Executive Summary
- BLUF: Available official evidence confirms an escalating Iranian campaign against internet-exposed OT, PLC, HMI and critical-infrastructure environments.
- The reported four-day shutdown of an unidentified British power plant remains officially unconfirmed in public sources.
- No public forensic evidence currently proves that electricity generation, rather than supporting IT or safety-dependent operations, was directly manipulated.
- US authorities separately confirm disruptive Iranian-affiliated activity against PLCs and HMIs in the water, wastewater and energy sectors.
- The most plausible intrusion chain is exposed remote access or edge infrastructure, weak authentication, IT-to-OT traversal, operator lockout and precautionary shutdown.
- Direct modification of turbine, generator or protection logic remains possible but presently carries substantially lower evidentiary support.
- Strategic effect matters more than plant size: Iran-linked operators may have crossed from demonstrative access into repeatable cyber-physical disruption.
- The 2026–2031 risk trajectory points toward automated reconnaissance, supply-chain compromise and attacks calibrated below the threshold of armed response.
- Immediate priority: eliminate internet-reachable control assets, isolate engineering workstations and prove recovery from immutable OT configurations.
Iran’s OT Offensive: The West’s New Infrastructure Front
Claims concerning an unnamed British power facility remain unconfirmed in the public record of the competent authorities. The strategic warning, however, is already documented. Iranian and Iran-affiliated operators have moved from reconnaissance of industrial systems to disruptive activity against internet-connected PLCs, HMIs and operational-technology networks. What was once treated as peripheral cyber risk now reaches the machinery governing electricity, water and industrial production. The immediate danger is not necessarily a national blackout. It is the forced shutdown of individual facilities because operators can no longer trust their controls, alarms or engineering configurations. For governments and investors, the distinction between a minor cyber intrusion and a major energy event is consequently narrowing: a technically unsophisticated breach can still immobilise a plant, trigger costly validation and expose shared vulnerabilities across an entire industrial supply chain.
The Evidence Line
The British case demands discipline. No publicly accessible document from the National Cyber Security Centre, the Department for Energy Security and Net Zero, Ofgem or the National Energy System Operator identifies the plant, confirms its generating capacity or publishes forensic evidence of Iranian responsibility. It would therefore be premature to describe the incident as proven manipulation of a British SCADA system.
The surrounding threat is nevertheless official. On 02/03/2026, NCSC assessed that Iranian state and Iran-linked actors “almost certainly” retained cyber capability and advised UK organisations to review exposure to ICS targeting, phishing and denial-of-service attacks. NCSC simultaneously judged that the direct Iranian threat to the UK had not significantly changed, while warning of an “almost certainly” heightened indirect risk linked to the Middle East conflict (Alert: NCSC advises UK organisations to take action following conflict in the Middle East).
On 17/06/2026, NCSC Chief Executive Dr Richard Horne disclosed that the agency had managed more than 200 incidents affecting UK critical national infrastructure and its supporting ecosystem in the year to May 2026. Approximately 75% were assessed as linked to hostile states, including Iran, Russia and China. NCSC also judged that, by 2028, attackers would likely use AI-enabled capabilities to exploit known vulnerabilities in legacy critical-infrastructure technology at scale (NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK’s critical systems).
From Bowman Dam to PLC Disruption
The first decisive Iranian precedent dates to 28/08/2013–18/09/2013. According to the US Department of Justice, Hamid Firoozi repeatedly obtained unauthorised access to the SCADA system of the Bowman Avenue Dam in Rye, New York. He viewed water levels, temperature and the status of the sluice gate. The access would ordinarily have permitted remote operation of that gate, but it had been physically disconnected for maintenance.
The same Justice Department case, unsealed on 24/03/2016, charged seven Iranian nationals associated with ITSecTeam and Mersad Company. Their wider campaign targeted 46 US financial institutions over more than 176 days; traffic reached as much as 140 gigabits per second on certain days. The indictment linked the organisations to projects conducted for the Iranian government and the Islamic Revolutionary Guard Corps (Seven Iranians Working for Islamic Revolutionary Guard Corps-Affiliated Entities Charged).
Bowman established the enduring model: select an inadequately protected asset, acquire visibility over a physical process and convert technically modest access into strategic leverage. It also demonstrated the value of independent physical safeguards. Digital authority did not become physical control because maintenance had broken the command chain.
The CyberAv3ngers Model
The next transformation became visible in November 2023, when IRGC-affiliated actors operating under the CyberAv3ngers persona targeted Israeli-manufactured Unitronics Vision Series PLCs. The affected technology was used across water, wastewater, energy, food, healthcare and distribution environments.
On 02/02/2024, the US Treasury’s Office of Foreign Assets Control sanctioned six officials of the IRGC Cyber-Electronic Command. Treasury stated that the actors had accessed Unitronics PLCs and displayed political imagery on their screens. The identified incidents caused minimal impact and did not interrupt critical services, but Treasury warned that intentionally impairing public infrastructure would be destabilising and potentially escalatory (Treasury Sanctions Actors Responsible for Malicious Cyber Activities on Critical Infrastructure).
By 22/07/2026, the capability had advanced. A joint advisory led by the US Cybersecurity and Infrastructure Security Agency assessed that Iranian-affiliated operators were targeting internet-connected operational technology to cause disruption across US critical infrastructure, including water, wastewater and energy. The advisory added guidance for detecting malicious modifications to reusable PLC code modules (Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure).
The progression matters. In 2013, Iranian access exposed a physical process but did not move the actuator. In 2023, operators penetrated controllers and used their displays for political signalling. In July 2026, US authorities assessed disruptive intent and documented disruptive effects. This is not yet evidence of an Iranian equivalent to the specialised malware used against Ukrainian electricity infrastructure or safety-instrumented systems. It is evidence of a repeatable, lower-cost model capable of producing local operational consequences.
Access Without a Cyber Weapon
A power facility can be immobilised without destructive malware. Attackers may compromise an exposed controller, vulnerable perimeter appliance, remote-maintenance service or privileged supplier account. They may also enter through enterprise systems and move toward the historian, engineering workstation, virtualised HMI environment or IT–OT jump host.
Once control-system integrity becomes uncertain, the operator faces a safety decision. Continuing production may be impossible until engineering files, controller logic, protection settings, alarms and sensor readings have been compared with trusted baselines. The resulting outage may therefore be defender-ordered rather than directly commanded by the attacker. That distinction changes the forensic description but not the commercial consequence: unavailable capacity, specialist recovery costs, regulatory scrutiny, insurance exposure and delayed restart.
Iranian operations already combine credential acquisition, exploitation of known vulnerabilities and monetisation. On 14/09/2022, the US Department of Justice charged three Iranian nationals with exploiting commonly used network devices and software, exfiltrating data and conducting encryption attacks against hundreds of targets, including utilities, healthcare centres and transportation providers (Three Iranian Nationals Charged with Computer Intrusions and Ransomware-Style Extortion). The overlap between state-linked operators, contractors and financially motivated actors creates deniability—and allows access obtained for espionage to be transferred, monetised or activated for political disruption.
The Supplier Is the Battlefield
The principal systemic risk lies beyond any individual generator. Utilities in Britain, the United States and continental Europe may rely on the same control-system vendors, remote-access platforms, telecommunications services, integrators and specialist maintenance companies. Physical generation can be diversified while digital trust remains concentrated.
ENISA’s NIS Investments 2025, published in February 2026, found that ransomware concerned 55% of surveyed organisations, supply-chain attacks 47% and phishing 35%. In the preceding reporting period, denial-of-service attacks affected daily operations at 22% of respondents, ransomware at 18%, phishing at 10%, and supply-chain or third-party compromise at 10%. ENISA also identified weaker confidence among smaller organisations in their capacity to anticipate, withstand and recover from incidents (NIS Investments 2025).
This asymmetry changes the economics of defence. The weakest contractor may create more aggregate exposure than the largest power station. A single supplier credential can cross corporate boundaries; one vulnerable remote-management product can recur across jurisdictions; simultaneous incidents can exhaust the limited pool of engineers qualified to validate industrial systems. Boards must therefore measure how much generating capacity or essential service is reachable through each digital dependency—not merely how many devices have been patched.
Britain’s Regulatory Test
The UK’s proposed Cyber Security and Resilience (Network and Information Systems) Bill, introduced for first reading on 12/11/2025, would reform the NIS Regulations 2018, extend protection across essential and digital services, bring relevant managed-service providers within scope and enable the designation of critical suppliers. Energy, drinking water, transport, health and digital infrastructure already sit within the existing regime (Cyber Security and Resilience Bill).
The legislation addresses a genuine structural gap, but compliance will be meaningful only if it proves operational resilience. High-impact operators should be able to enumerate every external OT connection, revoke supplier access centrally, validate controller logic against an immutable baseline and operate essential functions when cloud identity or enterprise IT is unavailable. Supplier sessions should be time-limited and recorded. Recovery exercises should require restoration from trusted engineering configurations rather than completion of a tabletop checklist.
The NCSC Cyber Assessment Framework already provides basic and enhanced profiles for organisations responsible for essential services. The next step is supervisory evidence: controller histories, access records, validated architecture maps and demonstrated recovery performance. A power plant cannot be considered resilient merely because its policies are complete.
Europe’s Uneven Shield
The European Union possesses a broader legal architecture but faces uneven national implementation. Directive (EU) 2022/2555, the NIS2 Directive, was adopted on 14/12/2022 and requires risk management, supply-chain security, incident reporting, supervision and enforcement across critical sectors. Directive (EU) 2022/2557 complements it by requiring critical entities to prevent, resist, absorb and recover from disruptive incidents.
The Cyber Solidarity Act, Regulation (EU) 2025/38, was adopted on 19/12/2024, published in the Official Journal on 15/01/2025 and entered into force on 04/02/2025. It created a European Cybersecurity Alert System based on national and cross-border Cyber Hubs, a Cybersecurity Emergency Mechanism and an EU Cybersecurity Reserve of trusted incident-response providers (Regulation (EU) 2025/38). The Digital Europe Work Programme 2025–2027 allocates €36 million to support the Reserve’s response and reporting capabilities (EU Cybersecurity Reserve).
For Italy, France and Germany, the strategic requirement is interoperability: common thresholds for reporting OT compromise, comparable evidence standards, cross-border notification of affected products and incident teams qualified in industrial processes rather than enterprise IT alone. A controller vulnerability in one Member State is a European warning if the same platform operates elsewhere.
The Five-Year Contest
The decisive period runs to 2031. NCSC’s 2028 assessment indicates that AI will compress reconnaissance and exploitation cycles against legacy infrastructure. Distributed energy resources, remote maintenance and converging IT–OT architectures will enlarge the number of digitally mediated control points. Regulation will expand, but attackers will continue to seek the minority of assets where authentication, segmentation or supplier governance remains weak.
