Humans, Not Rogue AI, Are Still the Biggest Cyber Risk to Energy Systems, Experts Say
Experts say human attackers using AI remain the biggest cyber threat to energy systems as utilities race to keep pace.
The concern predates recent high-profile hacks that renewed fears about AI, including whether advanced models could one day kill all humans. Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology, told The Verge last year that energy systems were already disturbingly vulnerable, at a time when the Department of Homeland Security warned that Iranian actors and sympathizers could target the United States with cyberattacks.
In a recent conversation with The Verge about rogue AI agents orchestrating complex cyberattacks, Corman and other cybersecurity experts said they remain more worried about generative AI in the hands of bad actors than about rogue agents. As technology companies race to build more powerful AI models, utilities will have to strengthen their defenses regardless of who or what starts an attack.
"It's literally any sociopath that wants to [attack] is now more powerful than they used to be," Corman told The Verge. "This has been a force multiplier and continues to grow."
Much of the critical energy infrastructure that keeps lights on, food cold and life-saving devices working in hospitals was never designed to connect to the internet. Power plants typically operate for decades, and the average age of a nuclear reactor in the United States is about 44 years. They were not built with today's cybersecurity risks in mind, making them easy targets for hackers.
Eventually much of that infrastructure was connected to the internet, and fixing the resulting vulnerabilities has been difficult. Some companies that originally designed equipment still used in the power sector have gone out of business, leaving no one to develop software patches for orphaned devices. Even when a patch exists, applying it quickly is another challenge. Operational technology systems that control physical machinery for critical infrastructure may be designed to apply updates only once each quarter or year. Smaller utilities may also lack the resources, staffing and expertise to use the latest defensive measures.
"The true difference from AI is that it's letting adversaries move more quickly — but it's very challenging for those defending the infrastructure to match that pace," Sophie McDowall, a research associate at the Foundation for Defense of Democracies' Center on Cyber and Technology Innovation, told The Verge.
Intent is a key factor in assessing the risks posed by generative AI. When an OpenAI model managed to break out of the company's training parameters to attack AI lab Hugging Face, Rob Denaburg, cybersecurity program senior manager at the American Public Power Association, said some of the sophistication, capabilities and effectiveness were eye-opening and terrifying. The association represents community-owned utilities across 2,000 municipalities.
Denaburg pointed out that even in the Hugging Face hack and similar instances of AI agents breaking into systems they were never supposed to target, the rogue agents remained focused on fulfilling their training goals. If someone trained a model to attack energy infrastructure and agents broke out of the sandbox in that scenario, it would probably be a bigger concern for a utility. That again involves human adversaries with malicious intent.
Historically, adversarial nation-states were considered the biggest cybersecurity threat to critical infrastructure. Corman said they are more disciplined and more capable of carrying out sophisticated cyberattacks. Now, AI is making it easier for less-skilled adversaries to launch an effective assault.
"A bad-actor human can use these tools to be better than they naturally would be to attack things they normally didn't know how to ... because whereas they may not know OT protocols and OT networks and OT strategies, the LLM has read the manuals and does know what to do," Corman said.
Utilities have to be more prepared, and defensive strategies are similar regardless of who the bad actor is, according to The Verge.