Episode 072: CERT Polska maps a 30-site energy intrusion in detail

Episode Description CERT Polska maps a 30-site energy intrusion in detail Poland's national incident response team published a rare, technically granular account of a multi-stage cyberattack that began in December 2025 and compromised roughly thirty energy facilities, including renewable installations and a combined heat-and-power plant. Investigators traced a chain from VPN compromise through private APN abuse to OT network tunneling across segments many operators still treat as isolated — no threat actor was named. Also this week, AWS disclosed it cannot restore customer data from its Bahrain region or one UAE availability zone after war-related destruction of physical infrastructure, making cross-region replication a hard requirement rather than a best practice. U.S. battery storage additions are on track for a record 24 gigawatts in 2026, nearly double last year's pace. Energy defenders and cloud architects alike have concrete, specific findings to act on this week. ...

September 25, 2026

Episode 067: Iran-Linked Attack Shuts Down UK Power Plant

Episode Description Iran-Linked Attack Shuts Down UK Power Plant Iran-linked actors caused an operational shutdown at a small UK power plant following a cyberattack disclosed August 23–24, with The Guardian framing the incident as emblematic of vulnerabilities across smaller UK generating facilities. Confirmed physical operational impact is rare in public reporting, and the attack signals geographic expansion beyond the U.S.-focused advisories most operators have relied on. Separately, supply chain attacks now account for 25 percent of significant cloud incidents — up from roughly 10 percent in the second half of 2025 — with a single compromise of the LiteLLM library affecting an estimated 434,000 CI/CD pipelines. Battery storage is breaking deployment records globally while Wood Mackenzie warns the U.S. grid-scale market could contract by nearly 29 percent in 2026 due to tariffs and policy uncertainty. Generation operators should verify PLC and engineering workstation exposure now, and procurement teams should pressure-test storage timelines against near-term policy risk. ...

September 6, 2026

Episode 064: Volt Typhoon Reframed as Disruption Threat in Energy Grids

Episode Description Volt Typhoon Reframed as Disruption Threat in Energy Grids Multiple credible analyses now argue that China-linked Volt Typhoon operators embedded in U.S. electric, oil, and gas networks are positioned for disruption, not espionage. Ampyx Cyber's January 2026 whitepaper draws a firm line between data theft and disruptive-intent access, placing Volt Typhoon in the latter category, and the International Institute for Strategic Studies ties the capability to potential Indo-Pacific crisis scenarios. CISA's advisory AA24-038A details living-off-the-land techniques and publishes rare eviction guidance, while the Congressional Research Service has now briefed Congress, moving this beyond classified channels. Also this week, AWS disclosed a twenty-eight-hour recovery from a thermal event in Northern Virginia, and NERC filed a wildfire risk report to FERC that repositions wildfire mitigation as a national grid reliability obligation — both stories carry direct implications for infrastructure planners and operators. ...

August 9, 2026

Episode 055: FERC pushes public disclosure for grid cyber violators

Episode Description FERC pushes public disclosure for grid cyber violators Federal energy regulators are advancing a joint proposal to publicly name utility companies that violate grid cybersecurity standards, ending over a decade of enforcement anonymity. Under the proposed framework, violators facing statutory civil penalties of up to one million dollars per day will also contend with severe reputational exposure. While the utility industry has raised concerns about providing actionable intelligence to potential adversaries, regulators explicitly separated entity identities from sensitive technical vulnerabilities. Compliance teams must immediately prepare for a new era of grid enforcement where cyber failures carry public accountability stakes similar to data breach notifications in other critical sectors. ...

June 21, 2026

Episode 046: Mythos and the Utility Industry: Detection Without a Patch Path

Mythos and the Utility Industry: Detection Without a Patch Path Special edition — June 6, 2026 Anthropic has built a frontier model that can find and chain industrial-grade vulnerabilities, and stood up Project Glasswing — now around one hundred fifty organizations across critical infrastructure — to gate its use. The detectors and hyperscalers are inside the consortium. The equipment OEMs whose firmware is the actual attack surface for the bulk electric system — SEL, ABB, Siemens, Schneider Electric, GE Vernova — are, with a single Hitachi-shaped exception, conspicuously silent. This episode argues the load-bearing question for the grid is not who has access to Mythos; it is what happens between a Mythos finding and a patched protective relay, and the corpus says that pipeline has not been built. ...

