A Cyber Attack Shut Down a UK Power Plant for Four Days. What Would Happen to Your Business?
A cyber attack against a UK power-generation facility has provided businesses with another reminder that cyber security is no longer only about protecting information. It can also be about keeping an organisation operating.
In July 2026, a small British energy facility was taken offline for four days following a cyber attack attributed in reporting to hackers linked to Iran. The government has stressed that the incident did not threaten the wider UK electricity system, but the affected facility itself was unable to operate normally while systems were restored.
The incident is unusual because of the target, but the question it raises applies to almost every organisation: If your technology became unavailable tomorrow, how long could your business continue operating?
What Actually Happened?
Public information remains limited. Reports describe the affected facility as a small gas-fired “peaker” power plant with a capacity of around 15MW. Peaker plants provide additional electricity during periods of higher demand and can make significant use of remote and industrial control technology.
The facility reportedly remained offline for four days.
The National Cyber Security Centre was notified, and the Department for Energy Security and Net Zero has been working with organisations across the energy sector following the incident. The government has emphasised that there was no wider threat to national electricity supply.
What has not publicly been established is exactly how the compromise occurred. We don't know whether an account was stolen, a vulnerable system was exploited, an exposed industrial device was targeted or another route was used. That distinction matters.
It would be easy to use an incident like this to produce a list of things the organisation “should have done”. Without the evidence, that would be speculation. The more useful lesson is broader.
Cyber Security Can Reduce Risk. It Cannot Remove It Completely.
Businesses sometimes approach cyber security as though there's a final point where they become “secure”.
Install enough security tools.
Turn on MFA.
Patch everything.
Complete a certification.
Done.
Unfortunately, cyber security doesn't work like that.
Good controls can dramatically reduce the likelihood and potential impact of an attack. But no responsible cyber security professional can promise an organisation will never experience an incident.
The NCSC itself frames cyber security as risk management: organisations should understand what they are trying to protect, reduce their exposure and minimise the impact when incidents do happen.
That means a mature security strategy needs to answer two different questions.
How do we make an attack less likely?
And:
What do we do if an attack succeeds anyway?
Businesses often spend considerably more time answering the first.
Prevention Still Matters
Planning for an incident is not an excuse to accept weak security.
The first objective should always be making compromise as difficult as reasonably possible.
That means understanding what systems and information your organisation relies upon, keeping devices and software appropriately maintained, controlling access, protecting user accounts, monitoring systems and ensuring employees understand their responsibilities.
It also means knowing what technology actually exists within the business.
The NCSC highlights asset management as a fundamental part of cyber security because unmanaged or forgotten systems can create vulnerabilities, from unpatched services to exposed cloud resources.
Logging and monitoring matter too. They can help organisations identify unusual behaviour and understand what happened if an incident occurs. These controls reduce risk. But the power-plant incident demonstrates why businesses need to think beyond prevention.
What Happens If Your Systems Stop Working?
Forget cyber security for a moment.
Imagine it's 8:30 on Monday morning.
Employees begin reporting that they can't log in.
Your main systems aren't responding.
Files are unavailable.
Your IT team believes the organisation may have suffered a cyber incident and advises employees to stop accessing certain systems while they investigate.
What happens next?
For some organisations, the answer is surprisingly unclear.
Who has authority to make decisions?
Who calls the IT provider?
Who contacts the cyber insurer?
Who tells employees what to do?
How do you communicate if email itself is unavailable?
Which systems are restored first?
How long can the business operate without them?
What information do customers need?
Who handles regulatory or contractual reporting?
Where is the incident response plan stored?
And can you access that plan if the network it's saved on is unavailable?
Those questions are not really IT questions.
They're business resilience questions.
You Need an “If” Plan
Hopefully your business never experiences a serious cyber incident.
But planning shouldn't be based purely on hope.
A useful approach is to ask:
If this happens, what do we do?
If Microsoft 365 becomes unavailable, how will employees communicate?
If your line-of-business system is offline, which processes stop?
If your files cannot be accessed, what can still be done manually?
If your office cannot access the internet, can essential operations continue elsewhere?
If a cyber attack compromises part of the network, can the organisation isolate affected systems without stopping everything?
The NCSC advises organisations to identify which systems, information and business processes are essential to keeping the organisation running before an incident occurs.
That gives you a much clearer starting point for recovery planning.
Having a Backup Is Not the Same as Being Able to Recover
“We have backups” is reassuring.
But it isn't the end of the conversation.
You also need to know whether those backups are protected, whether they contain what you actually need and whether they can be restored within a timescale the business can tolerate.
Attackers know backups matter too.
NCSC guidance warns that destructive attackers can deliberately target backup systems to make recovery more difficult. It recommends keeping multiple copies, including copies isolated from the primary environment, and regularly testing that data can genuinely be restored.
Consider a business that can tolerate four hours of disruption.
Its backups work perfectly.
But restoring its critical applications, configurations and data takes three days.
Technically, the business has a backup.
Operationally, it still has a serious problem.
Recovery needs to be designed around how quickly the business needs to function again, not simply whether a copy of the data exists somewhere.
