
Energy on the front line: Lessons from the peaker plant hack
With Iran-linked hackers shutting down a small UK energy facility for four days, Utility Week asks cyber-security experts whether this attack exposes a significant vulnerability in the energy system.
By David Blackman, policy correspondent
Energy on the front line: Lessons from the peaker plant hack
With Iran-linked hackers shutting down a small UK energy facility for four days, Utility Week asks cyber-security experts whether this attack exposes a significant vulnerability in the energy system.
By David Blackman, policy correspondent

Over recent months, a complex web of geopolitical tensions has started to feel uncomfortably close to home for the UK. This was especially evident with the revelation in late August that hackers thought to be affiliated with the Iranian regime shut down a small gas-fired “peaker” plant.
The attack on the plant, which was connected to a local distribution network rather than the transmission grid, shut it down for four days in July.
The plant is one of an estimated 300 such plants on the GB system that can be switched on rapidly to top up UK generation capacity when there are acute mismatches between demand and supply for power. Such plants are just one type of the embedded generation, alongside renewable generation and battery storage among others, which is playing an increasingly important role in Britain’s electricity system. These embedded assets, which now add up to as much as 7GW of capacity, are seen as a key tool in maintaining the grid’s stability as it relies more on intermittent renewable generation.
However, the suspected Iranian sabotage points to a key vulnerability underpinning this dream of distributed energy. Such small-scale plants, which only generate when demand calls for it, can only be cost-effective if they are run remotely.
“For a small operator, the cost of robust security engineering can feel disproportionate to the asset,” says Martin Riley, chief technology officer at infrastructure security consultancy Bridewell.
“It’s not going to be staffed and maintained all the time,” agrees a cyber-security expert, who requested to remain anonymous. “Rapid deployment of that facility’s capability is the whole point, so being able to remotely access to do that when necessary is critical.”
According to another industry source, a typical peaker plant’s physical defence will also be limited. “It will have a fence around it and their security is basically to call the police,” they say.
These small-scale facilities also fall outside the industry’s formal cyber-security regime, the Network and Information Systems Regulation, which involves annual evaluation visits from Ofgem.
“Embedded generation doesn’t have to go through any of these protocols; that may be fine, but clearly there is a vulnerability,” says the industry source.
The cyber-security expert says it looks like the Programmable Logic Controller (PLC), which is in effect a virtual operating room that connects the peaker plant to the internet, was hacked in the suspected Iranian attack. The hackers were able to access the PLC over the internet and take over the operating technology that controlled the plant’s physical systems, which for example turn its burners on and off.
It is not the first time that UK power plants have suffered intrusions by a foreign power, says Elisabeth Braw, a London-based senior fellow at the US foreign policy thinktank Atlantic Council. “In previous incidents, either the intrusion was quite small or the intruders didn’t do very much,” she says. “Essentially, they just parked themselves there. Nobody was really quite sure what they were doing and it was assumed that they were essentially setting themselves up to carry out an attack at a later date.
“What makes this [peaker plant hack] different is that the attack was quite significant, even though it appears to have been unsuccessful.”
It’s “good news” that the attack was foiled, but its impact can’t just be measured on the disruption to supply, she says. “The effect can be measured also in in the fear created from such an incident". She adds that there were “significant” waves of unease in Whitehall.
“You can say that it did have an effect,” she continues. “Namely that lots of ordinary people, MPs and others are concerned that UK CNI [critical national infrastructure] can be disrupted and that Iran is now so sophisticated that it can disrupt UK CNI. That in itself is an effect.”
The energy cyber-security experts agrees. “Just because it’s small, it shouldn’t be treated as insignificant,” they say. “The added worry is that attacks like this are easily repeatable.”
A sign of things to come
The peaker plant attack may be a “proof of concept” move that could be a precursor to larger, AI-fuelled potential incidents, they add.
The National Cyber Security Centre (NCSC) and the Department for Energy Security and Net Zero (DESNZ) have been widely applauded for responding quickly to the incident, briefing energy CEOs and writing directly to operators with advice and next steps.
“This loophole is going to be closed because everyone’s going to take it seriously and the NCSC has sent around its guidance,” says the cyber security expert, noting that the NSCS and DESNZ have developed a “much closer relationship” with the industry on resilience issues over the past year.
The answer to the peaker plant attack, he says, is to use the existing ISA/IEC 62443 standards to split up the design of the electricity network into zones facing differing levels of security threat, which would be linked to one another by “secure” conduits.
However, keeping ahead of potential attacks is an increasingly challenging, says Adam Berman, director of policy and advocacy at Energy UK. “The threat is evolving very, very quickly now. It is not reasonable to say that a renewables-led or a clean energy-led system is more or less secure. It is just that the vulnerabilities change.”
As an example of how crafty hackers are becoming, a Utility Week source describes how they are generating AI deep fake voice messages of senior managers to issue instructions to staff.
“Most times of day and year it will not be the end of the world if any of these facilities go offline,” they continue. “But if someone were to be really strategic about it and choose a high-pressure period where the wind’s not blowing, it’s quite cold and margins are tight, you could imagine that having a more substantial system-wide impact because of the cumulative impact across multiple different assets.
“It opens up a question about if you want more resilience, because we are facing more sophisticated but different threats.”
DESNZ is preparing an Energy Resilience Strategy, which ministers have said will be published before the end of the year.
Jon Saltmarsh, chief technology officer at the Energy Systems Catapult, insists there need be no trade-offs between resilience and a more distributed electricity system. “There’s a big difference between taking out a 3.2GW nuclear station compared to 3.2GW distributed across 100 different generators,” he says, pointing to how the Ukrainian grid has become more resilient since the Russian invasion through the deployment of more renewable energy.
“The big benefit from distribution is that you get a lot more resilience,” he continues. “It’s not a matter of trading off: we are very much moving to a more secure and reliable system that can cope with bits of it failing without a lot of it failing.”
It is “really important” that any resilience strategy doesn’t end up applying the same levels of security to all types of energy assets, Saltmarsh says: “If you’ve got a control centre that’s controlling a lot of assets, then you need a different regime [compared to the] individual asset.”
The “first step” in any resilience strategy should be train all power and water company staff to be on the alert about potential threats, says Braw: “In a number of recent cases, it was only thanks to an alert employee of some kind that disruption was averted.”
Pointing to the recent suspected Russian drone attack on Leipzig Airport in Germany that was spotted by a vigilant employee in the middle of the night, she says: “That sort of awareness training will go a long way.”
Braw also says the government should ensure that companies running CNI, like utilities, are involved in any war game exercises that it conducts to test responses to potential military or terrorist attacks.
Welcoming the government’s announcement last month that it would be distributing emergency preparedness leaflets to households, she says: “The more comfortable you are that you’ll be able to handle a crisis, the less you need to panic when one happens.”
And having that level of readiness will help to deter enemies from mounting attacks, Braw says: “That is what we need to communicate, both internally within the country and to those entities that seem interested in carrying out attacks against us.”
“It is not reasonable to say that a renewables-led or a clean energy-led system is more or less secure. It is just that the vulnerabilities change.”
Adam Berman, director of policy and advocacy, Energy UK
“It is not reasonable to say that a renewables-led or a clean energy-led system is more or less secure. It is just that the vulnerabilities change.”
Adam Berman, director of policy and advocacy, Energy UK
