Editor’s Note: A cyberattack forced a small British generator offline for four days in July, and the minister for energy has since said nobody lost power. Both facts matter legally, and not in the way the headlines suggested.
Two tests stand between an incident and a mandatory notification under the UK’s NIS Regulations. The first asks whether the operator is regulated at all, assessed against an undertaking’s cumulated capacity across affiliated companies rather than a plant’s rating, with supply above 250,000 customers a separate route in. The second asks whether the incident had “a significant impact on the continuity of the essential service”, judged on users affected, duration and geography. An unidentified operator makes the first unanswerable. The minister’s own words speak to the second.
Seventeen days before this story broke, the Department for Energy Security and Net Zero and the regulator Ofgem published a consultation response in which the electricity generation threshold drew more proposed changes than any other threshold. The department plans to consult on revised thresholds within 2027 if the review concludes amendments are needed and the Cyber Security and Resilience Bill receives Royal Assent. Lords committee stage is scheduled for Sept. 1. Watch what happens to the perimeter.
Content Assessment: Four days offline, and a threshold already under review
Information - 92%
Insight - 92%
Relevance - 91%
Objectivity - 91%
Authority - 92%
92%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "Four days offline, and a threshold already under review."
Industry News – Cybersecurity Beat
Four days offline, and a threshold already under review
ComplexDiscovery Staff
Reports say a cyberattack forced a small British energy generator offline for four days in July. An unnamed government source told The Telegraph the site was nowhere near the thresholds for mandatory notification, and because the operator remains unidentified, its full regulatory status cannot be established from the public record.
What the public knows about that outage starts with two newspaper reports and has since been answered, in part, by a minister on X.
The Telegraph reported Aug. 22 that hackers linked to Iran had forced the generator to stop producing electricity for four consecutive days the previous month, and the Financial Times reported the incident as well. The Telegraph described it as believed to be the first occasion on which anyone had brought a British power plant to a standstill through a computer network. A government source, in comments reported by the paper and repeated across later coverage, put the site’s output below a rounding error measured against national grid capacity, and said the thresholds obliging important generators to notify the government of cyber activity sit far above a site that size.
Read the source of that characterization with care. An unnamed official describing an intrusion that The Telegraph attributed to Iran-linked hackers as smaller than a rounding error against grid capacity is a source with an interest in the reader reaching exactly that conclusion, and it reaches this article at second hand: The Telegraph’s report could not be independently reviewed.
What the government has said on the record
Britain briefed energy company chief executives Monday, Reuters reported, and Michael Shanks, the minister for energy, addressed the incident in a post on X without saying who was behind it or where it happened.
“To be clear: there was no threat to the wider grid and nobody lost power,” Shanks wrote. “The generator in question is tiny, especially compared to what most of us would class as a ‘power plant/station’.”
A spokesperson for the Department for Energy Security and Net Zero had told CNBC a day earlier that “this story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system,” adding that “the U.K. has a highly resilient energy system.” DESNZ also wrote to companies with guidance on next steps and has said it is updating its cybersecurity regulations. The National Cyber Security Centre declined to comment on specifics. Reuters reported that the Iranian embassy in London had not responded to its request for comment.
Several accounts say the incident was reported to the NCSC, though none establishes who submitted the report. If, as the unnamed government source suggests, no mandatory Network and Information Systems (NIS) notification was owed, that contact would have sat outside the compulsory channel. What is less clear is whether any mandatory notification was owed at all, and that question has two parts that the cited incident reports do not clearly separate.
Two tests, not one
The first part is whether the operator is regulated. Schedule 2 of the NIS Regulations 2018 reaches generation only inside the threshold for electricity supply, and only for “electricity undertakings that carry out the function of supply, and generation via generators” whose capacity is “greater than or equal to 2 gigawatts.” That figure is not a plant rating. As the government’s own summary of the regime puts it, “the generation capacity of all affiliated undertakings is cumulated and assessed against the threshold.” A modest site inside a large corporate group can sit above the line; a standalone site of the same size can sit below it.
