GCS Threat Briefing
Critical National Infrastructure

Too Small To Notify

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
August 2026 · 9 min read
GCS Threat Briefing cover: Too Small To Notify. A dark brand panel showing the 2 GW Operator of Essential Services designation threshold for UK electricity generation, with the obligations that apply above the line and the absence of obligations below it, in Garzon Cyber Solutions red and white.

The most revealing statement about the cyberattack on a British power plant did not come from the attacker. It came from the government. A source told The Telegraph the site was “less than a rounding error compared to grid capacity” and sat nowhere near the threshold at which a generator is legally required to notify the state of cyber activity. That was offered as reassurance. Read it a second time as a targeting criterion and it becomes the finding.

What happened

In July 2026, hackers linked to Iran’s Islamic Revolutionary Guard Corps took a British power plant offline. Staff worked for four days to restore it. The Telegraph disclosed the incident on 22 August 2026, describing it as the first occasion on which hackers affiliated to the Iranian regime have succeeded in closing down such a facility in the UK.

Officials have not named the site, citing security. The plant was small and the outage did not affect the wider power supply at any stage. The incident was reported to the National Cyber Security Centre, part of GCHQ, which has not commented on the specifics. Government has since warned power companies and businesses about the incident and issued guidance on how to respond.

  • July 2026A small UK power generator is taken offline. Four days to restore. No impact on the wider grid at any point. The site is not named.
  • 26 July 2026First reports of attacks on US water infrastructure, beginning in Minnesota.
  • July to August 2026Dozens of wastewater treatment plants affected across 12 US states. Flooding and loss of pressure. Boil water notices issued. The FBI attributes the incidents to malicious cyber actors. US government sources later indicate Tehran as the most likely origin.
  • 22 August 2026The Telegraph discloses the UK incident. Government confirms it has warned industry and provided guidance.
  • 24 August 2026No further UK regulatory statement. The NCSC has not commented on the specific incident.
4Days the generator stayed offline
2 GWUK designation threshold the site sat below
12US states hit in the concurrent water campaign
5-25%Cabinet Office estimate of a serious successful attack on domestic infrastructure
Infographic titled the threshold gap, two regimes one grid. Above 2 GW an electricity generator carries a statutory incident notification duty, assessment against the NCSC Cyber Assessment Framework, Ofgem and DESNZ as competent authorities, and exposure to enforcement powers and financial penalties. Below 2 GW there is no designation, no duty to notify, no framework assessment, no competent authority relationship, and security spend is set by the business rather than the regulator. The site attacked in July 2026 was a small generator, offline four days, reported to the NCSC voluntarily.
Designation under the NIS Regulations 2018 turns on capacity, not on consequence. The line is drawn at 2 GW, cumulated across affiliated undertakings and measured as input to a transmission system.

Why this one is different

The attack is not thought to have been designed to harm civilians. The more probable intent, on the reporting so far, was to demonstrate that actors linked to the IRGC could reach UK infrastructure and switch it off at will.

That reframes the outcome entirely. A four-day outage at a generator nobody outside the industry noticed is not a failed attack. It is a completed proof of concept, delivered below the level at which anyone was obliged to tell anyone.

What separates this from the operational technology incidents of the past decade is not the malware, the entry path or the sector. It is that the size of the target looks chosen rather than incidental.

Under the UK’s NIS Regulations 2018, an electricity generator becomes a designated Operator of Essential Services when its capacity, cumulated across affiliated undertakings and measured as input to a transmission system, reaches 2 GW. Below that line there is no designation, no Cyber Assessment Framework, no competent authority relationship and no statutory duty to notify. The government’s own defence of the incident, that the site was nowhere near the threshold, is also a precise description of why it was worth attacking.

An adversary running a demonstration wants three things: a real physical effect, a low probability of a national-level response, and deniability. A below-threshold asset supplies all three. The effect is genuine. The reporting is voluntary. The response is a local engineering problem rather than a matter of state.

Infographic titled the central argument, below the line is the target. One, a real physical effect: generation stops and the consequence is genuine, measurable and undeniable. Two, a low chance of national response: no statutory notification means slower national visibility and a local engineering response rather than a state one. Three, deniability: no named victim, no regulatory filing and no disclosure timetable, so the event stays inside the operator. The conclusion is that a four-day outage at a generator nobody outside the industry noticed is a completed proof of concept.
The regulatory threshold and the attacker’s targeting criteria turn out to be the same number, read from opposite directions.

