Security
Cybersecurity for Energy Systems: AI or Human Risk?
Cybersecurity for energy systems faces growing threats, but human error remains a bigger risk than rogue AI, putting business continuity in the balance.
Key takeaways
- Human error remains the greatest cybersecurity risk for energy systems today.
- High-tech AI defenses can fail if staff lack training and security awareness.
- Investing in a strong security culture provides better ROI than chasing AI hype.
AI-generated from the cited source and editorially curated by AINEVERSTOPS. Read our editorial policy →

Evaluating Cybersecurity Priorities Amid AI Fears
Business leaders in the energy sector now face a strategic crossroad: invest heavily in AI defense mechanisms or address the persistent risks posed by human error. Headlines about AI-driven attacks may grab attention, but industry veterans, like Joshua Corman of the Institute for Security and Technology, point to longstanding vulnerabilities. These gaps existed long before artificial intelligence became a boardroom concern. The question has become less about whether AI could one day threaten infrastructure, and more about how to address the human missteps that still open the door to cyberattacks.
Energy Infrastructure: A Target Long Before AI
Discussions of AI 'killing all humans' distract from a reality that predates smart algorithms: energy grids have always been prime targets for cyber criminals. As Corman put it, operators have historically survived "at the appetite of our predators." The sophistication of threats might change, but the fundamental weakness often lies with people—staff who fall for phishing attempts or misconfigure access controls. High-profile warnings from agencies like the Department of Homeland Security, including alerts about possible attacks from Iranian actors, consistently highlight the human factor over machine agency.
Human Error: The Persistent Weak Link
In the scramble to counter theoretical AI threats, many overlook that accidental lapses by trained professionals remain the most likely point of failure. Lax password practices, unpatched software, miscommunication, and a culture reluctant to flag security issues can each set the stage for large-scale disruption. The best machine learning model in the world can't compensate for an employee clicking a malicious link or ignoring a critical update. For executives, the ROI on cybersecurity training and culture-building often dwarfs new tech deployments.
Rethinking Investment: People or Technology First?
The temptation to pour money into AI-based defense tools is understandable. Vendors promise analytics that flag anomalies in real time and automated systems to shut down attacks before they spread. Yet, without a workforce that understands its own role in security, these tools risk becoming expensive band-aids. Corman and other experts argue that resilience starts with people—training, clear protocols, accountability, and a willingness to report missteps without fear of reprisal. Decision-makers must weigh whether their budgets best serve the business by closing human gaps first.
The Real Decision: Building a Human-Centric Security Culture
Choosing where to focus resources—AI or human training—defines not just security posture, but business continuity. Energy sector leaders need to foster a culture in which every employee feels responsible for cybersecurity. This involves regular, realistic drills, transparent communication about threats, and incentives for sound security practices. The allure of high-tech solutions shouldn’t overshadow the proven effectiveness of educated, engaged staff in thwarting both old and evolving threats.
- cybersecurity
- energy systems
- human error
- infrastructure
- ai risk
- business continuity
Source: The Verge AI
Keep reading
Want AI in production at your company?
Tell us about your project: we reply with a free first assessment and the next steps.
Join the Observatory list
Leave your email to hear about new pieces from the Observatory — concise AI analysis from real projects.



