By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Human Error Remains Top Cybersecurity Threat to Energy Systems
Human error remains the predominant cybersecurity threat to energy systems, superseding concerns about sophisticated AI-driven attacks, according to Joshua Corman, executive in residence for public safety and resilience at the Cybersecurity Collaborative. Corman stated that energy systems have historically been vulnerable, describing them as "prey" constantly at risk from "predators." This assessment comes at a time when discussions around artificial intelligence's potential to disrupt critical infrastructure are intensifying, yet the foundational vulnerabilities stem from human actions and inactions. The increasing interconnectedness of energy grids, often referred to as the "Internet of Energy," amplifies these risks by expanding the attack surface. Each new connection, whether for operational efficiency or smart grid functionalities, introduces potential entry points for malicious actors.
The complexity of modern energy infrastructure, encompassing generation, transmission, and distribution, involves numerous human touchpoints. These include system operators, maintenance crews, IT personnel, and third-party vendors, all of whom can inadvertently create security gaps. Phishing attacks, weak password practices, misconfigurations of network devices, and insider threats are persistent challenges that exploit human fallibility. The consequences of such breaches can be severe, leading to widespread power outages, economic disruption, and even threats to public safety. For instance, a successful attack on a regional power grid could disable electricity for millions of people, impacting hospitals, transportation, and communication networks.
While the capabilities of AI in cyber warfare are rapidly evolving, Corman's perspective highlights that current threats are often less sophisticated, exploiting well-known human vulnerabilities. The focus on AI as the primary existential threat may distract from the immediate and ongoing need to address fundamental security hygiene and human-centric risks. Organizations within the energy sector are investing in advanced security technologies, but these are often undermined by basic security lapses. The challenge lies not only in deploying cutting-edge defenses but also in fostering a robust security culture that educates and empowers the human element of the workforce to be a line of defense rather than a point of weakness.
The Cybersecurity Collaborative, an organization focused on improving cybersecurity practices, emphasizes the importance of resilience in the face of inevitable threats. Their work often involves bridging the gap between technical security measures and the human factors that influence their effectiveness. The ongoing digital transformation within the energy sector, while promising greater efficiency and integration, necessitates a parallel evolution in cybersecurity strategies that prioritize the human element. This includes comprehensive training programs, stringent access controls, regular security audits, and incident response plans that account for human error as a primary causal factor. The growing reliance on digital systems means that the energy sector must continuously adapt its defenses to protect against both novel and persistent human-driven threats.
Original source — read the full reporting at the publisher:
Read on The VergeGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.