
By Anthony Upward | 3 min read
The Wire Nobody Owns
What Poland’s Power Grid Attack Should Teach Britain About OT Security. On 29 December 2025, at approximately 7:00 a.m., the industrial control systems of a combined heat and power plant supplying roughly 50,000 residents in Poland came under attack. A steam turbine and the water treatment system feeding it were shut down. Plant staff, midway through routine maintenance, initially assumed a contractor’s engineers had made an error and logged the event for information only. It was Poland’s national CERT, aware of a related incident three months earlier, that recognised the pattern and opened a full investigation.
Left to the plant’s own judgement, this incident does not get investigated at all.
That single fact, an unexplained failure nearly written off as routine, sits at the centre of everything wrong with how Britain currently regulates operational technology.
How the attack actually worked
CERT Polska’s published forensic account, released as a follow-up to its January 2026 report on a related incident affecting more than thirty renewable energy sites, reconstructs the intrusion in detail.
The entry point was a wind farm substation. A FortiGate device, serving as both firewall and VPN concentrator, exposed its VPN interface to the internet with no multi-factor authentication, only credentials configured on the device itself. From there, the attacker reached a cellular router, a Teltonika RUTX50, which connected to a private Access Point Network, a mobile network sold to industry as a secure, isolated way of linking remote sites back to a grid operator’s SCADA systems. The router’s administrative interface should never have been reachable from that network. It was, because no one had defined requirements for how its management access should be configured.
Logs recovered from the router show repeated successful SSH logins throughout December, and the attacker used SSH tunnelling to move from the wind farm onto the private APN itself. Once inside, they scanned for industrial protocols, S7, Modbus, CODESYS, and for VNC, HTTP and RDP. On 18 December they found what they needed, a WAGO PFC200 programmable controller at the CHP plant, with its web administration interface exposed to the APN and configured with default admin credentials. SSH, disabled by default on that interface, was somehow enabled, most likely through the same web interface, and used to tunnel directly into the plant’s operational network.
What followed was not a smash-and-grab. The attacker spent a week conducting reconnaissance, attempting and failing to access the plant’s firewall directly, then scanning the internal network instead. On 21 December, a Sunday, eight days before the disruptive act, they scanned systematically across the subnet, one scan beginning conspicuously at the IP address of the SCADA system itself, suggesting the target had already been identified during earlier reconnaissance. On 25 December, Christmas Day, they successfully connected to three separate Siemens PLCs, an S7-300, an S7-1200 and an S7-1500, using the S7 protocol. CERT Polska’s assessment is that this was reconnaissance of the controllers themselves, in preparation for what came four days later.
On 29 December, over roughly five hours, the attacker forced all three PLCs into STOP mode and locked them with a password to prevent recovery. The steam turbine and the water treatment system it depended on shut down. Plant operators began recovery around 7:30 a.m., while the attacker was still active in the network. Before finally leaving, the attacker damaged the WAGO controller by corrupting its partition table, an act of deliberate anti-forensics, then reset both the cellular router and the original FortiGate device to factory settings, destroying the logs that would otherwise have shown exactly how they got in.
CERT Polska’s own conclusion is worth quoting directly, this was, to their knowledge, the first observed real-world use of a private APN as a lateral movement path between two unrelated organisations. The security control became the route in.
The part that should worry a UK reader more than the technical detail
Every device involved in this attack had an owner. The wind farm operator owned its firewall. The distribution system operator owned the private APN. The CHP plant owned its controllers. Nobody owned the connection between them, the actual path the attacker walked from one organisation’s network into a completely unrelated company’s operational technology.
That is not a Polish peculiarity. It is how supply chain and third-party connectivity works across most of UK critical infrastructure. Operators know their direct suppliers. Almost nothing requires them to know, or to verify, what those suppliers connect to, or whether a route exists into their own operational network that nobody has mapped.
Where UK law actually stands
The UK’s principal cyber security law, the NIS Regulations 2018, covers four of Britain’s thirteen recognised critical national infrastructure sectors outright: energy, transport, water, and health. A further four, communications, civil nuclear, finance, and defence, sit outside NIS entirely but have another regulatory regime covering them, Ofcom and the Telecoms Security Act for communications, the Office for Nuclear Regulation for civil nuclear, the Bank of England, PRA and FCA for finance, and the Ministry of Defence’s own contractual framework for defence. That leaves five sectors, chemicals, emergency services, food, government, and space, with no cyber regulator, no statutory reporting duty, and no penalties for a serious failure, cyber or otherwise.
The Cyber Security and Resilience Bill, currently before the House of Lords and billed as this Parliament’s flagship cyber legislation, does not change that sector list. It adds new categories of regulated entity, data centres above 1 megawatt brought under Ofcom, managed service providers brought under the ICO, large load controllers above 300 megawatts brought under DESNZ and Ofgem, and a mechanism for regulators to designate individual critical suppliers one at a time. After Royal Assent, all nine of those sectors remain outside the law’s core coverage. Four entity types added. Zero sectors.
Europe, whose original directive the UK’s 2018 regulations implemented, has since moved on. NIS2, the EU’s successor directive, covers eighteen sectors. Four of Britain’s five uncovered sectors, chemicals, government, space, and food, sit inside it. Wastewater, which the UK excludes from NIS entirely, sits in NIS2’s highest-criticality annex. Britain is not diverging from Europe by considered choice. It has simply stood still while the comparator moved.
But adopting NIS2 wholesale would only close half the gap Poland exposed. NIS2 keeps a size threshold, broadly, medium enterprise and above, fifty staff or ten million euros in turnover, with narrower exceptions for specific critical activities. Most of the thirty-odd Polish sites compromised in the December 2025 incident would likely fall below a threshold of that kind. The lesson of that attack is not that thirty sites represent thirty times the risk of one, it’s that thirty sites built from an identical technical template represented, in practice, a single point of failure replicated thirty times over. A threshold measured site by site, however it is set, will never see that pattern. Fixing the sector list, which NIS2 does, and fixing the aggregation problem, which it does not, are two separate defects, and closing only the first leaves Britain exposed to exactly the failure mode Poland demonstrated.
The state threat this sits inside
None of this exists in a vacuum. In July 2026, NCSC and thirteen partner agencies across Australia, Canada, the Czech Republic, Denmark, Estonia, Finland, France, Italy, New Zealand, Poland, Sweden and the United States jointly published an advisory on Russian state-sponsored targeting of network infrastructure, warning that FSB-linked actors were exploiting default and weak SNMP community strings, the Cisco Smart Install feature, and end-of-life devices left in service, across the communications, defence, energy, financial services, government and healthcare sectors. NCSC’s own director of national resilience, Jonathon Ellison, described it as providing “decisive, actionable direction” for defenders. None of the techniques named are sophisticated. They are housekeeping failures, not zero-days, which is precisely why they are so widespread and so hard to eliminate through voluntary effort alone.
That same month, the UK and EU jointly and formally attributed the December 2025 attack on Poland’s energy sector to FSB Centre 16, the signals intelligence arm of Russia’s federal security service, also tracked under names including Turla, Energetic Bear and Static Tundra depending on the reporting body. Coordinated sanctions followed, targeting more than thirty individuals and entities. British officials called the attack “reckless” and “another example of the Russian state’s irresponsible attempts to sow chaos across Europe.” The EU’s foreign policy chief, Kaja Kallas, said the bloc “strongly condemned Russia’s behaviour and misuse of this cyber ecosystem, targeting public services and critical infrastructure.”
Put those two facts together and the shape of the problem becomes clear. A state actor with demonstrated intent and capability against European energy infrastructure is exploiting exactly the kind of unmanaged, unmapped connectivity that let the Poland attacker walk from a wind farm into an unrelated power plant. The techniques required to replicate that path, default credentials, exposed administrative interfaces, absent multi-factor authentication, are not exotic. They are common, and they are exactly what nine of Britain’s thirteen CNI sectors have no statutory obligation to defend against, report on, or even disclose.
What should change
The answer is not a new regulator, and it is not simply transplanting NIS2’s sector list into UK law, though that alone would help. Three narrower changes would close the specific gap Poland exposed.
First, operators of critical infrastructure need visibility into their suppliers at least two tiers deep, not merely who they contract with directly, but what those suppliers in turn depend on, and whether a genuine second source or failover exists if the first fails. A supplier register that stops at Tier 1 would not have caught the Poland attack, the wind farm and the CHP plant had no direct commercial relationship at all.
Second, suppliers need a statutory duty to notify the operators they serve at the same moment they notify a regulator, not after. Discovery currently depends on the notifying organisation choosing, unprompted, to tell everyone downstream who might be affected.
Third, and most importantly, the trigger for mandatory reporting needs to include unexplained operational failure, not only confirmed compromise. The Poland incident was initially logged as a contractor error. It became a national security investigation only because someone at CERT Polska recognised a pattern from unrelated prior activity. A reporting regime that waits for confirmation before it activates will always be one step behind an attacker who is, by Poland’s own account, patient enough to spend Christmas Day quietly reconnoitring three separate controllers before waiting four more days to act.
Every asset inside a British power station, water treatment works, or hospital has someone responsible for it. The connection between that asset and the next organisation down the chain, in Poland’s case, and very plausibly in Britain’s, usually does not. Until that changes, the next unexplained failure at a UK site below the threshold will look exactly like the one CERT Polska nearly filed away as routine maintenance.
Sources: CERT Polska, Follow-Up Analysis of the 29 December 2025 Energy Sector Incident; NCSC, “UK and Allies urge critical sectors to improve defences against Russian intelligence targeting,” 13 July 2026; The Record, “Russia’s FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions,” July 2026; The Register, “UK, EU officially pin Poland energy cyberattack on Russia.”



