The UK government will develop baseline cyber resilience requirements for every Ofgem licensee in the downstream gas and electricity sector, and separately review whether the Network and Information Systems (NIS) Regulations 2018 still apply to the right companies. The plan follows a consultation that drew 49 responses, most of them in favor of stronger cyber oversight for the sector in England, Scotland and Wales.
Two work streams, not one
The baseline requirements are meant to set a consistent floor of cyber resilience across all Ofgem licensees, without duplicating or clashing with the cyber security obligations these companies already have. Ofgem will lead that work, alongside the Department of Energy Security and Net Zero (DESNZ) and the National Cyber Security Centre (NCSC). Separately, the government will keep working with Ofgem, the National Energy System Operator, the NCSC and the Department for Digital, Culture, Media and Sport (DCMS) to check whether the current NIS Regulations definitions and thresholds still fit an energy system that keeps changing.
A middle tier stays on hold
The consultation also asked about a tier of requirements sitting above the new baseline but below the NIS Regulations. Responses on that question were mixed, so the government will focus first on the baseline requirements and the NIS Regulations review. Once those are further along, it will assess how well they are working and decide whether the evidence supports adding a middle tier.
Why the review started
Ofgem and DESNZ opened the original consultation citing the shift toward Clean Power 2030 and a rising cyber security threat to the sector. Their starting proposal was to give every Ofgem licensee baseline cyber requirements, putting cyber resilience on every company's agenda, and to examine whether the NIS Regulations' scope should widen through a review of thresholds and which services count as essential in the downstream gas and electricity sector.
The response
The consultation drew 49 responses from Ofgem licensees, developers, industry bodies, think tanks and academics. Respondents broadly supported tighter cyber oversight of the sector, but wanted any new rules sized to risk and free of extra duplication or burden. The government calls the response a milestone toward the objectives in its cross-government energy cyber strategy.


