This is Icebreaker One’s response to Ofgem’s consultation: Securing Open Data in Energy. It can be published openly. Please note that throughout this consultation, Icebreaker One uses the terms Open, Shared and Closed data as defined here.
If you have any questions about our submission or require clarifications please do not hesitate to contact us via policy@ib1.org. We have omitted questions which we did not answer.
Overall Position
We welcome Ofgem’s focus on strengthening the governance of energy system data but believe this consultation should fundamentally be about improving decision-making rather than selecting a technical solution. Before investing in new infrastructure, there must be a clear, transparent, and consistent process for assessing what data should be open, shared, or closed. Processes must be applicable at the level of individual datasets, however the sector also requires a mechanism for considering publishing decisions at the aggregate level, for example when risks associated with publication multiply at scale. Without this, there is a risk of building technology that does not address the underlying governance challenge.
We support the Educational Model as the preferred approach, subject to some adjustments, as it addresses the challenge of improving decision-making without introducing centralised infrastructure that has potential to compound security and resilience risks. We also recommend expanding the assessment criteria to explicitly consider liability, governance, resilience, and interoperability. Responsibility should remain clearly assigned to each data publisher while recognising that some risks require collective assessment. A Trust Framework provides the appropriate mechanism for a collective approach to decision-making, data triage and risk assessment without centralised data infrastructure.
Effective governance should define, articulate, mandate, and enforce a monitoring, reporting, and verification process to ensure published data meets agreed requirements while allowing technical implementation to remain decentralised. This approach avoids creating single points of failure, strengthens system resilience, and maintains interoperability through common standards and assurance mechanisms. The Digitalisation Coordinator should focus on establishing and maintaining governance processes rather than operating centralised technical services.
We strongly recommend the adoption of a transparent, evidence-based approach to risk assessment. The consultation proposes solutions before clearly describing the threats, vulnerabilities, or risk reduction expected from each option. A structured risk assessment with established methodologies, such as the NCSC Framework, should underpin any changes to Open Data policy. Security considerations must also be balanced against the UK’s net zero objectives, recognising that unnecessarily restricting data access may hinder consumer benefits, innovation, system coordination, and decarbonisation without reducing risk. Given that much infrastructure information is already publicly available, decisions should be made based on demonstrable risk reduction rather than assumptions about the benefits of data restriction.
Consultation question responses:
Question 1: Please provide examples of where data made available under DBP Guidance has allowed your business model to develop either new products and services, or make efficiency savings?
Icebreaker One and partners have used the data extensively in our work to assess and develop use cases enabling data to work harder to support energy system decarbonisation. Data made available under the DBP guidance has supported use cases in areas including, but not limited to:
- EV infrastructure development, including a targeted use case serving households without off-street parking
- Heat decarbonisation and heat pump roll-out
- Local authority planning and LAEP development
- Cross sector data sharing between energy-water-telecoms for e.g. storm response
- Community energy build out supporting the Local Power Plan
Use cases are especially valuable in considering data security as these provide an opportunity to clearly define the purpose of data access, identify relevant stakeholders, and understand user needs. This approach helps minimise unintended consequences by ensuring that decisions about whether data should be open, shared, or closed are based on clear understanding of who needs the data, for what purposes, and under what conditions.
Currently, we are using the data to form part of our development work to assess how a data sharing scheme could accelerate Industrial and Commercial (I&C) participation in electricity flexibility. Data included in the landscape assessment supporting the use case includes: network flexibility data (e.g. forecasts, zoning, trades), network constraints/headroom, and connections data (e.g. LCT connections, capacity registers).
Question 2: Do you agree with the criteria underpinning the Options Analysis as described above?
The proposed criteria provide a useful basis for the Options Analysis, but we believe they are currently incomplete and, in some cases, do not fully support an objective comparison of the proposed models. We make the following observations on the existing criteria.
Ownership and accountability: We are concerned that the current scoring does not appear to reflect that distributed responsibilities, when supported by common standards and governance, can provide clear and consistent accountability. There is a risk that the scoring methodology unintentionally favours centralised delivery models by assuming that the Digitalisation Coordination Function (DCF) is able to define and operate triage standards and processes internally that cannot be disseminated and carried out by data publishers. The scoring should assess how standardisation and governance can reduce risk irrespective of architecture. They should also flag where risks are present with regards to assigning responsibilities to the DCF as a body whose remit has not yet been defined.
The assessment should also consider how conflicts of ownership and decision-making would be managed in practice. For example, tensions may arise between network operators and a central coordination body where publication decisions differ, particularly if decisions contradict current publication requirements set out by sector governance regimes such as the Codes. Similar complexity exists for smart meter data, where governance may overlap between the Smart Energy Code (SEC), Central Switching Service (CCS/RECCo), UK GDPR, the Data (Use and Access) Act, Data Access and Privacy Framework, and Ofgem’s Data Best Practice Guidance. We therefore recommend that the assessment explicitly considers governance arrangements and conflict resolution mechanisms, in addition to whether any proposed central body (e.g. DCF) would assume the role and responsibilities of Data Controller under UK GDPR.
