Cybersecurity Regulation Under Nis Regulations

Cybersecurity Regulation Under NIS Regulations

1. Introduction

Cybersecurity regulation under the NIS Regulations means the legal framework requiring operators of essential services to protect their network and information systems against cyber risks. In the UK, the Network and Information Systems Regulations 2018 (NIS Regulations) came into force on 10 May 2018. They were designed to improve the security and resilience of systems supporting essential services. (Legislation.gov.uk)

For the energy sector, cybersecurity is particularly important because electricity and gas services increasingly depend on digital systems such as SCADA, smart meters, digital substations, control centres, communication networks and automated systems.

2. Purpose of the NIS Regulations

The main objectives of the NIS regime are:

identifying operators of essential services;

requiring appropriate cybersecurity measures;

preventing and reducing the impact of cyber incidents;

requiring notification of significant incidents;

establishing regulatory supervision; and

providing enforcement mechanisms.

The basic principle is that cybersecurity should protect the continuity and resilience of essential services.

3. Operators of Essential Services

The Regulations establish the concept of an Operator of Essential Services (OES).

An organisation can fall within the regime where it provides a specified essential service and satisfies the applicable statutory requirements and thresholds. Competent authorities can also designate qualifying organisations as OESs. (Legislation.gov.uk)

In the electricity sector, Ofgem identifies relevant OES categories including:

transmission network operators;

distribution network operators;

system operators;

large electricity generators; and

interconnectors. (Ofgem)

This approach ensures that cybersecurity regulation focuses on organisations whose systems are important to essential energy services.

4. Security Duties Under Regulation 10

Regulation 10 is central to the NIS framework.

An OES must take appropriate and proportionate technical and organisational measures to manage risks to the security of the network and information systems on which its essential service relies. (Legislation.gov.uk)

The measures must:

address relevant cybersecurity risks;

reflect the state of technology;

provide security appropriate to the risk; and

prevent or minimise the impact of incidents.

Therefore, the NIS regime uses a risk-based approach rather than requiring identical security measures from every operator.

5. Prevention and Incident Impact

The NIS Regulations recognise that complete prevention of cyberattacks may not always be possible.

Therefore, OESs must also take measures to prevent and minimise the impact of incidents, with the objective of maintaining continuity of essential services. (Legislation.gov.uk)

This creates a broader resilience model:

Prevention → Detection → Response → Recovery

For electricity operators, this means cybersecurity planning should include both technical protection and business continuity.

6. Critical Energy Systems

Energy operators may rely on:

SCADA systems;

control centres;

digital substations;

protection systems;

remote terminal units;

telecommunications;

smart meters; and

automated control systems.

These systems should be protected through measures such as:

network segmentation;

strong authentication;

secure remote access;

access controls;

vulnerability management;

security monitoring;

secure backups; and

tested recovery arrangements.

The objective is to prevent a cyber incident from developing into a major disruption of electricity supply.

7. Incident Reporting

The NIS regime also creates duties concerning significant cybersecurity incidents.

Under the Regulations, an OES must notify the competent authority where an incident has a significant impact on the continuity of the essential service. (Legislation.gov.uk)

The regulatory framework considers factors such as:

the number of users affected;

the duration of the incident; and

the geographical extent of the impact.

This reporting system helps regulators understand threats and coordinate responses.

8. Role of Ofgem

For relevant electricity and downstream gas operators in Great Britain, Ofgem is a competent authority under the NIS framework.

Ofgem monitors how OESs comply with cybersecurity requirements and provides guidance on security and resilience. (Ofgem)

Ofgem's current guidance includes requirements and reporting arrangements designed to help OESs continually manage cybersecurity risks. Ofgem updated its downstream gas and electricity NIS guidance in January 2026, including self-assessment and annual-reporting materials. (Ofgem)

9. Governance and Management

Cybersecurity is not only a technical issue.

