Posts from this author will be added to your daily email digest and your homepage feed.
Before recent high-profile hacks raised the specter of AI possibly “killing all humans,” our energy systems were already disturbingly vulnerable to cyberattack — and the risk is growing.
“We were always prey. We were just kind of surviving at the appetite of our predators,” Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology (IST), told me last year. At the time, I was preoccupied with a Department of Homeland Security warning that Iranian actors and sympathizers could target the US with cyberattacks.
Last week, I called Corman up to chat about recent incidents of rogue AI agents orchestrating their own complex cyberattacks. Even AI executives are talking about whether the technology they’re building could grow so out of control that it triggers an apocalypse. If there is now a 10 percent chance of artificial intelligence one day killing all humans, as some AI developers warn, surely there’s a chance it could knock our lights out in the meantime?
“Any sociopath that wants to [attack] is now more powerful than they used to be.”
But when I spoke to Corman and other cybersecurity experts, they were still more worried about generative AI in the hands of bad actors than they were about rogue agents. As tech companies race to build ever more powerful AI models, utilities will similarly have to shore up their defenses — no matter who or what initiated the attack.
“It’s literally any sociopath that wants to [attack] is now more powerful than they used to be,” Corman tells me. “This has been a force multiplier and continues to grow.”
Much of our critical energy infrastructure — keeping the lights on in our homes, food cold in our refrigerators, and life-saving devices working in hospitals — was never designed to connect to the internet. The lifespan of a power plant is typically decades long. The average age of a nuclear reactor in the US is about 44 years. They weren’t constructed with today’s cybersecurity risks in mind, making them easy targets for hackers.
Eventually much of this infrastructure did connect to the internet. It’s been difficult to fix any resulting cybersecurity vulnerabilities ever since. Some of the companies that originally designed the equipment still in use in the power sector have gone out of business, leaving no one behind to develop a software patch for those orphaned devices. Even when there is a patch available, applying it in a timely manner is another challenge. Unlike IT software upgrades, operational technology (OT) systems that control physical machinery for critical infrastructure might only be designed to apply updates once each quarter or year. Smaller utilities might also lack the resources, staffing, and know-how to use the latest defensive measures.
“The true difference from AI is that it’s letting adversaries move more quickly — but it’s very challenging for those defending the infrastructure to match that pace,” says Sophie McDowall, a research associate at the Foundation for Defense of Democracies’ Center on Cyber and Technology Innovation.
... continue reading