Critical Infrastructure Is Becoming a Disruption Target

State-linked cyber activity against power and water systems signals an operational-continuity risk for any organisation with physical operations or utility dependencies.

What changed

A cyber-attack attributed to Iranian state-sponsored actors shut down a UK power plant, according to Infosecurity Magazine. The reporting framed the incident as a significant escalation in hostile activity against Western critical national infrastructure, with weaknesses exposed in operational technology and industrial control systems.

The business signal is not limited to one plant, one country, or one sector. It is that state-linked actors are moving beyond espionage and data theft into deliberate disruption of civilian physical infrastructure. That changes the risk conversation for senior leaders. Any organisation with physical operations, or a dependency on utilities and infrastructure it does not control, now has an operational-continuity exposure that belongs in board-level scenario planning.

This is not just a technical control failure. OT and ICS environments run physical processes. When those systems are exposed, poorly segmented, or managed below the security standard applied to corporate IT, the consequence is not only data loss. It can be interrupted production, constrained service delivery, safety concerns, regulatory pressure, and loss of confidence in operational resilience.

The pattern is wider than power

The UK power plant attack should be read alongside CISA’s confirmation that, during July 2026, more than 100 US water and wastewater systems were targeted by suspected Iran-backed hackers, as reported by TechCrunch. That activity exploited internet-facing systems and weak security controls, leading to unauthorised access and potential disruption.

The sectors differ, but the exposed layer is similar: operational systems that are connected, reachable, or dependent on digital access paths that may not have been designed for sustained hostile pressure from well-resourced actors. Power and water are also dependency sectors. A disruption there can create second-order consequences for organisations that were never the direct target.

That is why this development matters across manufacturing, healthcare, transport, logistics, food, energy, finance, retail, and public services. Many organisations do not operate critical infrastructure themselves, but nearly all depend on it. If power, water, wastewater, or other physical services are disrupted, business continuity plans that focus mainly on cloud outages, ransomware recovery, or office availability may be too narrow.

The exposure

The exposed risk is a gap between physical operational dependency and cyber governance. Corporate IT security has matured under pressure from ransomware, data breach regulation, and cloud risk. OT and internet-facing operational systems have not always moved at the same pace.

The public reporting points to weaknesses in OT and ICS in the UK case, and to internet-facing systems and weak security controls in the US water and wastewater activity. Those are not niche technical details. They describe a management problem: systems that affect physical operations may sit outside normal security visibility, asset management, patching discipline, logging, segmentation, and incident response assumptions.

Senior leaders should also avoid treating this as a problem only for utilities. A company with plants, warehouses, depots, vehicles, building systems, industrial equipment, or outsourced physical operations may carry similar exposure. A company without those assets may still depend on providers that do.

Management questions

Boards and executive teams should ask whether operational disruption from state-linked cyber activity is included in continuity planning, not only whether cyber teams are tracking the threat. The useful question is not whether the organisation is the likely target. It is whether disruption of operational systems, or disruption of dependent infrastructure, would create a material business interruption.

Management should consider where OT, ICS, and internet-facing operational systems exist, who owns their security, how they are separated from corporate IT, and whether incident response plans account for physical process interruption. They should also test whether supplier and utility dependencies are mapped in a way that supports real decisions during disruption.

The signal from these incidents is straightforward: civilian infrastructure is now part of the disruption surface for state-linked cyber activity. Organisations that still treat operational technology as a specialist engineering domain, separate from enterprise risk, may be underestimating where business continuity can fail.