Brian Sims
Editor

Cyber Security Strategy for the Energy Sector: Leadership Must Act Now

RIGHT NOW, security in the energy sector is top of the political agenda, affirms Rafael Nazerri. Across Europe, investments are being made to reduce the reliance on Russian oil. Launched in 2022, the European Commission’s REPowerEU Plan stands as a prime example of this with its mandate to phase out Russian fossil fuel imports.

The ongoing US-Iran conflict is also re-emphasising just how fragile energy systems can be. With shipping limited through the Strait of Hormuz, which previously carried around 25% of global seaborne oil trade prior to the conflict, plans have been made to scale-up Saudi Arabia’s East-West pipeline to the Red Sea and the United Arab Emirates’ pipeline to Fujairah as alternative oil transportation routes.

On home shores, the UK itself is dialling up the focus on energy security. Most recently (in May, in fact), that has led to the roll-out of a new four-year strategy aimed at strengthening cyber security across the country’s energy system.

Dubbed the Energy Sector Cyber Security Strategy, the document lays out a roadmap for strengthening cyber security and resilience across the national energy sector, while in parallel aiming to support national ambitions for the clean energy transition.

Strategic priorities

The policy paper highlights the concerns emanating from the National Cyber Security Centre (NCSC) about a stark increase in threats posed to the UK’s Critical National Infrastructure (CNI) and essential services (including, of course, its energy systems).

The document flags the fact that recent years have shown the far-reaching consequences of cyber attacks. Within an increasingly unstable geopolitical landscape, it’s now more important than ever for the UK to focus on robust and co-ordinated cross-sector action and enhance sector security and resilience.

In order to achieve that ambition, the Government has spotlighted four key strategic priorities between now and 2030:

*ensure that cyber security risks posed to the energy sector are identified, assessed, understood and managed

*ensure that cyber security and resilience are increased at pace across the sector, appropriate to the risks faced

*ensure that response and recovery plans are in place and tested for cyber incidents, including sophisticated attacks from capable actors

*ensure that cyber requirements are expanded in scope and depth, proportionate to the risk faced and keep pace with the evolving threat and system landscape

The ‘Call to Action’ is clear. It states: “Private organisations and Government need to work even more effectively together to secure the energy sector and will need to make the most of all the resources at our disposal to protect our national security and way of life. Cyber security should be a Board-level priority, recognising that cyber security is a critical enabler of public trust, resilience and competitive advantage.”

Prescriptive actions

Like any regulatory changes, this will not be happening overnight. Indeed, the Energy Sector Cyber Security Strategy – led by the Department for Energy Security and Net Zero, Ofgem, the National Energy System Operator and the NCSC (collectively known as the ‘Quad Partners’) – will be rolled out in a phased manner, with organisations expected to remain abreast of and respond in kind to key annual milestones.

Much of the groundwork will be laid this year. There’s a desire to develop preliminary supply chain security principles and carry out a cross-industry and Government exercise to test collective cyber security capabilities.

More prescriptive actions will then follow. For example, the strategy will explicitly extend the need for baseline cyber resilience requirements to be introduced for operators not currently under NIS proposals to all Ofgem licensees. This is expected to be readied by the end of 2027.

In this sense, the idea that you are ‘too small to regulate’ is now over. Indeed, cyber risk should be considered a Board-level and CEO problem, not just an IT ticket, and sit as high up the priority ladder as safety and financial risk.

If you own or operate renewable generation, storage or grid-connected assets, this responsibility now lands firmly on your desk. You will now be in scope, even if you were not beforehand.

Prioritising detection and governance

For organisations, being proactive will pay dividends. Accelerating the protection of critical assets ahead of ministerial deadlines is advised. Acting late in the day will mean acting under pressure and increased scrutiny.

Where, exactly, should firms focus their attention? Investing in reliable and robust threat detection mechanisms is critically important. For too long, organisations have relied on a reactive approach, identifying threats only after a breach or attack has occurred.

In the case of CNI, this can be catastrophic. In Denmark in 2023, for example, almost two dozen energy companies were hit by a wave of attacks, duly resulting in several energy providers shutting off their Internet connections to limit the damages.

To mitigate what could be highly costly or societally damaging consequences, such as extended power outages, those organisations engaged in the energy value chain must focus on improving their ability to mitigate attacks in the first instance and identify malicious activities at speed.

One of the most effective ways in which to bolster defences in this manner is to ensure that new assets are ‘Secure by Design’. Retrofitting can be a costly, disruptive and time-consuming (albeit necessary) exercise. Therefore, organisations should prioritise cyber security Best Practice within every new substation, renewable asset, battery storage facility or digital platform from Day One.

Heightened regulatory expectations 

By proactively improving governance, real-time visibility and threat detection, energy companies will give themselves a head start on the heightened regulatory expectations that will be unfolding in the coming months and years.

These changes shouldn’t just be viewed as a compliance necessity, but also an opportunity to strengthen operational resilience and gain a strategic advantage. In the current geopolitical and cyber crime environment, making security a priority will be viewed favourably by partners, customers, and regulators.

It remains to be seen whether the new Prime Minister Andy Burnham will make any tweaks to the Energy Sector Cyber Security Strategy. Either way, the direction of travel is clear: in an increasingly digitalised energy industry, cyber resilience is now a core operational requirement. Those who make it so will be best placed to maintain trust, resilience and long-term operational success.

Rafael Nazerri is CEO and Co-Founder of Centrii (www.centrii.com)

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up