Episode 072: CERT Polska maps a 30-site energy intrusion in detail

Episode Description CERT Polska maps a 30-site energy intrusion in detail Poland's national incident response team published a rare, technically granular account of a multi-stage cyberattack that began in December 2025 and compromised roughly thirty energy facilities, including renewable installations and a combined heat-and-power plant. Investigators traced a chain from VPN compromise through private APN abuse to OT network tunneling across segments many operators still treat as isolated — no threat actor was named. Also this week, AWS disclosed it cannot restore customer data from its Bahrain region or one UAE availability zone after war-related destruction of physical infrastructure, making cross-region replication a hard requirement rather than a best practice. U.S. battery storage additions are on track for a record 24 gigawatts in 2026, nearly double last year's pace. Energy defenders and cloud architects alike have concrete, specific findings to act on this week. ...

September 25, 2026

Episode 067: Iran-Linked Attack Shuts Down UK Power Plant

Episode Description Iran-Linked Attack Shuts Down UK Power Plant Iran-linked actors caused an operational shutdown at a small UK power plant following a cyberattack disclosed August 23–24, with The Guardian framing the incident as emblematic of vulnerabilities across smaller UK generating facilities. Confirmed physical operational impact is rare in public reporting, and the attack signals geographic expansion beyond the U.S.-focused advisories most operators have relied on. Separately, supply chain attacks now account for 25 percent of significant cloud incidents — up from roughly 10 percent in the second half of 2025 — with a single compromise of the LiteLLM library affecting an estimated 434,000 CI/CD pipelines. Battery storage is breaking deployment records globally while Wood Mackenzie warns the U.S. grid-scale market could contract by nearly 29 percent in 2026 due to tariffs and policy uncertainty. Generation operators should verify PLC and engineering workstation exposure now, and procurement teams should pressure-test storage timelines against near-term policy risk. ...

September 6, 2026

Episode 064: Volt Typhoon Reframed as Disruption Threat in Energy Grids

Episode Description Volt Typhoon Reframed as Disruption Threat in Energy Grids Multiple credible analyses now argue that China-linked Volt Typhoon operators embedded in U.S. electric, oil, and gas networks are positioned for disruption, not espionage. Ampyx Cyber's January 2026 whitepaper draws a firm line between data theft and disruptive-intent access, placing Volt Typhoon in the latter category, and the International Institute for Strategic Studies ties the capability to potential Indo-Pacific crisis scenarios. CISA's advisory AA24-038A details living-off-the-land techniques and publishes rare eviction guidance, while the Congressional Research Service has now briefed Congress, moving this beyond classified channels. Also this week, AWS disclosed a twenty-eight-hour recovery from a thermal event in Northern Virginia, and NERC filed a wildfire risk report to FERC that repositions wildfire mitigation as a national grid reliability obligation — both stories carry direct implications for infrastructure planners and operators. ...

August 9, 2026

Episode 062: FERC Puts All Six U.S. Grid Operators on Notice

Episode Description FERC Puts All Six U.S. Grid Operators on Notice The Federal Energy Regulatory Commission opened six simultaneous show-cause proceedings on June 18 against every major U.S. grid operator — PJM, MISO, CAISO, NYISO, ISO New England, and SPP — ordering each to defend or rewrite its rules for connecting large electricity consumers above 50 megawatts. It is the first time FERC has placed all major U.S. markets under simultaneous formal scrutiny on the load side, with full tariff responses due in mid-to-late August 2026. Also this week, inference workloads now represent roughly two-thirds of all large-scale AI compute, the first time inference has overtaken training, reshaping infrastructure planning priorities. And NIST has set explicit post-quantum migration deadlines, with critical infrastructure urged to begin cryptographic inventories now ahead of 2030 deprecation targets. ...

July 26, 2026

Episode 055: FERC pushes public disclosure for grid cyber violators

Episode Description FERC pushes public disclosure for grid cyber violators Federal energy regulators are advancing a joint proposal to publicly name utility companies that violate grid cybersecurity standards, ending over a decade of enforcement anonymity. Under the proposed framework, violators facing statutory civil penalties of up to one million dollars per day will also contend with severe reputational exposure. While the utility industry has raised concerns about providing actionable intelligence to potential adversaries, regulators explicitly separated entity identities from sensitive technical vulnerabilities. Compliance teams must immediately prepare for a new era of grid enforcement where cyber failures carry public accountability stakes similar to data breach notifications in other critical sectors. ...

