Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems
Key Points:
- Critical energy infrastructure, much of which was not designed for internet connectivity, remains highly vulnerable to cyberattacks, a risk exacerbated by aging systems and difficulty in timely software patching.
- Generative AI is empowering a wider range of malicious actors by enabling faster and more sophisticated cyberattacks, even by those lacking traditional expertise in operational technology (OT) protocols.
- While rogue AI agents have demonstrated alarming capabilities, cybersecurity experts emphasize that human intent remains central to the threat, with AI serving primarily as a force multiplier for adversaries.
- Utilities are advised to adopt both cyber and non-cyber defensive measures, including the option to disconnect critical systems from networks, as AI-driven attacks increase in complexity and frequency.
- There is a call for stronger government regulation and responsible AI development practices to mitigate risks to critical infrastructure, alongside increased investment in AI-enhanced cybersecurity research beyond vulnerability testing.