An energy company should have:

clear cybersecurity responsibilities;

senior-management oversight;

adequate resources;

regular risk assessments;

employee training;

incident-response plans;

supplier-security procedures; and

regular testing and auditing.

Good cybersecurity governance ensures that security responsibilities are incorporated into the organisation's overall management structure.

10. Supply-Chain Security

Energy infrastructure depends on third parties providing:

software;

telecommunications;

SCADA equipment;

cloud services;

maintenance;

security services; and

control-system technology.

A weakness in a supplier's system may therefore affect an energy operator.

Operators should assess supplier risks and control third-party access through contracts, authentication requirements, vulnerability-management arrangements and incident-reporting procedures.

11. Enforcement

The NIS Regulations are legally enforceable.

Ofgem states that it can penalise companies and issue enforcement notices for failures and contraventions under the NIS Regulations. (Ofgem)

Ofgem's enforcement framework is intended to provide a structured approach to addressing breaches and encouraging improvement in cybersecurity compliance. (Ofgem)

Thus, NIS cybersecurity requirements are not merely voluntary recommendations.

12. Relevant Case Laws

Direct reported cases specifically interpreting the NIS Regulations in the electricity sector remain limited. However, broader cybersecurity cases provide useful legal principles.

Warren v DSG Retail Ltd [2021] EWHC 2168 (QB)

The UK High Court considered a claim following a major cyberattack in which attackers accessed personal information. The Court examined whether particular legal causes of action created a duty to maintain data security. (BAILII)

The case is relevant because it shows that after a cyberattack, liability depends upon the specific legal duty applicable to the organisation. For an energy OES, statutory NIS duties are therefore particularly important.

Various Claimants v WM Morrison Supermarkets plc [2020] UKSC 12

The Supreme Court considered organisational responsibility for an employee's misuse of personal data.

The case is relevant to energy operators because employees and contractors may have access to sensitive systems. It demonstrates the importance of identifying the precise legal basis for organisational liability.

Digital Rights Ireland, Joined Cases C-293/12 and C-594/12

The Court of Justice considered extensive data retention and fundamental rights.

The judgment is useful for cybersecurity governance because security monitoring and information collection should remain connected to principles of necessity and proportionality, particularly where personal information is involved.

13. NIS and the Modern Cybersecurity Framework

The original NIS framework has also influenced the development of newer cybersecurity legislation.

At EU level, the NIS2 Directive 2022/2555 provides an updated and broader cybersecurity framework covering the energy sector, with requirements concerning risk management, incident handling, business continuity, supply chains and access control.

However, the UK NIS Regulations 2018 remain a separate UK legal framework. They should not be treated as identical to NIS2.

14. Importance for Energy Law

The NIS regime changes the traditional understanding of energy regulation.

Previously, energy regulation mainly focused on:

reliability;

pricing;

licensing;

competition;

consumer protection; and

physical infrastructure.

Cybersecurity now forms another important regulatory dimension:

Physical infrastructure + Digital infrastructure + Cyber resilience = Modern energy security.

15. Conclusion

Cybersecurity regulation under the NIS Regulations 2018 creates a structured legal framework for protecting essential services from cyber risks. Its central requirements are:

Identify OES → assess risks → implement proportionate security measures → prevent and minimise incidents → report significant incidents → maintain service continuity → comply with regulatory supervision.

Regulation 10 establishes the core security duties, while the wider NIS framework provides mechanisms for incident reporting and regulatory enforcement. (Legislation.gov.uk) Ofgem supervises relevant electricity and gas OESs and can take enforcement action for NIS failures. (Ofgem)

The cases Warren v DSG Retail, Morrisons and Digital Rights Ireland provide wider principles concerning cybersecurity responsibility, organisational liability and proportionality.

Ultimately, the NIS regime treats cybersecurity as part of essential-service governance. For the energy sector, this means protecting not only data and computer networks but also the digital systems that support the safe, reliable and continuous operation of electricity and gas infrastructure.

LEAVE A COMMENT