Whole energy cyber resilience requirements: reshaping cyber regulation in downstream gas and electricity

Imported from official source

Cybersecurity Classified by Officially

After considering the feedback we received to the Reshaping Cyber Regulation in Downstream Gas and Electricity (DGE) consultation, we intend to take forward proposals to review the applicability of the Network and Information Systems (NIS) Regulations 2018 in the DGE sector, and to develop baseline cyber resilience requirements for all Ofgem licensees.

We will tailor our approach to reflect stakeholder feedback, including the need for requirements to be appropriate and aligned with existing frameworks where possible.

On reviewing NIS applicability, we intend to continue working with Ofgem, the National Energy System Operator, the National Cyber Security Centre (NCSC) and the Department for Digital, Culture, Media and Sport (DCMS) to assess whether the current definitions and thresholds remain appropriate for the evolving energy system.

On baseline cyber resilience requirements, Ofgem will lead further development of detailed proposals, working with DESNZ and NCSC. We intend for these requirements to establish a consistent baseline level of cyber resilience across Ofgem licensees, while avoiding duplication and/or misalignment with any existing cyber security obligations.

On the need for intermediate requirements (above baseline but below NIS), responses were mixed. We intend to focus first on implementing baseline requirements and reviewing NIS applicability. Once these changes are established, government will review their effectiveness and consider whether there is evidence to support the need for further intermediate requirements.

This response is a key milestone towards strengthening cyber resilience across the DGE sector and meeting the objectives set out in the cross-government energy cyber strategy.

We received 49 responses to this consultation from a wide range of interested parties.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.gov.uk/government/consultations/whole-energy-cyber-resilience-requirements-reshaping-cyber-regulation-in-downstream-gas-and-electricity

Officially imported this from Ofgem’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Ofgem — imported from official source
Official source
https://www.gov.uk/government/organisations/ofgem.atom ATOM
Imported
September 18, 2026 11:34
Versions
1 recorded
Identity
https://www.gov.uk/government/consultations/whole-energy-cyber-resilience-requirements-...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.