The conversation about artificial intelligence and critical infrastructure has taken on an almost apocalyptic quality in recent months. Headlines warn of AI-powered cyberweapons capable of taking down power grids, water treatment plants, and pipeline networks with surgical precision. The fear is real, but the framing is dangerously incomplete. Long before any AI system posed a credible threat to energy infrastructure, humans were already doing a remarkably efficient job of leaving the door open.
Joshua Corman, executive in residence for public safety and resilience, puts it with unsettling clarity: "We were always prey. We were just kind of surviving at the appetite of our predators." That sentence deserves to sit with readers for a moment. Not thriving. Not defending. Surviving on the tolerance of those who chose not to strike harder, or hadn't yet found the right angle of attack. That is the actual baseline for much of the energy sector's cybersecurity posture — and it existed well before anyone started worrying about rogue AI.
Energy Systems Were Already Vulnerable Before AI Entered the Picture
In December 2015, Ukrainian electricity distribution companies suffered a coordinated cyberattack that left roughly 230,000 customers without power for several hours. The attackers, later attributed to a Russian state-sponsored group known as Sandworm, exploited spear-phishing emails — a technique that relies entirely on a human clicking something they shouldn't. A year later, a more sophisticated attack hit a Ukrainian transmission substation, briefly knocking out about one-fifth of Kyiv's power capacity. The weapons were custom malware; the entry point was human behavior.
Six years later, on the American side of the Atlantic, a ransomware gang called DarkSide infected Colonial Pipeline's IT network in May 2021. The company, which supplies roughly 45 percent of the fuel consumed on the East Coast, shut down operations proactively. Fuel shortages spread across southeastern states within days. The entry vector, according to investigators, was a compromised VPN account — one that lacked multi-factor authentication. A single credential, probably obtained through a phishing campaign or credential-stuffing attack, triggered the largest publicly known disruption to U.S. fuel infrastructure in recent history. No advanced AI required.
These incidents are not outliers. The Cybersecurity and Infrastructure Security Agency (CISA) has documented years of targeted intrusion campaigns against U.S. energy sector networks, including a sustained campaign between 2016 and 2017 in which threat actors gained access to operational technology environments at multiple utilities. Each time investigators trace the kill chain backward, they find the same categories of failure: compromised credentials, unpatched systems, insufficient network segmentation, and employees who were deceived or simply made mistakes.
Why Humans Remain the Weakest Link in Energy Cybersecurity
The energy sector is not staffed by careless people. Many utilities employ trained security professionals and follow NERC CIP reliability standards that impose rigorous requirements on critical infrastructure operators. Yet the sector continues to suffer breaches for reasons that are stubbornly human.
Read next Laika's Wildwood: Stop-Motion Fantasy at TIFF 2026Social engineering remains extraordinarily effective. A well-crafted phishing email, a convincing phone call, a USB drive left in a parking lot — these are not sophisticated in the technical sense, but they exploit the one vulnerability that no firewall addresses: human judgment under pressure. Operational technology environments compound the problem. Many control systems running substations, pipelines, and generation facilities were designed decades before cybersecurity was a serious engineering consideration. They were built to last, and they have. Replacing them is expensive and operationally risky. In the interim, they depend on human procedures to compensate for their lack of native security controls — procedures that are only as reliable as the people following them.
Workforce turnover, contractor access, and organizational complexity add further exposure. Large utilities manage sprawling networks of vendors and subcontractors, each with their own security hygiene and each representing a potential entry point. The principle of least privilege — granting users only the access they actually need — is routinely violated simply because managing granular permissions at scale is difficult and time-consuming. Human error cybersecurity energy systems researchers consistently identify access management failures as a primary contributor to successful intrusions.
How the AI Narrative Distracts from Ground-Level Risks
The fixation on AI as the emerging threat to energy infrastructure is not entirely misplaced. Machine learning tools can accelerate vulnerability discovery, automate spear-phishing at scale, and potentially assist in navigating complex industrial control system environments. These capabilities are real and deserve serious attention from security researchers and policymakers alike.