Western strategy must therefore shift from perimeter defence to cyber-informed engineering: independent protection layers, constrained command ranges, verified sensor diversity, local operating capability and rapid restoration from known-good configurations. The objective is not to promise that every intrusion will be prevented. It is to ensure that access does not automatically become operational leverage.
Iran’s advantage is economic asymmetry: inexpensive reconnaissance against thousands of exposed systems can reveal the few that are vulnerable. Europe’s answer must be an equally systemic defence—shared warning, disciplined supplier governance and plants engineered to fail safely. The reported British episode matters not because of the size of an unidentified facility, but because it suggests where the contest is moving: from data theft to uncertainty over who controls the machine.
Navigational Index
- Incident Reconstruction and Attribution — evidentiary baseline, probable access vectors, IT–OT escalation path and confidence grading.
- SCADA Campaign Architecture — historical precedents, Iranian operating models, competing hypotheses and cyber-physical consequences.
- Five-Year Strategic Outlook — Bayesian forecasts, Monte Carlo scenarios, systemic exposure and UK–US–European resilience requirements.
Master Abstract
An incident not yet publicly attributable
The central analytical judgment is necessarily bifurcated. The unidentified British plant’s reported four-day unavailability constitutes a credible lead requiring government-level investigation, but it is not yet a publicly verified fact under the source standard governing this report. As of 23 August 2026, no accessible publication by NCSC, DESNZ, Ofgem, NESO or another competent British authority publicly names the installation, discloses forensic indicators, confirms a four-day loss of operational capability, or attributes that event to Iran. The distinction is substantive: an electricity-generating site may become “offline” because attackers manipulated process-control logic, because defenders isolated operational technology as a containment measure, because business IT needed for dispatch or maintenance became unavailable, or because safety governance prohibited restart until configuration integrity was independently established. These mechanisms produce very different assessments of adversary capability. Nevertheless, the surrounding threat picture is officially corroborated. On 2 March 2026, NCSC assessed that Iranian state and Iran-linked actors almost certainly retained cyber capability, identified a heightened indirect threat, and explicitly directed organisations toward guidance on ICS targeting, external attack-surface review and severe-threat preparation — Alert: NCSC advises UK organisations to take action following conflict in the Middle East – National Cyber Security Centre – March 2026. On 17 June 2026, NCSC reported that it had managed more than 200 incidents affecting UK critical national infrastructure or its supporting ecosystem during the year to May 2026, assessing approximately 75% as linked to hostile states including Iran; it further judged that AI-enabled attackers would likely exploit known weaknesses in legacy critical-infrastructure technology at scale by 2028 — NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK’s critical systems – National Cyber Security Centre – June 2026. Accordingly, the incident should be classified reported, plausible and strategically consistent, but technically unverified, while claims of direct SCADA manipulation, lost generation and definitive IRGC command remain unproven.
The probable intrusion architecture
The strongest forensic analogue is not a bespoke destructive implant comparable to TRITON or CrashOverride, but the Iranian-affiliated campaign against exposed industrial controllers. US authorities reported in July 2026 that CyberAv3ngers, assessed as affiliated with Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command, targeted internet-connected operational technology across US critical infrastructure, including water, wastewater and energy environments, and caused disruptive effects involving PLCs and HMIs — Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure – Cybersecurity and Infrastructure Security Agency – July 2026. That activity extends the pattern documented in 2023, when the same persona compromised Israeli-manufactured Unitronics Vision Series PLCs used across water, energy, food, healthcare and other sectors. The earlier operation exploited publicly reachable devices and weak access control rather than demonstrating a universal ability to defeat segmented, safety-engineered power-generation environments — IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities – Cybersecurity and Infrastructure Security Agency – December 2023. Applied to the British case, the analytically plausible sequence is reconnaissance of exposed VPNs, firewalls, remote-maintenance gateways, HMIs or controllers; compromise through a known vulnerability, stolen credential or unchanged device credential; persistence within an edge or management system; discovery of engineering assets and protocol relationships; interference with operator visibility, supervisory control or supporting services; and finally either attacker-induced disruption or defender-ordered shutdown. NCSC separately confirms that Iranian actors have repeatedly exploited known weaknesses in Fortinet, Microsoft Exchange and Log4j deployments to obtain initial access before extortion, encryption or other malicious action — UK and allies expose Iranian state agency for exploiting cyber vulnerabilities for ransomware operations – National Cyber Security Centre – September 2022. A four-day restoration interval would therefore be compatible with containment, credential rotation, engineering-baseline validation, controller reimaging, safety testing and controlled restart; it does not independently prove four continuous days of attacker command over the physical process.
Competing hypotheses and strategic trajectory
The initial Analysis of Competing Hypotheses retains five explanations. H₁, an exposed OT asset was directly accessed and altered, has the best precedent alignment but lacks plant-specific telemetry. H₂, enterprise or remote-access infrastructure was compromised and the operator shut the plant down defensively, fits the four-day recovery period and requires less adversary sophistication. H₃, ransomware or destructive IT activity disabled operational dependencies without changing PLC logic, is consistent with known IRGC-affiliated monetisation and encryption activity. H₄, a third-party maintainer, integrator or vendor pathway enabled traversal into the plant, remains material because trusted remote support can bypass otherwise strong perimeter separation. H₅, the reported outage and Iranian attribution combine unrelated operational failure, ambiguous telemetry or influence amplification, cannot be excluded until official technical evidence emerges. The working Bayesian distribution used in the dashboard assigns provisional probabilities of 29%, 35%, 18%, 12% and 6% respectively; these are structured analytic judgments, not measured frequencies. The posterior would move sharply toward H₁ only if investigators recovered authenticated controller writes, unauthorised project downloads, altered ladder logic, protection-setting changes or attacker-controlled HMI commands. It would move toward H₂ or H₃ if evidence remained confined to identity systems, virtualisation, backup infrastructure or operator workstations. Over 2026–2031, the most likely development is an increase in inexpensive campaigns that discover exposed OT automatically, exploit long-lived edge vulnerabilities, reuse stolen identities and select politically resonant targets. The most dangerous development is not necessarily simultaneous national blackout: it is the accumulation of latent access, manipulated engineering baselines and uncertainty about whether safety and protection systems can be trusted during a geopolitical crisis. NCSC already assesses that Iran is willing to target the UK for disruptive and destructive objectives and that hostile actors increasingly focus on industrial control systems — NCSC Annual Review 2024: Countering the cyber threat – National Cyber Security Centre – December 2024. The five-year defensive requirement is therefore architectural: verified IT–OT separation, brokered and time-limited remote access, phishing-resistant authentication, independent safety layers, controller allow-listing, passive OT detection, offline “golden” configurations and rehearsed manual operation.
Iran–UK Cyber-Physical Risk Model
Scenario stressors
Competing-hypothesis posterior
Iran’s OT Breach: Reconstruction and Attribution of the UK Power-Plant Incident
Evidentiary baseline: what is known, what is reported, what remains unproved
The reconstruction must begin by separating three evidentiary layers that public discussion has improperly compressed into a single claim. First, the existence of an Iranian and Iran-aligned campaign against Western operational technology is strongly established by governmental reporting. Second, a British power facility was reportedly unavailable for four days following hostile cyber activity, but the operator, plant type, generating capacity, location, control-system architecture, affected operational layer and forensic indicators have not been disclosed publicly by the competent British authorities. Third, attribution of that particular incident to an Iranian state-controlled entity remains unconfirmed in the public governmental record, even though the reported timing and target profile are consistent with documented Iranian operations. On 2 March 2026, NCSC assessed that Iranian state and Iran-linked actors almost certainly retained cyber capability, warned of collateral threats from Iran-linked hacktivists and directed British organisations toward guidance on ICS targeting, external attack-surface review and preparation for severe cyber threats. Crucially, however, the alert did not identify a compromised generating station or publicly attribute a four-day outage — Alert: NCSC advises UK organisations to take action following conflict in the Middle East – National Cyber Security Centre – March 2026. The evidentiary classification should therefore be E₂–C₃: credible reporting reinforced by a highly consistent threat environment, but without incident-specific technical confirmation. The phrase “shut down a power plant” must also be treated cautiously. It could describe an attacker-commanded interruption of physical generation; an operator-initiated safe shutdown after loss of trusted visibility; isolation of a site whose output had already stopped for operational reasons; or prolonged unavailability of supporting systems preventing authorised restart. Until authenticated controller histories, engineering-project files, protection-system records, HMI event logs and dispatch data become available, describing the episode as proven SCADA sabotage would exceed the evidence.
| Intelligence proposition | Public evidence | Confidence | Principal collection gap |
|---|---|---|---|
| Iran-linked actors were conducting operations against Western OT during the relevant period | UK and US government warnings and advisories | High | Internal tasking and command relationships |
| A British power facility suffered a cyber-related four-day outage | Credible reporting, no named official confirmation | Moderate–low | Operator disclosure, regulator notification, incident timeline |
| Attackers directly manipulated PLC, DCS or protection logic | No public plant-specific telemetry | Low | Controller audit logs, logic comparisons, engineering workstation images |
| The incident produced no material UK supply impact | Consistent with a small facility or reserve margin, but not independently quantified | Moderate | Plant capacity, dispatch status, NESO balancing records |
| The operation was controlled by the IRGC | Strong precedent for the campaign family, absent incident-specific attribution | Moderate–low | Infrastructure overlap, operator identity, intelligence reporting |
| Restoration required four days of OT revalidation | Operationally plausible, publicly unverified | Moderate–low | Recovery records, safety approvals, configuration-restoration evidence |
The nearest forensic analogue: CyberAv3ngers and exposed industrial controllers
The strongest public analogue is the activity attributed by the United States to CyberAv3ngers, a persona associated with Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command. In July 2026, CISA and partner agencies warned of continuing Iranian-affiliated targeting of internet-connected operational technology across US critical infrastructure, including water, wastewater and energy environments, and reported disruptive effects involving PLCs and HMIs — Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure – Cybersecurity and Infrastructure Security Agency – July 2026. That campaign extended a pattern formally documented after November 2023, when IRGC-affiliated actors compromised Israeli-manufactured Unitronics Vision Series PLCs deployed across multiple sectors. The earlier advisory’s strategic significance lies less in sophistication than in operational economy: the actors selected externally reachable controllers, exploited weak authentication and converted access into visible political signalling. This is important for reconstruction because a small British power facility, embedded generator, reserve unit, waste-to-energy installation, industrial combined-heat-and-power site or remotely maintained auxiliary plant could possess a less mature security perimeter than a major nuclear or transmission facility. It might use vendor remote support, cellular telemetry, engineering laptops, building-management interfaces or legacy edge gateways that create a path into operational functions without requiring a purpose-built weapon. The public record nevertheless does not establish that the British facility used Unitronics equipment; importing that detail from the US campaign would be analytically unsound. The defensible inference is narrower: Iranian-affiliated actors have demonstrated intent and capability to enumerate exposed industrial devices, authenticate to inadequately protected interfaces, alter operator-facing functions and cause disruption. The transition from such capability to a UK generating site is technically plausible, but any assertion about a specific controller model, vulnerability or protocol would require evidence presently unavailable. The US advisory supplies a campaign precedent, not a forensic fingerprint for the unnamed British incident.
