VerbatimParliament, as it happens

Energy: Cybercrime

Asked by David ReedConservativeDepartment for Energy Security and Net ZeroTabled Answered 23 December 2025UIN 100250

The question

To ask the Secretary of State for Energy Security and Net Zero, whether his Department will require a cyber incident database with compulsory fixes to be created for attacks on the energy system.

Answered by Michael Shanks

The Department for Energy Security and Net Zero takes the security and resilience of UK energy infrastructure extremely seriously, including the cyber security of critical infrastructure. Maintaining a secure and reliable energy supply is a key priority. The Network and Information Systems (NIS) Regulations, impose strict incident-reporting obligations on critical energy operators.

The Government has recently introduced the Cyber Security and Resilience (Network and Information Systems) Bill. The Bill proposes expanding incident-reporting requirements, broadening the scope of reportable events, and enhancing the powers of regulators to oversee compliance and require remedial actions where necessary.

Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →

Open this question in Verbatim →

Every written question, searchable

155,000 questions tabled since the election, with the answer each department gave — and the ones still unanswered, with the clock running. Free to search.

Search written questions →Read on Verbatim