Capacity is also not the only route in. Supply to above 250,000 final customers is a separate qualifying threshold, and January guidance from Ofgem, the energy regulator that shares competent authority under the regulations with DESNZ, cautions that identifying essential services under Regulation 8 is a question of consumer impact as well as generation or network capacity. Sub-paragraph (6) then removes nuclear generators and generators not connected to a transmission system. Northern Ireland works differently again, reaching generation licence holders at 350 megawatts.
So a small, standalone generator could fall outside the generation-based threshold in several ways, depending on its operator’s supply activities, affiliated capacity and grid connection. Which of those apply here is unknowable while the operator is unnamed, and the government source’s remark is the only public evidence on the point.
The second part receives less attention in the cited incident coverage. Being regulated does not make every incident reportable. The regulations call a designated operator an operator of essential services, and Regulation 11(1) requires notification of “any incident which has a significant impact on the continuity of the essential service which that OES provides.” Regulation 11(2) then sets out how significance is judged, and an operator “must have regard to the following factors”: “the number of users affected by the disruption of the essential service”, “the duration of the incident”, and “the geographical area affected by the incident”. Only when that test is met does the 72-hour clock in Regulation 11(3) begin.
Set the minister’s words beside those factors. Nobody lost power, Shanks said, which speaks to the first. The outage ran four days, which speaks to the second. Whether the third was engaged is unknown. Two incidents at operators of identical size can therefore produce different reporting outcomes, depending on their effects on continuity. That second-stage analysis does not turn on the 2-gigawatt figure at all.
Preservation when nothing external starts the clock
Here is the operational problem, and it is why this story belongs to records people as much as to security people.
A four-day restoration effort would ordinarily generate some combination of operational technology logs, engineering workstation images, vendor incident response correspondence, executive decision records, insurer notifications and restoration timelines. Some of those materials may now exist at the company that operated the plant. They would also be over a month old and sitting under retention schedules written without reference to this event.
What may be absent is one predictable external artifact: a mandatory NIS incident notification to the competent authority. That is worth less than it sounds, though not nothing. It does not establish that no other records exist or that nobody can ever reach them. A report to the NCSC may exist. Insurance notifications, contractual reporting to counterparties, licence obligations and any investigation could each generate their own records. English civil procedure supplies routes to those records in litigation: a party that considers another’s disclosure inadequate can apply for specific disclosure under Practice Direction 31A, and the court can order a search.
The narrower and more useful point is about escalation. A mandatory regulatory notification can supply a documented escalation moment for legal, compliance and records teams, a fixed date that a hold can be hung on. Without one, preservation depends on internal incident escalation, anticipated claims, contractual duties, insurance requirements or other facts indicating that proceedings or an investigation may follow. A press report may prompt that assessment. It is not automatically a legal trigger: under Practice Direction 57AD in the Business and Property Courts, the duty attaches to a person who knows it is or may become a party to proceedings that have been or may be commenced. Where it does attach, it reaches documents that would otherwise go under a retention policy or in the ordinary course of business, and it carries an obligation to suspend those deletion processes. That is the provision an untouched retention schedule runs into.
Note also who learns what, and when. The operator knew about its own outage while restoring the plant; a newspaper was not its first notice. For counterparties, insurers, prospective acquirers or counsel not already informed, Aug. 22 may have supplied the first public notice. That possible asymmetry, rather than any absence of records, is the practical problem.
The move worth making this week is narrow. Ask whether any asset in the portfolio might sit outside the NIS perimeter, then ask what the retention period is on the operational systems at those assets, because sites nobody expects to be regulated may be the ones where logging was scoped to operational need rather than evidentiary need. A hold that reaches corporate email and misses the historian preserves the conversation about the incident and loses the incident. For information governance, the durable fix is a defined retention floor for operational telemetry at those sites.
How far the American comparison reaches
Set the UK outage beside the intrusions into US water systems that federal investigators have been examining since late July. CBS News reported that at least a dozen states had seen such attacks and was careful to say investigators suspect Iran-backed actors without having made any formal attribution. Minnesota authorities announced on July 28 that treatment plants across over 30 communities had been hit, and one of the affected Minnesota communities, Braham, has around 1,700 residents, TechCrunch reported.