June 21, 2026

Episode 046: Mythos and the Utility Industry: Detection Without a Patch Path

Mythos and the Utility Industry: Detection Without a Patch Path Special edition — June 6, 2026 Anthropic has built a frontier model that can find and chain industrial-grade vulnerabilities, and stood up Project Glasswing — now around one hundred fifty organizations across critical infrastructure — to gate its use. The detectors and hyperscalers are inside the consortium. The equipment OEMs whose firmware is the actual attack surface for the bulk electric system — SEL, ABB, Siemens, Schneider Electric, GE Vernova — are, with a single Hitachi-shaped exception, conspicuously silent. This episode argues the load-bearing question for the grid is not who has access to Mythos; it is what happens between a Mythos finding and a patched protective relay, and the corpus says that pipeline has not been built. ...

June 6, 2026

Episode 035: Congress unveils energy cyber bill as grid attacks surge

Episode Description Congress unveils energy cyber bill as grid attacks surge Congress advanced the Energy Threat Analysis Center Act to explicitly combat threat actors like Volt Typhoon targeting American power grids. This legislation follows a 70 percent surge in utility cyberattacks, with over 3,300 industrial organizations compromised last year and average recovery costs surpassing $3.12 million. In response, the Department of Defense issued specialized Zero Trust guidance, while utilities like PG and E launched multibillion-dollar, AI-driven mitigation plans to harden infrastructure. Because hardware procurement and grid upgrades lock in your risk profile for decades, integrating these defenses now is a strict financial imperative to prevent costly operational downtime. ...

April 12, 2026

Episode 027: DoD Unveils Grid Security as Ransomware Surges

Episode Description DoD Unveils Grid Security as Ransomware Surges State-linked hackers from Volt Typhoon embed deeply into United States utility networks while a destructive Amazon Web Services data center fire exposes physical weaknesses in cloud architecture. The unprecedented multi-day outage eliminated eighty-four global services, compounding alarm as ransomware attacks against industrial systems simultaneously surged forty-nine percent. In response to these escalating infrastructure dangers, the Department of Defense unveiled its first zero trust framework while utilities like PG and E expanded their automated grid defenses. Engineering and security teams must urgently decouple their cross-region dependencies and deploy localized network segmentation to keep physical facilities operational during targeted disruptions. ...

March 5, 2026

Episode 025: Scale Meets Constraint: Agentic AI, Gigawatt Infrastructure, and a 30% Ransomware Surge

Episode Description Scale Meets Constraint: Agentic AI, Gigawatt Infrastructure, and a 30% Ransomware Surge This week's through-line is scale colliding with limits — and the response shifting from building bigger to orchestrating smarter. Google forecasts agentic security operations centers that cut breach likelihood threefold, while AMD locks in a multi-year, six-gigawatt GPU partnership with Meta. The International AI Safety Report, led by Yoshua Bengio, documents risks that current techniques can't fully eliminate — just as AI-assisted attackers compromise hundreds of FortiGate devices across 55 countries. On the grid, FERC orders PJM to write colocation rules by April 30th as PJM approves an $11.8B transmission expansion, and PG&E commits $73B to grid upgrades while deploying AI from wildfire detection to dynamic line rating. AWS, Azure, and Google Cloud all ship major agent and inference upgrades, while ransomware activity runs 30% above 2025 levels and Chinese APT campaigns target energy infrastructure. ...

March 2, 2026

Episode 021: AI power demand surges force massive grid expansion

Episode Description AI power demand surges force massive grid expansion PJM Interconnection approved an 11.8 billion dollar transmission expansion to support the explosive load growth of new artificial intelligence data centers. The massive infrastructure push follows a stark warning from Harvard’s Belfer Center projecting that US AI facilities alone could consume 90 gigawatts of electricity by 2030. To manage this unprecedented capacity squeeze, federal energy regulators mandated major tariff reforms for co-located generation, while the Trump Administration leveraged 21 billion dollars in broadband funding to preempt state-level AI governance. Technology teams must immediately factor these physical grid limits and shifting compliance rules into their infrastructure budgets, as multi-year transmission delays will inevitably stall enterprise deployments. ...

February 28, 2026