Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant

Written by

Experts have expressed grave concerns over the resilience of the UK’s critical national infrastructure (CNI) after reports emerged that Iranian hackers managed to shut down a power plant for several days last month.

The Telegraph revealed the news on August 22, claiming that the attack happened at the same time as a large-scale operation targeting US water plants. It has not been revealed which plant was targeted.

What is known is that the facility was disabled for four days, although because it was relatively smally, the outage reportedly had little impact on the country’s power supply.

Read more on Iranian threats: Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage

Graeme Stewart, head of public sector at Check Point, said the attack should concern every CNI provider in the country.

“We have to ask what happens if the next target is bigger, more critical or more deeply connected to the services millions of people rely on,” he added.

“Britain’s CNI underpins almost every part of modern life, including electricity, water, transport and communications, and those systems are increasingly digital, interconnected and dependent on one another. A serious attack on one part of that ecosystem has the potential to cause disruption far beyond the original target.”

If the purpose of the attack was to demonstrate that serious compromise of CNI is possible, the size of the facility is not as important as the face that the breach succeeded, Stewart continued.

"The question now has to be whether Britain is genuinely ready if something more serious follows,” he said.

“Operators of essential services need to know exactly how they keep functioning when systems are compromised, how quickly an attack can be contained and how they recover without allowing disruption to spread.”

Huntress vCISO EMEA, Muhammad Yahya Patel, warned of a potential visibility gap when it comes to smaller CNI operators.

“If smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of our infrastructure is being targeted or successfully compromised,” he argued.

“Attackers will look for the weakest route in, so resilience, monitoring and rehearsed recovery need to extend across the wider energy ecosystem. The real measure of cyber resilience is no longer simply whether you can prevent an intrusion. It’s whether you can contain one quickly enough that a cyber incident doesn’t become an operational crisis.”

Iran Tools Up for Cyber Conflict

In July 2025, UK lawmakers warned that Iran posed a major cyber threat to the country, although they singled out petrochemical, utilities and finance sectors as likely targets of disruption.

An Intelligence and Security Committee (ISC) report noted at the time that the UK was “not a top priority for Iranian offensive cyber activity,” but that “this could change rapidly in response to regional or geopolitical developments.”

Although the UK government has not explicitly backed US military action in the region, it allowed its ally to launch “defensive” operations from British bases hosting American planes.

The UK power plant breach was “unfortunately inevitable,” according to James Griffiths, former military and GCHQ advisor and founder of UtopianKnight Consultancy.

“This is something that most will have been worried about happening for a long time,” he added. “The under-investment in protecting our CNI in the UK has always been an issue, with legacy and aged systems running the core of what we take for granted: power.”

In late July, Iran-backed hackers caused operational disruption across at least 12 US states by targeting programmable logic controllers (PLCs) across several CNI sectors including government services and facilities, water and wastewater systems, and energy.

What’s Hot on Infosecurity Magazine?