The UK is increasing its focus on securing critical national infrastructure and its associated supply chains in the wake of a cyberattack that temporarily shut down a British power plant. The attack, attributed to Iran-linked hackers, involved a "peaker" plant, a small-scale energy generator, and although the government stated there was no risk to the wider energy system, it highlighted vulnerabilities within the supply chain.
This incident underscores a growing concern among cybersecurity professionals regarding supply chain breaches, where attackers infiltrate organizations through trusted third parties. Such attacks allow hackers to gain access to numerous networks, potentially impacting hundreds of downstream customers and companies. For example, a 2020 attack by Russian intelligence on SolarWinds, an IT company, exposed approximately 18,000 of its customers, including US government agencies.
In response, the UK government is introducing measures to bolster cyber resilience. This includes the cyber resilience pledge, launched in July, which encourages businesses to adopt the government-backed Cyber Essentials scheme across their supply chains. Companies like M&S and Microsoft UK have already committed to this pledge. Additionally, a new cyber security and resilience bill is progressing through parliament, aiming to make government guidance on supply chain security mandatory. The National Cyber Security Centre (NCSC) has also issued advisories, urging organizations, particularly those with operations or supply chains in the Middle East, to enhance their cybersecurity posture and report any suspicious activity.