- The question is no longer whether they will be targeted, but whether their defenses — technical, organisational, and procedural — will hold when they are.
Energy infrastructure has become one of the most heavily targeted sectors in the global cyber threat landscape.
Whether it is a natural gas pipeline, an offshore wind farm, or the control systems that keep power flowing into millions of homes, the underlying reality is the same: these assets represent high-value targets, and adversaries — state-sponsored and criminal alike — are increasingly capable of compromising them.
A new report from GlobalData, the London-based intelligence and analytics firm, argues that the convergence of geopolitical turbulence, rapid digitisation, and the proliferation of generative AI tools is reshaping the threat environment faster than most energy companies are adapting to it.
The report’s central message is unambiguous: cybersecurity can no longer be treated as an IT compliance function — it must become a board-level strategic priority embedded across the entire operational value chain.
The energy sector’s vulnerability is not a matter of neglect so much as structure. Energy companies operate sprawling, interdependent ecosystems that span exploration, production, transmission, distribution, and retail — each with its own set of digital systems, many of which were designed decades ago and never intended to be connected to the internet.
As GlobalData’s Strategic Intelligence report makes clear, the ongoing convergence of information technology (IT) and operational technology (OT) is connecting these legacy assets to modern grid technologies, dramatically expanding the attack surface.
A compromise that begins in a corporate email system can, in a converged environment, find its way into the industrial control systems that physically operate pipelines, refineries, and power plants.
The numbers are striking. CISA reported that in December 2025, a coordinated cyberattack targeted more than 30 renewable energy sites across Poland — wind farms, solar installations, and a combined heat and power plant — damaging remote terminal units and wiping human-machine interface data in what analysts have described as one of the most destructive OT-focused attacks on European energy infrastructure in recent years.
The incident carried the hallmarks of a Russian government-linked group, and CISA subsequently issued an alert urging all critical infrastructure operators to review their OT and ICS security postures.
Poland was not an isolated case. A 2023 CSIS study found that the energy sector experienced nearly 40 percent of all cyberattacks across critical infrastructure sectors, and the pattern has only intensified since. During the first half of 2025 alone, more than 3,000 cyberattacks targeted critical infrastructure globally, with energy and government systems among the most affected.
The supply chain problem
What makes the energy sector’s risk profile especially complex is its dependence on vast third-party ecosystems. Oil and gas majors do not build or maintain their own drilling equipment, pipeline monitoring software, or grid management platforms — they buy them from hundreds of specialised vendors, each of whom represents a potential entry point.
Ravindra Puranik, Oil and Gas Analyst at GlobalData, frames this directly: “Energy companies depend on extensive third-party ecosystems, making supplier vulnerabilities a major cyber risk that can spread into IT and OT environments.” He points to attacks that exploited widely used file-transfer tools — software that companies use to move sensitive documents between systems — as a prime example of how a single vendor compromise can cascade across an entire industry.
The data supports this concern. Third-party involvement in breaches rose from 15 per cent to 30 per cent in 2025, and 44 per cent of zero-day attacks that same year targeted managed file transfer systems — the very category of software Puranik highlights.
The MOVEit file transfer platform breach, which affected more than 620 organisations globally, demonstrated just how efficiently single supply chain vulnerability can be weaponised at scale. For energy companies, where vendors routinely handle seismic data, drilling plans, pipeline schematics, and grid telemetry, the stakes are particularly acute.
Puranik’s prescription is detailed and practical: “Mitigation requires stronger vendor governance, such as continuous monitoring, standards, segmentation, least privilege, audits, and joint incident response.”
Each element of that list matters. Continuous monitoring means energy companies must stop treating vendor risk assessments as one-time onboarding exercises and instead build systems that track supplier security posture in real time.
Segmentation and least-privilege access — the principle that a vendor should only have access to the systems and data it strictly needs — are technical controls that can limit the blast radius when a supplier is compromised. Joint incident response planning ensures that when something does go wrong, the company and its vendors are not improvising coordination under crisis conditions.
Generative AI reshapes threat landscape
GlobalData’s report highlights a dimension of the cybersecurity challenge that has accelerated dramatically in the past eighteen months: the role of generative AI in empowering adversaries. Large language models and AI-assisted coding tools are now being used by threat actors to generate convincing phishing emails at scale, write and adapt malware faster than human operators could manage, and automate the reconnaissance phase of attacks — scanning networks for vulnerabilities with a speed and thoroughness that would have required entire teams just a few years ago.
The net effect is a compression of defenders’ response windows. Where security teams once had hours or days to detect and contain an intrusion, they may now have minutes. Puranik’s conclusion reflects this urgency: “Oil and gas firms should invest in specialized cybersecurity services that provide continuous monitoring and rapid response, expert validation, and strong operational readiness.”
The recommendation is significant precisely because it acknowledges that in-house security teams — however well-resourced — can no longer keep pace with the volume and velocity of AI-augmented attacks alone. Specialised managed security service providers, particularly those with OT-specific expertise, are becoming an operational necessity rather than a discretionary expense.
OT as the real battlefield
The Poland attack crystallised something that cybersecurity practitioners in the energy sector have been warning about for years: OT environments are no longer isolated, and they are now the primary target. Unlike a corporate data breach — which can be costly and reputationally damaging — a successful OT compromise can cause physical destruction, environmental damage, and, in the worst case, loss of life.
CISA’s alert following the Poland incident emphasized that the attack was not sophisticated in the sense of exploiting zero-day vulnerabilities. Instead, it exploited well-known gaps: insecure remote access configurations, insufficient network segmentation between IT and OT environments, and a lack of monitoring on OT networks that allowed the adversary to move laterally and execute destructive commands without detection.
The lesson is that energy companies do not necessarily need to defend against exotic, nation-state-grade exploits — they need to get the basics right, consistently, across their entire operational footprint.
GlobalData’s report situates this challenge within the broader trends reshaping the energy industry: digitalisation, the rise of distributed energy resources (DERs) such as rooftop solar and battery storage, grid modernisation initiatives, and the growing complexity of global supply chains. Each of these trends creates new digital connections between systems, and each connection represents a potential attack vector.
From compliance to resilience
Puranik closes with an observation that reflects a broader shift in how the energy industry thinks about cybersecurity: “Cybersecurity is integral across the oil and gas value chain, for securing data, safeguarding asset integrity, and preventing financial losses.” The phrasing matters. It treats cybersecurity not as a technical discipline confined to the IT department, but as a value-chain-wide concern that touches everything from exploration data to pipeline integrity to the financial bottom line.
For equipment manufacturers and oilfield service providers, the implications extend to product-level security. Puranik argues that these firms should “add product-focused services such as secure development support and security audits/certification to reduce supply chain risk and maintain customer trust.”
The logic is straightforward: if a drilling control system or a turbine monitoring platform ships with security vulnerabilities baked in, no amount of network-level defense will fully mitigate the risk.
