Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems
The Verge

Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

The Core Risk

Despite recent high-profile hacks raising fears of AI potentially "killing all humans," energy systems have long been vulnerable to cyberattacks-and the risk is growing. Humans remain the biggest cybersecurity risk to energy systems, though they are becoming more dangerous with AI involved.

Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology (IST), explained the situation: "We were always prey. We were just kind of surviving at the appetite of our predators." While he had previously been focused on warnings about Iranian actors targeting the US, his conversation shifted after learning about rogue AI agents orchestrating complex cyberattacks. Even AI executives are debating whether current technology could spiral into an apocalypse. However, cybersecurity experts interviewed by the author were more concerned about generative AI in the hands of bad actors than autonomous rogue agents.

Why Energy Infrastructure Is Vulnerable

Much of our critical energy infrastructure-powering homes, keeping food cold, and operating life-saving hospital devices-was never designed to connect to the internet. Key characteristics include:

  • Long lifespans: Power plants operate for decades; the average age of a US nuclear reactor is about 44 years.
  • Legacy design: These systems weren't built with modern cybersecurity risks in mind, making them easy targets.
  • Orphaned equipment: Some original designers have gone out of business, leaving no one to develop patches for outdated devices.
  • Patch delays: Operational technology (OT) systems often receive updates only quarterly or yearly, unlike IT software that can be updated frequently.

These factors make legacy infrastructure particularly susceptible to exploitation.

AI as a Force Multiplier

While AI itself isn't the primary threat, it significantly amplifies existing risks. Generative AI acts as a force multiplier for adversaries:

"The true difference from AI is that it’s letting adversaries move more quickly-but it’s very challenging for those defending the infrastructure to match that pace."

Rob Denaburg, cybersecurity program senior manager at the American Public Power Association, noted that AI enables less-skilled adversaries to launch effective attacks. A bad actor can leverage large language models (LLMs) that have read operational technology (OT) manuals to understand and exploit systems they wouldn't naturally know how to attack.

Expert Perspectives

Joshua Corman (IST)

Corman emphasizes that while AI changes the landscape, the fundamental nature of the threat remains human-driven:

"But when I spoke to Corman and other cybersecurity experts, they were still more worried about generative AI in the hands of bad actors than they were about rogue agents."

He warns that AI has made attacks more sophisticated and rapid, but the core challenge is matching that speed with defense.

Sophie McDowall (Foundation for Defense of Democracies)

McDowall highlights the gap between AI development and responsible governance:

"Governments and the companies developing advanced AI models hold responsibility... There aren't yet the same policy safeguards for AI as there are for nuclear technologies and hazardous materials."

She calls for balanced approaches that allow continued development while implementing responsible safeguards.

Technical Challenges in Defending OT Systems

Defending operational technology environments presents unique hurdles compared to traditional IT security:

  • Limited update frequency: OT systems may only receive updates once per quarter or year, unlike IT systems that can be patched more rapidly.
  • Resource constraints: Smaller utilities often lack the staffing, expertise, and budget to implement cutting-edge defensive measures.
  • Risk of introducing instability: Adding AI agents into OT environments carries danger due to the sensitivity of these systems. Corman warns: "It’s also really dangerous to introduce too much change too fast in an OT environment."

Path Forward: Best Practices and Responsibility

Utilities must adopt a multi-layered approach to safeguard critical infrastructure:

  1. Non-cyber solutions: Ensure systems can switch to manual operations when needed and consider reducing interconnectivity where possible.
  2. Disconnection strategy: In some cases, disconnecting critical systems entirely may be necessary rather than trying to secure them.
  3. Collaboration with external stakeholders: Engaging with organizations like OpenAI (which pledged $1 billion to subsidize training and access to models for defending critical infrastructure) can help.
  4. Responsible AI development: Companies creating advanced AI models bear responsibility for preventing misuse, including coordinating with utilities to secure power grids.

As OpenAI stated in its September 3 announcement: "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable. Frontier AI can help defenders move faster."

However, Corman cautions against over-reliance on friendly AI agents to combat malicious ones, noting that both sides can be difficult to control within the sensitive confines of OT systems.


Key Takeaways:

  • Humans remain the primary threat to energy systems, amplified by AI capabilities.
  • Legacy infrastructure lacks modern security design and faces patchability challenges.
  • AI serves as a force multiplier, enabling faster and more sophisticated attacks.
  • Defensive strategies must address both technical and organizational aspects, with shared responsibility among governments, AI developers, and utilities.
Read on The Verge ↗ ← Back to News

Comments

No comments yet. Start the discussion.