Why digital architecture is key to Britain’s energy future
10 Sep 2026 - 4 minute read
Sign in to add this page to your favourites
Sign in or registerSign in or register to manage your favourites
Sign in or register
Following recent reports of a cyber hack shutting down a GB generation asset, questions about the cyber security of the energy network have been brewing. Purvi Kay, NESO’s newly appointed chief information security officer, discusses how she will use her experience from national security and defence to minimise the threat of cyber risks on the system and how this will in turn aid in the energy transition.
“Last week I joined the National Energy System Operator (NESO) after spending much of my career in national security and defence. The sector is new to me, but the challenge is a familiar one.
“The energy system is rapidly transforming and becoming more digitised. There is more interaction than ever between datasets and systems and deployment of artificial intelligence, helping the system to become cleaner and more flexible.
“For too long, cyber security has been seen as something best left to IT departments to quietly get on with. But the more our critical national infrastructure depends on digital technology, the less appropriate that approach is.
“Cyber resilience is key to operational resilience and is essential to protect the services that underpin our daily lives. Building that resilience into the energy system from the start is critical.
“This summer offered a reminder of why. A cyber attack reportedly forced a British electricity generator offline for four days. Customers did not lose power and the wider electricity system remained secure. Even so, we cannot understate the significance of the incident and the appeal to cyber criminals of targeting energy infrastructure.
“My experience in national security and defence taught me an important lesson: technology alone is not enough.
“I see best practice where organisations are willing to understand their risks in depth and test their assumptions. They prepare for disruption itself rather than assuming it can always be prevented. They make cyber resilience a shared responsibility.
“More than anything, they recognise that it is easier to build cyber resilience in from the start than it is to add in at a later date.
“At NESO, we’re embedding security by design in all activities by considering cyber risk from the earliest stages of new technology, services and ways of operating. We monitor and combat threats in real-time. We exercise for the scenarios we hope never happen. We prepare, so we can respond and recover, keeping essential services running if an incident ever occurs.
“No single organisation can tackle these challenges in isolation, and it is refreshing to see how well this is understood in the energy sector. NESO, government, Ofgem and national security partners have built a strong foundation together. Building these relationships ahead of an incident is much simpler than doing introductions after one has begun.
“We must also be willing to learn from other industries. Finance, communications, defence and aviation face sophisticated cyber threats as an everyday reality. Sharing what worked, what failed and how organisations recovered is sensitive but is central to strengthening resilience across sectors.
“Great Britain is already embracing a more digital energy system. Not doing so would preclude industry and consumers from future opportunities. But sector wide cyber resilience must evolve in parallel.
“Getting it right doesn’t mean slowing the energy transition down. If anything, it will provide the confidence to accelerate it.”