Probable access vectors and Bayesian weighting
Initial-access assessment should use a Bayesian structure in which prior probabilities derive from officially documented Iranian activity and posterior movement depends on plant-specific evidence. Government advisories describe Iranian actors using password spraying, multifactor-authentication fatigue, credential access, exploitation of known vulnerabilities and compromise of internet-facing services. Australian authorities, drawing on FBI engagements with affected critical-infrastructure organisations, reported Iranian actors conducting brute-force and credential-access activity and recommended strong passwords and a second authentication factor — Iranian Cyber Actors’ Brute Force and Credential Access Activity Compromises Critical Infrastructure – Australian Signals Directorate’s Australian Cyber Security Centre – October 2024. British authorities previously identified IRGC-affiliated exploitation of vulnerable Fortinet, Microsoft Exchange and Log4j deployments to obtain access before subsequent extortion, encryption or other malicious activity — UK and allies expose Iranian state agency for exploiting cyber vulnerabilities for ransomware operations – National Cyber Security Centre – September 2022. These observations support four principal access families: direct access to an exposed OT endpoint; compromise of a perimeter appliance or remote-access service; compromise of an enterprise identity followed by IT-to-OT traversal; and entry through a maintainer, integrator or managed-service provider. A fifth family—insider-enabled access—cannot be eliminated but has little affirmative public support. The starting weights below are analytical priors rather than observed incident frequencies. Evidence of unauthorised controller sessions would raise V₁ sharply; authentication logs showing impossible travel, repeated failures or token abuse would favour V₂ or V₃; remote-support artefacts and supplier credentials would increase V₄; and employee access coincident with unexplained configuration changes would increase V₅. Absence of logging cannot be treated as exculpatory because legacy OT devices frequently provide limited forensic persistence and may overwrite events during recovery.
| Vector | Initial prior | Evidence that would increase posterior probability | Evidence that would reduce it |
|---|---|---|---|
| V₁ Direct internet access to PLC, HMI or gateway | 26% | External controller sessions, unauthorised HMI commands, exposed management interface | No external route; cryptographically verified access controls |
| V₂ Exploited VPN, firewall or remote-access appliance | 25% | Vulnerable version, anomalous administrative login, changed configuration | Patched immutable image, no relevant exposure |
| V₃ Compromised enterprise identity and IT–OT traversal | 23% | Credential spraying, token theft, jump-host access, lateral movement | Strong separation and no shared identity plane |
| V₄ Third-party maintainer or supply-chain pathway | 18% | Vendor account activity, remote-tool artefacts, supplier compromise | Time-limited brokered access with complete session recording |
| V₅ Malicious or coerced insider facilitation | 8% | Privileged misuse, removable-media evidence, collusive communications | Independent dual control and consistent personnel telemetry |
IT–OT escalation path: from perimeter access to operational unavailability
The most probable escalation path does not require an attacker to understand turbine thermodynamics or rewrite complex control logic. A power facility can become unavailable when defenders can no longer prove that its control state, protection settings, process history or safety interlocks remain trustworthy. The intrusion may start in conventional IT, but operational consequences arise through dependency and assurance failure. NIST describes ICS environments as combinations of SCADA, distributed control systems, PLCs and associated configurations whose security requirements are constrained by reliability, timing and safety — Guide to Operational Technology Security, NIST Special Publication 800-82 Revision 3 – National Institute of Standards and Technology – September 2023. NCSC’s OT guidance similarly requires operators to identify and document external connectivity and understand the potential consequences of its compromise — Principle 4: Identify and document connectivity within your OT system – National Cyber Security Centre – October 2025. A plausible sequence begins with reconnaissance of public address space, certificate records, exposed services, procurement information, personnel profiles and vendor relationships. The adversary then obtains a credential or exploits a perimeter weakness, establishes persistence in a low-risk management layer, enumerates trust relationships and seeks a route toward a historian, patch server, remote desktop service, engineering workstation or jump host. From there, the attacker may disrupt availability by disabling operator accounts, corrupting supporting virtual machines, changing HMI parameters, terminating process-visualisation services or generating uncertainty about controller integrity. Operators may then invoke a safe-state procedure and keep the plant unavailable until known-good configurations are restored, protection systems are tested and engineering authority approves restart. Four days is entirely compatible with this containment-and-assurance cycle; it is not proof that the adversary retained uninterrupted control throughout the interval.

Determining whether SCADA was truly compromised
A government-grade investigation must differentiate compromise of the SCADA environment from compromise of equipment physically located at a power plant. SCADA is a supervisory architecture: it collects telemetry, presents plant state, allows authorised commands and may coordinate geographically distributed assets. A generating plant may instead rely principally on a DCS, plant control system, turbine control system, balance-of-plant controllers, protection relays and independent safety instrumentation. Calling every industrial incident a “SCADA attack” obscures which layer failed. The forensic priority is therefore reconstruction of command provenance and process truth. Investigators must compare firewall, VPN, identity-provider, remote-access, historian, HMI, engineering-workstation, controller and protection-relay timelines against physical telemetry such as frequency, voltage, breaker position, valve position, turbine speed, temperature and vibration. An unauthorised HMI login demonstrates supervisory access but not necessarily process manipulation. An altered display can deceive operators without changing the underlying process; conversely, direct PLC writes may change the process while a compromised HMI continues displaying normal values. Strong evidence of cyber-physical manipulation would include controller-program downloads outside a maintenance window, changed checksums, altered setpoints, unauthorised forces, disabled alarms, modified relay settings, abnormal command sequences or divergence between independent sensors and displayed values. NCSC explains that OT malware can compromise a management workstation to change a SCADA-controlled process or conceal valid alarms, while more specialised attacks can change PLC state directly — What is OT malware? – National Cyber Security Centre – February 2021. However, the same guidance distinguishes purpose-built OT malware from ordinary IT malware whose disruption of operational workstations produces indirect effects. Without the artefacts listed below, the British episode cannot responsibly be elevated from “cyber-related operational outage” to “confirmed manipulation of power-generation SCADA.”
| Evidence class | Indicative artefact | Attribution value | Cyber-physical significance |
|---|---|---|---|
| Network | Session records, protocol flows, remote-access source, command timing | Medium–high | Medium |
| Identity | Authentication attempts, token issuance, privilege elevation | Medium | Low–medium |
| Engineering | Project-file differences, controller checksum changes, unauthorised download | High | Very high |
| Process | Sensor/HMI divergence, anomalous setpoints, uncommanded actuator movement | Medium–high | Very high |
| Safety and protection | Relay-setting changes, inhibited trip, SIS diagnostic anomalies | High | Critical |
| Adversary infrastructure | Reused domains, certificates, hosting, toolmarks | High | Low |
| Intelligence | Operator identity, tasking, sponsor communications | Very high | Contextual |
| Recovery | Reimaging records, restored logic, test and restart approvals | Medium | High |
Analysis of competing hypotheses
Five competing hypotheses remain necessary because the same observable outcome—four days of plant unavailability—can result from materially different mechanisms. H₁ proposes direct OT manipulation by an Iran-linked actor: unauthorised access reached an HMI, engineering workstation, PLC, DCS server or protection device and changed operational state. H₂ proposes a precautionary shutdown after compromise of an edge, enterprise or supervisory system: the attacker did not necessarily command the physical process, but defenders could not safely continue operation. H₃ proposes ransomware or destructive IT activity affecting systems essential to plant administration, maintenance, communications or dispatch, with operational shutdown as an indirect consequence. H₄ proposes compromise through a third-party supplier or maintainer, potentially by an Iranian operator, criminal access broker or contractor account subsequently used by another actor. H₅ proposes reporting conflation, misattribution or opportunistic propaganda around an unrelated operational event. The baseline posterior is H₁ 27%, H₂ 36%, H₃ 16%, H₄ 15% and H₅ 6%. H₂ leads because a four-day interval corresponds closely to containment, validation and controlled restart, while direct logic manipulation would normally generate a stronger technical and governmental response if publicly confirmed. H₁ nevertheless remains substantial because the CyberAv3ngers campaign establishes intent and disruptive OT access. H₄ deserves more weight than conventional reporting gives it: remote maintenance compresses operational costs but transfers risk into supplier identities, unmanaged laptops and persistent connectivity. H₅ remains low but non-zero because the public narrative lacks a named victim, technical indicators or official attribution. The ACH result must be updated mechanically rather than rhetorically: verified PLC writes would move H₁ above 70%; evidence confined to VPN and identity systems would move H₂ above 60%; encryption artefacts would favour H₃; a supplier account used from anomalous infrastructure would favour H₄; and a regulator-confirmed non-cyber equipment failure would make H₅ dominant.
| Discriminating evidence | H₁ Direct OT | H₂ Defensive shutdown | H₃ IT disruption | H₄ Supplier path | H₅ Conflation |
|---|---|---|---|---|---|
| Unauthorised controller-program change | ++ | −− | −− | + | −− |
| Compromise limited to VPN or enterprise identity | − | ++ | + | + | − |
| Ransom note, encryption or wiper artefacts | − | + | ++ | 0 | − |
| Vendor remote-maintenance credential used | + | + | 0 | ++ | − |
| Safe shutdown ordered before process anomaly | − | ++ | + | + | 0 |
| Physical telemetry diverges from HMI display | ++ | − | − | + | −− |
| No cyber artefacts after complete forensic acquisition | − | − | − | − | ++ |
| Infrastructure overlap with attributed Iranian activity | ++ | ++ | + | ++ | −− |
Attribution: actor, sponsor and command relationship
Attribution should be expressed as a layered judgment rather than a single label. Technical attribution asks whether infrastructure, tools, credentials, command patterns or operational mistakes overlap with a known cluster. Behavioural attribution asks whether target selection, timing, messaging and risk tolerance match previous campaigns. Organisational attribution asks whether the operators belong to an IRGC element, an affiliated contractor, a state-tolerated patriotic group, a financially motivated crew or a coalition assembled for a specific operation. Strategic attribution asks whether Tehran directed, approved, encouraged or merely benefited from the attack. Public evidence presently supports a moderate assessment that the incident, if accurately reported, was conducted by an Iran-aligned actor; it supports only low-to-moderate confidence that the operation was directly commanded by the Iranian state. Iran’s cyber ecosystem can blur institutional and commercial boundaries, allowing personnel to conduct intelligence collection, disruptive operations and monetisation through partially overlapping infrastructures. This ambiguity creates plausible deniability and complicates proportional response. It also introduces the “mercenary” dimension: access brokers, ransomware affiliates, hosting providers, credential vendors and contractors can supply discrete capabilities without possessing the political objective of the final operator. Liquidity flows may therefore pass through cryptocurrency, informal settlement channels, contractor remuneration or criminal revenue-sharing rather than an identifiable government budget line. No such transaction has been publicly tied to the British incident, so these pathways remain collection requirements rather than findings. The UK’s broader threat assessment nevertheless supplies important context: NCSC reported in June 2026 that it had handled more than 200 incidents affecting British critical national infrastructure and its supporting ecosystem during the preceding year, with approximately 75% assessed as linked to hostile states including Iran — NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK’s critical systems – National Cyber Security Centre – June 2026. That statistic raises the prior probability of state nexus; it does not substitute for incident-specific proof.
