A cyber attack reportedly forced a small British power generator offline for four days in July. The incident did not put the wider UK energy system at risk, according to the government, but it offers a useful warning for smaller firms: cyber disruption does not have to hit a household name to stop real-world operations.
For SME owners, the lesson is less about the identity of the attackers and more about operational resilience. A compromised account, remote-access tool or supplier connection can interrupt production, payments, bookings or deliveries just as effectively as a physical fault.
What happened?
The BBC reported that a small-scale power generator was shut down during a cyber attack last month. The Department for Energy Security and Net Zero said there was no risk to the wider energy system and has contacted power companies about the threat of cyber attacks.
The affected site has not been identified for security reasons. The BBC, citing the Daily Telegraph, said the shutdown lasted four days and reported that the attackers were affiliated with the Iranian regime. The government and the National Cyber Security Centre have not provided further details about the site or confirmed that attribution publicly.
That distinction matters. Businesses should avoid drawing conclusions from unconfirmed details, while still treating the operational impact as a prompt to review their own defences.
Why this matters to SMEs
Small businesses may assume that state-linked attackers and critical infrastructure are separate from their day-to-day risks. In practice, many of the controls that reduce sophisticated threats also protect against common ransomware, phishing and account takeover attempts.
Smaller firms can also be exposed through supply chains. A company may hold access credentials for a larger customer, manage connected equipment, provide maintenance services or rely on one software provider for essential work. An attacker does not need to target the biggest organisation directly if a smaller partner offers an easier route.
The four-day disruption reported in this incident is a useful planning scenario. Owners should ask how the business would take orders, contact customers, pay staff and recover data if a core system were unavailable for several working days. The same operational thinking applies to banking outages and payment disruption; our earlier guide on what small businesses should do during a banking app glitch covers related continuity steps.
A practical cyber resilience checklist
The National Cyber Security Centre says its Cyber Action Toolkit is a good starting point for smaller organisations. Its wider guidance stresses that security is part of organisational resilience, not merely an IT task. SME owners can begin with six checks:
- Protect important accounts. Turn on multi-factor authentication for email, cloud administration, finance and remote-access accounts. Remove access promptly when somebody leaves.
- Keep systems current. Apply security updates to computers, phones, routers, servers and internet-connected operational equipment. Replace products that no longer receive updates.
- Test backups. Keep backups separate from the main network and confirm that files can actually be restored. A backup that has never been tested is only an assumption.
- Limit remote access. Review which suppliers and employees can connect from outside the workplace. Close unused accounts, restrict administrator privileges and record who owns each connection.
- Plan for manual workarounds. Decide how the firm will communicate, record orders and serve priority customers when a core platform is unavailable.
- Write down incident contacts. Keep current details for the IT provider, cyber insurer, bank and key suppliers somewhere accessible even if company email is down.
Questions to ask suppliers
Businesses that rely on managed IT, cloud software or connected machinery should ask providers how they protect privileged access, notify customers of incidents and support recovery. Contracts should make responsibilities clear, but owners also need a usable response plan rather than relying on contractual wording after disruption begins.
Ask when recovery was last tested and how long it would take to restore the service that matters most to your business. If a provider cannot give a clear answer, treat that as a continuity risk to manage.
What to do now
Start with one 30-minute review this week: identify the three digital systems without which the business could not trade for a day. Check account protection, backups, supplier access and the fallback process for each. Then give one person responsibility for closing the gaps and retesting them.
The UK power incident did not threaten national energy supplies, but it shows how a cyber event can stop physical operations. Small firms do not need a large security department to respond to that lesson. They do need clear ownership, basic controls and a recovery plan that works when normal systems do not.
