A power plant incident is a warning beyond the energy sector
The report that a UK power plant was taken offline by a cyberattack should concern far more than electricity generators and operators of industrial control systems. For UK SMEs, its significance lies in the reminder that cyber risk is no longer confined to stolen customer databases, fraudulent invoices or inaccessible email accounts. A successful attack can interrupt a physical operation, affect suppliers and customers that have no direct connection to the initial victim, and create costs long before the technical investigation is complete.
The available headline reporting does not, by itself, establish the attack method, the identity of those responsible, the duration of the outage or the full operational consequences. Businesses should resist filling those gaps with assumptions. Nonetheless, an offline power facility demonstrates the kind of real-world disruption that cyber insurance, business continuity planning and supplier due diligence must address.
For a small manufacturer, food wholesaler, care provider, logistics firm, retailer or professional-services practice, the immediate question is not whether it operates a power plant. It is: what happens to our ability to trade if a cyber incident disables a supplier, a utility-dependent process or one of our own operational technologies?
Why cyber disruption can become an SME cash-flow crisis
Cyber incidents affecting operational environments differ from a typical office IT outage. In an office-only scenario, staff may temporarily use mobile phones, manual procedures or an alternative cloud platform. Where production, refrigeration, machinery, building access, dispatch, stock control or point-of-sale systems are affected, the disruption may stop revenue generation altogether.
A power-related disruption can have several knock-on effects for smaller firms:
- Interrupted production: Machinery cannot run, batches may be lost, and contracted delivery dates can be missed.
- Spoiled stock: Temperature-controlled goods, pharmaceuticals, hospitality stock and refrigerated inventory can become unusable.
- Lost trading hours: Shops, venues and service businesses may be unable to process payments, access bookings or serve customers.
- Supplier delays: A business may have electricity but still be unable to obtain materials, transport capacity or digital services from affected counterparties.
- Contractual exposure: Customers may seek service credits, compensation or alternative suppliers after repeated missed deadlines.
- Reputational damage: Clients often distinguish poorly between a business that was directly hacked and one that was simply unprepared for disruption.
These losses matter because most SMEs operate with tighter cash reserves than large corporates. A three-day interruption can create a chain of payroll pressure, delayed receivables, expedited shipping charges and customer churn. The eventual technical cause may be outside the SME's control, but its financial exposure is very real.
What the incident says about third-party and systemic cyber risk
Cyber insurance is often discussed as protection against an attack on the policyholder's own network. That remains essential, but it is only part of the picture. The power plant report brings attention to systemic and contingent risk: losses caused when an important external organisation suffers a cyber event.
Direct attacks versus contingent business interruption
A direct cyberattack occurs when an SME's own systems are compromised, such as ransomware encrypting a file server or criminals taking over Microsoft 365 accounts. Cover may help pay for incident response, legal advice, data restoration, customer notification, cyber extortion and lost income, subject to policy terms.
Contingent business interruption (CBI), sometimes described as dependent business interruption, concerns loss arising from a cyber event at a named or qualifying supplier, service provider or customer. This is particularly relevant where a business relies heavily on one cloud provider, managed IT company, payment processor, logistics partner, manufacturer or software platform.
However, SMEs should not assume that every external outage is insured. Policies may require a covered cyber event at a specifically defined dependent business. They may exclude or limit losses associated with utilities, telecommunications failures, widespread infrastructure events, physical damage, war, or systemic outages. Waiting periods, sub-limits and strict definitions of "computer system", "network interruption" and "supplier" can materially affect a claim.
Critical infrastructure is not just an enterprise issue
Many SMEs are indirectly dependent on critical national infrastructure every day. Electricity supports digital payments, cloud access, fuel pumps, warehousing, alarms and communications. Water, transport, telecoms and energy are interconnected. A cyber incident in one part of that chain can undermine operations elsewhere even when an SME's own cyber controls are strong.
This does not mean every business can or should insure every conceivable outage. It means insurance buying needs to follow a realistic assessment of concentration risk. If one failure could prevent trading for two or five days, that dependency deserves attention in both the continuity plan and the insurance placement.
How UK SMEs should review their cyber insurance now
A renewal conversation should focus on the business's actual dependency map rather than a generic request for "cyber cover". Owners and finance leaders should ask their broker or insurer for plain-English answers to the following points.
1. Is business interruption cover based on profits or turnover?
Check how loss is calculated. A policy may cover lost net profit, increased cost of working, or a combination. Understand the indemnity period: a 12-month period may sound generous, but a short waiting period and a low sub-limit can reduce the practical value of the cover. Keep current management accounts and sales records accessible away from the main network, as these will be important evidence following a claim.