Data security: We agree that data security should remain a core assessment criterion. However, security should be assessed across the entire data lifecycle, including how data is stored, governed, transferred, and accessed, rather than focusing solely on publication decisions. In particular, the analysis should recognise that centralising data storage or transferring data to a central body may increase systemic risk by creating attractive targets for attack and introducing potential single points of failure. These architectural trade-offs should be explicitly reflected in the assessment.
Data quality: We welcome the inclusion of data quality into the assessment. To clarify scoring in this area, we suggest providing an authoritative definition of what is meant by “data quality”, distinguishing, for example, between schema compliance, completeness, accuracy, timeliness, and fitness for purpose. This distinction is particularly important when assessing the extent to which automated processes can improve quality. The assessment should also identify who is responsible for improving data quality under each option, together with the associated implementation and operational costs.
Cost:
We encourage further transparency on the assumptions underpinning the cost assessment. In particular, it is unclear how anticipated savings for individual licensees have been calculated and whether these represent genuine efficiency gains or simply the transfer of costs to a central coordination function. The analysis should also consider how any savings would be used in practice. For example, would reduced expenditure on local publishing platforms enable greater investment in data quality, governance, and workforce capability, or would these simply be treated as financial savings? In addition, we are concerned that indirect costs – including staff training, specialist expertise, organisational change, and ongoing governance – are underrepresented relative to technical implementation costs. In our experience, these organisational costs frequently exceed technology costs and should form part of any comparison of delivery models.
Question 3: Would you suggest any other criteria that you would consider critical for analysis?
We recommend the following additions to Ofgem’s analysis criteria:
Liabilities: while ownership/accountability is an analysis criteria, this does not fully enable the required assessment of who/which body would be held liable for publication decisions, nor assess processes required to handle situations in which data publishers and other relevant decision-makers disagree. In the Hybrid model, it is also notable that the use of automated processing may incur a specific discussion of liability where machine decision-making interacts with human decisions. Liabilities assigned to a potential DCF are also significant and not yet discussed, which requires further thought – particularly where liabilities are affected by other forms of legislation (e.g. Data Use and Access Act (DUAA)) or Codes (e.g. DCUSA data publishing specifications).
Governance: The governance of a system cannot be left as separate to the architecture of the system, but governance details would benefit from further depth in all options. In the Central and Hybrid functions in particular, this creates a large and undefined burden on a future body, whose own format and governance model remains subject to future consultation. As part of governance assessment, we suggest that Ofgem considers the clarity, transparency, and accountability of decision-making processes. For example, processes for assessing risks at the collective level, and determining action, would benefit from further detail. Such processes are important as they intersect with liability assessments. For example, if a licensed entity’s decision to publish Open data is challenged, this is left at conflict with the licensee’s internal process and/or potential obligations under industry codes.
Resilience: current analysis does not identify and assess risks emerging from the potential to create new single points of failure within the energy data landscape. This consideration goes beyond practices within monopoly bodies to also implicate single points of failure regarding aspects such as:
- An open data publishing portal (central/hybrid models)
- Decision-making (central model)
- Automation processes (central/hybrid models)
Interoperability: while the consultation presents arguments for open data publishing to be architecturally separate from other Trust Frameworks, this separation should not be extended to process and data assurance. IB1 suggests that the triage process – and the off-ramp for sharing data subject to restrictions (Shared data) – is not adequately discussed. Rather than presenting a vulnerability, consistency of process and data governance between the DSI, adjacent Trust Frameworks (e.g. CCS, Open Banking, IB1) and Open Data practices lend benefit to data security. Additionally, integration with Trust initiatives in the sector could offer the benefit of integrating Identity and Verification (ID&V) for data users and publishers, thereby streamlining onboarding, increasing confidence in the provenance of published Open Data and reducing the capacity for bad actors to misrepresent themselves across different platforms and processes. Failing to integrate could also unintentionally increase costs through duplication, as flagged via industry engagement groups in relation to Trust Frameworks being developed for the DSI and CCS.
We include analysis under these four categories as part of our response to Q4-6 below.
Question 4: Do you agree with our Option Assessment scoring and conclusion for the Centralised Model?
Our analysis suggests that a Centralised model presents the highest risks and lowest additional advantage as a pathway for improving the sector’s open data security, as well as uncertainty on costs. While the current Options Assessment captures some of these risks, we suggest that the full depth of risks to data security presented through centralised infrastructure have not been fully explored. There are also considerable legal and governance implications for permitting a central coordination body to view and triage all raw data. We suggest a number of points below that, if incorporated in the scoring, we believe would downgrade the Centralised model to the lowest scoring option.
