Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

Recent high-profile cyberattacks on energy infrastructure have shifted attention toward artificial intelligence as a potential threat, yet human error remains the primary…

By Vane September 20, 2026 1 min read
Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

Recent high-profile cyberattacks on energy infrastructure have shifted attention toward artificial intelligence as a potential threat, yet human error remains the primary vulnerability. Joshua Corman of the Institute for Security and Technology noted that critical systems were already exposed before the latest scares regarding rogue algorithms. Current data suggests that malicious actors, including state-sponsored groups like Iranian hackers, continue to exploit weak human processes rather than sophisticated machine learning models. The Department of Homeland Security has repeatedly warned that these external threats target operational technology through social engineering and credential theft. Security experts argue that while AI tools may assist attackers in the future, the immediate danger stems from flawed configuration and insider negligence. Utilities and grid operators must prioritise human training and access controls over hypothetical AI scenarios. The focus should remain on basic security hygiene to prevent breaches caused by staff mistakes.

  • Most breaches involve stolen credentials rather than automated exploits.
  • Human oversight failures account for the majority of grid incidents.
  • Defence strategies must centre on personnel protocols instead of AI fears.
Scroll to Top