Recovery duration as forensic evidence
The reported four-day outage is itself an observable, but it must be interpreted through operational recovery mechanics. A plant restart after suspected cyber intrusion is not equivalent to rebooting an enterprise server. The operator must establish a trusted configuration baseline, determine whether controller logic and protection settings match authorised versions, verify that sensors and actuators represent physical reality, inspect remote-access paths, rotate privileged credentials, validate time synchronisation, confirm that safety systems remain independent and test the unit under controlled conditions. If clean backups are incomplete, undocumented engineering changes have accumulated or replacement hardware requires vendor support, recovery can extend even when the original intrusion was technically simple. NCSC’s architectural guidance stresses resilience through redundancy, backup, disaster recovery and continuous knowledge of system health because the availability and integrity of OT information are essential during restoration — Principle 2: Create and maintain a definitive view of your OT architecture – National Cyber Security Centre – October 2025. Consequently, four days weakly favours H₂ over H₁: the interval is consistent with a conservative safety case and configuration validation after uncertain compromise. It neither proves advanced attacker persistence nor implies that malicious commands continuously prevented generation. The absence of national supply consequences similarly reveals little about technical depth. Britain’s system can absorb the loss of a small unit through reserve capacity, balancing actions, interconnectors or substitution from other generators, while the compromised facility still experiences severe local operational impact. A strategically rational adversary may deliberately select a small target because it reduces escalation risk, generates a demonstrable proof of access and tests incident-response procedures. Such an operation would function as reconnaissance by action: Tehran or an aligned group could measure detection time, government coordination, disclosure discipline, restoration procedures and political response without attempting a nationally consequential blackout.
Five-year outlook and Monte Carlo scenario structure
For 2026–2031, the core risk is the industrialisation of low-cost OT targeting rather than the sudden universal acquisition of highly specialised destructive malware. ENISA’s 2025 threat landscape found that OT threats represented 18.2% of the threat-category distribution in its analysed environment, while supply-chain risks accounted for 10.6%, reflecting increasing connectivity and indirect access pathways — ENISA Threat Landscape 2025 – European Union Agency for Cybersecurity – October 2025. ENISA’s foresight work identifies increasingly targeted ICS and OT networks, insecure transient assets, third-party access, legacy technology and state-sponsored or hackers-for-hire activity as material threats toward 2030 — Identifying Emerging Cyber Security Threats and Challenges for 2030 – European Union Agency for Cybersecurity – March 2023. A transparent Monte Carlo framework using 100,000 conceptual trials can model four variables: annual geopolitical activation, probability of exploitable exposure, probability of successful IT–OT traversal and probability that compromise produces operational interruption. The baseline projection rises from a 9% annual probability of material intrusion in 2026 to 21% in 2031 for a persistently exposed facility class; the annual probability of confirmed cyber-physical manipulation rises from 2% to 8%. These are analytical scenario values, not observed sector-wide frequencies. Under accelerated remediation, intrusion probability declines after 2028; under geopolitical escalation combined with weak remote-access governance, it approaches 33% by 2031. NCSC separately assesses that attackers will likely use AI-enabled capabilities to exploit known weaknesses in legacy critical-infrastructure technology at scale by 2028, reinforcing the expectation that reconnaissance and vulnerability matching will become faster even if physical-process engineering remains difficult. The decisive five-year variable is therefore not adversary intent—which is already present—but whether operators reduce externally reachable assets, separate identity planes, control vendor access, retain known-good configurations and detect lateral movement before trust in the process is lost.
| Year | Baseline material intrusion | Cyber-physical effect | High-escalation intrusion | Resilience case | Principal driver |
|---|---|---|---|---|---|
| 2026 | 9% | 2% | 14% | 8% | Exposed remote access and credential abuse |
| 2027 | 11% | 3% | 18% | 8% | Expanded scanning and exploitation automation |
| 2028 | 14% | 4% | 23% | 7% | AI-assisted discovery of legacy weaknesses |
| 2029 | 16% | 5% | 27% | 6% | Supplier compromise and access brokerage |
| 2030 | 19% | 7% | 30% | 5% | Cross-sector campaign coordination |
| 2031 | 21% | 8% | 33% | 5% | Persistent access combined with crisis activation |
Cyber norms, geopolitical signalling and the multilingual cross-check
The multilingual official record does not provide independent Russian or Chinese confirmation of the British event, and it must not be presented as doing so. It does, however, expose the normative environment in which attribution and response will occur. China’s delegation to the UN Open-Ended Working Group stated in March 2025 that states should not use ICT capabilities to damage another country’s critical infrastructure, destroy or steal its critical-infrastructure data, or disseminate targeted disinformation; it also argued that states bear responsibility for protecting critical and critical-information infrastructure — Remarks by Mr. Wang Lei, Head of Chinese Delegation and MFA Coordinator for Cyber Affairs, at the 10th Substantive Session of the UN OEWG on ICT Security – Ministry of Foreign Affairs of the People’s Republic of China – March 2025. This position is relevant because a confirmed state-directed attack on a British power facility would contradict the restraint principles publicly endorsed by major non-Western powers, even though those statements are political commitments rather than an incident-attribution mechanism. Russian official discourse similarly frames attacks on critical and cross-border energy infrastructure as destabilising, but Moscow’s statements do not corroborate the UK allegation and cannot resolve responsibility. The strategic “shadow” effect is therefore an expanding gap between formal norms and deniable practice. States can endorse non-interference while using proxies, contractors, patriotic personas or criminal intermediaries to conduct operations below an evidentiary and political threshold. For Britain, the appropriate response is not premature public certainty but an attribution package combining technical artefacts, victim testimony, intelligence holdings, infrastructure analysis, financial tracing and allied corroboration. Public attribution should specify confidence and distinguish the operator from the sponsor. Defensive action need not await that threshold: exposed OT services, unmanaged supplier pathways, shared IT–OT identities and incomplete controller baselines remain dangerous regardless of who conducted this incident. The highest-confidence conclusion is thus operational rather than political: the episode is consistent with a documented Iranian-affiliated campaign model, but the available public evidence cannot yet prove direct SCADA manipulation or IRGC command.
Iran’s SCADA Campaign Architecture: From Access to Cyber-Physical Disruption
The evolution from reconnaissance to operational effect
Iran’s operational-technology campaign architecture should not be interpreted as a linear progression toward a single, indigenous equivalent of Stuxnet, CrashOverride or TRITON. The public evidence instead reveals a modular ecosystem capable of selecting among espionage, credential acquisition, disruptive access, ransomware, psychological operations and politically timed interference according to the target’s exposure and Tehran’s strategic requirements. Three phases define the historical trajectory. The first was exploratory: Iranian operators acquired access to Western industrial systems and learned how apparently minor, internet-reachable assets could expose physical-process information. The 2013 intrusion into the Bowman Avenue Dam is the clearest officially documented example. Between 28 August and 18 September 2013, Hamid Firoozi repeatedly accessed the dam’s SCADA environment and obtained information on water levels, temperature and sluice-gate status. According to the US Department of Justice, the access would ordinarily have permitted remote operation of the gate, but the gate had been manually disconnected for maintenance — Seven Iranians Working for Islamic Revolutionary Guard Corps-Affiliated Entities Charged for Conducting Coordinated Campaign of Cyber Attacks – United States Department of Justice – March 2016. The second phase expanded into scalable enterprise compromise, intellectual-property theft, denial-of-service operations and ransomware, producing expertise in initial access, identity exploitation, persistence and monetisation. The third phase, visible in the CyberAv3ngers activity documented from 2023 onward, converted exposed PLC access into politically branded disruption. The architecture is therefore evolutionary but uneven: Iran does not need to defeat the most secure control systems if it can repeatedly locate smaller utilities, embedded generators, remote pumping assets and industrial sites whose connectivity decisions have collapsed the separation between external networks and physical control. The British incident, if accurately reported, could mark a further transition from opportunistic controller compromise to sustained unavailability of an electricity-generating facility; public evidence does not yet establish whether that transition involved direct process manipulation or a defensive shutdown caused by loss of operational trust.
| Phase | Period | Officially documented precedent | Principal capability demonstrated | Cyber-physical ceiling actually observed |
|---|---|---|---|---|
| Exploratory access | 2013 | Bowman Avenue Dam | Repeated unauthorised SCADA access and process reconnaissance | Potential gate control, prevented by physical disconnection |
| Scalable disruption | 2011–2013 | US financial-sector DDoS campaign | Botnet construction, coordinated disruption, government-linked contracting | Economic disruption without physical-process effect |
| Enterprise penetration | 2013–2026 | Mabna Institute and related operations | Credential theft, research theft, contractor mobilisation, global targeting | Strategic intelligence acquisition |
| Extortion convergence | 2015–2024 | SamSam and later Iranian access-and-ransomware operations | Vulnerability exploitation, encryption, access brokering | Indirect interruption of essential services |
| Branded OT targeting | 2023–2026 | CyberAv3ngers and internet-exposed PLCs | Controller access, HMI interference and politically signalled disruption | Localised operational disruption |
| Emerging power-sector phase | 2026 onward | Reported UK plant incident and US OT campaign | Possible sustained site unavailability | Direct generation manipulation remains unproved |
Bowman Avenue Dam as the foundational Iranian SCADA precedent
The Bowman Avenue case established several characteristics that remain visible in later Iranian campaigns. First, target importance was initially misread because the word “dam” implied a large strategic installation, whereas the actual asset was comparatively small. Operational relevance nevertheless exceeded physical scale: the attacker obtained access to information about a controlled water process and, absent the manual disconnection, could reportedly have operated the sluice gate. This demonstrated the asymmetric value of poorly protected municipal or industrial assets. Second, the intrusion coexisted with a much larger campaign against financial institutions, showing that Iranian cyber activity could combine economic disruption, politically motivated retaliation and critical-infrastructure reconnaissance within one operational ecosystem. The Justice Department alleged that operators associated with ITSecTeam and Mersad worked on projects for the Iranian government and used botnets composed of thousands of compromised systems; the financial campaign affected 46 institutions, operated across more than 176 days and, on some days, generated traffic reaching 140 gigabits per second — Manhattan U.S. Attorney Announces Charges Against Seven Iranians for Conducting Coordinated Campaign of Cyber Attacks Against U.S. Financial Sector – United States Department of Justice – March 2016. Third, the Bowman event showed that cyber access does not guarantee physical effect. A mechanical maintenance state prevented the digital command path from reaching the actuator, producing an early example of independent physical control acting as a security barrier. This distinction is central to the British power-plant assessment. An attacker may possess valid SCADA credentials, see process values and issue commands, yet fail to affect generation because permissive logic, local control, protection relays, safety systems or manual disconnection interrupt the control chain. Conversely, an apparently unsophisticated access event may still force shutdown if the operator cannot prove that logic, alarms and protection settings remain trustworthy. Bowman therefore supplies three enduring analytic lessons: small assets can carry strategic signalling value; hybrid campaigns may unite financial, intelligence and physical objectives; and incident severity must be measured by the complete sensor-to-actuator chain rather than by the attacker’s presence on a screen.