Data security:
- 3.9: ‘The process flow diagram above shows how licensees would send ESD (untriaged) through their Data Preparation Node (DPN) across the Data Sharing Infrastructure (DSI), where it would be subject to Data Quality (DQ) review and then passed to a Triage Function within the Digitalisation Coordination Function.’:
- Transference of large volumes of data to a central body creates a large threat risk, as acknowledged in the wider literature on information security and engineering. While section 3 describes this as ‘reducing the threat surface area’ this is not an accurate representation of risk; rather than reducing the threat, it concentrates it.
- Currently, the Options Assessment does not specify how the proposed central structure would handle key governance decisions such as data deletion. If the body decides that data should not be published, it is unclear how the data is handled, where it sits within the central body vs licensees, and how decisions are documented and recorded.
- The boundaries of what raw data is transferred to the central function on this basis are unclear, as well as who makes the decision about what is or isn’t included for analysis. Scope creep presents a potential issue which could increase costs and act as a resource drain in the central body.
- 3.16 ‘the risk of accidental over-publication is lowered’ – analysis currently makes the assumption that trained individuals in the centralised process are less likely to create errors. It is unclear how this is different to equivalently-trained individuals in distributed licensees. Additionally, when they occur, a centralised body potentially increases the scale of consequences for errors.
- We suggest that tooling or methods applied to check triage compliance and consistency could be decentralised, defined and enforced via a Trust Framework. Centralisation of this function is not necessary to deliver the same outcomes.
Cost:
- We agree with the assessment on cost (score 1 – poor). Design, implementation and operation of the triage/data publishing service would duplicate functions already present in DNOs.
- The overall cost score appears to be contradicted by point 3.14: ‘The model should provide savings for the licensees, as the costs of triage and running an Open Data Platform would be reduced significantly’. This depends on how the DCF is funded and managed, which is not yet determined.
Data quality:
- We query why this metric is scored as 4. In particular, we raise concerns that assumptions have been made about the necessity and feasibility of the role that the central function is envisaged to perform in 3.16 ‘Additional data utility benefits can be accrued through a single centralised portal, increasing interoperability, and allowing for data quality and schema validation as part of data processing, increasing the consistency of data offerings across the sector.’:
- Analysis assumes that the digital coordinator is successful in defining a schema all parties agree with, and
- Will ensure that data provided using the schema is conformant (this may be costly or face limits on compliance).
- We suggest that schema agreement and conformance do not require centralisation; the same outcomes could also be achieved in a decentralised manner via mandating the use of a Trust Framework.
Liability:
- Structure not currently discussed, though the model implies a high degree of reliance on the process and decisions of the DCF.
- Potential for liability conflict unless clarified.
Governance:
- Governance of key processes run by the DCF are as yet undefined.
- Governance of the process to decide whether metadata is published openly is unclear.
Resilience:
- This model creates single points of failure in relation to process/decision-making and technical architecture (portal).
- Relationships/liabilities between data providers and the DCF require clarifying with regards to how licensees may be impacted by a failure or breach of centralised systems.
Interoperability:
- If successfully imposed (this is a risk – see Q2-3), the application of Schema could result in a high degree of data interoperability with the DSI. However, a centralised approach is not the only way to ensure this.
- Legal interoperability must also be addressed; the consultation currently does not propose a function to address licence consistency.
- Interoperability with other Trust Frameworks has not been actively considered in the consultation document.
Question 5. Do you agree with our Option Assessment scoring and conclusion for the Hybrid Model?
Presentation of the Hybrid model offers advantages in terms of checks for consistent application of triage processes, while retaining primary decision-making as a decentralised function. However, the current Option Assessment for the Hybrid Model does not adequately address the governance of automated checks, how this functions with human decision-making, how collective decision-making will be conducted, or how data quality improvements are guaranteed. We believe that amendments to scoring based on points raised below would downgrade the Hybrid model’s overall score and encourage Ofgem to consider this when determining their minded-to position.
Data security:
- Issues related to data centralisation and deletion remain, as described in Q4.
- The automated component of the model may function for certain aspects of assessment – e.g. providing an additional compliance function to check triage steps have been followed – however further exploration of how this interacts with human decision-making would be beneficial.
- Governance of automated checks is not fully described at present. This potentially interacts with gaps in liability assessment identified in Q2-3. Example: dataset is approved by automated compliance function but later found to present risks that were not picked up: does the original data publisher, centralised body, or provider of the tool (if third party) hold liability?
- The model does not fully address how decisions beyond compliance will be made, particularly regarding data which:
- requires an assessment of risk at the collective level, and
- requires an assessment of risk related to landscape changes over time.
