Cyber resilience for Ofgem-regulated energy companies

A practical guide for CEOs and CFOs as the energy system becomes more connected and the regulatory baseline rises.

In December 2025, Russian state-linked attackers targeted Poland's energy grid. The UK and its allies later attributed the attack to Russia's FSB Centre 16 and estimated that, had it succeeded, around 500,000 people could have lost electricity. The attackers exploited vulnerable routers and network devices, a reminder that serious disruption does not always require an unusually sophisticated route into an organisation.

The incident came as energy systems across Europe are becoming more digital and distributed. Remote monitoring, smart devices, cloud platforms, battery storage and distributed generation allow the system to operate more efficiently, but also connect organisations and technology that were once more isolated. The UK government's 2026 Energy Sector Cyber Security Strategy describes a sector becoming increasingly digital and interconnected, while the International Energy Agency has warned that connected devices and distributed energy resources expand the number of places an attacker can target.

Regulation is starting to reflect that change. Ofgem and the Department for Energy Security and Net Zero (DESNZ) have proposed baseline cyber requirements for all Ofgem licensees, alongside a review of which organisations should fall within the Network and Information Systems Regulations. The Cyber Security and Resilience Bill, which would update the NIS regime, has passed the Commons and is now in the House of Lords.

For a chief executive or finance director, this is wider than an IT security issue. The questions are operational and financial: what must continue to work, what does it depend on, what would an interruption cost, and how quickly could the company contain an incident and recover?

Three areas deserve particular attention: increasingly connected operations, a rising regulatory baseline, and the growing role of suppliers, software and AI.

Why energy is different

Energy companies face many of the same attacks as other businesses. Criminals steal credentials, exploit vulnerable software, manipulate employees and use ransomware. The difference lies partly in what those attacks can reach.

Energy businesses increasingly operate a mixture of conventional information technology and operational technology (OT), the systems that monitor or control physical equipment. That can include substations, generation equipment, storage assets, remote telemetry and industrial control systems. A failure in ordinary business IT can stop people working or expose information. An incident that reaches operational systems can also interfere with the company's ability to generate, distribute or supply energy safely.

Research from three different sources helps put the risk into context.

There is an important caveat to the Verizon numbers. Its Utilities category follows the North American NAICS classification and is broader than UK electricity and gas, including water and related utilities. It should therefore be read as a view of the wider utility threat rather than a breach rate for Ofgem licensees. The combination of high external activity and a strong espionage motive is nevertheless relevant to an industry operating critical infrastructure.

1. Energy operations are becoming more connected

The commercial case for digitisation is easy to understand. Remote monitoring can reduce site visits, better data can improve maintenance and forecasting, and connected assets make it easier to manage increasingly distributed generation and demand. IBM's 2026 research found that digitally advanced utilities reported 17% faster outage recovery and 14% greater forecasting accuracy, while utilities investing in OT transformation reported 20% faster integration of distributed energy resources. These are survey findings rather than guaranteed returns, but they help explain why greater connectivity is likely to continue.

The security consequence is that each new connection can create another dependency. An energy company may rely on an identity provider to let engineers log in, a telecommunications company to reach remote assets, a cloud platform to collect operational data and specialist suppliers to maintain equipment. An interruption or compromise in any one of them may affect services some distance away from where the original problem occurred.

The IEA describes a similar shift towards the "grid edge". As distributed generation, electric vehicles, storage and connected consumer devices grow, cyber risk becomes less concentrated in a small number of large operators. Digital connections can also create routes through which failures spread between systems.

Segmentation becomes more important

One of the practical answers is segmentation: separating systems so that access to one does not automatically give access to another. If an attacker compromises an employee laptop or corporate cloud account, there should be controls between that environment and systems used to operate physical assets.

