Siemens Energy

Increasing Cyberthreats in the Time of AI

"Our world -- including our digital world -- is at an inflection point, where the decisions we make today will determine the direction of our world for decades to come." Those words come from the Biden Administration's proclamation on cybersecurity awareness month, and as a cybersecurity practitioner who works with energy sector clients around the world, they resonate deeply. Already caught in a cybersecurity arms race, the advancement of AI technologies significantly escalates cyber threats against energy infrastructure. More than ever before, critical infrastructure operators face an existential need to strengthen cybersecurity and respond as a community to global trends that threaten stability.

For years, three trends have converged to amplify the importance of cybersecurity in the energy sector. First, a digital revolution has transformed the energy business from mostly analog and air-gapped to mostly digitized and network-connected. Second, the energy transition, with its drive toward cleaner, more efficient energy sources, has made energy infrastructure both intrinsically digital and more broadly distributed, with solar panels, car chargers, smart meters, and other infrastructure requiring a more decentralized paradigm for how electricity is made and controlled. Third, cyberattacks have escalated, with criminals and nation-states taking advantage of the increasing number of network-connected devices to inject ransomware and lay the groundwork for disrupting rival economies.

The result of these trends has been something of a clandestine arms race that puts infrastructure operators on the front lines. Groups with nation-state backing have successfully compromised electricity utilities in the United States without those utilities becoming aware of the intrusion. Attackers facing hardened targets have sometimes circumvented defenses by penetrating suppliers and contractors. Ransomware attacks have resulted in the disruption of fuel movement to the Atlantic coast, with corresponding shocks that rippled through the economy and brought Presidential-level response. Regulators have increased their emphasis on visibility, detection, and monitoring for large critical infrastructure operators. 

This year, a fourth trend arose -- generative AI. The full consequences of AI in the ongoing cybersecurity arms race remain to be seen, but some consequences are easy to imagine or already felt. For example, AI that can write convincing prose means higher-quality phishing attacks become easier to generate. The same processing power that underpins AI capabilities will make password protections even more fragile. Generative AI that can write or modify code reduces the skill requirements for malicious actors and may enable more sophisticated attackers to circumvent some types of defenses that rely on recognizing known malicious code.

"Sharing best practices and threat information can help strengthen weak links in the global energy ecosystem"

All of the consequences above are already squarely within the capabilities of AI systems available for free today. As AI technologies advance and become more capable, or as attackers find ways to leverage other AI capabilities like voice mimicry to formulate new attacks, defenders will need to keep up.

That's why the White House call to action this month resonates so deeply for me. The decisions made this year will matter for decades. Companies need to take action to protect themselves and to set up sustainable systems that anticipate continuous innovation and escalation in the threat environment. I firmly believe that cross-sector and international collaboration must be part of the solution. Sharing best practices and threat information can help strengthen weak links in the global energy ecosystem. Sharing threat information at machine-like speeds may be necessary to answer the challenges posed by AI. Suppliers and manufacturers will need to build in cybersecurity by design, including thinking through how to ensure that equipment fails toward a safe state when compromised. Regulatory and certification bodies will need to establish clear standards that enable suppliers, customers, and governments to clearly communicate about their cybersecurity maturity and how it is measured and monitored.

The kind of economic prosperity that we have come to expect in the United States can only exist when the energy systems that underpin it remain reliable. That's what is at stake as we work to secure critical infrastructure against attack. We know attackers will appropriate any new technology advancement and will seek and exploit any new vulnerability. The White House is right that this is a time of unprecedented innovation and unprecedented threats. It is our responsibility to answer this moment, this inflection point, with innovations of our own.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.