The UK’s energy network is undergoing one of the biggest transformations in its history. As operators modernise infrastructure to support the transition to net zero, they are also becoming more connected than ever before. Digital control systems, remote monitoring, predictive maintenance and greater data sharing are helping to improve efficiency, reliability and responsiveness across the network.
That connectivity brings enormous benefits. It also changes the nature of operational risk. For years, cyber security has largely been viewed through an IT lens. The emphasis has been on preventing attacks, detecting malicious activity and improving visibility across increasingly complex networks. Those capabilities remain important, but they no longer tell the whole story.
For organisations responsible for keeping the lights on and the gas flowing, the question is shifting from Can we see a cyber-attack? to Can we continue operating safely when one happens?
That may sound like a subtle distinction, but it represents a significant change in thinking. As operational technology becomes increasingly integrated with day-to-day engineering and operational processes, cyber resilience is becoming less about technology alone and more about how organisations manage their assets, people and decision-making under pressure.
Ultimately, resilience is not measured by how many alerts appear on a dashboard. It is measured by whether critical services continue to operate safely when systems are disrupted.
Engineering has always been about resilience
The energy sector understands resilience better than most industries. Infrastructure operators have always planned for equipment failure, severe weather, supply chain disruption and unexpected operational events. Assets are designed with redundancy, maintenance regimes are built around reliability, and emergency procedures are routinely tested because failure is not an option.
Cyber resilience deserves to be treated with the same discipline. Too often, organisations continue to measure cyber maturity using technical indicators such as the number of vulnerabilities patched, systems monitored or security alerts investigated. These metrics provide useful operational insight for security teams, but they reveal relatively little about how an organisation will perform when faced with a genuine operational disruption.
Customers, regulators and government are asking different questions.
Can essential services continue during an incident? How quickly can critical systems be restored? Do engineering and operations teams understand how to respond if digital systems become unavailable? Can decisions be made quickly without compromising safety?
These are operational questions rather than technical ones, and they increasingly define what good cyber resilience looks like.
This shift is reflected in the government’s Cyber Security and Resilience Bill, which aims to strengthen the resilience of essential services by updating the existing Network and Information Systems regime. While the legislation includes new reporting requirements and broader regulatory oversight, its wider significance is that it places greater emphasis on an organisation’s ability to prepare for, withstand and recover from disruption rather than simply demonstrate compliance with security controls.
That is an important distinction because compliance is a snapshot. Resilience is an ongoing capability.
Operational technology changes the conversation
One reason this shift matters is that operational technology is fundamentally different from traditional IT.
Business systems are primarily designed to process information. Operational technology controls physical processes. Electricity transmission, gas distribution and industrial control systems interact directly with assets that keep essential services running. Decisions made during a cyber incident can therefore have immediate consequences for safety, reliability and continuity of supply.
That risk is becoming more acute as artificial intelligence changes the pace at which vulnerabilities can be identified and exploited. Attackers are increasingly able to use AI-enabled tools to explore weaknesses, develop exploits and deploy them faster than many organisations can respond. For legacy industrial control systems, which were often designed for long operational lifecycles rather than today’s agile threat environment, the risk of compromise has never been higher.
That changes the role of cyber security.
In an office environment, disconnecting a compromised device is usually a straightforward decision. In an operational environment, isolating equipment at the wrong moment may introduce greater risk than leaving it connected while engineers implement a controlled response.
Technology can identify an anomaly. It cannot determine the safest operational decision.
Those decisions depend on engineering knowledge, operational experience and an understanding of how interconnected systems behave under pressure.
Cyber resilience therefore cannot sit solely within a security function. It has to become part of the wider engineering culture that already exists across the energy sector.
Building resilience into everyday operations
One of the clearest examples is remote access. Modern infrastructure depends on specialist engineers, equipment manufacturers and suppliers being able to support operational systems from different locations. Remote access reduces travel, speeds up maintenance and enables expertise to be deployed wherever it is needed. Without it, maintaining complex infrastructure would become slower, more expensive and less efficient.
The challenge is not remote access itself. The challenge is governing it effectively. Every connection into an operational environment should be understood, justified and proportionate to the task being carried out. Organisations should know who has access to critical systems, why that access is needed, how long it will remain active and how quickly it can be withdrawn if circumstances change. These sound like relatively simple governance questions, but they are often the difference between a manageable incident and one that escalates unnecessarily.
More broadly, resilience is shaped by hundreds of small operational decisions rather than a handful of major technology investments. Legacy supplier accounts that remain active after projects have finished, inconsistent engineering practices across multiple sites or temporary workarounds that quietly become permanent all create uncertainty about what an organisation actually controls.
The greatest risk is often not the sophisticated cyber-attack that captures headlines. It is the gap between what organisations believe they understand about their operational environment and what exists in practice.
Bringing disciplines together
Technology alone cannot close that gap. Cyber specialists understand emerging threats and defensive technologies. Engineers understand how physical assets behave under abnormal conditions. Operations teams understand the practical realities of maintaining continuity of supply. Each discipline brings a different perspective, yet they frequently work within separate reporting structures and measure success in different ways.
During a cyber incident, those distinctions quickly disappear. Effective responses depend on security, engineering and operations working from a shared understanding of operational priorities before disruption occurs. That means developing common playbooks, exercising together and ensuring that cyber risk is considered alongside safety, reliability and operational performance rather than as a separate technical issue.
This is increasingly becoming a board-level responsibility. Executive teams need confidence that resilience extends beyond technology procurement and into governance, operational planning and organisational culture. Cyber investment should be viewed in the same way as investment in asset reliability or safety: as a means of protecting essential services rather than simply reducing technical risk.
From confidence to proof
The energy sector has never relied on assumptions when it comes to physical resilience. Critical infrastructure is routinely inspected, maintained and tested because operators understand that capability has to be proven, not presumed.
Cyber resilience should follow the same principle. Across the industry, organisations are increasingly using representative operational environments to rehearse realistic cyber scenarios before they affect live systems. At Thales’ cyber resilience facility in Ebbw Vale, developed with partners from the energy sector, engineers, operators and cyber specialists can test how systems, processes and people respond together under realistic operating conditions. The objective is not to demonstrate technology. It is to identify weaknesses in decision making, coordination and recovery while the consequences remain manageable.
Exercises like these often reveal issues that would never appear in a risk register. Responsibilities may be unclear, communication between teams may slow decision making or recovery plans may prove difficult to execute under operational pressure. Discovering those weaknesses during a rehearsal is infinitely preferable to discovering them during a live incident affecting essential national infrastructure.
The lessons extend well beyond the energy sector. Manufacturers face many of the same challenges as production systems become increasingly connected, suppliers require secure remote access to equipment and operational technology becomes inseparable from day-to-day operations. The organisations that thrive will be those that treat cyber resilience as part of operational excellence rather than a standalone security programme.
The UK’s energy sector has made enormous progress in strengthening its cyber capabilities over the past decade. The next phase of maturity is not about deploying more tools or generating more data. It is about embedding resilience into the way organisations design, operate and maintain critical infrastructure.
Visibility will always matter. But the real measure of resilience is much simpler.
When disruption occurs, can the organisation continue operating safely, protect the services society depends upon and recover with confidence?
That is the question that will define the next generation of industrial resilience.
For more stories like this visit our Leadership channel


