Energy infrastructure's shift toward connected digital systems is expanding the attack surface available to cybercriminals and state-sponsored hackers, according to a new GlobalData strategic intelligence report on cybersecurity in the energy sector.
The report draws out the central tension: the same IT/OT convergence that improves operational efficiency and supports grid modernisation creates new pathways for attack. When information technology systems and operational technology — which controls physical assets directly — connect, a compromise on the IT side can propagate to the physical side. That is a different class of risk to a data breach, and one with outsized potential to disrupt essential services.
Geopolitical pressure is adding urgency. Energy critical national infrastructure is a documented target for state-linked cyber espionage, and generative AI is compressing the time available to defenders: attackers are using it to automate reconnaissance and attack planning that previously required greater time and specialisation.
The supply chain angle sits alongside direct attack risk. Third-party vendors with access to energy operators' systems have historically been a reliable entry point — the SolarWinds breach demonstrated the pattern at scale. Energy companies' extensive OT maintenance ecosystems present similar exposure. GlobalData recommends continuous vendor monitoring, network segmentation, least-privilege access and regular audits as mitigation layers.
The report covers cybersecurity across oil and gas as well as the power sector, benchmarking efforts from operators including Equinor, Saudi Aramco and TotalEnergies.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter