This week, the government confirmed what had been suspected for weeks: a small UK power generation facility was knocked offline for four days in July after a cyberattack linked to Iran-nexus hackers. Officials say the impact was contained to the one site, with no wider disruption to the national grid, but the confirmation matters because it turns a three-week-old warning into a documented, real-world event.
Back on 3 August, the National Cyber Security Centre flagged an elevated, indirect cyber threat to UK organisations linked to the ongoing Middle East conflict, warning that collateral attacks on Western infrastructure and businesses were “almost certain” for anyone with regional exposure. This incident is the first confirmed case landing on UK soil since that advisory, and it’s a useful reminder of what “collateral” actually looks like in practice: a facility with no direct link to the conflict, taken offline for days, seemingly because it fell within the blast radius of a much bigger geopolitical fight.
Why this isn’t just an energy-sector story
The obvious reaction is “not my industry”, and for most SMEs that’s technically true. But the more useful question isn’t whether you’ll be directly targeted, it’s what happens to your business if a supplier, utility, or logistics partner you depend on gets taken offline for four days with no warning. Very few small businesses have mapped out which of their critical inputs, power, connectivity, a key supplier’s systems, sit on infrastructure they don’t control and can’t influence.
That dependency risk has been the theme of several stories this month, from third-party breaches at fulfilment and CRM vendors to this power site incident. The common thread isn’t that any one vendor was careless. It’s that modern businesses run on a chain of other people’s systems, and a four-day outage anywhere in that chain becomes your outage too, whether or not you were ever the target.
Four days without power or connectivity is enough to stall production, miss delivery windows, or lose a week’s worth of bookings for a lot of small businesses, even ones nowhere near the site itself. If your suppliers, logistics partner, or hosting provider sit on infrastructure you’ve never actually questioned, this is the kind of story worth using as the prompt to finally ask.
What’s actually worth doing about it
Write down what you’d do if a key utility or supplier went dark for four days. Not a formal disaster recovery document, just an honest answer to “what breaks first, and what do we do instead”. Most businesses have never actually written this down, which means the first time they think it through is during the outage itself.
Ask your critical suppliers what their own incident response looks like. A one-line email asking whether they have a business continuity plan and how they’d notify you of an outage costs nothing and tells you a lot about how seriously they take this.
Don’t confuse “not directly targeted” with “not affected”. The businesses hit hardest by incidents like this are rarely the ones the attacker was aiming at. If your revenue depends heavily on one utility connection, one supplier, or one platform with no fallback, that’s the gap worth closing first. If you want a structured view of where your own exposure sits, KeepSafe monitors for exactly this kind of third-party and infrastructure risk.
The takeaway
The NCSC’s warning three weeks ago wasn’t hypothetical, it just took until this week to have a confirmed, named incident attached to it. The lesson for most UK businesses isn’t about Iran specifically, it’s about knowing which pieces of infrastructure you quietly depend on, and having at least one answer ready for when one of them goes down.