Russian cyber attacks on Western energy: ICS risk lessons for engineers
Reviewed by Tom Sullivan

First reported on New Civil Engineer
30 Second Briefing
Russian state-supported cyber attackers have been targeting Western government and commercial organisations, including operators in the electricity, oil and gas sectors, according to UK and allied intelligence agencies. The activity, attributed to groups linked to the Russian state, focuses on compromising operational and corporate IT networks that interface with SCADA and other industrial control systems. For infrastructure owners, this raises immediate questions over network segregation, patching of legacy control hardware and resilience of critical assets such as substations, compressor stations and pipeline control centres.
Technical Brief
- UK intelligence attribution enables operators to align defences with known Russian TTPs and IOC signatures.
- Joint advisory from UK and allied agencies implies cross-border incident reporting and coordinated response expectations.
- Focus on “government and commercial organisations” widens scope beyond licensed utilities to contractors and consultants.
- Energy-sector inclusion means substations, compressor stations and control centres must be treated as primary threat surfaces.
- State support suggests well-resourced, persistent campaigns, requiring continuous monitoring rather than one-off hardening projects.
- Engineering project data (design models, as-builts, asset registers) becomes a high‑value target for pre-positioning attacks.
- Safety cases for major infrastructure (e.g. nuclear, rail, pipelines) now need explicit cyber-physical interaction analysis.
Our Take
New Civil Engineer’s recent webinars on BIM, common data environments and digital handover highlight that UK infrastructure owners are already wrestling with fragmented data; state-backed cyber activity against energy operators in the United Kingdom will exploit exactly these weakly governed interfaces between design, construction and operations systems.
Within our 918 Infrastructure stories, only a subset of the 2462 safety-tagged pieces deal with cyber risk rather than physical safety, suggesting UK energy clients and contractors may still be underweight on OT/IT security compared with the attention given to structural and site hazards.
The Heathrow Airport innovation competition covered by New Civil Engineer shows major UK operators are open to early-career digital ideas; channelled towards cyber-resilience, similar programmes could rapidly seed practical defences such as anomaly detection on SCADA-linked assets in energy networks.
Prepared by collating external sources, AI-assisted tools, and Geomechanics.io’s proprietary mining database, then reviewed for technical accuracy & edited by our geotechnical team.