The federal reporting regime created by the Cyber Incident Reporting for Critical Infrastructure Act does not yet impose its planned requirements. Guidance from the Cybersecurity and Infrastructure Security Agency says organizations are not required to submit incident or ransom payment reports under the act until the final rule takes effect, and the agency has not set that date. In the meantime CISA asks organizations to share voluntarily.
That is the whole of the comparison, and it is narrower than it first appears. It does not establish whether the affected utilities had reporting duties under state law, another federal program, contracts, insurance policies or sector-specific requirements, none of which this article examined. What can be said is that neither CIRCIA nor, on the reported account, the British generator’s status appears to have produced the particular mandatory notification each regime contemplates. Whether that reflects anything about how targets get chosen is a question, not a finding, and no agency has formally attributed either campaign.
Scale supplies the context. In the 12 months to August 2025 the NCSC handled 204 attacks in its “nationally significant” category, which the agency defines as carrying a substantial impact on national security, the economy or critical infrastructure, up from 89 the year before and an average of four each week. A separate count, over a different period and a different population, points the same way. Richard Horne, chief executive of the NCSC, told the Royal United Services Institute in June that his teams had handled over 200 incidents affecting critical infrastructure in the year to May, about three-quarters of them believed to be state work, and he repeated the four-a-week figure in the same lecture. “Cyber security is now a matter of business survival and national resilience,” Horne said in the agency’s most recent annual review.
The threshold was already contested
Seventeen days before the Telegraph published, DESNZ and Ofgem answered a consultation on exactly this question.
Their joint response, updated Aug. 5, records 49 respondents to the question of whether current thresholds capture the right operators, four of whom gave no answer. The counts that follow overlap, since a single respondent can appear in several of them. The electricity generation threshold drew more proposed changes than any other threshold, from 19 of the 49. Fifteen wanted the supply and customer-number threshold changed. Twenty-one argued thresholds should be risk or impact driven rather than resting on a supply or generation approach, and 19 said a sector that has grown more distributed has outrun thresholds that no longer track where risk actually sits among smaller operators. Seven, all Ofgem licensees, said the thresholds remain broadly appropriate and warned against loading regulatory burden onto operators posing less system risk.
The government’s answer was to commission advice rather than to move. It has asked the National Energy System Operator for recommendations on how to ensure the regulations capture the most critical operators, and says it will then evaluate whether amendments are appropriate and reconsult. The dates sit in two layers. From the Energy Sector Cyber Security Strategy, restated in this response, the government has committed publicly “to assess the NIS regulatory thresholds, including whether new critical sub-sectors need to be captured, by the end of 2027”, and to shape baseline resilience proposals for all Ofgem licensees on the same timetable, with a baseline across the whole downstream gas and electricity system by the end of 2030. The response’s own next steps then set out the mechanism: Ofgem to consult within 2027 on baseline requirements, and DESNZ to consult within 2027 “on proposals for revised NIS thresholds and essential services”, that second commitment expressly subject to the Cyber Security and Resilience Bill receiving Royal Assent.
Those conditions matter for the calendar, and they do not reach everything. The commitment to assess the thresholds by the end of 2027 stands on its own. A further consultation on revised thresholds is subject to the bill receiving Royal Assent, and to the government concluding, after considering NESO’s advice and the consultation responses, that amendments are needed.
The words the Lords did not use
Parliament has been rewriting this regime all year, and the second reading record is worth reading against the consultation.
The bill cleared the Commons in June and had its second reading in the Lords on July 14. Baroness Lloyd of Effra, moving it for the government, told peers it brings data centres meeting its thresholds into the regime as essential services, along with large load controllers, meaning organisations managing electricity flows to and from smart appliances. She also described a change to reporting: where the present duty bites only after disruption has occurred, operators would report a wider range of incidents to their regulator and the NCSC “within 24 hours and provide a full report within 72 hours”, covering “incidents such as pre-positioning and ransomware, where an incident may not cause immediate damage but poses a real threat to the UK economy or society.”
Scope was argued hard. The Earl of Effingham pressed the government to “confirm to your Lordships’ House that the overwhelming majority of SMEs will remain outside the scope of these new regulatory requirements” and asked “by what benchmark will an SME be defined in the legislation?” Lord Birt went the other way, proposing the perimeter reach every company big enough to need a statutory audit, roughly 15 million pounds of turnover and above 50 employees, which he put at 2 percent of UK companies accounting for 70 to 80 percent of the economy. Baroness Northover read into the record a submission warning that swathes of the economy would sit outside what it called the regulatory perimeter.
