Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • QinetiQ helps UK electricity sector prepare for cyber-attacks

Security

QinetiQ helps UK electricity sector prepare for cyber-attacks

QinetiQ (Lead Exercise Integrator), with strategic partner Inzpire, working in partnership with the National Cyber Security Centre (NCSC) and the Department for Business, Energy and Industrial Strategy (BEIS), has successfully completed the first ever series of UK sector-wide, cyber resilience exercises for the UK’s Critical National Infrastructure (CNI) Electrical Distribution organisations.


Courtesy QinetiQ

Cyber-attacks on individuals, commercial organisations, CNI and Government departments are increasingly common and constantly evolving, impacting on reputation, safety and share price.  Whether it is due to hacktivists, cyber criminals or nation states, the cyber threat is one which the UK is trying to stay one step ahead of, in an environment without traditional boundaries and where the threat cannot always been seen and the impact is not immediately obvious.

Advertisement
ODU RT

Future generations of board level executives, operational managers and technical engineers must be equipped with the knowledge, skills and confidence in cyber capabilities to maximise the opportunities that cyberspace creates and ensure resilience against the potential threats.  Cyber Security needs to form part of ‘business as usual’ activities, requiring education, training, operational planning & preparation and consideration throughout a capability or service lifecycle.  Only then will an organisation be able to increase the awareness, skills and knowledge of operations within cyberspace and better understand how to plan and respond to threats, and to synchronise operations in both the physical space and cyber domains.

QinetiQ’s expertise, with over 20 years of experience in providing training, exercising and operational assurance, has been applied to the UK’s electricity sector in a first of its kind series of sector wide cyber resilience exercises.  Exercising increases the confidence of individuals, teams, organisations and sectors in their ability to identify, protect, detect, respond and recover in order to sustain operations in the event of cyber-attack.

QinetiQ as the Lead Exercise Integrator, working in partnership with BEIS, NCSC and strategic partner Inzpire, facilitated a series of exercises collectively known as “PowerPlay”.  PowerPlay was specially designed and executed to prepare and equip the electricity sector’s engineering, operational and executive teams with the knowledge, skills and confidence in their processes and technologies to maximise the opportunities that cyberspace creates whilst ensuring resilience against the cyber threat.

The three exercises, started with an operational / command & control focused exercise to understand the role of individual organisations and how communications and decisions are made within the context of a much larger, coordinated sector wide incident.  Following this was a live-exercise focused on the 3rd party supply chain (without knowledge that they were being exercised) to examine how they would analyse and fuse multiple cyber-incidents to create common situational awareness and coordinate incident response.  The exercise series culminated in a large, distributed exercise involving over 170 participants at 13 different locations across the UK and abroad.  A complex set of inter-connected events played out based on attacks varying from spearphishing to more specialist attacks on both IT and Operational Technology networks.

Dr Richard Randel, Principal System Engineer Cyber, Information and Training at QinetiQ said: “The exercise demonstrates how QinetiQ can work with Government partners and the CNI sector, bringing together our capabilities and experience, to increase the resilience of the UK and recognise the importance of exercising as a means to assure operations.“

Advertisement
ODU RT

John, Scottish and Southern Electricity Networks said: “We would like to thank the NCSC for the invitation and our subsequent involvement in the sector-wide cyber security test. The challenge and results from the scenario exercising has been invaluable in applying improvements to our emergency planning and resilience processes, along with recognising the importance of cross industry support and alignment during such events.”

A participant said: “It provided us with a greater awareness of the cyber threats within the sector and how all business functions need to work together to respond to a cyber-incident.”

 

Advertisement
FIA2026 animated banner
MGI conducts first TigerShark flights with Auterion

Aerospace Defence Security

MGI conducts first TigerShark flights with Auterion

2 April 2026

MGI Engineering Ltd (MGI) has announced the successful first flights of its TigerShark uncrewed deep strike platform, in partnership with Auterion.

Logiq acquires Savient

Security

Logiq acquires Savient

1 April 2026

Logiq has acquired Savient Ltd, a technology and data specialist focused on delivery in highly regulated environments, strengthening its capability and further expanding its presence in the South-West.

SIA introduces changes for close protection operatives

Security

SIA introduces changes for close protection operatives

1 April 2026

Today, the Security Industry Authority (SIA) have introduced changes to training for those holding, or applying for, a close protection licence.

NCSC warns of messaging app targeting

Security

NCSC warns of messaging app targeting

1 April 2026

Alongside international partners, the National Cyber Security Centre (NCSC) has issued actions for individuals at risk of attacks against messaging apps, as a result of growing malicious activity from Russia-based actors using messaging apps - such as WhatsApp, Messenger and Signal - to target high-risk individuals.

Advertisement
ODU RT
LexisNexis Risk Solutions releases Cybercrime Report

Security

LexisNexis Risk Solutions releases Cybercrime Report

31 March 2026

LexisNexis Risk Solutions has released its latest Cybercrime Report which reveals rapid growth in synthetic identity fraud, bot-driven attacks and account takeover activity across global markets, whilst first-party fraud remains the most reported fraud type.

Getac launches CommandCore

Defence Security

Getac launches CommandCore

27 March 2026

Getac has announced the launch of its CommandCore rugged drone control solution.

Advertisement
ODU RT
Advertisement
Gulfstream banner