Conflicts in Ukraine and the Middle East, as well as growing tensions with Russia and China, are having direct consequences for critical national infrastructure (CNI) security worldwide, including UK operators of essential services.

They are driving measurable increases in cyber threats targeting the industrial systems that keep energy flowing, water clean, and manufacturing operational.

Attackers are no longer constrained by organisational silos. Hybrid threats – whether state-backed or criminal – are combining multiple attack vectors to achieve their objectives, actively exploiting the gaps between them. State-backed groups increasingly operate through intermediaries such as criminal networks to obscure their involvement, while those with purely criminal intent are adopting techniques traditionally associated with nation states, further blurring the lines.

Rising number of attacks on outdated technology

Over three-quarters of UK utilities organisations were hit by cyber-attacks involving outdated software or unavailable patches on legacy equipment in the last year – making legacy system attacks the most common cyber incident currently facing the sector. Critical operational technology can be difficult to update, patch, or take offline, leaving utilities more exposed than standard IT environments. Advances in artificial intelligence (AI) are likely to accelerate the threat further, exposing cyber flaws in national infrastructure, with the coming years likely to be when such a threat crystallises. Adversaries are already leveraging AI to increase the speed and volume of their campaigns, automating reconnaissance, adapting malware, and scaling social engineering attacks.

With 81% of architecture reviews revealing poor IT-OT segmentation, operators should be assessing whether an adversary with IT access has a viable path into their OT systems. Less than 10% of OT networks are monitored globally – and what isn't seen isn't detected. Despite increased investment in security, UK businesses operating critical infrastructure are becoming more exposed to disruption, driven by threats that evolve quietly across domains and below traditional response thresholds.

AI has changed the rules of the game

The latest AI tools, such as Anthropic’s Claude Mythos, have changed the rules of offensive security by creating a paradigm shift in the economics of a cyber-attack. AI has lowered the cost and skill barrier so that more threat actors can find and exploit vulnerabilities faster than organisations can patch them. This means that the fundamentals of cyber security, including identity, segmentation, multi-factor authentication (MFA), patch discipline, and zero-trust are now even more important. This extends along the entire supply chain in every sector. 

The consequences of a significant cyber-attack are rarely confined to operational disruption and recovery costs. Where personal data is involved, organisations also face a number of legal risks. 

Essential safeguarding rules

Under the UK GDPR, organisations must implement appropriate technical and organisational measures to safeguard the personal data they process, which includes protection against cyber-attacks.  

Where a cyber-attack exposes weaknesses in an organisation's security posture, the UK Information Commissioner's Office (ICO) may investigate whether those measures were appropriate. Regulatory scrutiny tends to focus on whether reasonable steps were taken beforehand to prevent or mitigate the impact of a potential attack. Reasonable steps generally include robust security governance, risk assessments, employee training, incident response planning, and proportionate technical controls.

Water company fined after data theft

In May this year, the ICO fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 following a cyber-attack that resulted in the exfiltration and publication of personal data relating to over 630,000 individuals. The ICO found that a phishing email enabled an attacker to gain access to the organisation's network and remain undetected for almost 20 months. The ICO identified deficiencies in access controls, security monitoring, use of obsolete software and vulnerability management, concluding that the organisation had failed to implement appropriate technical and organisational measures.

Litigation risk

In addition to regulatory enforcement, significant personal data breaches can result in claims for compensation from affected data subjects. For organisations with large customer bases, this could mean defending a large-scale group litigation. Claimant law firms and litigation funders are increasingly pursuing collective actions arising from cyber incidents and data breaches. Such claims can run for years and prove costly to defend or settle. 

New Cyber Security and Resilience Bill for the UK 

Organisations operating within critical national infrastructure and other essential sectors should also be monitoring the progress of the Cyber Security and Resilience Bill. The proposed legislation will reform and expand the existing Network and Information Systems (NIS) regime, strengthening cyber security and incident reporting obligations for organisations providing essential services such as energy, transport, health, drinking water, and digital infrastructure. 

As the rules around cyber security continue to evolve, organisations need to do more than meet compliance requirements. They need confidence that they can identify risks, respond effectively to incidents and keep critical services running when under pressure. 

This evolving technical and legal landscape serves as a reminder that cyber security is no longer solely an IT issue. It is a board-level governance issue which presents serious operational and legal risk.  

How we can help

For organisations looking to strengthen cyber resilience, the focus must be on understanding risk, improving preparedness, and ensuring security controls can withstand both evolving threats and growing regulatory scrutiny. Quorum Cyber and Burness Paull help organisations build and maintain that resilience, as well as respond to incidents effectively where they arise.

Click here to contact our cyber security & data protection lawyers. 

This article has been written by Rebecca Roberts, director in the cyber security & data protection team at Burness Paull, and Quorum Cyber. 

Written by

Related News, Insights & Events

Error.

No results.

Law Lab Yt

Webinar recording: Employment law lab - July 2026

11/08/2026

Listen to our bi-monthly employment webinar. Your one-stop for all things employment law-related.

Read more
AI Perspectives On Pitfalls And Possibilities For Pension Schemes Final

AI: perspectives on pitfalls and possibilities for pension schemes

10/08/2026

This blog explores how to implement appropriate AI governance into pension schemes.

Read more
Getting Your Data Ducks In A Row

Getting your data ducks in a row: putting the Data (Use and Access) Act 2025 into practice for pension schemes

09/06/2026

In this blog, we consider how The Data (Use and Access) Act 2025 (the “DUAA”) raises the bar for how pension trustees’ role as data controllers must be performed.

Read more

Want to hear more from us?

Subscribe here Subscribe here