Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Can We Really Stop the Next Attack on Power?Privacy and Security
5 min readFor Board and Audit Committee Members

Can We Really Stop the Next Attack on Power?

Context: Questions from the front lines

The Iranian shutdown of a UK power plant for four days last month has sparked urgent questions from board members, CISOs, and operational teams across critical infrastructure sectors. These aren't theoretical discussions anymore. Audit committees want to know if their incident response plans account for multi-day outages. CISOs are being asked to quantify containment speed. Risk managers are trying to explain why smaller facilities might not show up in mandatory reporting.

Below are the questions we're hearing most often, with direct answers drawn from regulatory requirements, operational realities, and lessons from this incident.


Q1: Our facility is relatively small. Does that mean we're off the hook for mandatory cyber reporting?

It depends on your jurisdiction and sector, but falling below a reporting threshold doesn't make you less vulnerable. It makes you less visible.

Muhammad Yahya Patel from Huntress noted that if smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of infrastructure is being targeted or compromised. Attackers look for the weakest route in. A small power plant might not affect national supply, but if it shares control systems, network architecture, or vendor relationships with larger facilities, it's a reconnaissance target.

Your board needs to understand that regulatory thresholds define reporting obligations, not risk exposure. If you're interconnected with larger operators or use common programmable logic controllers (PLCs), you're part of the attack surface whether you're required to report or not.


Q2: We've invested heavily in prevention. Isn't that enough?

No. The UK power plant incident shows that prevention alone isn't enough.

The facility was disabled for four days. That's not a detection failure or a patching gap. It's a containment and recovery problem. Your Incident Response Structure must answer three questions that Graeme Stewart from Check Point raised: How do you keep functioning when systems are compromised? How quickly can an attack be contained? How do you recover without allowing disruption to spread?

If your Incident Response Structure focuses primarily on detection and initial triage, you're missing the operational half of resilience. Your Chief Audit Executive should test whether your documented recovery procedures account for multi-day outages of critical control systems. Can you operate manually? Do you have isolated backup control paths? Have you rehearsed failover without access to primary systems?

The real measure of cyber resilience isn't whether you can prevent an intrusion. It's whether you can contain one quickly enough that a cyber incident doesn't become an operational crisis.


Q3: How do we quantify "rapid containment" for our board?

Start with your recovery time objectives (RTOs) for critical operational technology systems, then work backward to define containment windows.

If your RTO for power distribution control is four hours, your containment window is shorter. You need to isolate compromised systems, confirm the scope of the breach, and initiate recovery procedures within that window. For most CNI operators, this means:

  • Network segmentation that allows you to isolate compromised zones without losing visibility into adjacent systems
  • Pre-positioned incident response playbooks specific to OT environments (not just IT)
  • Authority matrices that define who can authorize emergency shutdowns, system isolation, or manual operations

Document these containment targets in your Cybersecurity Risk Register with clear ownership. Your board should see containment speed as a Key Control Indicator, measured in hours, not days.


Q4: The Intelligence and Security Committee said Iran wasn't a top priority for the UK. Why did this happen?

Threat prioritization changes faster than most risk assessments.

The ISC report from July 2025 noted that the UK wasn't a top priority for Iranian offensive cyber activity, but this could change rapidly in response to regional or geopolitical developments. One month later, Iranian hackers shut down a UK power plant while simultaneously targeting US water plants across at least 12 states.

Your Enterprise Risk Oversight process must account for geopolitical volatility. If your Cybersecurity Risk Register treats nation-state threats as static, you're building your defenses around last quarter's threat landscape. Effective risk oversight requires monitoring geopolitical developments that could shift adversary priorities, not just tracking CVE scores and vulnerability counts.

This doesn't mean you redesign your security architecture every time tensions escalate. It means your monitoring intensity, incident response staffing, and executive communication cadence should flex based on threat environment changes.


Q5: We're interconnected with other facilities. How do we prevent a breach from cascading?

Interconnectivity is both an operational necessity and a containment challenge. As Stewart noted, Britain's CNI systems are increasingly digital, interconnected, and dependent on one another. A serious attack on one part of that ecosystem has the potential to cause disruption far beyond the original target.

Your containment strategy must include:

  • Network segmentation with enforced boundaries: Shared control networks need isolation points that can be activated without manual intervention
  • Coordinated incident response with interconnected parties: If you share systems with other operators, your incident response plans must define communication protocols, isolation authorities, and recovery coordination
  • Regular testing of isolation procedures: Tabletop exercises should simulate scenarios where you must isolate from partner systems while maintaining safe operations

Document these interconnection points in your Risk Portfolio with specific containment procedures for each connection type. Your audit committee should understand which connections can be severed automatically, which require manual intervention, and what operational impact each isolation scenario would create.


Q6: What should our board be asking us right now?

Your board should be asking whether you can answer the questions Stewart raised: Do you know exactly how you keep functioning when systems are compromised? How quickly can you contain an attack? How do you recover without allowing disruption to spread?

Specifically, they should ask:

  • What's our containment window for critical OT systems, and how is it measured?
  • Which of our facilities or systems fall below mandatory reporting thresholds, and how do we monitor their security posture?
  • When did we last test our Incident Response Structure against a multi-day compromise scenario?
  • What interconnections could allow a breach to cascade, and what isolation procedures do we have?

If you can't answer these questions with specific timeframes, documented procedures, and tested capabilities, you're not ready for what Stewart called "something more serious."


Where to go for more

Start with your current Incident Response Structure. Map your containment procedures against realistic compromise scenarios, not just detection and triage steps. Identify gaps between your documented RTOs and your actual containment capabilities.

Review your Cybersecurity Risk Register for geopolitical threat factors. If nation-state risks are listed as static assessments, build a process for updating them based on regional developments.

Finally, if you operate below mandatory reporting thresholds or maintain interconnections with other CNI operators, document those relationships in your Risk Portfolio with specific containment and isolation procedures. The next attack won't announce itself by targeting only the largest, most visible facilities.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like