UK Bolsters Energy Cyber Resilience: New Regulation for Gas & Electricity

Executive summary
The UK government, in partnership with Ofgem, is reshaping cyber regulation for the downstream gas and electricity sectors to address evolving cyber threats. This initiative aims to strengthen resilience across the energy system by reviewing critical organisations and introducing baseline cyber resilience requirements for all Ofgem licensees. It builds on broad support from industry stakeholders.
Reporting based on gov.uk
Why it matters
A secure and resilient energy system is fundamental to national security, economic stability, and daily life, especially as the system becomes increasingly digital, decentralised, and interconnected. For AI infrastructure, which is highly reliant on stable electricity supply, robust cyber resilience in the energy sector directly mitigates risks of operational disruption, safeguarding significant investment and crucial computational resources.
Sector impact
Analysis by AI Energy Intelligence UK
Reporting indicates that a secure and resilient energy system underpins national security. The government acknowledges that cyber threats are evolving in scale and sophistication, making stronger, more adaptive regulation essential. The December 2025 attack on the Polish energy system is cited as an example demonstrating that energy is an attractive target for adversaries. The proposed changes aim to ensure a consistent baseline level of cyber resilience across Ofgem-licensed organisations, thereby enhancing the overall security of energy supply.
Reporting indicates that all Ofgem licensees will need to meet new, consistent baseline cyber resilience requirements, aimed at protecting their businesses and the services they provide. There will be a review to determine which organisations are most critical within the Downstream Gas and Electricity (DGE) subsectors, potentially expanding the scope of the Network and Information System (NIS) Regulations 2018. The Cyber Security and Resilience Bill (CSRB) will facilitate these changes, implying new compliance obligations for regulated entities.
The new cyber resilience requirements for Ofgem licensees are aimed, in part, at protecting the services they provide to consumers. This suggests that the regulatory changes are intended to safeguard the reliability and continuity of energy supply for the public.
Key statistics
Figures as reported by gov.uk. See original source for context.
Quotations
"A secure and resilient energy system underpins the country’s national security, economic stability, and everyday life."
"As our energy system rapidly becomes increasingly digital, decentralised and interconnected, cyber threats are evolving in scale and sophistication. Stronger, more adaptive regulation is essential. Cyber security should be a fundamental requirement for anyone operating in our energy system."
"The December 2025 attack on the Polish energy system demonstrated that adversaries see energy as an attractive target."
Long-term implications
The initiative marks a decisive step in strengthening the resilience of the UK's downstream gas and electricity system against evolving cyber threats. Long-term, it suggests a more adaptive and comprehensive regulatory framework that can better respond to increasing digitalisation and interconnectedness within the energy sector, potentially setting precedents for other critical national infrastructure sectors. The government plans to work closely with industry and partners for ongoing effectiveness and responsiveness.
Frequently asked questions
What is the primary goal of this government response?
The primary goal is to strengthen the cyber resilience of the UK's downstream gas and electricity system by reshaping existing regulations and introducing new requirements.
Which organisations will be affected by these changes?
All Ofgem licensees will be subject to new baseline cyber resilience requirements, and a review is underway to potentially expand the scope of the NIS Regulations to cover more critical organisations in the downstream gas and electricity sectors.
What prompted these regulatory changes?
The changes are driven by the increasing digitalisation, decentralisation, and interconnectedness of the energy system, coupled with the evolving scale and sophistication of cyber threats, as evidenced by incidents like the December 2025 attack on the Polish energy system.
Explore related tools
Original source
This story summarises reporting from gov.uk. Read the original for full context.
Read on gov.ukRecommended reports
Independent UK research that expands on the themes in this story.

The environmental cost of AI-generated answers versus conventional search, benchmarked for UK decision-makers. An independent, evidence-based comparison of electricity, water and carbon per query across Google, Gemini, ChatGPT, Copilot, Perplexity and Claude — with forecasts to 2035.
Read the report
The definitive UK view of AI's electricity, grid and infrastructure impact in 2026. An independent, evidence-based report on demand growth, data centre build-out, AI Growth Zones and the trajectory to 2035 — for UK policymakers, operators and investors.
Read the report
In development: a planned briefing on UK policy at the intersection of AI and energy. No document is available yet.
Read the reportGet the UK AI Energy briefing
Analysis on AI, electricity and the UK grid, straight to your inbox.
The measured evidence behind this story
Our reporting sits on top of the UK AI Energy Index — a sourced, dated record of AI and data-centre electricity demand, data-centre development and grid pressure.
View the full index