In the Hansard text available on Aug. 24, across 25 speakers, the words generation, generator, power station, power plant, megawatt and gigawatt do not appear at all. Data centre appears 16 times, and threshold and thresholds seven times between them. Hansard notes that the record for that sitting was still being processed.
The omission is specific to the Lords debate, and it should not be read as government inattention. Outside Parliament, DESNZ and Ofgem had already consulted on the generation threshold and committed to consulting again on revised thresholds within 2027. What the transcript shows is that the chamber revising the parent legislation spent its scope argument on company size and on the digital layer, while the generation threshold was being contested somewhere else entirely.
Where this goes next
Committee stage in the Lords is down to begin Sept. 1, and the bill has not received Royal Assent. Committee is a principal stage at which peers can propose and debate scope amendments, and it is the next scheduled legislative opportunity to raise the July outage while examining the bill’s perimeter. It is also one step toward the Royal Assent that DESNZ made a condition of any 2027 consultation on revised thresholds.
Whether the perimeter moves down the capacity curve remains genuinely open. The consultation records substantial support for impact-driven thresholds: of the 49 respondents, 21 gave that as a reason for change, while seven, all Ofgem licensees, said the current thresholds were sufficient and warned against pulling smaller operators in. The burden argument that Effingham and Lord Arbuthnot made in that debate about smaller firms does not evaporate because a plant went offline for four days.
For anyone holding a preservation obligation, the question is nearer. If the first notice you get of an incident at a counterparty, an insured or an acquisition target arrives as a headline rather than a notification, what in your process turns that into an assessment?

News sources
- UK briefs energy chiefs after Iran-linked cyber attack reports (Reuters)
- Small UK power generator shut after Iran-linked cyberattack: report (CNBC)
- The Network and Information Systems Regulations 2018, Regulation 11 (legislation.gov.uk)
- Practice Direction 57AD, Disclosure in the Business and Property Courts (Ministry of Justice)
- Practice Direction 31A, Disclosure and Inspection (Ministry of Justice)
- Reshaping cyber regulation in downstream gas and electricity: government response (Department for Energy Security and Net Zero and Ofgem)
- Iranian hackers shut down UK power plant (The Telegraph)
- Iran-linked hackers force UK power generator offline (Financial Times)
- UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks (Security Affairs)
- UK experiencing four ‘nationally significant’ cyber attacks every week (National Cyber Security Centre)
- The Network and Information Systems Regulations 2018, Schedule 2 (legislation.gov.uk)
- Cyber Security and Resilience (Network and Information Systems) Bill, Second Reading, House of Lords, 14 July 2026 (Hansard)
- Cyber Security and Resilience (Network and Information Systems) Bill Stages (UK Parliament)
- Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) (Cybersecurity and Infrastructure Security Agency)
- At least 12 states report cyberattacks on water systems possibly linked to Iran-backed hackers, sources say (CBS News)
- What we know about the alleged Iranian hacks on U.S. water utilities (TechCrunch)
- NIS Guidance for Downstream Gas and Electricity Operators of Essential Services in GB, v3.0 (Ofgem)
- Hostile states behind three-quarters of attacks on Britain’s critical infrastructure, cyber chief warns (The Record)
Assisted by GAI and LLM technologies
Additional reading
- A program not yet publicly operational, and an untested Computer Fraud and Abuse Act defense
- Recent AI evaluation incidents expose gaps in containment, configuration and evidence
- When hacktivists join the fight: A closer read of Cyber Law Toolkit scenario 36
- Beijing contests House Salt Typhoon report as Congress weighs a wider cleanup
- Restore the controller, risk losing evidence: federal water guidance leaves the sequence open
- Policy without control: the AI governance gap in IBM’s 2026 Cost of a Data Breach Report
- ShinyHunters’ July 31 deadline for EY arrives after third-party tax-data breach
- The new negligence baseline: how voluntary CI Fortify guidance becomes Exhibit A in post-breach litigation
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.


