The contractor-state ecosystem
Iran’s operating model is better represented as a layered market than as a monolithic military unit. At the centre sit state requirements generated by the IRGC, its Cyber-Electronic Command, the Ministry of Intelligence and Security and other security institutions. Around that centre operate nominally private institutes, cybersecurity companies, university-linked personnel, contractors, freelancers and hackers-for-hire. Some execute state tasking; some pursue independent financial gain; some reuse access acquired for one purpose in a separate extortion operation; and some move between government service and private activity. The model provides surge capacity, specialist recruitment and deniability while complicating the distinction between state-sponsored, state-directed and state-tolerated conduct. The Mabna Institute demonstrates this architecture. US authorities described its personnel as leaders, contractors, associates, hackers-for-hire and affiliates conducting intrusions on behalf of the IRGC and other Iranian governmental clients. The 2018 case concerned compromises of 144 US universities, 176 foreign universities across 21 countries, private companies, government institutions and international organisations, involving more than 31 terabytes of stolen academic and proprietary material — Nine Iranians Charged With Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps – United States Department of Justice – March 2018. In August 2026, the Justice Department expanded the case through charges against 17 Iranian nationals, describing a continuing ecosystem of employed, contracted and affiliated personnel — 17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities – United States Department of Justice – August 2026. For SCADA operations, this structure implies that initial access, infrastructure hosting, credential collection, operational engineering and public messaging may be divided among separate actors. Attribution based on one server or persona can therefore identify an operational component without proving the complete command relationship. It also creates a marketplace in which compromised VPN credentials or remote-maintenance accounts can move from espionage operators to ransomware affiliates or politically activated OT teams.
| Architectural layer | Typical function | Strategic advantage | Attribution complication |
|---|---|---|---|
| State sponsor or security institution | Defines target class, intelligence requirement and escalation boundary | Aligns cyber activity with national strategy | Direction may remain classified or deliberately indirect |
| State-affiliated contractor | Builds access, tools and operational infrastructure | Expands capacity outside formal military staffing | Corporate cover blurs official status |
| Access specialist | Exploits edge systems, identities or exposed devices | Generates reusable entry into multiple sectors | Access may be sold or transferred |
| OT exploitation cell | Interprets HMI, PLC, DCS and process context | Converts network access into operational leverage | May use commodity tools rather than unique malware |
| Criminal or ransomware affiliate | Monetises access through encryption or extortion | Generates revenue and provides plausible criminal motive | Financial activity can mask strategic preparation |
| Influence persona | Claims attacks, publishes screenshots and amplifies fear | Magnifies impact beyond technical damage | Claims may exaggerate, recycle or fabricate access |
| Infrastructure broker | Supplies hosting, domains, VPNs and relays | Separates operators from victim-facing infrastructure | Shared services produce false technical overlaps |
CyberAv3ngers and the operational logic of vulnerable-by-selection
The CyberAv3ngers model relies on target selection more than advanced exploitation. In November 2023, CISA reported active exploitation of Unitronics PLCs used in water and wastewater systems — Exploitation of Unitronics PLCs Used in Water and Wastewater Systems – Cybersecurity and Infrastructure Security Agency – November 2023. The subsequent joint advisory attributed the campaign to IRGC-affiliated actors and stated that the targeted Vision Series PLCs were deployed across water, energy, food and beverage, healthcare and other sectors — IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities – Cybersecurity and Infrastructure Security Agency – December 2023. The operational method is economically rational. Instead of developing malware for every industrial platform, the actors enumerate exposed systems, identify products associated with Israeli technology or politically relevant operators, attempt access through weak or default authentication and alter the visible interface or controller state where possible. Selection substitutes for sophistication: a global scan can identify the minority of assets whose insecure configuration makes exploitation feasible, while publicity converts modest local impact into a strategic narrative. The US Treasury’s February 2024 sanctions announcement stated that IRGC-affiliated actors hacked Unitronics PLCs and posted images on their screens; Treasury emphasised that the identified activity was remediated with minimal impact and did not disrupt critical services, while warning that unauthorised access could enable harmful and escalatory consequences — Treasury Sanctions Actors Responsible for Malicious Cyber Activities on Critical Infrastructure – United States Department of the Treasury – February 2024. By July 2026, the campaign had evolved: the FBI observed Iranian-affiliated actors targeting internet-exposed PLCs with the intent to cause disruption, and the joint advisory described disruptive effects across US critical infrastructure — Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure – Cybersecurity and Infrastructure Security Agency – July 2026. The change from screen defacement with minimal service impact to documented disruptive effects is the most important indicator of campaign maturation.
The reusable intrusion stack
The Iranian campaign stack contains at least six reusable components. The first is broad reconnaissance: attackers identify public services, virtual-private-network portals, internet-facing management interfaces, cloud identities, exposed controllers and personnel associated with operations or maintenance. The second is low-cost initial access through password spraying, multifactor-authentication abuse, known vulnerabilities and stolen credentials. CISA, the FBI, NSA and international partners reported that Iranian actors used brute force and password spraying from October 2023 to compromise accounts across critical-infrastructure sectors — Iranian Cyber Actors’ Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations – Cybersecurity and Infrastructure Security Agency – October 2024. The third component is persistent enterprise access. MuddyWater, attributed by US agencies to the Iranian government, uses publicly available tools and legitimate system utilities, maintains access through several mechanisms and can provide stolen data and victim access to the Iranian government or other malicious operators — Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks – Cybersecurity and Infrastructure Security Agency – February 2022. The fourth component is access transfer: credentials and footholds can be used for espionage, ransomware or OT targeting depending on later tasking. The fifth is operational conversion, in which an attacker enumerates process assets, learns controller relationships and identifies the minimum intervention capable of forcing a safety response. The sixth is influence amplification through branded personas, political imagery, public claims and selective disclosure of screenshots. This stack can generate cyber-physical consequences without specialised malware. Disabling an authentication service used by plant operators, corrupting a virtualised HMI server, modifying a setpoint, interrupting historian availability or compromising a remote-support account can all create sufficient uncertainty to make continued operation unsafe. The architecture’s danger lies precisely in its ability to reuse ordinary enterprise access techniques against the digital dependencies surrounding physical processes.

Albania as the precedent for strategic destructive coercion
The 2022 attack against Albania demonstrates a different Iranian model: destructive cyber activity deployed as coercive statecraft rather than as opportunistic controller exploitation. The UK, United States, Albania and Israel attributed the July 2022 campaign to Iran; the British government described this as its first attribution of malicious cyber activity to the Iranian state — National Cyber Strategy 2022 Annual Progress Report 2022–2023 – Cabinet Office – August 2023. The operation targeted Albanian government services, and subsequent Iranian-attributed activity affected the State Police and compromised critical databases — Conflict, Stability and Security Fund Annual Report 2023 to 2024 – Foreign, Commonwealth and Development Office – December 2024. Albania matters for SCADA analysis because it demonstrates Iranian willingness to accept conspicuous national-level disruption when Tehran perceives a political grievance sufficiently important to justify escalation. It also illustrates combined operations: intrusion, data compromise, service disruption and psychological messaging can reinforce one another. Applied to British energy, the relevant hypothesis is not that the same tools were transferred directly into a power plant, but that the decision logic is transferable. Iran can calibrate cyber action across a spectrum from intelligence collection to publicly visible disruption. A small plant outage produces a useful middle option: more consequential than website defacement, less escalatory than a regional blackout and difficult to classify as armed force if physical damage and casualties are absent. Such calibration would allow Tehran to signal access to Western infrastructure, impose remediation costs and generate public anxiety while preserving deniability. Albania therefore increases the prior probability that a politically motivated Iranian operation could deliberately seek operational unavailability. It does not establish that the British plant was targeted under direct Iranian governmental orders, nor that industrial process manipulation occurred.
Ransomware, access brokerage and dual-purpose operations
The boundary between Iranian state operations and financially motivated intrusion is structurally porous. In August 2024, US agencies described an Iranian group conducting a high volume of network intrusions and enabling ransomware attacks against organisations in multiple sectors — Iran-Based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations – Cybersecurity and Infrastructure Security Agency – August 2024. Earlier criminal proceedings alleged that three Iranian nationals exploited known vulnerabilities in common network devices and applications, exfiltrated information and conducted encryption attacks against hundreds of victims, including utilities, healthcare organisations and transportation providers. The Justice Department distinguished personal gain from direct state tasking but stated that Iran provided a safe haven in which such activity could flourish — Three Iranian Nationals Charged with Engaging in Computer Intrusions and Ransomware-Style Extortion Against U.S. Critical Infrastructure Providers – United States Department of Justice – September 2022. This dual-use access economy creates four attribution hazards. First, a foothold initially established for espionage may later be monetised without formal authorisation. Second, criminals may provide state entities with access or data in exchange for protection, status or commercial benefit. Third, a state-directed disruption can be disguised as ransomware to obscure political intent. Fourth, an independently motivated ransomware incident can be misclassified as strategic sabotage because the operators are Iranian. For a power facility, the technical consequences may be indistinguishable during the first hours: operator accounts fail, virtual machines become unavailable, engineering files cannot be trusted and plant management orders isolation. Financial tracing becomes strategically important, but absence of a ransom demand does not eliminate criminal infrastructure, while presence of a payment demand does not eliminate state interest. Investigators should examine wallet clustering, payment instructions, negotiations, access-broker communications, shared infrastructure and timing relative to geopolitical events. No public evidence currently connects such liquidity indicators to the British plant. The correct assessment is that ransomware-style operations form part of Iran’s broader cyber ecosystem and provide both an alternative explanation and a deniable delivery mechanism for operational disruption.
