AI & ML

Enhancing Cybersecurity for Vulnerable Critical Infrastructure in the UK and US

Recent cyberattacks on smaller power systems highlight a growing vulnerability in critical infrastructure that demands urgent attention and protective measures.

Aug 27, 2026 3 min read
Sign in to save

A recent cyberattack on a small electricity generator in the UK brought to light a significant vulnerability within the realm of critical infrastructure. While this specific attack, attributed to Iranian-linked hackers, did not trigger widespread power outages, it uncovered lasting weaknesses prevalent among smaller generators, water systems, and other industrial sites lacking robust cybersecurity protocols.

Reports emerged in July claiming that an unidentified British generator fell victim to this cyber incident, setting off alarm bells across the media. However, the UK government has not provided detailed information about the facility or confirmed if the Iranian hackers were indeed responsible. Energy Minister Michael Shanks downplayed the situation, stressing that the affected generator was relatively small and not reflective of larger, more critical power facilities.

Still, the incident was serious enough for the UK government to engage with energy executives and collaborate with the National Cyber Security Centre to assess the potential impact and bolster cybersecurity measures where necessary. This situation is reminiscent of patterns observed in the United States, where a rise in cyber incidents targeting operational technology (OT) systems has drawn attention from regulatory agencies.

Understanding the Pattern of Vulnerabilities

The vulnerability illustrated by the UK attack aligns with documented cyber threats faced by US water and wastewater utilities. In a recent report published by the FBI and the Environmental Protection Agency, these agencies warned that malicious actors had targeted internet-facing programmable logic controllers (PLCs) across various states, successfully altering operational protocols and disrupting essential services.

The Cybersecurity and Infrastructure Security Agency (CISA) has raised concerns over the scale of these attacks, suggesting that more than 100 systems within the water sector were at risk. Insights from cybersecurity firms reveal that, among their clients, numerous instances of compromise were detected during the same campaign—notably resulting in altered PLC project files and control discrepancies that could lead to operational disruptions.

While media reports often sensationalize individual incidents, experts emphasize the importance of focusing on the broader implications of these attacks. Phil Tonkin, a field CTO at Dragos, cautions against jumping to conclusions about the scale and nature of an attack, as firsthand information is often lacking.

The Consequences of Aging Infrastructure

The core issue manifesting in both the UK and US scenarios stems from systemic vulnerabilities inherent to smaller operational systems. Unlike large energy providers, smaller municipal entities frequently lack stringent security regulations, leading to significant risks associated with the internet exposure of operational technology.

As these facilities digitize for enhanced monitoring and management capabilities, they simultaneously expose older equipment originally designed without cyber threats in mind. Many of these smaller organizations have neither the governance structures to enforce security protocols nor the funding to develop comprehensive cybersecurity measures.

This over-reliance on undifferentiated technology without adequate protections places them in a precarious position, where thousands of vulnerable devices are left open to exploitation. The threat of coordinated attacks across interconnected systems adds a layer of complexity that could potentially disrupt a broader network of services.

Urgent Cybersecurity Recommendations

Addressing these vulnerabilities requires immediate, no-nonsense actions. Agencies like the FBI recommend that utilities eliminate direct internet exposure for their PLCs, transitioning remote access protocols behind secured gateways. Security measures should include updating default credentials, limiting communication through secure channels, and implementing physical or software locks to inhibit unauthorized changes.

Moreover, operators should ensure the availability of known-good configurations for PLCs and maintain operational capabilities for manual intervention. This latter point is particularly crucial for facilities that may not have the capacity to perform remote maintenance.

The challenge intensifies for smaller utilities, which often operate on tight budgets and limited personnel. The Biden administration is reportedly taking steps to aid these entities by engaging private cybersecurity firms to identify and address exposed systems.

Collaboration Among Critical Infrastructure Operators

A broader collaborative approach among larger infrastructure operators is also imperative. While their cybersecurity teams may not control smaller municipal systems directly, the dependence on these systems for overall service stability highlights the need for mutual support and resource sharing within the supply chain. The concept of mutual-aid agreements used after natural disasters—where resources are pooled to address crises—should apply in this context as well.

Ultimately, the objective should be to ensure that these smaller entities can defend themselves against the evolving threats posed by cyber attackers. Operators must enhance their defensive capabilities, regardless of the source of the threat. Whether facing domestic or international actors, the focus must be on improving security measures and preparedness in the face of potential attacks.

In conclusion, as the cyber landscape continues to evolve, the vulnerabilities faced by critical infrastructure, especially the smaller, less fortified systems, demand urgent and sustained attention. Without proactive measures, the risks posed by unsecured devices could culminate in larger-scale disruptions affecting far more than just localized facilities.

Source: John Davis · www.csoonline.com

Comments

Sign in to join the discussion.