Authors: Barry Jones Jamie Gee Sidharth Wahi

null

The recent cyber-attack against a UK power generation facility, reportedly attributed to Iranian-affiliated threat actors, is being described as one of the first successful disruptive cyber-attacks against British energy infrastructure. While the affected facility was a relatively small-scale generator and the wider UK power grid remained unaffected, the incident raises an important question for energy companies worldwide: how resilient are critical infrastructure operators in an increasingly volatile geopolitical environment?

Although the attackers' precise objectives remain unclear, the incident shows that threat actors can infiltrate operational environments and disrupt essential services. Security specialists have suggested that this may form part of a broader campaign targeting critical infrastructure, increasing the likelihood of further attacks against energy, utilities and other essential service providers.

The event also reinforces a long-standing concern within the energy sector that Operational Technology (OT), Industrial Control Systems (ICS) and connected control devices often do not benefit from the same levels of security maturity as traditional IT environments. As a result, they continue to present an attractive attack surface for threat actors seeking to cause operational disruption.

Had the attackers been able to manipulate critical operational processes, the consequences could have extended well beyond a temporary outage. Cyber compromise of OT systems can result in prolonged operational shutdowns, significant business interruption losses, physical damage to assets, environmental incidents and in extreme cases, risks to life and safety. For energy operators, cyber risk has evolved from an IT concern into a core operational and asset protection issue.

The incident is particularly relevant for Middle East operators given the region's concentration of strategically important energy, petrochemical and industrial infrastructure. While the specific circumstances of this attack are unique, the underlying risk is not. Energy companies across the region rely on operational technology, industrial control systems and third-party connectivity that can create potential pathways into critical operating environments. The key question is therefore not whether the UK incident could be replicated in precisely the same way, but whether a cyber intrusion could escalate into production disruption, business interruption, physical damage or safety-related consequences at a regional facility. Publicly reported activity by Iranian-affiliated actors against operational technology environments demonstrates that critical infrastructure remains an attractive target in periods of heightened geopolitical tension.

The key lesson for the industry is the need for a holistic approach to cyber resilience across both IT and OT environments. There are of course key areas for organisations to focus on to build cyber resilience, such as securing remote access pathways, segmenting critical systems and strengthening OT monitoring. However, there is also no substitute for testing incident response procedures through realistic crisis response workshops, penetration testing and stress testing business continuity plans.

Technician using laptop while analyzing server in server room

For company boards, maintaining visibility on their cyber vulnerabilities can often be challenging, along with where investment should be directed. Working with the in-house Cyber security and IT teams, structured risk assessments and risk quantification from Cyber specialists can be a useful tool to provide a clear view of the control maturity and help companies prioritise investment where weaknesses could allow an intrusion to escalate into an operational or physical loss event.

From an insurance perspective, the incident is a timely reminder of the value of specialist cyber risk transfer solutions, supported by cyber risk quantification to translate technical vulnerabilities into financial loss scenarios. This can help inform board-level decision-making, insurance programme design and the adequacy of business interruption, data and system restoration, cyber extortion, regulatory investigation and third-party liability cover.

For power and energy businesses, cyber-induced physical damage should be assessed carefully. Traditional property policies typically contain cyber exclusions, which may leave damage to physical assets arising from an uninsured cyber event. Specialist cyber physical damage and cyber business interruption solutions can help address this exposure where cyber-attacks impact operational technology, equipment and critical infrastructure.

As geopolitical tensions continue to influence cyber activity, incidents such as this underline that critical infrastructure operators must be prepared to withstand, respond to and recover from attacks that have the potential to disrupt physical operations. For Middle East energy businesses, the lesson is not to focus solely on the threat actor or the specific circumstances of this event, but to understand the cyber scenarios that could have the greatest operational and financial impact on their own organisations. Combining robust IT and OT controls, structured risk assessments, cyber risk quantification, realistic crisis exercises and appropriately structured insurance programmes provides a more effective means of protecting operations, assets and balance sheets in an increasingly hostile threat environment.

Author Information

Barry Jones

Barry Jones

Executive Director — Power & Construction

Jamie  Gee ,  CA

Jamie Gee, CA

Director — Financial Lines

Sidharth Wahi

Sidharth Wahi

Head of Cyber Risk Advisory


Disclaimer

This information is not intended to constitute any form of opinion or specific guidance, and recipients should not infer any opinion or specific guidance from its content. Recipients should not rely exclusively on the information contained in the article and should make decisions based on a full consideration of all available information. We make no warranties, express or implied, as to the accuracy, reliability or correctness of the information provided. We and our officers, employees or agents shall not be responsible for any loss whatsoever arising from the recipient's reliance upon any information we provide and exclude liability for the statistical content to the fullest extent permitted by law.

Gallagher Re Ltd is authorised and regulated by the Dubai Financial Services Authority (DFSA).
Registered Business Address: Office 702. Level 7, Gate Building, West Wing, DIFC, Dubai,
UAE, PO Box 507061, Dubai, UAE. Registered in Dubai, UAE.
DFSA Reference Number: F005278.