UK seeks supply chain security overhaul following Iran-linked cyber attack
The UK government is proposing major legislative changes to block companies from buying products from high-risk suppliers, after revelations that an Iran-linked cyberattack forced a small energy facility offline for four days in July.
Under amendments introduced to the Cyber Security and Resilience Bill, ministers could soon demand that businesses in critical sectors – including energy, healthcare, and telecommunications – implement phased removals of specific vendors or face bans on acquiring technology from them.
The security push comes in the wake of confirmation that hackers targeted a small-scale power generator, disrupting operations and underscoring vulnerabilities in the UK’s critical national infrastructure.
While government officials emphasized that the incident posed no wider risk to the national energy grid, the breach triggered urgent briefings with major energy executives.
Cyber Security Minister Baroness Liz Lloyd stated that the new veto powers will allow the government to act “before a threat materialises, not just after the damage is done.”
However, the proposed powers present major hurdles for green energy sectors heavily dependent on foreign manufacturing.
Analysts note that energy companies reliant on Chinese supply chains- which dominate global production of solar panels, batteries, and electric components – could face significantly higher costs and longer deployment timelines as they seek alternative vendors.
The updated bill also mandates that regulated entities report significant cyber incidents to the National Cyber Security Centre (NCSC) within 24 hours, followed by a comprehensive report within 72 hours, introducing strict financial penalties for non-compliance.
Discover more from Tech Digest
Subscribe to get the latest posts sent to your email.

