JoshMein

Humans Pose Biggest Cybersecurity Risk to Energy Systems

· fashion

Energy’s Unseen Threat: Humans, Not AI, Remain the Biggest Risk to Our Grids

The recent high-profile hacks have brought attention back to the vulnerabilities of our energy systems. However, this is not a new issue. For years, experts have been warning about the risks of cyberattacks on our power grids, and it’s not because of some hypothetical “rogue AI” scenario. The real threat has always been – and continues to be – human error.

Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology (IST), made a stark observation last year: our energy systems are already vulnerable to cyberattack. As he put it, “We were always prey. We were just kind of surviving at the appetite of our predators.” This highlights the reality that human operators have been putting our energy infrastructure at risk through negligence and incompetence.

The Department of Homeland Security issued a warning last year about the threat of Iranian actors targeting US energy systems with cyberattacks. While this warning was specific to state-sponsored threats, it underscores the broader issue: human decision-makers are the weakest link in the security chain. High-profile hacks have raised concerns about AI-powered attacks, but these incidents were carried out by humans.

The growing risk of cyberattacks on our energy systems is a symptom of a larger problem: our inability to prioritize cybersecurity as an integral part of system design and operation. For decades, the focus has been on building more efficient infrastructure without adequate attention paid to potential risks. This short-sighted approach has created an environment where vulnerabilities are exploited with alarming regularity.

Energy companies must invest in cybersecurity as a core part of their business strategy – not just a necessary evil or afterthought. Companies need to adopt a mindset shift, recognizing that security is not a one-time fix but an ongoing process requiring constant vigilance and adaptation.

The threat landscape is constantly evolving, with new threats emerging as our reliance on digital infrastructure grows. The US energy sector has been slow to respond, often prioritizing short-term gains over long-term security. This complacency is unacceptable, especially given the devastating consequences of a successful cyberattack: widespread power outages, economic disruption, and potential loss of life.

The situation demands a more proactive approach from industry leaders, policymakers, and regulatory bodies. Governments must provide clearer guidance on cybersecurity standards and best practices, while energy companies must prioritize investing in robust security measures that can withstand ever-present threats. As Corman’s quote suggests, we are not just fighting against hypothetical predators; we are already prey – and it’s time for a different response.

Confronting the reality of human vulnerability to cyberattack is essential. We need to adopt a comprehensive approach to security that prioritizes people, processes, and technology. Only then can we hope to safeguard our energy systems from the threats that truly matter – those posed by humans, not machines.

Reader Views

  • NB
    Nina B. · stylist

    It's time for energy companies to stop treating cybersecurity as a Band-Aid solution. We need systemic changes, not just reactive measures. Investing in robust security protocols and training programs is essential, but also crucial is reforming the very culture of these organizations. By recognizing that human error is often at the root of these problems, rather than excusing it with "negligence and incompetence," we can start to build a more resilient energy infrastructure. This requires acknowledging that our current approach is inadequate and embracing a fundamentally different way of designing and operating these systems.

  • TH
    Theo H. · menswear writer

    It's about time we stop beating around the bush: human error is not just a contributor to energy system vulnerabilities, but the primary cause. While AI-powered attacks get all the hype, we're overlooking the elephant in the room - our own industry's sloppiness. Energy companies are too quick to rely on tech fixes and too slow to invest in comprehensive security protocols. Until they prioritize people over profits, we'll continue to see high-profile hacks that leave us scrambling for Band-Aids rather than lasting solutions.

  • TC
    The Closet Desk · editorial

    The irony is that we've been warning about human error as the root cause of cyber threats for years, yet energy companies continue to prioritize efficiency over security in their infrastructure design. But what's often overlooked is the role of outdated protocols and legacy systems in amplifying this risk. These systems can't be easily updated or patched, making them a ticking time bomb waiting to be exploited by hackers who know exactly where to look for vulnerabilities. It's time for a more holistic approach to cybersecurity that addresses not just human behavior but also the technology itself.

Related articles

More from JoshMein

View as Web Story →