Back
23 July, 2026

Conflict, regulation and AI: reshaping cybersecurity in Europe’s energy sector

In December 2025, a coordinated cyberattack struck more than 30 energy sites across Poland, affecting close to 500,000 residents. Attributed with moderate confidence to the ELECTRUM group, the assault was halted before it could cause lasting damage, but it demonstrated an adversary’s ability to reach operational technology (OT) systems at scale across distributed infrastructure.

The recent closure of the Strait of Hormuz has shown what large-scale energy disruption actually costs; a cyberattack could deliver the same outcome of disruption, economic damage and political fallout. Protecting the systems that keep the lights on is more important than ever.

These drivers formed the backdrop to a recent SANS Policy Roundtable in Brussels, which convened senior figures from NATO, European institutions, national governments, energy companies and cybersecurity firms. Four converging forces dominated the discussion: a deteriorating threat landscape for the energy sector, an expanding regulatory architecture, the double-edged role of AI, and traditional cybersecurity skills in need of adaptation.

A threat environment of “stable instability”

Attacks on European energy infrastructure have risen since 2024, with the sector’s post-Ukraine investment making it a prime target for state-sponsored and financially motivated actors alike. ENISA’s Threat Landscape report, covering 4,875 incidents in 2025, confirms that threat groups are collaborating specifically to target EU critical infrastructure.

Two recent incidents help define the threat in concrete terms. In Poland, ELECTRUM moved away from targeting centralised control systems toward the distributed edge of the grid, corrupting OT configurations beyond recovery. In Sweden, a Russian-linked group targeted a thermal power plant in an attempt to disrupt heating supply. Sweden’s Civil Defence Minister stated that actors that once relied on denial-of-service attacks are now targeting OT systems, with potentially significant consequences for society.

During the roundtable, participants characterised this as a period of “stable instability”, continuous vulnerability mapping and pre-positioning below the threshold of a “digital 9/11.” They distinguished between energy producers, increasingly exposed to agentic AI weaponisation through escalation and exfiltration, and distributors, more vulnerable to proximity attacks such as those carried over Bluetooth.

Structural weaknesses, legacy devices, poor IT/OT segmentation and opaque supply chains, remain the most attractive attack surface.

A regulatory “legal tsunami”

Europe’s regulatory framework has expanded fast, and the pace is not slowing. NIS2, whose transposition deadline expired in October 2024, requires board-level accountability, mandatory incident reporting, and national control frameworks. Yet, several member states have still not fully transposed it, creating uneven obligations across the single market.

The revision of the Cybersecurity Act (CSA2) is expected to introduce a supply chain security framework that could bar energy firms from sourcing equipment from high-risk vendors, while sector-specific rules such as the Network Code on Cybersecurity add further layers. Roundtable participants describe the cumulative result as a “legal tsunami” that diverts resources from actual security.

Participants argued that cybersecurity should be treated as a shared responsibility across the ecosystem, but warned that overlapping obligations are causing the compliance burden to pile up, especially in specific use cases such as smart meters.

In the context of the implementation of the Cyber Resilience Act, they questioned whether Europe has sufficient conformity assessment capacity to implement the legislation at scale and urged pragmatism on certification and support for international mutual recognition.

AI: threat multiplier and defensive tool

AI is reshaping cybersecurity faster than any single regulation. Frontier models are accelerating vulnerability discovery and exploitation, and the UK National Cyber Security Centre expects a vulnerability patch wave. This is an acute problem especially for the energy sector, where legacy or end-of-life energy systems cannot be updated. Yet AI also offers defensive gains, from threat-intelligence analysis and alert triage to source-code scanning and automated containment that compresses the window between compromise and response.

At the roundtable, participants agreed that AI is fundamentally reshaping the cybersecurity landscape by accelerating the scale, speed, and overall automation of cyber operations. AI-enabled tooling is already being used for phishing personalisation, automated reconnaissance, malware adaptation, and exploit development, with the interval between disclosure and exploitation shrinking.

The conversation also highlighted operational challenges created by the rapid growth in AI-generated vulnerability reporting and management. Participants noted that organisations are increasingly struggling to prioritise and validate large volumes of vulnerability reports, many of which may be low-quality or difficult to assess operationally.

Frontier models create few genuinely new threats, but they democratise vulnerability discovery and exploitation – an acute danger in a sector defined by legacy products. This leaves defenders only a narrow but vital window to harden systems before offensive capabilities mature.

Traditional skills no longer fit for purpose

These pressures are directly affecting the people expected to manage them. The SANS 2026 Cybersecurity Workforce Research Report finds regulation is reshaping hiring in real time: 68% of organisations report a moderate-to-extreme regulatory impact on recruitment, and 54% have created new specialist roles purely to meet compliance demands. The nature of the shortage has changed as well: asked to choose between lacking the right skills and simply lacking enough people, 60% of organisations now point to the skills gap as the greater problem – up from a near-even split (52%) a year earlier.

AI is also changing how junior professionals enter the field: as it automates entry-level tasks, their work is shifting from manual analysis toward oversight, validation and AI-augmented investigation.

Participants at the roundtable framed this as a shift from a quantitative shortage to a qualitative capability gap, with organisations lacking professionals able to operate across cybersecurity, AI, regulation, and OT systems. It seems clear that AI is reshaping cybersecurity roles faster than education systems, training frameworks, and workforce development initiatives can adapt. As a result, roundtable speakers called for dynamic skills frameworks and hands-on, simulation-based learning.

In light of emerging risks, including AI-enabled threats, operational technology security, and post-quantum cryptography, participants discussed the broader resilience implications of workforce shortages, concluding that cybersecurity skills gaps should increasingly be viewed as a strategic resilience issue rather than solely a recruitment challenge.

The narrow window

Cybersecurity in Europe’s energy sector is now a strategic resilience challenge, shaped in equal measure by geopolitics, AI acceleration, supply chain dependencies, and workforce readiness.

The window to invest in defensive AI, streamline an overloaded regulatory landscape, and rebuild the workforce around hybrid expertise is open, but narrow, and Europe has already glimpsed the cost of failing to keep the lights on.


Contact us

Need a problem solved?

Our dedicated experts, located around the world, are here to help.