Iran-linked cyber attack on UK power plant was inevitable
Tue, 25th Aug 2026 (Today)
James Griffiths of UtopianKnight said a cyber attack on a British power plant linked to the Iranian regime was inevitable. His comments followed weekend reports that a UK facility had been hacked and shut down.
Griffiths, a former military signals specialist and ex-GCHQ adviser, said the incident should warn operators across the UK's critical national infrastructure, particularly those relying on older operational systems.
He said the attack has renewed attention on longstanding concerns about cyber defences in the energy sector. Ageing infrastructure and under-investment, he argued, have left parts of the country's essential services exposed to serious disruption.
"A UK power plant hacked and linked to the Iranian regime was unfortunately inevitable. Although we don't know which power plant was targeted and successfully shut down, what is clear is that this is a wake-up call for the rest of the critical national infrastructure community.
Unfortunately, this is something that most will have been worried about happening for a long time. Under-investment in protecting our critical national infrastructure in the UK has always been an issue, with legacy and ageing systems running the core of what we take for granted: power.
Although nothing has been released about how this happened, what is interesting is that it took four days for the power plant to come back online. Depending on the scale of the attack, that could be deemed quite a quick recovery. Quite a few other UK and global power suppliers will now be looking to harden their defences.
Clearly, had this been an attack on a larger power plant, it could have led to major disruption, affecting the national grid and causing blackouts. But the more serious question is how interconnected that power plant was to the rest of the grid network and whether the attackers could have moved into other areas.
If made public, it will be interesting to see what lessons are identified so we can all understand how frail some of the smaller power plants are," said James Griffiths, founder of UtopianKnight.
The account points to one of the central issues in industrial cyber security: not every attack on a single site remains confined to that site. In electricity systems, analysts often focus on whether a compromised plant is isolated enough to prevent wider operational impact or whether network links and shared systems could create routes into other parts of the grid.
That question carries particular weight for smaller generators, which may not attract the same public scrutiny as major power stations but can still play an important role in national supply. A temporary shutdown at one site may be manageable, but concerns rise if attackers can use the initial breach to gather information, test controls or move into adjacent systems.
Legacy systems
Griffiths said legacy technology remains a persistent weakness across critical national infrastructure. Many industrial control systems were designed for reliability and long service lives, not exposure to modern cyber threats, and operators often face difficult choices when replacing or securing them.
In practice, that can mean plants continue to run with equipment and software built before current cyber risk standards became widespread. Operators may add newer protective layers around those systems, but specialists have repeatedly warned that patching around old infrastructure does not always remove structural vulnerabilities.
The reported four-day period before the affected power plant returned online has also raised questions about incident response and resilience. Recovery time in industrial environments can depend on several factors, including the extent of the disruption, the need to verify safety conditions and the challenge of restoring operational technology without causing further faults.
While Griffiths said that timeline could be considered relatively quick, depending on the scale of the incident, it also underlines how cyber attacks on energy assets differ from attacks on conventional office systems. Restoring electricity generation involves more than reconnecting servers, particularly when engineers must confirm that control systems, safety mechanisms and site operations are stable.
Sector pressure
The incident is likely to increase pressure on operators to review their cyber readiness, especially in sectors considered essential to public life. Power generation sits at the centre of that debate because any successful compromise can have consequences beyond the company directly targeted, affecting households, transport networks, public services and other businesses.
It also comes amid broader concern over state-linked cyber activity against Western infrastructure. Security officials and industry experts have increasingly warned that energy, water, transport and telecommunications networks remain attractive targets because disruption in those areas can have both economic and political effects.
Griffiths has spent 25 years in IT and cyber security and previously served for 17 years in the British Army's Royal Corps of Signals as a foreman of signals information systems. He later co-founded Cyber Security Associates in Gloucester and, as technical director, helped grow the business to about 100 people with annual revenue of more than GBP £15 million.
He now runs UtopianKnight, where his work includes advisory roles covering operational technology and industrial control system security. "This is a wake-up call for the rest of the critical national infrastructure community," Griffiths said.