays a critical role in balancing and settling payments between power plants and electricity suppliers - was left locked out of its internal systems due to a ransomware attack.

The British government has confirmed that Russian state-sponsored hackers have successfully penetrated the computer networks of the UK's energy grids, without disrupting them.

Former defence secretary Gavin Williamson warned that "thousands and thousands and thousands" of people could be killed if an attempt at disruption was made.

But the high thresholds for companies working across the gas and electricity sectors to report cyber security incidents to Ofgem risks leaving the regulator blind to how the sector is actually coping in the face of these threats.

These thresholds are based on the impact of hacks to the continuity of the companies' services, a metric that does not record the sector's security capabilities, just the intentions of the attackers.

Dr Jamie Collier, a threat intelligence consultant at FireEye, told Sky News that the thresholds could be useful considering the varying levels of sophistication across attacks on critical infrastructure organisations, allowing defenders to "focus on what really matters".

But the cyber security expert added: "Despite this, essential service providers and regulators should be careful not to neglect the threat posed from less sophisticated attacks."

FireEye has detected an increase in critical infrastructure incidents caused by novice hackers due to the growing availability of tools enabling these hackers to interact with industrial control systems.

The company also warns that multiple, highly-prolific criminal organisations with a financial motivation are currently "active inside essential service provider networks with the intent of profiting from a ransom of stolen information and disrupted services".

FireEye warns that novice hackers are now targeting industrial control systems.


"Most of the concern around cyber security has been focused on operational technology (OT) networks that interact with physical processes and machinery, such as power plant equipment or water treatment facilities," Dr Collier explained.

"Yet the traditional information technology (IT) networks that involve the flow of data - such as file storage or email - should not be neglected. This is because whilst the impact of malicious activity can be far more severe against OT systems, these attacks typically start out on IT networks. It is therefore vital to consider security across an entire service provider's infrastructure."

Dr Collier stressed that critical infrastructure providers "deserve credit for their use of fail-safe mechanisms that can mitigate the destructive impacts of many attacks".

Responding to Sky News, a government spokesperson said: "The UK's critical infrastructure is extremely well protected and over the past five years we have invested £1.9bn in the National Cyber Security Strategy to ensure our systems remain secure and reliable."

They added that a formal review of the impact of the cyber security law, the Network & Information Systems Regulations, will take place within the next 12 months.

AI Disclaimer: An advanced artificial intelligence (AI) system generated the content of this page on its own. This innovative technology conducts extensive research from a variety of reliable sources, performs rigorous fact-checking and verification, cleans up and balances biased or manipulated content, and presents a minimal factual summary that is just enough yet essential for you to function as an informed and educated citizen. Please keep in mind, however, that this system is an evolving technology, and as a result, the article may contain accidental inaccuracies or errors. We urge you to help us improve our site by reporting any inaccuracies you find using the "Contact Us" link at the bottom of this page. Your helpful feedback helps us improve our system and deliver more precise content. When you find an article of interest here, please look for the full and extensive coverage of this topic in traditional news sources, as they are written by professional journalists that we try to support, not replace. We appreciate your understanding and assistance.
Newsletter

Related Articles

0:00
0:00
Close
U.S. and Hungarian Officials Talk About Economic Collaboration and Sanctions Strategy
Technology Giants Activate Lobbying Campaigns Against Strict EU Regulations
Pope Francis Admitted to Hospital in Rome Amid Increasing Speculation on Succession
Zelensky Calls on World Leaders to Back Peace as Tensions Rise with Trump
UK Leader Keir Starmer Calls for US Security Guarantee in Ukraine Peace Deal
NATO Chief Urges Higher Defense Expenditure in Europe
The negotiation teams of Trump and Putin meet directly, establishing the groundwork for a significant advancement.
Rubio Touches Down in Riyadh Before Key U.S.-Russia Discussions
Students in Serbian universities Unite to Hold Coordinated Protests for Accountability.
US State Department Removes Taiwan Independence Statement from Website
Abolishing opposition won't protect Germany from Nazism—this is precisely what led Germany to become Nazi!
Transatlantic Gold Rush: Traders Shift Bullion in Response to Tariff Anxieties and Market Instability
Bill Ackman Backs Uber as the Company Shifts Towards Profitability
AI Titans Challenge Nvidia's Supremacy in Light of New Chip Innovations
US and Russian Officials to Meet in Saudi Arabia Over Ending Ukraine Conflict. Ukraine and European leaders – who profit from this war – excluded from the negotiations.
Macron Calls for Urgent Summit as Ukraine Conflict Business Model is Threatened
Trump’s Defense Secretary: Ukraine Won’t Join NATO or Regain Lost Territories
Zelensky Urges Europe to Bolster Its Military in Light of Uncertain US Backing
Chinese Zoo Confesses to Dyeing Donkeys to Look Like Zebras
Elon Musk is Sherlock Holmes - Movie Trailer Parody featuring Donald Trump's Detective
Trump's Greenland Suggestion Sparks Sovereignty Discussions Amid Historical Grievances
OpenAI Board Dismisses Elon Musk's Offer to Acquire the Company.
USAID Uncovered: American Taxpayer Funds Leveraged to Erode Democracy in Europe Until Trump Put a Stop to It.
JD Vance and Scholz Did Not Come Together at the Munich Security Conference.
EU Official Participates in Discussions in Washington Amid Trade Strains
Qatar Contemplates Reducing French Investments Due to PSG Chief Investigation
Germany's Green Agenda Encounters Ambiguity Before Elections
Trump Did Not Notify Germany's Scholz About His Ukraine Peace Proposal.
Munich Car Attack Escalates Migration Discourse Before German Elections
NATO Allies Split on Trump's Proposal for 5% Defense Spending Increase
European Parliament Advocates for Encrypted Messaging to Ensure Secure Communications
Trump's Defense Spending Goal Creates Division Among NATO Partners
French Prime Minister Bayrou Navigates a Challenging Path Amid Budget Preservation and Immigration Discourse
Steering Through the Updated Hierarchy at the European Commission
Parliamentarian Calls for Preservation of AI Liability Directive
Mark Rutte Calls on NATO Allies to Increase Defence Expenditures
Dresden Marks the 80th Anniversary of the World War II Bombing.
Global Community Pledges to Aid Syria's Political Transition
EU Allocates €200 Billion for AI Investments, Introduces €20 Billion Fund for Gigafactories
EU Recognizes Its Inability to Close the USAID Funding Shortfall Due to Stalled US Aid
Commission President von der Leyen Missing from Notre Dame Reopening Due to Last-Minute Cancellation
EU Officializes Disinformation Code for Online Platforms, Omitting X
EU Fails to Fully Implement Key Cybersecurity Directives
EU Under Fire for Simplification Discussions Regarding Corporate Sustainability Reporting
Shein Encountering Further Information Request from the EU During Ongoing Investigation
European Commission Initiates Investigation into Shein as It Aims at Chinese E-Commerce Regulations
German Officials Respond to U.S. Proposal for Peace Talks with Russia
Senate Approves Robert F. Kennedy Jr. as Secretary of Health and Human Services.
Trump and Putin Engage in Discussions on Ukraine Peace Negotiations Amid Worldwide Responses
Honda and Nissan End Merger Talks
×