- We suggest that tooling or methods applied to checking triage compliance and consistency could be decentralised, using a Trust Framework to both define good and enforce it.
Data quality:
- Observations outlined in Q4 are also applicable to the Hybrid model; it is unclear how data quality improvements are guaranteed through this proposal in a manner that is different to improved coordination/accountability applied to decentralised data triage.
Liability:
- The Hybrid model’s liability structure, and relationship to DCF liabilities, is not yet defined.
- Liabilities for automated processing decisions are not discussed.
Governance:
- Governance of key processes run by the DCF requires definition.
- Governance of automated processes is not currently discussed.
- Monitoring, Reporting, and Verification (MR&V) mechanisms are missing to ensure data published conforms to requirements.
Resilience:
- This model reduces certain single points of failure present in the Centralised model by keeping triage processing decentralised and adding an automated process check.
- However, the data portal element remains centralised, as does data Schema assessment.
Interoperability:
- If successfully imposed (this is a risk – see Q2-3), the application of Schema could result in a high degree of data interoperability with the DSI. However, this can also be achieved in a more decentralised manner than the Hybrid model presents.
- Legal interoperability must also be addressed; the consultation currently does not propose a function to address license consistency.
- Interoperability with other Trust Frameworks has not been actively considered in the consultation document.
Question 6: Do you agree with our Option Assessment scoring and conclusion for the Educational Model?
We disagree with the current scoring of the Educational Model. In particular, the Options Assessment does not address how decentralisation automatically increases security threats despite high cybersecurity standards within licensees, why data quality cannot be assured with effective data governance, or any MR&V mechanisms for the proposed model.
Ownership and accountability:
- We suggest that this score is revisited; distributed ownership does not necessarily complicate accountability. All data publishers are regulated parties whose accountability to Ofgem, and other bodies, is guaranteed in relation to many other functions they deliver. We disagree with the current assessment score on this basis.
Data security:
- We disagree with the low scoring for this category. Licensees are required to maintain high cybersecurity standards for many forms of operational data, including critical national infrastructure. Based on this, it is unclear why distributed responsibility equates to low cybersecurity scoring.
- We suggest that distributed data presents a lower security threat than centralised infrastructure for several reasons. This includes:
- No single point of failure or leverage
- Different internal security infrastructure at each licensee makes “full spectrum” breaches much harder
- Untriaged data does not leave the organisation boundary
- On this basis we suggest that the data security score is reviewed and recategorised.
Data quality:
- We disagree with the low scoring for this category. The assessment appears to define data quality through only a centralised scheme validation despite the ability for agreed standards, accountability, and assurance processes with effective data governance.
- The same data quality investments considered for the Centralised and Hybrid model should be included for the educational model.
Liability:
- Liability is clearly assigned to each data publisher.
- Collective liability would need to be addressed, e.g. in the case where data publishing needs to be assessed at the collective level. This could be addressed meaningfully through a Trust Framework approach with appropriate governance and associated decision-making.
Governance:
- Effective governance within a Trust Framework can define what is required and enforce it without centralisation.
- MR&V mechanisms would be required to ensure data published conforms to requirements.
- The Educational Model could be adapted to give publishing parties the triage check tooling from the Hybrid Model that otherwise sits centrally in the digitalisation coordinator. The DCF, or anyone else who has the specifications and technical ability, could provide the checking functionality, allowing the DCF to focus only on decision-making and collective assessments.
Resilience:
- See security section above: this option presents significant advantages by avoiding the creation of single points of failure and making a full spectrum breach less likely.
- We do not believe that system resilience has been adequately accounted for in Ofgem’s current analysis – doing so could significantly change the minded to position.
Interoperability:
- A Trust Framework can support interoperability by establishing common requirements and assurance mechanisms across publishers.
- Identities and standards established in the DSI trust framework may be used to harmonise trust signals for Open data, such as provenance and assurance, with those for data shared securely within the DSI, with both operating the same peer-to-peer data sharing principle.
Question 7: Do you agree with our minded to position? If not, what is your view as to the best approach to this issue?
We support Ofgem’s focus on strengthening data governance but believe the key challenge is improving the decision-making framework and governance processes that determine whether data should be Open, Shared, or Closed, rather than developing new technical infrastructure. Our preferred approach is the Educational Model, strengthened through a Trust Framework, enabling collective decision-making and standard-setting for data triage and risk assessment. With the addition of governance, liability, resilience, and interoperability as core criteria, the Educational Model provides more robust assurance while avoiding unnecessary centralisation of technology or liability. Effective governance should establish clear standards with monitoring, reporting, and verification processes, allowing the DCF to focus on oversight and decision-making. Any changes to Open Data policy should be supported by evidence-based risk assessment that balances security considerations with consumer benefits, innovation, system coordination, and progress towards net zero.