Key takeaways
- Because information and operational technology (IT and OT) now share the same connected infrastructure, a cyberattack on either one may carry the same stakes as a physical hazard. It’s no longer just about a data breach.
- Secure systems are the first line of defense; people are the second. In Poland’s December 2025 energy-sector attacks, security software stopped malware at one plant, and the operators’ quick response contained an attack at another. Building that second line takes a workforce skilled across the four disciplines the threat now touches: IT, OT, cybersecurity, and AI.
- Training people to spot fakes isn’t enough on its own. The more promising path is to help them develop habits that don’t depend on any one person spotting a fake, such as verifying requests through separate channels and reporting suspicions, which a large study found could flag new phishing campaigns within minutes.
- The energy sector already trains at scale, from continent-wide grid exercises to yearlong national programs. What’s still scarce, across the industry, is public evidence of which training changes behavior on the job.
My previous two articles made the case for energy cybersecurity from different angles. The first framed cyber threat as a safety issue, arguing that as connected infrastructure brings information and operational technology (IT and OT) together, cyberattacks can harm both data and operations. The other article framed cybersecurity as a sustainability issue, making the case that emissions data is only as trustworthy as the systems that produce it. If regulators, investors, customers, and the public know systems are secure, decarbonization claims will feel credible. Trust will follow.
What neither article addressed is the people responsible for keeping those energy systems secure, an urgent focal point given how fast the threat is growing. Through the first quarter of 2025, energy and utility companies worldwide faced an average of 1,872 cyberattacks per week per organization—an increase of 53% over the year before, according to Check Point Research.
The attack surface keeps widening, too. The US grid spans more than 55,000 substations and 22,000 generators, according to the US Department of Energy (DOE). Across the grid, the North American Electric Reliability Corporation (NERC), a federally designated enforcement authority responsible for the reliability and security of the electrical networks across North America, counted between 23,000 and 24,000 vulnerable points in hardware and software by the end of 2023, and said that number increases by roughly 60 a day.
In this environment, the technologies that help energy companies connect and secure systems also allow attackers to become more sophisticated. Each generation of attack is harder to detect than the last, which makes our first line of defense—maintaining secure systems—even harder. What energy companies need now more than ever is to prepare their workforces to be the second line of defense.
People catch some threats but still need a process
The technical and governance aspects of the first line of defense are well documented, spanning secure-by-design architecture, zero-trust access controls, and standards from bodies such as NERC and the National Institute of Standards and Technology (NIST). The second line—the people working those systems—matters most when an attack is underway. Real incidents illustrate how the lines work together.
In December 2025, attackers struck a large combined heat and power plant (CHP) supplying heat to almost half a million customers, according to CERT Polska, Poland’s national computer emergency response team. Antivirus software missed the wiper malware deployed to destroy plant data, but the plant’s endpoint detection and response software caught and stopped it. The same day, attackers also hit at least 30 wind and solar farms through their grid-connection substations, which are typically unmanned. Many devices there still used default passwords. The attackers used that vulnerability to disable equipment and cut the sites’ communication with the grid operator, though power generation continued.
A follow-up report from CERT Polska revealed a parallel attack on a second, smaller CHP plant serving 50,000 residents. It shut down a steam turbine. There, operators responded quickly enough that the outage was brief and heat supplies were never disrupted. Those examples illustrate the two lines of defense: Systems catch what they’re built to catch, and people respond when an attack gets by those systems.
Evidence beyond Poland’s case points in the same direction, with a caveat. Dragos, a cybersecurity firm that specializes in industrial and energy-sector systems, reviewed its 2025 incident-response cases and found that nearly a third of OT incidents began not with an alert, but with a human noticing something was wrong, something they couldn’t explain. Yet that instinct often runs on chance, not process. The same Dragos review also showed that 82% of organizations have no clear rule for when an unexplained anomaly should prompt a formal investigation.
