A small generator shutdown is a large warning for UK SMEs
Reports that a small UK power generator was shut down following a cyberattack reportedly linked to Iran should not be viewed solely as a critical-national-infrastructure story. It is also a practical warning for every UK small and medium-sized enterprise that depends on electricity, cloud platforms, logistics, card payments, outsourced IT or a small group of suppliers.
The incident matters precisely because the affected organisation was described as small. Cyber risk is not restricted to household-name utilities, banks or government departments. Smaller operators can be attractive targets because they may have lean IT teams, older operational technology (OT), limited monitoring, and little capacity to keep services running when one critical system is taken offline.
For SMEs, the central lesson is not that every business is likely to be directly targeted by a state-linked actor. It is that a disruptive attack on one organisation can rapidly become a trading, contractual and cash-flow problem for many others. A power interruption can stop production, spoil temperature-sensitive stock, prevent access to premises, disrupt online fulfilment, interrupt customer support and create missed delivery commitments. Cyber resilience therefore needs to extend beyond company laptops and email accounts.
Why the alleged link changes the risk conversation
Attribution in cyber incidents is difficult and often develops over time. The reported connection to Iran should be treated as an allegation in the reporting, rather than as a final technical or legal conclusion. That distinction matters, particularly when considering insurance. A business should not make coverage assumptions from headlines before its insurer, broker and legal advisers have reviewed the facts and policy wording.
However, the possibility of a geopolitically motivated attack does change the questions directors should ask. Criminal ransomware gangs commonly seek payment. State-aligned or politically motivated groups may prioritise disruption, espionage, reputational harm or access to strategically valuable networks. Their targets may include energy, transport, telecommunications, manufacturing and the suppliers that support them.
An SME does not have to operate a power station to be affected. An engineering firm maintaining industrial equipment, an IT provider with remote access into operational networks, a payroll bureau, a facilities contractor or a manufacturer supplying critical components can all become an entry point or a downstream casualty. The UK's interconnected economy means a cyber incident at one node can cause physical consequences elsewhere.
Operational technology is not ordinary office IT
Many SMEs assume cyber security is mainly about phishing emails, antivirus software and staff passwords. Those controls remain essential, but companies operating machinery, refrigeration, building management systems, production lines, generators, pumps or remote monitoring equipment face an additional challenge: OT systems often prioritise continuous availability and safety.
A routine IT response, such as immediately isolating a network segment, can have real operational implications if it affects machinery or controls. Equally, leaving remote-access tools exposed can create a serious route into the business. Owners should know which systems can affect physical operations, who can access them remotely, whether multi-factor authentication (MFA) is enforced, and whether a safe manual process exists if digital controls fail.
The business interruption exposure most SMEs underestimate
A cyberattack does not need to encrypt your own files to damage your business. Consider a small food distributor whose cold storage is affected by a local power disruption, an online retailer unable to dispatch parcels because its warehouse system is unavailable, or a dental practice unable to access patient systems and appointment records. Lost revenue is only part of the cost.
Businesses may also face overtime, alternative premises, emergency equipment hire, spoiled inventory, customer refunds, contractual penalties, forensic investigation, legal advice, public relations support and notification costs where personal data is involved. For a small business with tight margins, a few days of interrupted trading may be more dangerous than the initial technical incident.
This is where cyber insurance can be valuable, but it must be assessed realistically. Policies vary substantially. First-party cyber cover may help with incident response, data restoration, cyber business interruption and, in some cases, dependent business interruption caused by a specified supplier's cyber event. Property or business interruption policies may respond differently where the trigger is a physical power outage rather than an attack on the policyholder's own systems.
Check the gap between a cyber event and a utility outage
A key practical issue is contingent or dependent business interruption. Ask whether your policy responds when a named or unnamed supplier, cloud provider, managed service provider, payment processor or utility suffers a cyber incident. Then ask how the policy defines a supplier, what waiting period applies, whether there is a sub-limit, and whether the loss must result from a security failure rather than a wider outage.
The most difficult area can be war, hostile acts and cyber-operation exclusions. Insurers have increasingly refined wording after major global cyber incidents. Cover may be restricted where an event is attributed to a state or forms part of a war-like cyber operation. Wording, evidential requirements and the applicable law all matter. This is not a reason to assume cyber insurance is pointless; it is a reason to compare policies carefully and obtain specialist advice before a claim occurs.
What UK SMEs should do this week
A credible response does not require a corporate-sized security budget. It requires prioritising the controls that reduce both likelihood and downtime.
1. Map critical dependencies
List the services without which you cannot trade for 24 hours: electricity, internet connectivity, cloud email, accounting, e-commerce, phones, card payments, warehouse systems, machinery, key suppliers and outsourced IT. For each, identify an owner, a fallback process and the maximum tolerable outage.
2. Secure remote access and privileged accounts
Remove dormant accounts, enforce MFA for email, VPNs, cloud administration and remote-support tools, and apply least-privilege access. If suppliers remotely maintain equipment, document exactly what they can reach, when, and how their access is monitored.
3. Test recovery, not just backups
Keep backups that are segregated from the main network and test restoring critical files and systems. A backup that cannot be restored quickly is not a business continuity solution. For OT or operational processes, document safe shutdown and manual fallback procedures with relevant engineers.
4. Prepare an incident decision team
Nominate who can authorise system isolation, customer communications, insurer notification and emergency spending. Keep the broker, insurer incident hotline, IT provider, solicitor and key supplier contacts available offline. Early notification may be a policy condition and can unlock access to approved forensic and legal specialists.
5. Review insurance before renewal, not after an outage
Request a plain-English explanation of cyber business interruption, dependent business interruption, system failure cover, waiting periods, exclusions and sub-limits. Ensure the declared turnover, dependency on digital systems and security controls accurately reflect the business. Misstating controls such as MFA or backups can complicate a claim.
Resilience is also a commercial advantage
Customers and larger supply-chain partners increasingly ask suppliers how they manage cyber risk. A documented incident plan, tested backups, MFA and appropriate insurance can help an SME meet tender requirements and reassure clients. More importantly, these measures improve the odds of continuing to trade when a supplier, utility or attacker creates disruption.
The reported generator shutdown demonstrates that cyber security now has operational and economic consequences, not simply IT consequences. UK SME owners should treat it as a prompt to identify their dependencies, rehearse their response and make sure their insurance is designed for the way their business actually operates.
FAQ
Does cyber insurance cover losses from a power cut caused by a cyberattack?
It may, but it is not automatic. Cover depends on whether the outage affected your own systems or a third-party utility, the business interruption wording, applicable waiting periods and policy exclusions. Ask specifically about utility-service and dependent business interruption cover.
Can a small business be targeted by a state-linked cyber group?
Yes. A small business may be targeted directly for access, intelligence or disruption, or indirectly because it supplies a larger organisation or relies on affected infrastructure. Size alone is not a reliable defence.
What is the most important cyber control for an SME?
There is no single complete control, but MFA for all critical accounts, secure and tested backups, prompt patching, restricted administrator access and staff phishing awareness provide a strong baseline. Businesses with operational technology must also secure and monitor remote access to those systems.
Should we wait for cyber insurance before improving security?
No. Insurance supports recovery but does not replace prevention or continuity planning. Strong controls can reduce disruption, improve insurability and make it easier to satisfy insurer conditions.
Source: CNBC — Sun, 23 Aug 2026 11:35:52 GMT