Last winter, someone switched off part of Poland's grid.
Last winter, someone switched off part of Poland's grid. IT systems and physical kit, both down.
The UK's response just landed: an 18-page Energy Sector Cyber Security Strategy. I read it so you don't have to.
Here's the signal under the press release.
DESNZ, Ofgem, NCSC and NESO have formed a boy band — the “Quad partners.” Every boy band has the talented one, the quiet one, the one who does the admin, and the one nobody's quite sure why he's there. I'll let you allocate.
Credit first: the threat section has teeth. China, Russia and Iran named out loud, and they keep pointing at that Polish attack on RENEWABLE infrastructure. The decentralised grid we're racing to build is a target-rich environment — and somebody already ran the live demo. On our friends. In Europe.
Then the plan. Build clean power at ludicrous speed:
→ twice the transmission in 5 years as the last decade
→ 30GW of offshore wind by 2030
All of it, and I quote, “without compromising security to achieve speed.” The have-your-cake-and-secure-it-too school of strategy. Anyone who's shipped against a deadline is laughing into their incident channel.
The proposed baseline for every grid-connected Ofgem licensee? Cyber Essentials. A self-assessed questionnaire. For the people keeping the lights on. It's a floor, fine — but a corner-shop padlock doesn't secure a substation.
The skills crisis they openly admit — not enough people who get OT AND cyber, plus a clearance bottleneck? The fix is to “foster a culture.” The plan for the talent shortage is vibes. Put it on a mug.
The genuinely good bits, because I'm not just here to swing:
→ a real sector-wide detection capability — full by 2028 (I know someone who would be great for this and has built the software 🤡). Proper assume-breach thinking. This is the one that matters.
→ CyAS adversary testing by 2030. CBEST-grade red teaming coming to energy.
→ critical SUPPLIERS regulated by 2030. The supply chain finally treated as the front door it's always been.
The catch: the powers with actual teeth depend on the Cyber Security and Resilience Bill getting Royal Assent. “Brilliant plans, pending Parliament not doing Parliament things.”
And my favourite line item: a CEO tabletop exercise. In 2028. So three years from now, energy CEOs will discover live what their CISO has been emailing them about since 2021.
Bottom line: strong diagnosis, honest about the threat, sensible direction — but the early years are government doing its own homework, and the bits that actually compel industry don't bite until 2027 and beyond.
Good strategy. Also four years of homework with the deadline set for the night before the exam.
The grid doesn't run on intent. It runs on architecture. Build it secure now or pay the interest later — and security debt is denominated in blackouts.
#CyberSecurity #CNI #OTSecurity #DevSecOps #NinjaSignal → https://ninja.ing
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·