Cybersecurity

Why energy leaders need to prepare for the cybersecurity threat of more powerful AI

AI is rapidly innovating and reshaping the cyber threat landscape for critical infrastructure in the energy sector.

CISOs must step up their cybersecurity maintenance to address AI threats. Image: Sylvain Cls/Pexels

Leo Simonovich
Vice-President; Global Head, Industrial Cyber and Digital Security, Siemens Energy
Filipe Beato
Manager, Technology and Innovation, World Economic Forum
This article is part of: Centre for Cybersecurity
  • Artificial intelligence is rapidly innovating and reshaping the cyber threat landscape for critical infrastructure in the energy sector.
  • Energy leaders should expect more vulnerabilities, more patches, and a wave of deprecated services threatening their systems.
  • Chief information security officers (CISOs) must step up the tempo of their cybersecurity maintenance to address such risks.

Artificial intelligence (AI) is rapidly innovating and reshaping the threat landscape for critical infrastructure. As these systems get smarter, energy systems face an unprecedented test of their resilience that leaders must urgently act on.

Just within the past year, AI coding capabilities have advanced so dramatically that the AI company Anthropic withheld its newest model and organized efforts to close vulnerabilities the model discovered across the technology sector.

Guardrails designed to prevent AI-assisted attacks on critical infrastructure underscore the severity of the threat fully potent models would pose. It remains unclear whether such guardrails will hold – or how soon open-weight models with less oversight will achieve the same capabilities.

Yet one thing is very clear: energy companies have limited time to prepare for a new normal in which AI can rapidly discover and exploit vulnerabilities in digital systems.

AI risks for the energy sector

Energy infrastructure is digitally controlled, long-lived and complex. Cyberattacks, ranging from ransomware to nation-state infiltration of rival economies, already target critical infrastructure.

Yet when asked, just 46% of cybersecurity practitioners say their own organization has adequate protection in their operational technology (OT) environments. Even the relatively sophisticated US market offers examples of energy companies that were unaware of long-running compromises of their infrastructure.

Loading...

Many utilities in the electricity sector are small organizations with limited budgets, yet they must defend against nation-state-level threats. Adding newly skilled AI that can discover and exploit vulnerabilities will exacerbate the existing mismatch between attacker and defender speed of action.

Typical OT defenders take more than a month to detect a cyber breach and over seven months to recover, yet must now contend with AI agents that can discover and exploit vulnerabilities within a 15-minute timespan.

Maintaining cybersecurity in a faster-moving era

Energy infrastructure operators now face a daunting reality. They must operate with known vulnerabilities in their systems, while AI scours code and networks for new ones. Meanwhile, attacks on the energy sector continue to escalate.

Phishing, voice phishing, and social engineering attacks – backed or run by AI agents and nation-states – continue to target and sometimes compromise valid accounts. This is not the future; it is the present.

Operators must expect and engineer for these harsh conditions. Defence in depth, network segmentation and least-privilege principles will remain fundamental to building and maintaining strong defences.

The same AI capabilities that rapidly discover and exploit bugs should enable software vendors to accelerate patch development. New patches won't take effect until they are deployed, so chief information security officers (CISOs) must speed up each step within their control.

Workflows meant to periodically shore up cybersecurity practices – such as audits of configuration – will need to happen more frequently. Notably, Apple recently cited malicious use of AI as the reason for changing its longstanding patch release philosophy – a clear signal that faster patching will be important for survival in the AI era.

Energy operators face more vulnerabilities

Operators should brace for early software deprecation. When we start seeing AI agents exploit software in the wild, many vendors will focus on securing current and future software iterations, leaving older versions unpatched and vulnerable.

Almost no one has the budget or operational bandwidth to update everything at once. CISOs in the energy sector will need to choose which essentials to update to current versions early, and which unsupported versions can be surrounded with compensating controls.

In addition to compensating controls like asset hardening, whitelisting, firewalls and data diodes, defenders should build visibility across their operational technology environments. Tracing anomalies across digital and physical systems helps defenders understand what’s happening and when to intervene.

The quality of information boards and executives will have for crisis decision-making depends on building visibility before the crisis arises. Done well, visibility can even enable defenders to retroactively confirm whether newly discovered vulnerabilities exist and were previously exploited in their networks.

In Europe, the US and many Middle Eastern markets, cybersecurity regulations increasingly require critical infrastructure to include cybersecurity monitoring capabilities.

Harnessing automation for cybersecurity

Automation will help defenders manage the faster tempos that come with the new normal. Already, automation can take on routine tasks, hunt for vulnerabilities, and respond to suspected cyber breaches with machine-like speed. Adding more capable AI to the toolbox will increase the workloads that can be reliably automated. Treating AI as a force multiplier, not a full replacement, looks promising.

In the short term, automation should free humans for other tasks. Asset inventory, vulnerability discovery and network monitoring can already be automated. Machine learning and AI make it easier to accurately detect anomalies and prioritize human attention to likely attacks while protecting analysts from a deluge of false positives.

Routinely capturing and securely storing a golden image of key systems can help minimize the costs of recovery in the event of a breach by ensuring known-safe backups exist. In the longer term, energy CISOs will need to evaluate the tradeoffs between productivity and security gains from AI-based automation, compared to the risks that come with their added complexity.

Energy leaders must recognize that inaction in the AI era is a non-zero risk. A CISO who sits still does more than forgo benefits of automation – they accumulate a growing number of obsolete, vulnerable technologies that threaten the entire sector.

Don't miss any update on this topic

Create a free account and access your personalized content collection with our latest publications and analyses.

Sign up for free

License and Republishing

World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.

The views expressed in this article are those of the author alone and not the World Economic Forum.

Stay up to date:

Cybersecurity

Share:
The Big Picture
Explore and monitor how Cybersecurity is affecting economies, industries and global issues
World Economic Forum logo

Forum Stories newsletter

Bringing you weekly curated insights and analysis on the global issues that matter.

Subscribe today

More on Cybersecurity
See all

AI incarnate, or agents of chaos? How to secure physical AI

Kary Bheemaiah and Ann Cleaveland

July 22, 2026

How shared intelligence protects against and disrupts online exploitation and cybercrime

About us

Engage with us

Quick links

Language editions

Privacy Policy & Terms of Service

Sitemap

© 2026 World Economic Forum