2. Does the policy respond to supplier and cloud-provider failure?
Ask whether contingent business interruption is included, whether key suppliers must be named, and whether the cover applies to cloud, software-as-a-service and managed-service providers. Clarify whether outages caused by a utility or critical infrastructure provider are included, excluded or subject to a separate extension.
Do not accept a vague answer. Request the relevant policy wording and have the broker explain the trigger, exclusions, deductible or waiting period, and maximum payable amount.
3. Are operational technology and connected equipment declared?
Businesses increasingly use internet-connected CCTV, smart heating controls, point-of-sale terminals, warehouse scanners, access-control systems and remotely managed machinery. These can create an operational dependency even where the business does not consider itself technical. Tell the insurer about systems that could stop trading if compromised. Non-disclosure or an inaccurate proposal can complicate coverage later.
4. Can the business meet insurer security requirements?
Many cyber policies require proportionate controls, particularly multi-factor authentication (MFA), timely patching, protected backups, endpoint security and secure remote access. The objective is not merely satisfying a questionnaire. These controls reduce the likelihood and severity of an event, and evidence of their operation can matter during a claim.
Practical actions that do not depend on buying more insurance
Insurance transfers part of the financial risk; it does not restore electricity, rebuild a supplier relationship or make staff able to work during an outage. SMEs should pair cover with tested resilience measures.
First, identify the processes that must function within four hours, 24 hours and 72 hours. This should include taking payment, communicating with customers, payroll, dispatching orders, accessing essential records and safeguarding perishable goods.
Second, document key dependencies. List the main technology providers, energy-dependent processes, single-source suppliers and external systems that could halt trade. For each, identify a fallback: manual order capture, secondary internet connectivity, backup power where justified, alternative payment acceptance, alternate suppliers or a pre-agreed customer communication process.
Third, test the plan with a short tabletop exercise. A useful scenario is: "Our principal software provider and normal communications are unavailable from 10am on a Monday; how do we serve customers, authorise spending and protect data for the next 48 hours?" Include the owner, IT provider, operations lead, finance contact and a decision-maker for customer communications.
Finally, preserve evidence during any incident. Keep an incident timeline, screenshots, invoices for emergency costs, records of cancelled orders and correspondence with suppliers. Notify the insurer or broker through the policy's incident-response channel promptly; appointing an unapproved forensic firm or making public statements without advice can sometimes affect policy handling.
The strategic lesson: resilience is a commercial advantage
The UK power plant cyberattack report should not prompt alarmism, but it should prompt better questions. SME leaders cannot control the security of every infrastructure operator or supplier. They can understand where disruption would hurt, reduce avoidable single points of failure, and purchase insurance that reflects the remaining exposure.
Customers increasingly expect suppliers to remain dependable during disruption. A documented continuity plan, basic cyber hygiene, tested backups and appropriately structured cyber insurance are therefore not only defensive measures. They can support tender responses, reassure major clients and protect the business's ability to recover revenue after a serious incident.
FAQ
Would a standard UK business insurance policy cover losses from a cyberattack?
Usually not in a comprehensive way. Property and business-interruption policies may contain cyber exclusions or only limited cover. A dedicated cyber policy is designed to address items such as forensic response, data restoration, cyber extortion, privacy liability and cyber-related business interruption. Always check the specific wording rather than relying on the policy name.
Does cyber insurance cover an electricity outage caused by an attack on a power supplier?
It may not. Cover depends on whether the policy includes utility-service interruption or contingent business interruption, how a covered cyber event is defined, and any exclusions or sub-limits. An outage at a power provider may be treated differently from an attack on your own systems or a named technology supplier. Ask your broker to confirm the position in writing.
What is the most important cyber control for a small business?
There is no single complete control, but MFA on email, remote access, administrator accounts and cloud systems is among the highest-value measures. It should sit alongside tested offline or immutable backups, prompt patching, staff phishing awareness, least-privilege access and an incident-response contact list.
What should an SME do in the first hour of a suspected cyber incident?
Disconnect affected devices from the network where safe to do so, do not wipe systems or pay a ransom without professional advice, contact the insurer's incident-response line and your IT provider, preserve evidence, and begin a clear internal log of actions and timings. Early containment and prompt notification can substantially reduce loss.
Source: Computing UK — Mon, 24 Aug 2026 09:06:58 GMT