This does not mean disconnecting operational technology from everything else. Modern energy systems need data exchange and, in many cases, remote access. The aim is to know which connections exist, why they are necessary and what someone can reach through them. Ofgem and DESNZ specifically identify separation between IT and OT as one of the measures that could supplement the proposed baseline for licensees.

Access control matters for the same reason. Engineers, contractors and equipment suppliers often have legitimate reasons to connect remotely to assets, but those routes should be identifiable, limited and removable. Permanent supplier accounts, shared administrator credentials and remote connections that cannot quickly be disabled make an incident harder to contain.

For boards, five questions cover much of the issue:

Where are our critical boundaries? Understand how corporate IT, cloud services, remote sites and operational systems connect, concentrating first on systems that could affect operations.

Who can cross them? Privileged and remote access should belong to identifiable people, use strong authentication and provide only the access required.

Can supplier access be stopped quickly? The company should be able to withdraw third-party access during an incident.

What happens when systems are unavailable? Critical services need tested recovery arrangements, including scenarios in which corporate IT or a major supplier is unavailable for several days.

Which assets cannot easily be patched or replaced? Operational equipment can remain in service for decades. Where modern controls cannot be applied, the surrounding architecture may need to compensate. The IEA notes that long asset lives leave many electricity systems operating a mixture of modern connected technology and older equipment designed for a much less connected environment.

For a CFO, this gives cyber investment a more useful frame. Instead of asking how much cyber security the company should buy, management can identify specific operational dependencies, estimate the consequence of losing them and compare that exposure with the cost of reducing it.

2. The regulatory floor is rising

The main cyber-specific regulation for critical energy operators today is the Network and Information Systems Regulations 2018. NIS introduced security and incident-reporting requirements for operators of essential services, including parts of the energy sector. The government's 2026 energy cyber strategy acknowledges a limitation in that approach: NIS was designed to cover the most critical operators and does not provide whole-system coverage.

Ofgem already uses the NCSC's Cyber Assessment Framework (CAF) as part of its NIS assurance for downstream gas and electricity, including a sector-specific CAF Overlay. CAF is broader than a basic technical baseline: version 4.0 assesses outcomes across managing security risk, protecting against cyber attack, detecting cyber security events and minimising the impact of incidents. It is designed around essential functions and can cover both IT and operational technology.

That matters because the structure of the energy system is changing. More organisations now generate, store, aggregate or otherwise support energy services, and their importance cannot always be judged simply by company size. Ofgem and DESNZ therefore argue that it is no longer sufficient to focus cyber requirements on a subset of large operators. Their March 2026 consultation proposed a baseline applying to all Ofgem licensees, alongside a review of NIS thresholds and the services covered by the regime.

The broad direction is easier to see as a timeline:

The exact requirements and implementation dates are still being developed, so companies should distinguish policy direction from settled regulation.

Where Cyber Essentials fits

Ofgem and DESNZ have proposed using Cyber Essentials as the starting point for the new baseline. The scheme covers five areas of basic technical security, including secure configuration, access control, malware protection, firewalls and security updates. Cyber Essentials uses a verified self-assessment, while Cyber Essentials Plus adds independent technical testing of the same controls.

Cyber Essentials and CAF play different roles. The proposed Cyber Essentials baseline is intended to raise the minimum level across all Ofgem licensees; CAF is the deeper, outcome-based framework already used in Ofgem's NIS assurance for Operators of Essential Services. For organisations already assessed against CAF, the proposed baseline should therefore be seen as complementary rather than a replacement.

The proposal is more nuanced than simply requiring Cyber Essentials across the energy sector. Ofgem and DESNZ recognise that the scheme is largely designed for conventional IT and that applying its controls to operational technology can be difficult or, in some circumstances, unsuitable. They also identify areas that Cyber Essentials does not cover in depth, including governance, personnel security, supply-chain resilience and incident response and recovery.

One option under consideration is therefore a hybrid: an established Cyber Essentials baseline, supplemented with controls specific to Ofgem licensees. The consultation identifies IT and OT separation, risk assessment, organisational policies and training, supply-chain security, and response and recovery as possible additions. The final model has not yet been set.