Comparative capability ceilings: CrashOverride and TRITON
Two non-Iranian precedents define the upper capability boundary against which Iranian SCADA activity must be measured. CrashOverride, deployed by Russian state actors against Ukrainian electricity infrastructure, contained functionality designed to interact with industrial protocols and disrupt grid operations — CrashOverride Malware – Cybersecurity and Infrastructure Security Agency – July 2021. The 2015 Ukrainian power-sector incident similarly demonstrated coordinated access to operational environments, unscheduled outages and interference with electricity distribution — Cyber-Attack Against Ukrainian Critical Infrastructure – Cybersecurity and Infrastructure Security Agency – July 2021. TRITON, attributed by US authorities to Russia’s Central Scientific Research Institute of Chemistry and Mechanics, was designed specifically to target Schneider Electric Triconex safety systems and could disrupt those systems — Tactics, Techniques, and Procedures of Indicted State-Sponsored Russian Cyber Actors Targeting the Energy Sector – Cybersecurity and Infrastructure Security Agency – March 2022. These operations required detailed understanding of target technology, engineering workflows and physical safety logic. Publicly documented Iranian operations have not demonstrated an equivalent reusable ability to manipulate protection or safety-instrumented systems at scale. That absence should reduce, but not eliminate, the probability of sophisticated cyber-physical sabotage. Capabilities can be acquired through research, contractors, compromised engineering data, commercial intrusion tools, technology transfer or learning from adversaries’ published methods. More importantly, Iranian actors may achieve strategically useful outcomes without reaching the CrashOverride or TRITON threshold. If defenders shut down a plant because the HMI, historian or engineering baseline cannot be trusted, the adversary obtains availability impact through uncertainty rather than direct physical control. The decisive distinction is therefore between process-native disruption, which commands industrial equipment, and process-dependent disruption, which compromises digital support deeply enough that safe operation cannot continue. Current evidence places Iran firmly in the second category and increasingly within the lower range of the first.
| Capability tier | Operational action | Representative precedent | Publicly demonstrated Iranian position |
|---|---|---|---|
| T₁ External disruption | DDoS, portal denial, public messaging | US financial-sector campaign | Established |
| T₂ Enterprise compromise | Credential theft, persistence, exfiltration | MuddyWater, Mabna | Established at scale |
| T₃ Operational dependency disruption | HMI server loss, identity failure, encryption, remote-access compromise | Iranian ransomware and access campaigns | Established or strongly supported |
| T₄ Direct controller access | PLC or HMI login, display change, limited commands | Bowman Dam, CyberAv3ngers | Established |
| T₅ Process-aware manipulation | Coordinated setpoint, actuator or protection changes | Ukraine power attacks | Not publicly established at comparable scale |
| T₆ Safety-system defeat and destructive engineering | Manipulation of SIS or protection architecture | TRITON | No public evidence |
| T₇ Multi-site grid campaign | Simultaneous, protocol-aware regional disruption | CrashOverride-type architecture | No public evidence |
Analysis of competing campaign hypotheses
The campaign architecture produces six rather than five serious hypotheses. H₁ holds that the British outage was a direct CyberAv3ngers-style operation against an exposed PLC, HMI or gateway, with access converted into local disruption. H₂ proposes enterprise compromise followed by a precautionary shutdown: the attackers reached identities, remote services or supervisory assets but did not directly command the generating process. H₃ treats the incident as a ransomware or destructive-IT operation whose operational consequence was collateral or opportunistically amplified. H₄ proposes a contractor-mediated state operation in which an Iranian security body used an external company or access broker to reach the plant, preserving deniability. H₅ proposes strategic pre-positioning that was accidentally detected or intentionally activated during geopolitical escalation; under this model, the four-day outage reveals a previously dormant foothold. H₆ proposes misattribution or conflation with a non-Iranian incident. Applying weighted consistency, diagnosticity, precedent strength and missing-evidence penalties produces provisional probabilities of H₁ 25%, H₂ 31%, H₃ 14%, H₄ 15%, H₅ 10% and H₆ 5%. H₂ remains the leading explanation because ordinary access methods can produce a long outage without requiring advanced process engineering. H₁ is elevated by the 2026 US advisory confirming disruptive Iranian-affiliated PLC operations. H₄ reflects Iran’s documented contractor ecosystem. H₅ carries strategic importance despite its lower probability because pre-positioned access could be activated across multiple sites during conflict. A public claim, screenshot or politically branded message would not by itself discriminate between H₁ and H₄; authenticated industrial commands, recovered tooling and infrastructure overlap would. H₃ would gain support from encryption artefacts, ransom communications or known access-broker behaviour. H₆ would become dominant only if official investigation established an unrelated equipment failure or a different actor with stronger forensic support.
| Hypothesis | Baseline | Strong confirming evidence | Principal contradiction |
|---|---|---|---|
| H₁ Direct exposed-controller operation | 25% | Unauthorised PLC/HMI session and Iran-linked infrastructure | No route to controller; no operational command |
| H₂ Enterprise compromise and defensive shutdown | 31% | Identity, VPN or supervisory compromise without altered logic | Verified attacker-induced process change |
| H₃ Ransomware or destructive IT | 14% | Encryption, extortion or wiper evidence | Clean enterprise layer with direct PLC activity |
| H₄ Contractor-mediated state operation | 15% | Supplier credential plus governmental tasking indicators | No third-party access relationship |
| H₅ Pre-positioned access activated in crisis | 10% | Long dwell time, dormant persistence and timed activation | Immediate opportunistic exploitation |
| H₆ Misattribution or reporting conflation | 5% | Official non-cyber cause or attribution to another actor | Multiple independent Iran-specific forensic links |
Cyber-physical consequences and escalation thresholds
Cyber-physical consequences should be modelled across availability, integrity, safety, equipment and systemic propagation rather than reduced to megawatts lost. At the lowest tier, loss of operator visibility or administrative services can delay maintenance, dispatch or restart. At the next tier, altered HMI displays, alarm suppression or historian corruption can force operators to distrust the control environment. Direct manipulation of setpoints, valves, breakers, excitation, fuel handling or auxiliary systems creates immediate process risk, but independent controllers and protection systems may prevent damage. The most serious tier involves defeating safety instrumentation or protection relays so that equipment operates beyond safe limits. Iran has publicly demonstrated access through T₄ but not the full T₆ or T₇ capability. The likely strategic objective is therefore coercive availability loss rather than catastrophic destruction. A four-day shutdown of a small plant could still produce substantial effects: emergency procurement, forensic and engineering costs, regulatory intervention, insurance disputes, reputational damage, reassessment of vendor access and wider government mobilisation. A campaign across several small assets could impose cumulative balancing costs while remaining below the visual threshold of a national blackout. It could also generate false-data risk: grid operators making decisions from manipulated telemetry may create instability even when individual devices remain functional. The probability of casualties remains low in the baseline model but rises sharply if attackers manipulate combustion, pressure, chemical treatment, rotating equipment or safety logic. Treasury explicitly warned that operations impairing critical infrastructure are destabilising and potentially escalatory, establishing the political significance of even limited PLC compromise. A deliberate attack causing physical damage, prolonged regional loss of electricity or fatalities would cross a qualitatively different threshold, potentially engaging collective diplomatic, economic, intelligence and military responses. Tehran therefore has incentives to pursue reversible, localised and deniable disruption—enough to demonstrate reach, but not enough to unify adversaries around a forceful response.
Five-year campaign forecast, 2026–2031
The most likely evolution is a widening separation between the number of accessible targets and the number of operations requiring sophisticated industrial engineering. Automated reconnaissance and AI-assisted vulnerability matching will increase the discovery rate for exposed gateways, remote-maintenance services and legacy controllers. Stolen credentials will remain valuable because identity systems frequently cross enterprise, cloud and operational-support boundaries. Contractor compromise will grow as utilities centralise remote support and depend on specialised integrators. Iran-linked actors will probably build inventories of accessible OT assets rather than immediately disrupting every compromised site, enabling deferred activation during geopolitical crises. The median campaign will continue to favour reversible effects: screen modification, operator lockout, supervisory disruption, data destruction, ransomware or forced safe shutdown. The high-impact tail will involve process-aware manipulation acquired through longer dwell time, stolen engineering documentation or contractor access. By 2031, the model assigns a 55% probability that Iranian-affiliated operators will have demonstrated repeatable disruptive access across more than one Western energy jurisdiction, a 31% probability of publicly confirmed process-aware manipulation at a power or water facility, and a 12% probability of a coordinated multi-site campaign producing regionally significant service interruption. These are structured estimates, not measured frequencies. Defensive intervention can materially change them. Removing direct internet exposure, imposing phishing-resistant authentication, recording vendor sessions, separating enterprise and OT identities, monitoring controller logic, maintaining offline engineering baselines and rehearsing manual operation reduce both access probability and recovery time. The principal strategic warning is that Iran does not need a universal cyber weapon. A portfolio of hundreds of weakly secured assets, combined with a contractor-access ecosystem and politically timed activation, can create aggregate coercive power. The British incident is important because it may represent the first visible European energy-sector proof of that portfolio model, even if direct SCADA manipulation remains unverified.
