14 December 2009 :
Parliamentary Question
Energy Supply: Cybercrime
Mark Pritchard: To ask the Secretary of State for Energy and Climate Change if he will consider the merits of bringing forward legislative proposals for a mandatory duty for energy utility companies to report breaches in their cyber-security to Ministers. [302669]
Mr. Kidney: Existing good practice is that a cyber security breach resulting in a loss or compromise of customers' details would be reported to the Office of the Information Commissioner. DECC works closely with other areas of Government (notably the Office of Cyber Security (OCS) and the Centre for the Protection of National Infrastructure (CPNI)) to identify and mitigate vulnerabilities in the national infrastructure that could be exploited by cyber threats, and to share best practice across the CNI.
If a cyber security breach impacts an energy utility company's operational capability leading to security of supply concerns, I have existing procedures (including my Department's emergency response plans) and existing powers (including, where appropriate, emergency powers under the Energy Act 1976) to intervene. |