For companies, that makes Cyber Essentials Plus a reasonable preparation point for conventional IT, rather than a complete answer to energy resilience. Organisations already subject to NIS or other energy-sector requirements must continue meeting those obligations, while operational technology, recovery and critical supplier dependencies need their own assessment.

3. Suppliers, software and AI are now part of the operational perimeter

An energy company no longer controls everything it needs to operate. Cloud providers host applications and data, telecommunications companies connect remote sites, equipment manufacturers maintain assets, software providers issue updates, and service companies may have privileged access into important systems.

The result is a wider operational perimeter. A company can maintain strong security internally and still lose an important service because a supplier is compromised or simply unavailable.

Ofgem is addressing this directly. In June 2026 it published proposed guidance for managing supply-chain security across downstream gas and electricity. The draft uses a risk-based supplier criticality model, recognising that a supplier maintaining operational infrastructure creates a different exposure from one providing a low-impact business service. The consultation closed on 30 June and remains listed by Ofgem as awaiting a decision.

For senior management, supplier risk becomes much easier to understand when expressed in operational terms:

This is also where software risk belongs. A critical application may depend in turn on cloud infrastructure, open-source components and third-party services that the energy company never contracted with directly. Mapping every technical dependency is unrealistic, but companies should understand those attached to their most important services.

AI changes the threat, but mostly by changing speed and scale

AI adds another dimension. The immediate cyber effect is more practical than some discussion of frontier AI suggests.

The NCSC assesses that AI will almost certainly make parts of cyber intrusion more effective and efficient. Attackers are already using it for reconnaissance, vulnerability research, exploit development, social engineering and basic malware development. Through 2027, the NCSC expects AI mainly to increase the volume and impact of existing attack techniques rather than produce fully automated, novel attacks.

That matters particularly where companies are slow to patch. The NCSC expects AI-assisted vulnerability research to shorten further the time between a vulnerability becoming known and attackers exploiting it. It identifies critical infrastructure and supply chains using less secure operational technology as an area of particular exposure.

AI also creates new dependencies inside energy companies themselves. Models and AI-enabled applications increasingly connect to corporate data and, potentially, operational systems. The NCSC warns that this enlarges the attack surface, including through software vulnerabilities, malicious prompts and supply-chain attacks against AI systems.

There is a clear operational upside too. AI is already being explored for forecasting, optimisation, predictive maintenance and network management. Ofgem has decided to launch a 12-month AI technical sandbox, targeting late autumn 2026, so energy companies can test defined uses under regulatory oversight.

The board-level questions are therefore fairly conventional. Which AI services are approved? What company or customer information can employees enter? Which important suppliers have AI embedded in their products? Which decisions require a person to check the result?

Payments, changes to supplier details and changes to operational systems are obvious places to retain independent verification. AI makes convincing emails, documents and voices easier to produce, which makes informal approval processes less dependable.

What should CEOs and CFOs do now?

The regulatory detail will continue to move, but most sensible preparation does not depend on predicting the final Ofgem rules. Start with the handful of services whose loss would cause the greatest operational, customer, financial or regulatory damage, then work backwards through the technology and suppliers required to provide them.

A board should be able to get clear, evidence-backed answers to six questions:

The shift in Ofgem's approach reflects a wider change in the energy system. Smaller operators and distributed assets can now matter to system resilience in ways that were less obvious when generation and control were more concentrated. Ofgem and DESNZ's consultation explicitly recognises that the growing number of organisations participating in the energy ecosystem has changed what should be considered critical.

For leaders, the immediate priorities are already clear: know which services the business cannot afford to lose, the systems and suppliers they depend on, the routes an attacker could use to reach them, and how quickly the company could recover. Regulation will formalise parts of that work over the coming years, but the operational exposure exists today.