Five-Year Strategic Outlook: Iranian OT Risk and Transatlantic Resilience, 2026–2031
Bayesian forecast architecture
The five-year forecast must distinguish four conditional events that are frequently collapsed into a single probability: A, an Iran-linked actor selects an energy or adjacent critical-infrastructure target; B, the actor obtains persistent digital access; C, that access reaches an operationally significant OT dependency; and D, the compromise produces service interruption, equipment damage or a safety consequence. The probability of a cyber-physical event is therefore conditional: P(D)=P(A)×P(B|A)×P(C|B)×P(D|C), adjusted for correlated exposures and defensive intervention. This structure prevents an increase in hostile reconnaissance from being misrepresented as an equivalent increase in destructive capability. The baseline 2026 priors used here assign 68% annual probability to continuing Iranian-affiliated reconnaissance against Western critical infrastructure, 24% probability that a representative materially exposed target suffers some form of unauthorised access, 31% conditional probability that a successful intrusion reaches an operational dependency, and 18% conditional probability that OT-relevant access causes a measurable service effect. These priors are analytical estimates, not sector-wide incident frequencies. They are informed by the documented Iranian targeting of internet-connected PLCs, credential-access campaigns and NCSC’s assessment that Iran retains disruptive and destructive intent toward the United Kingdom. In June 2026, NCSC reported more than 200 incidents affecting UK critical national infrastructure or its supporting ecosystem during the preceding year, with approximately 75% linked to hostile states; it also assessed that attackers would likely use AI-enabled capabilities to exploit known weaknesses in legacy critical-infrastructure technology at scale by 2028 — NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK’s critical systems – National Cyber Security Centre – June 2026. The Bayesian forecast consequently raises access probability faster than physical-impact probability: automated discovery and credential operations scale readily, whereas safe manipulation of heterogeneous industrial processes still requires engineering knowledge, target-specific reconnaissance and tolerance for escalation.
| Forecast variable | 2026 prior | 2031 baseline | 2031 high-escalation | Principal observable |
|---|---|---|---|---|
| A: Iranian selection of Western CNI | 68% | 82% | 94% | Campaign tasking, reconnaissance concentration, geopolitical triggers |
| B: Material access to an exposed target | 24% | 36% | 52% | Valid-account use, exploited edge device, supplier compromise |
| C: IT–OT or direct-OT penetration given access | 31% | 43% | 58% | Jump-host activity, engineering-station discovery, PLC/HMI sessions |
| D: Operational effect given OT penetration | 18% | 25% | 39% | Forced shutdown, loss of view, changed process state |
| E: Physical damage given operational effect | 5% | 8% | 17% | Equipment stress, disabled protection, safety-system interference |
| F: Multi-site systemic propagation | 3% | 7% | 15% | Common supplier, central platform or coordinated activation |
Bayesian updating and intelligence indicators
Posterior probabilities should be updated through likelihood ratios rather than intuitive escalation. Evidence E₁ consisting of Iranian-linked scanning or failed authentication attempts has a high probability under hostile reconnaissance but also occurs under generic internet activity; it therefore produces only a small increase in the probability of a targeted campaign. Evidence E₂ consisting of successful use of a supplier credential from infrastructure previously associated with an Iranian cluster is more diagnostic because it jointly supports actor identity and a pathway toward operational systems. Evidence E₃—unauthorised interaction with an HMI, engineering workstation or PLC—substantially raises the probability of OT intent, but it does not prove physical-process understanding. Evidence E₄—valid process commands timed to maximise operational disruption—would support deliberate cyber-physical action. Evidence E₅—modified protection settings, alarm suppression or divergence between independent sensors and displayed data—would sharply increase the probability of process-aware sabotage. The update discipline matters because Iran-linked personas may exaggerate impact, criminals may use Iranian infrastructure, and compromised servers may be shared among unrelated operators. Under the baseline model, a known Iranian source address alone moves the probability of state-affiliated operation from 25% to approximately 34%; the same indicator combined with credential reuse and command-and-control overlap raises it to approximately 57%. Add authenticated controller writes inconsistent with maintenance activity and the posterior reaches approximately 78%. Add classified intelligence demonstrating tasking or an operator relationship with the IRGC Cyber-Electronic Command, and confidence could exceed 90%. Conversely, complete forensic acquisition showing only enterprise ransomware, no OT traversal and a conventional extortion negotiation would reduce the probability of deliberate state cyber-physical action below 15%, even if the offenders operated from Iran. This hierarchy ensures that attribution follows evidence rather than geopolitical expectation. It also defines collection priorities: cross-border identity telemetry, supplier-session recording, controller-logic baselines, protection-relay histories and preserved network metadata carry greater diagnostic value than public claims or screenshots.
| Evidence update | Indicative likelihood ratio for state-linked OT hypothesis | Analytical effect |
|---|---|---|
| Generic scanning from Iran-associated infrastructure | 1.3 | Weak increase; infrastructure may be shared or compromised |
| Repeated valid-account use matching Iranian TTPs | 2.1 | Moderate increase |
| Supplier credential used through attributed infrastructure | 3.2 | Strong increase in access-transfer hypothesis |
| PLC or HMI commands outside authorised maintenance | 4.5 | Strong evidence of OT intent |
| Process-aware sequencing of commands | 6.0 | Very strong evidence of engineering preparation |
| Tooling or infrastructure overlap plus intelligence corroboration | 8.0–12.0 | Potentially attribution-grade |
| Ransomware confined to enterprise systems | 0.5 | Reduces deliberate OT-manipulation probability |
| Verified non-cyber equipment failure | 0.1 | Strongly favours conflation or misattribution |
Monte Carlo design and scenario boundaries
The Monte Carlo model uses 250,000 conceptual iterations across six annual periods from late 2026 through 2031. Each iteration samples geopolitical activation, exposed-asset prevalence, credential compromise, supplier concentration, IT–OT segmentation quality, operator-detection time, manual-operating capability and restoration maturity. Dependency between variables is essential: remote access increases both initial-access probability and the likelihood of reaching OT; poor asset visibility simultaneously lengthens dwell time and recovery; geopolitical crisis increases targeting intensity and the probability that previously acquired access is activated. The model therefore uses correlated rather than independent draws. Five scenarios frame the distribution. S₁, Managed Competition, assumes persistent Iranian reconnaissance, episodic access and limited political incentives for destructive action. S₂, Proxy Escalation, assumes conflict involving Iranian partners triggers politically timed attacks by affiliated groups without a formal decision for strategic cyber warfare. S₃, Direct State Confrontation, assumes Tehran authorises disruptive operations against UK, US and European infrastructure while seeking to avoid casualties. S₄, Systemic Supplier Compromise, assumes a common integrator, managed-service provider, remote-access platform or equipment vendor becomes the shared route into multiple operators. S₅, Cyber-Physical Threshold Crossing, assumes process-aware manipulation damages equipment, threatens safety or causes a multi-day regional service interruption. In the baseline output, at least one material Iran-linked OT incident affecting the transatlantic energy ecosystem during 2026–2031 appears in 71% of iterations; at least one publicly confirmed service interruption appears in 46%; process-aware manipulation appears in 27%; physical equipment damage in 11%; and a coordinated multi-site event in 8%. These figures represent scenario-model results, not predictions about a named facility. The largest sensitivity is supplier concentration, followed by direct internet exposure and recovery maturity. A 30% reduction in uncontrolled external connectivity lowers the modeled probability of service interruption from 46% to 32%; adding verified manual operation and immutable engineering baselines lowers the median restoration interval from 4.1 days to 1.8 days.
| Scenario | Five-year probability | Median service interruption | 95th-percentile interruption | Strategic interpretation |
|---|---|---|---|---|
| S₁ Managed Competition | 38% | 0–1 day | 3 days | Access and signalling dominate over physical effect |
| S₂ Proxy Escalation | 24% | 2.4 days | 9 days | Hacktivist and contractor activity intensifies around conflict |
| S₃ Direct State Confrontation | 17% | 4.8 days | 18 days | Pre-positioned access activated for coercive disruption |
| S₄ Systemic Supplier Compromise | 13% | 6.3 days | 27 days | Common dependency generates cross-operator propagation |
| S₅ Cyber-Physical Threshold Crossing | 8% | 10.6 days | 42 days | Equipment, protection or safety consequences dominate recovery |
Systemic exposure beyond the individual plant
Systemic risk does not arise principally from the loss of one small generator. It emerges when several operators depend on the same identity provider, telecommunications service, cloud environment, remote-access product, control-system integrator, firmware supply chain, managed-security provider or specialised engineering workforce. A geographically dispersed energy system can therefore contain hidden digital concentration even when physical generation is diversified. This concentration creates four propagation mechanisms. The first is technical commonality: one vulnerable appliance, remote-management platform or controller family appears across multiple plants. The second is administrative commonality: a supplier account or central identity service reaches several customers. The third is operational commonality: multiple sites depend on a common control centre, market interface, communications service or data pipeline. The fourth is recovery commonality: operators compete for the same incident responders, replacement equipment, vendor engineers and forensic specialists during simultaneous disruption. ENISA’s 2026 NIS360 assessment warns that smaller entities with less mature cybersecurity and limited resources can be targeted through supply-chain attacks with cascading effects on larger organisations — ENISA NIS360 2026 – European Union Agency for Cybersecurity – May 2026. ENISA’s investment analysis further found that ransomware concerned 55% of surveyed organisations, supply-chain attacks 47%, and phishing 35%, while smaller organisations reported the lowest confidence in their ability to anticipate, withstand and recover — NIS Investments 2025 – European Union Agency for Cybersecurity – February 2026. For systemic modelling, the smallest contractor may therefore matter more than the largest generator. The portfolio-level metric should be the number of essential-service megawatts, substations, treatment facilities or control zones reachable through a single digital trust relationship, not merely the number of vulnerable devices.

United Kingdom: from compliance to operational assurance
The UK resilience requirement is to convert an institutionally strong but unevenly implemented framework into measurable OT assurance. The Cyber Assessment Framework provides a structured basis for assessing organisations responsible for essential services and distinguishes baseline from enhanced profiles according to the capability of the relevant threat — Cyber Assessment Framework – National Cyber Security Centre – November 2025. The reported plant incident indicates why a documentary assessment is insufficient: regulators and boards need evidence that external connectivity is enumerated, supplier access is bounded, engineering baselines are recoverable and operators can continue safely without compromised digital services. The Cyber Security and Resilience Bill proposes reforms to the existing NIS regime, including broader protection of essential and digital services, stronger regulator powers and treatment of critical suppliers — Summary of the Cyber Security and Resilience Bill – Department for Science, Innovation and Technology – July 2026. The associated policy explicitly anticipates duties addressing supply-chain cybersecurity through contractual requirements, security checks and continuity planning — Cyber Security and Resilience Policy Statement – Department for Science, Innovation and Technology – April 2025. Between 2026 and 2031, the UK should require high-impact energy operators to report not merely significant incidents but defined loss-of-control indicators: unauthorised controller sessions, safety-system anomalies, unknown remote connections, logic-baseline deviation and loss of trusted process visibility. Designated critical suppliers should be assessed on the aggregate operational capacity reachable through their services. Every regulated operator should maintain an authoritative OT architecture record, an externally validated inventory of remote pathways and an annual proof-of-recovery exercise using known-good controller and protection configurations. NCSC’s guidance emphasises definitive OT architecture, categorised assets, documented connectivity and third-party risk — Creating and maintaining a definitive view of your OT architecture – National Cyber Security Centre – October 2025. The policy objective must be demonstrable operational continuity, not nominal framework conformity.
| UK requirement | 2027 target | 2029 target | 2031 target |
|---|---|---|---|
| High-impact operators with verified OT asset and connectivity record | 80% | 95% | 100% |
| Privileged vendor sessions brokered, time-limited and recorded | 70% | 90% | 100% |
| Critical controller logic covered by immutable baseline | 75% | 95% | 100% |
| Annual cyber-physical recovery exercise | 60% | 85% | 100% |
| Restoration without external cloud identity | 55% | 80% | 95% |
| Critical suppliers measured for aggregate downstream exposure | 50% | 85% | 100% |
United States: reducing the long tail of exposed infrastructure
US resilience faces a scale and fragmentation problem. The country’s electricity, water and industrial sectors include large sophisticated operators alongside small municipal utilities, cooperatives, distributed-energy aggregators and resource-constrained facilities. Iran-linked actors have repeatedly selected the long tail because exposed PLCs, weak credentials and inconsistent remote-access practices permit politically useful effects without breaching the best-defended bulk-power assets. CISA’s Cross-Sector Cybersecurity Performance Goals establish a baseline of high-impact practices for critical infrastructure — Cybersecurity Performance Goals 2.0 – Cybersecurity and Infrastructure Security Agency – December 2025. Its OT-specific mitigation guidance prioritises reducing exposure and implementing controls aligned with those goals — Primary Mitigations to Reduce Cyber Threats to Operational Technology – Cybersecurity and Infrastructure Security Agency – June 2025. The Department of Energy and NARUC have separately developed cybersecurity baselines for distribution systems and distributed-energy resources, recognising that grid modernisation expands both flexibility and the number of digitally managed endpoints — Cybersecurity Baselines for Electric Distribution Systems and Distributed Energy Resources – United States Department of Energy – January 2025. The five-year US requirement is an exposure-reduction programme with operationally measurable outcomes: no directly internet-accessible PLC administration; phishing-resistant authentication for remote access; unique credentials for industrial devices; centralised monitoring of external sessions; segmented and separately administered IT and OT identities; tested local control for essential processes; and coordinated federal-state support for small operators. Procurement policy should require controller vendors and integrators to support authenticated updates, configuration export, security logging and long-term vulnerability management. The United States should also treat exposed-device census data as operational intelligence: recurring discovery of the same product class or operator category should trigger direct notification, funded remediation and regulator visibility rather than another generic advisory.