What four days actually tells you

Duration is the metric that survived disclosure. Nobody has published how the attacker got in, and it may never be public. What is public is that restoring a small generator took four days.

Four days is not a patching failure. It is a statement about recovery capability. It says something about the segmentation between corporate IT and operational technology, the availability of known-good backups for control systems, the existence of a tested manual fallback, and whether anyone had ever rehearsed the decision to run the site without its automation. Operators at this scale rarely hold all four, not through carelessness, but because nothing has ever obliged them to.

Now scale the observation. Below-threshold operators are not a rounding error in aggregate. They are the distributed generation estate, the industrial parks, the logistics depots, the water and waste sites, the building management estates and the manufacturers embedded in the supply chain of every large UK business. Almost all of them sit outside the designation regime. Almost all of them sit inside somebody else’s operational dependency.

The wider pattern

The UK incident was concurrent with a campaign against US water infrastructure. Dozens of wastewater treatment plants across 12 states were affected, causing flooding and loss of pressure, with boil water notices issued in affected areas. Reports began in Minnesota on 26 July 2026, followed by Michigan, Georgia, South Dakota, New Jersey and Alabama. The FBI attributed those incidents to malicious cyber actors, and US government sources later indicated that the activity most likely originated in Tehran.

Iran has accelerated operations against Western targets since the US and Israel began air strikes in February. Suspected Iranian activity has been reported in Germany, Poland, Finland, Belgium and Albania. In March the NCSC advised British organisations to review their security posture in light of the wider conflict. In June, NCSC chief executive Richard Horne said the agency had handled more than 200 attacks on critical national infrastructure in the preceding year.

Set against that, the Intelligence and Security Committee reported last year that the chance of an Iranian cyberattack on British infrastructure was unlikely. A Cabinet Office risk assessment published in July 2026 put the probability of a serious and successful cyberattack on domestic infrastructure at between 5% and 25%, and warned that AI is making attacks faster and cheaper to run while lowering the technical bar for anyone attempting them.

The distance between those two assessments closed in a single month.

The commercial exposure for UK organisations

Regulatory. Two things are moving at once. The Cyber Security and Resilience Bill reached Lords Committee stage on 1 September 2026, with Royal Assent expected later this year and phased implementation running toward 2028. It brings managed service providers under direct oversight for the first time, creates a designated critical supplier category, and introduces a 24-hour early warning followed by a 72-hour full report to both the sector regulator and the NCSC. Penalties reach £10m or 2% of global turnover, rising to £17m or 4% for the most serious breaches. Separately, DESNZ and Ofgem are consulting on reshaping cyber regulation in downstream gas and electricity, with the National Energy System Operator advising on which services are essential and where the thresholds should sit. The threshold that failed in July is being redrawn now. Any organisation planning against the current line is planning against a number with a short remaining life.

Financial. Operational disruption does not generate a data notification cost. It generates production loss, emergency response, reconstruction and contractual penalty. Four days is the figure to model with, not the theoretical recovery time written into the plan. Insurers underwrite on demonstrable control maturity and settle on demonstrable facts, and a below-threshold operator has typically documented neither.

Contractual. This is where organisations outside the designation regime meet the regulation anyway. A firm outside NIS designation still sells to firms inside it, and both Article 21 of NIS2 and the incoming UK Bill push supply chain security obligations down the chain by contract. The regulatory floor is not the standard your customers apply. Their supplier assurance process is. A four-day operational outage at a supplier is a service credit event, a right-to-terminate event, and in a competitive retender it is the reason a bid does not reach the shortlist.

Governance. The board question is not whether the organisation is designated. It is whether the organisation is depended upon. Most executive teams cannot produce, on request, the list of customers whose operations degrade if theirs stop for four days, or the list of suppliers whose four-day outage would degrade their own. Without those two lists, a regulatory threshold is being used as a substitute for a risk assessment.

What leaders should do now

Five decisions, none of them a patching task.

1. Stop using the designation threshold as a proxy for risk appetite. Decide, in writing, what operational downtime the business can absorb, and let that number set the investment rather than the regulation.

