Zero-Trust Architecture Requirements For Utilities .
ZERO-TRUST ARCHITECTURE REQUIREMENTS FOR UTILITIES
Introduction
Zero-trust architecture is a cybersecurity model increasingly relevant to electricity, gas and other critical utilities because modern utility networks combine operational technology (OT), information technology (IT), smart meters, cloud services, remote access, distributed energy resources and third-party platforms. Under a zero-trust approach, access is not granted merely because a user or device is located inside the organisation’s network. Instead, every request is authenticated, authorised and assessed according to identity, device condition and other risk signals. The UK National Cyber Security Centre (NCSC) describes zero trust as an architecture in which inherent network trust is removed and the network is treated as potentially hostile.
UK Legal and Regulatory Framework
For utilities classified as Operators of Essential Services (OES), the principal cybersecurity framework remains the Network and Information Systems Regulations 2018 (NIS Regulations). Regulation 10 requires an OES to take appropriate and proportionate technical and organisational measures to manage cybersecurity risks and to prevent or minimise incidents affecting continuity of essential services. The measures must take account of the state of the art and provide security appropriate to the risk.
Ofgem is the competent authority for relevant downstream gas and electricity operators in Great Britain and publishes guidance intended to help OES manage the security and resilience of networks and information systems supporting essential services.
The legislation does not expressly command every utility to deploy a product labelled “zero trust.” Rather, zero-trust controls can provide an important means of demonstrating compliance with the broader statutory requirement for risk-based and state-of-the-art cybersecurity.
Core Zero-Trust Requirements
The NCSC identifies several principles particularly relevant to utilities.
Identity verification: Every user, device and software service should possess a reliable identity. Access should be based on verified identity instead of network location. Service accounts should receive only the privileges required for their functions.
Authentication and authorisation: Connections to protected systems should be authenticated and authorised regardless of whether they originate internally or externally. The NCSC specifically identifies multi-factor authentication as a requirement within zero-trust architecture.
Least privilege and policy-based access: Each request should be assessed against defined access policies. For utilities this is especially significant for control rooms, SCADA systems, generation-management platforms, substations and remote-maintenance interfaces.
Continuous monitoring: Utilities should monitor users, devices and services for abnormal behaviour, compromised devices and unauthorised network activity.
Asset visibility: Operators should understand their users, devices, applications, services and data. This is critical where legacy OT equipment cannot readily support modern authentication controls.
Network distrust and segmentation: Internal networks should not automatically be considered trustworthy. Secure communication protocols, segmentation and controls limiting lateral movement can reduce the consequences of compromised credentials or devices.
CASE LAW
Case Name/Citation
WM Morrison Supermarkets plc v Various Claimants [2020] UKSC 12
Facts
An employee with legitimate access to payroll information copied personal data relating to approximately 126,000 employees and subsequently disclosed information online. Thousands of affected employees brought claims against Morrisons.
Legal Issue
Whether Morrisons was directly or vicariously liable for the employee's unlawful disclosure of protected information.
Judgment
The Supreme Court held that Morrisons was not vicariously liable because the employee was pursuing a personal vendetta rather than acting in the ordinary course of employment.
Legal Principle/Ratio
Vicarious liability requires a sufficiently close connection between the employee's authorised functions and the wrongful conduct. An employee's mere possession of authorised system access does not automatically make the employer liable for every misuse.
Significance
Although not an energy-sector case, Morrisons illustrates a major zero-trust concern: insider access itself creates cybersecurity risk. Utility systems should therefore avoid treating authorised employees as inherently trustworthy and should apply least privilege, monitoring and access controls.
Case Name/Citation
Lloyd v Google LLC [2021] UKSC 50
Facts
The claimant alleged that Google secretly collected and processed information concerning millions of iPhone users in breach of data-protection obligations.
Legal Issue
The Supreme Court considered whether compensation could be claimed on a representative basis merely for unlawful processing without proving individual material damage or distress.
Judgment
The representative damages claim failed because individual compensation under the applicable statutory regime required proof of damage.
Legal Principle/Ratio
Cybersecurity and data-protection breaches do not automatically establish identical compensable loss for every affected individual.
Significance
For utilities operating smart meters and digitally connected infrastructure, the case demonstrates that cybersecurity governance intersects with data-protection duties and potential civil liability.
Conclusion
Zero-trust architecture for UK utilities is best understood as a risk-based cybersecurity implementation model rather than a single standalone statutory obligation. The NIS Regulations require appropriate and proportionate security, while NCSC guidance supports identity-based access, MFA, least privilege, continuous verification, monitoring and distrust of network location. For critical utilities, these principles can strengthen regulatory compliance and reduce risks from compromised credentials, insiders and lateral movement across increasingly interconnected energy systems.

comments