Energy cybersecurity now requires an aware, trained, multidisciplinary workforce

Published: 09/29/2026

Diego Santana
by  Diego Santana

Cybersecurity in energy used to be about protecting data. Today, it’s about protecting the infrastructure that data runs on, where an attack can shut down equipment, not just expose files. Secure systems catch some of those instances, but AI-generated voices, faces, and messages are built to get past them and reach people, who spot fakes with about the same accuracy as chance. The better defense isn’t sharper eyes. It’s a workforce trained to pause, verify requests through separate channels, and report anything amiss.

8 min read
Global

Key takeaways

  • Because information and operational technology (IT and OT) now share the same connected infrastructure, a cyberattack on either one may carry the same stakes as a physical hazard. It’s no longer just about a data breach.
  • Secure systems are the first line of defense; people are the second. In Poland’s December 2025 energy-sector attacks, security software stopped malware at one plant, and the operators’ quick response contained an attack at another. Building that second line takes a workforce skilled across the four disciplines the threat now touches: IT, OT, cybersecurity, and AI.
  • Training people to spot fakes isn’t enough on its own. The more promising path is to help them develop habits that don’t depend on any one person spotting a fake, such as verifying requests through separate channels and reporting suspicions, which a large study found could flag new phishing campaigns within minutes.
  • The energy sector already trains at scale, from continent-wide grid exercises to yearlong national programs. What’s still scarce, across the industry, is public evidence of which training changes behavior on the job.

My previous two articles made the case for energy cybersecurity from different angles. The first framed cyber threat as a safety issue, arguing that as connected infrastructure brings information and operational technology (IT and OT) together, cyberattacks can harm both data and operations. The other article framed cybersecurity as a sustainability issue, making the case that emissions data is only as trustworthy as the systems that produce it. If regulators, investors, customers, and the public know systems are secure, decarbonization claims will feel credible. Trust will follow.

What neither article addressed is the people responsible for keeping those energy systems secure, an urgent focal point given how fast the threat is growing. Through the first quarter of 2025, energy and utility companies worldwide faced an average of 1,872 cyberattacks per week per organization—an increase of 53% over the year before, according to Check Point Research.

The attack surface keeps widening, too. The US grid spans more than 55,000 substations and 22,000 generators, according to the US Department of Energy (DOE). Across the grid, the North American Electric Reliability Corporation (NERC), a federally designated enforcement authority responsible for the reliability and security of the electrical networks across North America, counted between 23,000 and 24,000 vulnerable points in hardware and software by the end of 2023, and said that number increases by roughly 60 a day.

In this environment, the technologies that help energy companies connect and secure systems also allow attackers to become more sophisticated. Each generation of attack is harder to detect than the last, which makes our first line of defense—maintaining secure systems—even harder. What energy companies need now more than ever is to prepare their workforces to be the second line of defense.

People catch some threats but still need a process

The technical and governance aspects of the first line of defense are well documented, spanning secure-by-design architecture, zero-trust access controls, and standards from bodies such as NERC and the National Institute of Standards and Technology (NIST). The second line—the people working those systems—matters most when an attack is underway. Real incidents illustrate how the lines work together.

In December 2025, attackers struck a large combined heat and power plant (CHP) supplying heat to almost half a million customers, according to CERT Polska, Poland’s national computer emergency response team. Antivirus software missed the wiper malware deployed to destroy plant data, but the plant’s endpoint detection and response software caught and stopped it. The same day, attackers also hit at least 30 wind and solar farms through their grid-connection substations, which are typically unmanned. Many devices there still used default passwords. The attackers used that vulnerability to disable equipment and cut the sites’ communication with the grid operator, though power generation continued.

A follow-up report from CERT Polska revealed a parallel attack on a second, smaller CHP plant serving 50,000 residents. It shut down a steam turbine. There, operators responded quickly enough that the outage was brief and heat supplies were never disrupted. Those examples illustrate the two lines of defense: Systems catch what they’re built to catch, and people respond when an attack gets by those systems.

Evidence beyond Poland’s case points in the same direction, with a caveat. Dragos, a cybersecurity firm that specializes in industrial and energy-sector systems, reviewed its 2025 incident-response cases and found that nearly a third of OT incidents began not with an alert, but with a human noticing something was wrong, something they couldn’t explain. Yet that instinct often runs on chance, not process. The same Dragos review also showed that 82% of organizations have no clear rule for when an unexplained anomaly should prompt a formal investigation.

“Instinct that works only by chance isn’t a defense. It’s a coin flip we’ve been lucky to win so far. The real question is what happens once the deception gets good enough that luck runs out, too.”
– Diego Santana

Cyberattacks are getting so good that some can even evade detection entirely. Dragos also noted that more than half of simulated attacks used an organization’s own tools rather than malware, triggering no alerts or human suspicions at all.

Strengthening the second line of defense rests on three pillars: awareness of AI-generated deception, training that focuses on pausing rather than detecting, and skills that span the disciplines the threat now touches.

AI-generated deception is sophisticated and demands awareness

The first of the three pillars—awareness—means knowing that the threat exists, how often it succeeds, and how much it costs. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, based on a survey of 800 global business leaders across 92 countries, 73% of respondents said that they or someone in their network had been personally affected by cyber-enabled fraud in 2025, with AI-generated voice cloning and phishing among the most common methods. Separately, Fortune reports that deepfake video fraud alone drained an estimated USD 1.1 billion from US corporate accounts in 2025—triple the previous year’s total.