But the breathless focus on AI-powered cyberattacks carries a cost: it diverts attention and resources away from the mundane, persistent, and entirely solvable problems that are actively exploiting energy systems right now. When boards and legislators become preoccupied with science-fiction scenarios, the basics suffer. Patch management gets deprioritized. Security awareness training budgets get squeezed. Multi-factor authentication rollouts stall.
There is also a psychological dimension to the AI distraction. Framing the threat as a sophisticated, almost unknowable adversary lets organizations off the hook for failures that are entirely within their control. If the enemy is an AI god, then losing begins to seem inevitable. If the enemy is a phishing email that an employee opened because they were tired and rushing before lunch, then accountability becomes unavoidable — and so does the mandate to do better.
The Growing Attack Surface of Modern Energy Infrastructure
The energy sector's attack surface has expanded dramatically over the past decade, and that expansion is driven by technology adoption, not AI. Smart grid deployments have connected millions of devices — meters, sensors, switches, substations — that previously had no internet-facing exposure. Distributed energy resources, including rooftop solar installations and battery storage systems, have introduced thousands of new network endpoints managed by third-party vendors with variable security practices.
Remote monitoring capabilities, accelerated by operational necessity during the pandemic years, have extended access to industrial control systems beyond the physical perimeter of facilities. Each remote access point is a potential entry vector. CISA's advisories on operational technology security consistently flag remote access as a top-priority concern, noting that many organizations still rely on legacy remote desktop protocols and VPN configurations that fall short of current hardening recommendations.
Cloud migration, while offering efficiency benefits, has also introduced new complexity. Hybrid environments — where some operational data flows through cloud infrastructure while other systems remain air-gapped — create boundary conditions that are notoriously difficult to secure consistently. Humans design these architectures, configure them, and operate them. Errors at any stage create exploitable gaps.
Building Resilience: From Survival to Active Defense
Corman's framing — surviving at the appetite of predators — describes a passive posture. The shift toward genuine resilience requires a different orientation: not merely avoiding catastrophic failure, but actively hardening systems, reducing dwell time when attackers do get in, and building the operational capacity to recover quickly when disruption occurs.
That means treating cybersecurity as an engineering discipline, not a compliance exercise. NERC CIP standards provide a regulatory floor, but meeting the minimum requirement does not mean achieving security. Organizations that have matured beyond compliance-driven security programs invest in continuous monitoring, red team exercises, and tabletop simulations that stress-test their incident response plans against realistic attack scenarios modeled on documented intrusion campaigns — not hypothetical AI threats.
Zero-trust architecture, while not a silver bullet, represents a meaningful structural shift. By eliminating implicit trust based on network location and requiring continuous verification of users and devices, zero-trust reduces the blast radius when credentials are compromised — which they will be. The question is not whether someone inside a utility's network will click a malicious link. The question is whether that click cascades into a grid disruption or gets contained.
What Policymakers and Operators Must Prioritize Now
Regulatory bodies and utility operators share responsibility for closing the gap between the sector's current posture and the level of resilience that modern threat actors demand. Several priorities stand out.
First, accelerate baseline security requirements across the supply chain. A transmission utility may have excellent internal security controls while relying on a subcontractor whose remote access credentials are one credential-stuffing attack away from compromise. CISA's supply chain risk management framework provides guidance; what is needed is consistent enforcement and industry-wide adoption.
Second, fund security workforce development. The cybersecurity talent shortage is acute across all sectors, but energy is particularly exposed because operational technology security requires a hybrid skill set — understanding both IT security principles and the engineering constraints of industrial control systems. That expertise takes years to build and cannot be outsourced.
Third, resist the narrative that the threat is too sophisticated to address incrementally. Multi-factor authentication, timely patching, network segmentation, and security awareness training are not glamorous. They also work. The Colonial Pipeline attack exploited the absence of MFA on a single VPN account. That is a solved problem. The fact that it remains unsolved in corners of critical infrastructure is a choice, not an inevitability.
The AI era of cybersecurity is coming, and preparing for it matters. But the predators exploiting human error cybersecurity energy systems vulnerabilities today are not waiting for tomorrow's tools. They are already inside. The first job is to stop handing them the keys.
Source: The Verge