European Union: harmonisation without false uniformity
European resilience depends on converting a broad legal architecture into consistent industrial outcomes across Member States. NIS2 establishes a common cybersecurity framework covering 18 critical sectors, requiring national strategies, risk-management measures, supply-chain security, incident reporting, supervision and enforcement — NIS2 Directive: securing network and information systems – European Commission – January 2023. The Critical Entities Resilience Directive complements NIS2 by requiring an all-hazards approach to prevention, resistance, absorption and recovery, including cyber incidents, sabotage, insider threats and cross-sector dependencies — Critical infrastructure resilience at EU level – European Commission – January 2026. The Cyber Solidarity Act, in force since 4 February 2025, adds cross-border detection, Cyber Hubs, an emergency mechanism and a European Cybersecurity Reserve of trusted incident-response providers — EU Cyber Solidarity Act – European Commission – June 2026. These instruments are strategically coherent, but implementation remains vulnerable to three gaps. The first is national heterogeneity: reporting thresholds, supervisory capacity, enforcement maturity and OT expertise vary. The second is cross-border invisibility: an incident may affect a small national operator while the underlying supplier or product exposure spans several Member States. The third is recovery scarcity: a simultaneous campaign could exceed the number of responders qualified to work safely on industrial control systems. The EU should therefore create a protected OT exposure registry connecting national CSIRTs, energy regulators, ENISA, transmission and distribution bodies without publishing exploitable detail. Italy, France and Germany should align plant-level evidence standards so controller changes, supplier-session records and operational consequences can be compared across jurisdictions. The European Cybersecurity Reserve should maintain explicitly OT-qualified teams, not only general enterprise responders. Cross-border exercises should test simultaneous compromise of common remote-access infrastructure, not merely isolated ransomware events.
| Resilience domain | UK mechanism | US mechanism | EU mechanism | Unresolved transatlantic gap |
|---|---|---|---|---|
| Regulatory baseline | NIS Regulations and proposed CSRB | Sectoral regulation and CPGs | NIS2 | Different scope and enforcement thresholds |
| Physical resilience | National CNI and all-hazards governance | Sector and state emergency frameworks | CER Directive | Cyber and physical exercises remain separated |
| OT technical guidance | NCSC CAF and OT principles | NIST SP 800-82, CISA and DOE baselines | ENISA and national authorities | No common minimum controller evidence standard |
| Supplier governance | Proposed critical-supplier designation | Procurement and sectoral requirements | NIS2 supply-chain measures | Aggregate downstream concentration is poorly measured |
| Incident surge capacity | NCSC-coordinated response ecosystem | Federal and private incident response | EU Cybersecurity Reserve | Scarcity of process-qualified responders |
| Cross-border warning | Allied intelligence and bilateral channels | CISA, FBI, DOE and allied exchanges | National and Cross-Border Cyber Hubs | Sharing speed and classification barriers |
Engineering resilience rather than perimeter security
The most important strategic shift is from preventing every intrusion to preserving a safe physical function when digital trust fails. NIST defines OT as programmable systems and devices that monitor or directly change physical processes and emphasises that cybersecurity must respect their distinctive performance, reliability and safety requirements — Guide to Operational Technology Security, NIST Special Publication 800-82 Revision 3 – National Institute of Standards and Technology – September 2023. The US Department of Energy’s Cyber-Informed Engineering strategy places cybersecurity at the foundation of energy-system design rather than adding it after deployment — Cyber-Informed Engineering – United States Department of Energy – June 2022. Applied across the UK, United States and Europe, this means eliminating single digital commands capable of producing intolerable physical consequences; retaining independent protection and safety functions; designing local control that survives central identity or cloud failure; constraining command rates and ranges; verifying process state through independent sensors; and enabling rapid restoration to a cryptographically or procedurally validated configuration. Security controls must be assessed against physical loss scenarios. A firewall rule matters because it prevents unauthorised access to a turbine-control network; an immutable baseline matters because it proves that protection logic is unchanged; recorded vendor access matters because it reconstructs command provenance; and manual operation matters because it converts a cyber crisis from service loss into a managed degradation. Investment should be prioritised by consequence-adjusted reach: the number of people, megawatts, treatment capacity or dependent services placed at risk by one compromised trust relationship. This approach also reduces geopolitical leverage. If an attacker can obtain access but cannot generate a sustained or unsafe outcome, the strategic value of the campaign falls. Resilience therefore functions simultaneously as safety engineering, economic risk reduction and deterrence by denial.
Early-warning architecture and common intelligence requirements
A transatlantic warning system should fuse five classes of data without centralising sensitive industrial configurations. Layer one is external exposure intelligence: internet-reachable OT devices, remote-access services, vulnerable edge appliances and certificates. Layer two is identity intelligence: password spraying, impossible travel, token misuse, dormant supplier accounts and abnormal privileged access. Layer three is operational-network telemetry: unexpected protocol relationships, new engineering stations, controller sessions, unauthorised firmware transfers and configuration deviations. Layer four is process telemetry: commands inconsistent with production plans, alarm suppression, sensor disagreement and abnormal actuator sequences. Layer five is adversary context: infrastructure reuse, malware artefacts, access-market activity, geopolitical triggers and intelligence reporting. The fusion engine should issue graded warnings rather than binary alerts. W₁ indicates exposed but unexploited infrastructure; W₂ indicates active reconnaissance or credential pressure; W₃ indicates confirmed enterprise access with a possible OT path; W₄ indicates interaction with an operational asset; and W₅ indicates process or safety consequences. Cross-border sharing should accelerate at W₃ because the same supplier or product may expose multiple jurisdictions before physical effects occur. The EU Cybersecurity Alert System is designed to connect national and cross-border Cyber Hubs using advanced technology and data analytics; its value will depend on whether Member States contribute sufficiently specific and timely operational indicators. The UK should remain technically interoperable with this system despite being outside the Union, while the United States should map CISA and sectoral alert categories to comparable thresholds. Shared intelligence should identify affected product classes and access mechanisms without publishing facility-specific topology. A common evidence schema—timestamp, identity, connection, asset class, command type, process consequence and confidence—would substantially improve Bayesian updating and reduce duplication during a fast-moving campaign.
Strategic indicators and decision thresholds
Between 2026 and 2031, policymakers should track movement from opportunistic targeting toward a prepared campaign through a set of observable thresholds. The first is concentration: repeated Iranian reconnaissance against the same vendor, operator class or energy subsector. The second is persistence: access maintained without immediate monetisation or publicity, indicating possible pre-positioning. The third is engineering collection: theft of diagrams, protection settings, controller projects, maintenance manuals or supplier documentation. The fourth is synchronisation: intrusion activity aligned across multiple countries or timed to military and diplomatic events. The fifth is consequence testing: attackers issue limited commands, alter displays or interrupt small sites to measure response without creating major damage. The sixth is supplier convergence: several victims share a maintainer, remote-access platform or managed-service provider. Crossing any three thresholds should trigger a coordinated UK–US–EU campaign assessment; crossing four should activate protected operator notifications, intensified monitoring and restriction of non-essential remote connectivity; evidence of altered safety or protection logic should trigger the highest response tier. The escalation framework must distinguish reversible service disruption from attacks threatening life or causing physical destruction, but governments should not wait for casualties before imposing costs. Available tools include technical disruption, infrastructure seizure, criminal charges, sanctions, diplomatic attribution, intelligence exposure and allied defensive operations. The resilience objective is measurable: by 2031, every high-impact energy operator should be capable of identifying all external OT connections, revoking every supplier session centrally, validating critical controller logic, operating essential functions locally and restoring from a known-good state within an established maximum tolerable outage. Anything less leaves geopolitical deterrence dependent on an adversary’s restraint.
Consolidated five-year judgments
The baseline judgment is that Iran-linked actors will almost certainly continue targeting Western critical infrastructure through 2031, while the probability of sophisticated, destructive engineering remains materially lower than the probability of credential-based or exposed-device disruption. The most likely high-impact event is not a nationwide blackout but a coordinated campaign against several smaller operators, suppliers or operational dependencies, producing multi-day local outages, precautionary shutdowns and substantial uncertainty about system integrity. The highest-risk pathway is a common supplier or remote-access platform that gives one operator access to several facilities across jurisdictions. The most dangerous low-probability pathway is compromise of protection or safety logic producing equipment damage or casualties. The UK’s principal vulnerability is uneven implementation across operators and suppliers; the US vulnerability is the long tail of small and distributed entities; the EU vulnerability is heterogeneous national enforcement and cross-border coordination. The common remedy is not simply increased cybersecurity expenditure but redirection toward OT-specific evidence, recovery and consequence control. Under the modeled resilience programme, the five-year probability of at least one material Iran-linked transatlantic OT service interruption falls from 46% to 27%, coordinated multi-site disruption declines from 8% to 3%, and median recovery falls below two days. The residual risk cannot be eliminated because geopolitical activation, unknown vulnerabilities, insider access and supplier concentration remain. It can, however, be converted from a potentially systemic crisis into bounded operational degradation. The strategic test for 2031 is therefore whether Western operators can lose enterprise systems, external communications or a trusted supplier without losing safe command of the physical process. If they can, Iranian access ceases to be equivalent to Iranian leverage.





