The mechanism behind those incidents is predictable. An attacker clones a familiar voice or face, offers a plausible pretext for the request, such as confidentiality or an unannounced deal, and adds urgency so the target acts before thinking to check. Each step is designed to keep the target inside the attacker’s channel.

Systems can still miss requests that look and sound right, which is why the response must begin with the person receiving it. What prepares someone for that moment? Cyber awareness training is the default answer, but whether the standard version is built to withstand deception like this is another matter.

Train for the pause instead of the detection

Lessons from behavioral science matter here because security depends on shaping people's behavior, not just on deploying new tools. And that’s where training, the second pillar, comes in.

Training is the discipline that turns awareness into action under pressure. Although security awareness training is mandatory in parts of the energy sector, the rules vary by region and operator. In the US and Canada, NERC’s Critical Infrastructure Protection standard requires role-based cybersecurity training at least once every 15 months and awareness reinforcement, such as emails, posters, or meetings, at least once every quarter, but only for utilities that own or operate the electric grid, not for oil and gas operators. Oil and gas aren’t entirely unregulated, though; directives from the Transportation Security Administration apply to designated critical pipeline operators. The EU’s Network and Information Security Directive 2 (NIS2) covers more sectors, including electricity, oil, gas, and hydrogen. NIS2 calls for cybersecurity training without specifying how often. These rules use different levers and reach different operators, but none prescribes which kind of training actually works.

Training exercises are another way to reach energy professionals. In November 2025, GridEx VIII, the largest grid security exercise in North America's history, with more than 28,000 players, included a leadership deepfake scenario, which shows that the industry is paying attention to the severity of these attacks. The research on standard training is sobering, though. Two independent controlled studies, one with 19,500 employees and another with 14,000, found that training didn’t make people any better at resisting phishing, and a meta-analysis of human deepfake-detection studies put accuracy barely above chance.

“When it comes to cybersecurity, a habit that fires every time beats a skill that only works when we’re paying close attention.”
– Diego Santana

That’s not an argument against training; it’s an argument against training people to spot fakes. The same 14,000-employee study also found something that did work: a simple reporting button. Added to the employees’ email, it surfaced new phishing campaigns within minutes. A sufficiently large number of employees continued to report over long periods. No single person sees enough of a mass campaign to catch it on their own, but many independent reports arriving together let organizations quickly spot a pattern.

What doesn’t have that kind of evidence behind it but is widely recommended by law enforcement is more direct: Remove decisions from the moment and the individual instead of trying to sharpen judgment under pressure. In real terms, that means

  • verifying a request through a separate channel from the one it came in on
  • calling back on the number in the corporate directory, not the one supplied
  • using agreed-upon code words
  • requiring two people to sign off on financial requests.

Each depends on access to something the deceiver doesn’t have—the verification channel, the code word, the right phone number, or a second person—so the check holds whether or not the person is fooled.

The talent pipeline needs four disciplines

A multidisciplinary talent pipeline is the third pillar. Companies need enough people who can work across the four vulnerable disciplines.

  • IT—which covers cloud, identity, networks, and data
  • OT—for availability, safety constraints, and control environments
  • Cybersecurity—spanning threat modeling, governance, controls, and response
  • AI—for model risk, data integrity, automation, and governance

The DOE runs the closest thing to a national program. It held six three-day events between October 2023 and mid-2024 as part of its Cybersecurity Training for the Utility Workforce series, training more than 600 utility, oil, and gas workers on industrial control system equipment. The multidisciplinary training covered IT, OT, and cybersecurity—three of the four disciplines.

Japan’s Industrial Cyber Security Center of Excellence takes a different approach. It’s full-time for a whole year, ending in a legally protected professional title and an exemption from a separate national IT security exam. So far, almost 500 graduates have come through the program. Across its first four cohorts, 70% of participants arrived knowing only IT, 16% only OT, and 14% both, a concrete picture of the gap this kind of training is meant to close.

The energy workforce is only ready when results prove it

Secure systems are the baseline for energy companies navigating AI-driven change. What separates the companies that keep pace with threats is the second line of defense: a multidisciplinary workforce that knows the threat and is trained to pause and verify.

Use these three moves to begin:

  1. Assess whether your training teaches people to spot AI-generated deception or develops the habit of pausing and verifying.
  2. Invest in cross-domain development, not just specialized roles.
  3. Measure behavior change and outcomes, not just completion.

The third move is the hardest because the industry doesn’t yet have much to measure against. Large exercises and national programs train thousands of people, but public evidence of which approaches change behavior on the job remains scarce. What isn’t in doubt is that energy companies need a cyber-aware workforce, trained to pause rather than detect, built across disciplines, and checked against results.

Somewhere, right now, a request is moving through a control network. It’s verified and logged, just as it should be. Every system does its job. And somewhere, right now, a cyber-aware engineer is picking up a call. The voice sounds exactly like a colleague’s and the request seems routine; nothing about it raises a flag. The engineer pauses and verifies anyway—and that’s what happens on every request like it, whether the system catches it or not.

Contributors
Diego Santana

Diego Santana

Awarded for contributing to the cybersecurity field

Diego Santana, CISSP, is a Cyber Security Practice Manager and Métier, with over 29 years of experience in SLB. His career spans various digital fields, including cybersecurity, automation, and IT management, along with being the organization’s former Cyber Security Operations Manager. He continues to help develop and mature the company’s worldwide long-term cyber security strategy, now focusing on talent management.