2. Establish the dependency map in both directions. Who fails if we stop, and who stops if they fail. Owned by the board, not held informally by an operations manager.

3. Commission an IT to OT segmentation assessment on the assumption that a corporate network compromise is a plausible route into operational systems, because in most estates of this size it still is.

4. Test the manual fallback, not the plan. Establish whether the site can run safely and lawfully without its automation, and how long that state can be sustained.

5. Adopt a voluntary reporting posture ahead of the Bill. Building the 24-hour and 72-hour reporting habit before it becomes compulsory converts a future compliance cost into present credibility with customers and insurers.

Infographic titled the response, five board decisions. One, stop using the threshold as risk appetite and decide in writing what operational downtime the business can absorb. Two, map dependency in both directions, owned by the board. Three, assess IT to OT segmentation assuming a corporate network compromise is a plausible route to operational systems. Four, test the manual fallback rather than the plan. Five, report voluntarily before you must, building the 24-hour and 72-hour reporting muscle ahead of the Bill.
Five decisions an executive team can take this quarter. The fourth is the one that determines whether four days becomes four hours.

Three questions for leadership

1. If our most operationally important site went offline for four days, what would that cost in revenue, penalties and contract renewals, and who has signed off that figure as acceptable?

2. Which of our customers would name us in their own incident report, and would we know it was happening before they did?

3. When the reporting threshold moves and we fall inside it, how long will we need to be ready, and have we started?

The strategic takeaway

The government’s statement was accurate on every point and still missed the argument. The UK does have a resilient energy system. The wider network was never at risk. And a hostile state proved it could switch off a piece of British generation and keep it off for four days, at a site nobody was legally required to hear about.

Adversaries have understood something that regulation is only now catching up with. The compliance perimeter and the operational perimeter are different shapes. Everything the regulator does not reach is still connected to something that matters.

For any organisation sitting below a threshold, the practical conclusion is short. The absence of a duty to report an incident has never been the same thing as the absence of consequence. Customers, insurers and competitors apply a standard the statute does not.

Meeting the regulation is the floor. It was never the objective.

Confidence note

Confirmed: the incident, the four-day duration, that it was reported to the NCSC, and that government subsequently warned industry and issued guidance, all per The Telegraph’s disclosure of 22 August 2026 and subsequent reporting by CNBC, Security Affairs and others.

Assessed rather than confirmed: attribution to IRGC-affiliated actors, and the judgement that the intent was demonstration rather than harm.

Not disclosed: the identity of the site, the initial access vector, and whether operational technology was directly manipulated.

Context, not claim: the 2 GW figure is the current designation threshold for electricity generation under the NIS Regulations 2018 in Great Britain. Beyond the government source’s description of the site as nowhere near the notification threshold, no capacity figure for the affected plant has been published.

Could your operations survive four days offline?

A focused resilience assessment for organisations sitting below the regulatory thresholds: where the dependency actually runs, what a four-day operational outage would cost you in contracts rather than fines, and what evidence you could put in front of a customer, an insurer or a regulator tomorrow.

Start the Conversation →

Sources: The Telegraph, “Iranian hackers shut down UK power plant”, 22 August 2026. CNBC, “Small UK power generator shut down after cyberattack linked to Iran”, 23 August 2026. Security Affairs, “UK Power Plant Disabled for Four Days by Iran-Linked Hackers”, 23 August 2026. Ofgem, NIS Guidance for Downstream Gas and Electricity Operators of Essential Services in GB. DESNZ and Ofgem, “Reshaping cyber regulation in downstream gas and electricity” consultation. UK Parliament, Cyber Security and Resilience Bill. NCSC statements, March and June 2026. Cabinet Office national risk assessment, July 2026. FBI statements on the US water sector incidents. Directive (EU) 2022/2555 (NIS2), Article 21. GCS Threat Briefings translate live incidents into the governance and commercial decisions boards and security leaders need to make.

#CriticalInfrastructure #OTSecurity #CyberResilience #NIS2 #SupplyChainRisk #Governance #CISO #GarzonCyberSolutions

Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification, and specialist technology recruitment as one integrated capability. We are a young firm, the founder personally runs the work, and our perspective comes from a career spent selling cybersecurity, compliance and technology to security and technology buyers across the UK, EU and Americas.