Skip to main content

Power Plant Cyberattack Underscores the Need to Plan for Operational Continuity

STATUS: Active Monitoring SEVERITY: 9/10 AUDIENCE: Critical Infrastructure, OT, Cybersecurity and Resilience Leaders 

Aug 25, 2026

·

Blog

·

Secure Communications

A reported cyberattack forced a small UK power generator offline for four days. The wider energy system remained secure, but the incident demonstrates a practical resilience test: organizations must be ready to contain an intrusion, isolate affected technology, and sustain essential operations while systems are unavailable.1 

What This Attack Is Doing — and Why It Works

A small-scale UK power generator was shut down during a cyberattack. The Department for Energy Security and Net Zero said the incident did not place the wider energy system at risk. 1 Reporting cited by the BBC attributed the attack to hackers affiliated with Iran. Public authorities did not identify the affected site or provide technical details. 1Reuters later reported that UK officials briefed energy leaders on protective steps and continued working with regulators and the National Cyber Security Centre to assess threats and strengthen protections.2 

The event should be read as an operational continuity warning, not a claim of systemic grid failure. The scale of the affected generator limited the broader impact. The four-day outage still shows that a cyber incident can create sustained, real-world disruption at an individual facility.1 

What Attackers Gained — And What They Can Do With It

Signal
What It Shows
Strategic Opportunity
Operational Opportunity
A cyber event caused a physical operating outage 
Cyber risk can become an availability and recovery problem, even when wider services remain stable. 
Measure resilience by the ability to sustain priority functions, not only by the ability to prevent intrusion. 
Define operating procedures for degraded, isolated, or offline conditions. 
The affected site remained undisclosed 
Incident details may be constrained while response and investigation continue. 
Build decision processes that work with incomplete information. 
Preassign authority, communication paths, and escalation thresholds.
Energy leaders received protective guidance 
Sector coordination can accelerate protective action after an incident.
Maintain trusted channels across leadership, cyber, OT, operations, and external partners.
Prepare concise status reporting that remains available during technology disruption.

Why This Matters

Old Assumption
Current Reality
BlackBerry Response
A limited facility presents limited cyber consequences 
A small generator can still experience a multiday operating outage without threatening the wider system 
Test continuity at the facility level, including sustained offline operations and recovery sequencing 
Isolation is the end state of incident response 
Isolation may contain risk, but it can also remove tools, visibility, and normal communications 
Pair isolation plans with procedures for command, coordination, and safe manual or alternate operations 
Cybersecurity and operations can plan separately 
OT environments prioritize safety, reliability, and availability. Connected environments require shared risk management3 
Integrate cyber response, OT safety, business continuity, and executive communications into one exercised plan 

IMMEDIATE 
Confirm which priority services must continue when OT systems, remote access, monitoring, or enterprise collaboration tools are unavailable.
IMMEDIATE 
Validate who has authority to isolate affected systems, declare degraded operations, and approve restoration. 
SHORT-TERM 
Create an isolation playbook that covers communications, decision rights, safety checks, manual workarounds, evidence preservation, and recovery sequencing. Joint international OT guidance recommends secure connectivity, reduced exposure, layered controls, and resilience by design.4
SHORT-TERM 
Exercise cyber, OT, operations, safety, legal, and executive teams together. Include a scenario in which normal collaboration channels and remote tools are unavailable.
ONGOING
Maintain an authoritative view of OT architecture, dependencies, external connections, and third-party access. Review it when systems or operating processes change.3

BlackBerry Secure Communications Advisory Position

The central lesson is not the size of the affected generator. It is the duration of operational disruption. Strong defenses remain essential, but resilience depends on what the organization can still do after systems are contained, isolated, or unavailable. Leaders should require a tested continuity model that protects safety, preserves trusted coordination, and restores operations in a controlled order. 

Citations:

1.  Iran-linked hackers behind cyber attack that shut down power plant (Tom Symonds, BBC News, August 23, 2026). 

2.  UK briefs energy chiefs after Iran-linked cyber attack reports (Kate Holton and Sam Tabahriti, Reuters, August 24, 2026, republished by AOL). 

3.  Operational Technology: Making sense of cyber security in OT environments (National Cyber Security Centre, March18, 2024). 

4. CISA, UK NCSC, FBI Unveil Principles to Combat Cyber Risks in OT (Cybersecurity and Infrastructure Security Agency, January 14, 2026). 

Get updates about the latest in-depth knowledge for secure communications.

Industry Discussion

On-Demand Webinar: What CI Fortify Doesn't Say About Communications

In July, CISA and other agencies released joint guidance titled "CI Fortify – Advice for Isolating Vital Systems," directing critical infrastructure operators to proactively isolate vital OT systems from unreliable third-party networks and sustain essential operations independently. Join us for an informative session about what CI Fortify asks operators to do, what it costs, and what it leaves unaddressed.

Watch now