Work Out What “Minimum Viable Operations” Looks Like
This is an area where current NCSC guidance is particularly useful.
Its July 2026 guidance for highly disruptive cyber attacks describes recovery in terms of restoring an organisation to minimum viable operations before rebuilding fully. That concept is valuable for businesses of all sizes. You may not need every system restored immediately. You need the systems that allow the organisation to perform its most important functions.
For example, perhaps customer communication and order processing are essential on day one, while some internal reporting can wait.
For a manufacturer, production systems may take priority.
For an accountancy practice, access to client information and key applications could be critical.
For a logistics business, communications and operational platforms may come first.
The answer will be different for every organisation.
But you should know it before you're in the middle of an incident.
Cyber Incidents Quickly Stop Being IT Incidents
A serious cyber attack can begin with technology. It doesn't stay there for long. It becomes a leadership problem. A customer-service problem. A finance problem. A legal problem. An HR problem. A communications problem. Potentially a regulatory problem.
The NCSC's incident-management guidance specifically recommends connecting incident response with disaster recovery, business continuity and crisis-management planning.
That is why cyber security should never be left entirely to the IT department or your outsourced provider.
Your IT team may handle the technical response.
Leadership remains responsible for how the organisation responds as a business.
Test the Plan Before You Need It
One of the simplest things businesses can do is practise. You don't need to deliberately break your infrastructure. Run a tabletop exercise. Put your leadership team around a table and give them a scenario.
Your organisation has suffered a suspected cyber attack. Core systems are unavailable. Employees cannot access email and there is uncertainty about whether data has been compromised. What do you do in the first hour?
Then start asking questions.
Who takes control?
Who contacts whom?
What systems are prioritised?
Where are emergency contact details stored?
How do employees receive instructions?
What do you tell customers?
How do you contact your insurer?
How do you determine whether regulators need to be informed?
What if your IT provider's contact details are only stored in Outlook?
You will probably uncover weaknesses. That's the point. The NCSC actively recommends practising incident-response plans and provides its free Exercise in a Box resources for organisations that want to test their response. Finding a problem during an exercise is cheap. Finding it during an actual attack is not.
“But Why Would Anyone Attack Us?”
The attack on a power facility involves a threat environment very different from that faced by the average SME.
Most businesses are not likely to become deliberate targets of a hostile state.
In fact, the NCSC says ransomware and wider criminal cyber activity remain the most prevalent threat for the majority of organisations, even while nation-state activity increasingly affects nationally significant incidents.
But the identity of the attacker isn't the important lesson for most businesses.
The operational consequence is.
You can lose access to technology because of ransomware.
A compromised supplier.
Hardware failure.
Human error.
A cloud-service outage.
A malicious insider.
A major internet failure.
Or a sophisticated attacker.
Different causes.
Same question: Can the business continue?
Why the Iran Connection Still Matters
The geopolitical context shouldn't be ignored either.
The NCSC warned UK organisations earlier in 2026 to review their cyber security posture following developments in the Middle East. At that point, it assessed that Iranian state and Iran-linked cyber actors retained the capability to conduct cyber activity, while advising organisations to prepare for potential collateral impacts from Iran-linked hacktivists.
More broadly, the NCSC said in June that around three-quarters of the cyber incidents affecting UK critical infrastructure that it had handled in the previous year were believed to have links to hostile states.
For most businesses, however, this shouldn't produce panic.
It should reinforce the importance of good fundamentals and resilience.
You cannot control international events.
You can control how prepared your organisation is.
Ask Yourself One Question
The power facility reportedly took four days to return to operation. Apply that to your own organisation.
What would four days without your critical technology actually mean?
Could your employees work?
Could customers contact you?
Could you access key information?
Could you process orders?
Could you invoice?
Could you pay suppliers?
Could you manufacture?
Could you deliver your services?
What would it cost?
And how confident are you that your answer is based on something you've actually tested rather than what you assume would happen?
That is where cyber security stops being a technical conversation. It becomes a business conversation.
Reduce the Likelihood. Reduce the Impact. Prepare for Recovery.
No cyber security strategy can eliminate every possible incident. The aim is to make successful attacks less likely, contain their impact and make recovery faster when disruption does occur.
That requires security controls. But it also requires policies. Backups. Monitoring. Defined responsibilities. Business continuity. Incident response. Recovery planning. And testing.
The strongest organisations don't simply ask: “How do we stop an attack?”
They also ask: “If something goes wrong tomorrow, how quickly can we get the business moving again?”
How Sunrise Technologies Can Help
At Sunrise Technologies, we approach cyber security as part of wider business resilience. That means helping organisations strengthen the security controls that reduce the likelihood of incidents, but also considering what happens when systems become unavailable.
We help businesses review their technology, foundational security, risk management, compliance and operational resilience so that weaknesses can be identified before they're exposed during a real incident.
Our Business IT Risk Assessment provides a practical starting point, helping organisations understand where potential risks exist across those five areas and where further investigation may be needed.
Because you can't guarantee that nothing will ever go wrong. But you can make sure your business is much better prepared if it does.