June 6, 2026

Episode 042: CISA redefines zero trust for industrial networks

Episode Description CISA redefines zero trust for industrial networks CISA just delivered a definitive zero trust roadmap engineered specifically for operational technology that abandons disruptive IT playbooks in favor of passive discovery. This guidance arrives as utilities execute massive risk mitigation efforts, such as PG and E locking in a nearly nineteen billion dollar wildfire plan after reporting a seventy-five percent reduction in reportable ignitions. In response to compounding industry threats, federal energy regulators are simultaneously stepping up enforcement by attaching heavy disgorgement orders to standard compliance penalties. You must master these new architectural standards to secure critical infrastructure without tripping physical safety systems or facing substantial financial clawbacks. ...

May 31, 2026

Episode 035: Congress unveils energy cyber bill as grid attacks surge

Episode Description Congress unveils energy cyber bill as grid attacks surge Congress advanced the Energy Threat Analysis Center Act to explicitly combat threat actors like Volt Typhoon targeting American power grids. This legislation follows a 70 percent surge in utility cyberattacks, with over 3,300 industrial organizations compromised last year and average recovery costs surpassing $3.12 million. In response, the Department of Defense issued specialized Zero Trust guidance, while utilities like PG and E launched multibillion-dollar, AI-driven mitigation plans to harden infrastructure. Because hardware procurement and grid upgrades lock in your risk profile for decades, integrating these defenses now is a strict financial imperative to prevent costly operational downtime. ...

April 12, 2026

Episode 030: White House unveils AI rule override as grid risks surge

Episode Description White House unveils AI rule override as grid risks surge The White House unveiled a sweeping blueprint to override state artificial intelligence laws just as United States utility cyber incidents surge roughly seventy percent. To combat escalating physical and digital threats, infrastructure operators like PG and E are rapidly deploying over 630 predictive cameras to mitigate operational risks. In response to this mounting complexity, authorities finalized a hard August 2026 deadline demanding documented operational proof of model transparency to gate audits and procurement. Technology leaders must validate their system inventories and establish compliance guardrails immediately, or they risk losing access to critical enterprise contracts. ...

March 21, 2026

Episode 019: PG and E Surges Capacity to Meet AI Data Center Demand

Episode Description PG and E Surges Capacity to Meet AI Data Center Demand Pacific Gas and Electric launched a massive nine point six gigawatt data center pipeline while energizing its first facility in San Jose to support the explosive growth of artificial intelligence. Data centers are projected to consume four point four percent of national electricity this year, while utilities plan a record eighty-six gigawatts of new generation to prevent a capacity crisis. Federal regulators are responding with permanent cybersecurity mandates as MIT researchers warn that physics-aware AI is now required to keep the evolving energy grid stable. These structural shifts dictate if your local grid can reliably handle the massive power demands of the AI era without triggering rate hikes or blackouts. ...

February 28, 2026

Episode 013: Autonomy Surges: Trust Lags, Infrastructure Unveils Gaps

Episode Description Autonomy Surges: Trust Lags, Infrastructure Unveils Gaps Automated systems are accelerating across all sectors, from AI-driven algorithm discovery to utility infrastructure, creating a sharp tension as security teams face an AI trust paradox in automated response, hesitant to hand over control despite machine-speed attacks. The practical risk of this rapid scaling became clear when the 15-hour Amazon Web Services outage generated over six million reports, triggered by an internal DNS race condition, highlighting acute concentration risk. Regulators and standards bodies pivot aggressively, with the Transportation Security Administration formalizing mandatory pipeline cybersecurity requirements effective May 2025 and the IEC 62443 standard pushing industrial networks toward zero trust microsegmentation. These governance gaps and architectural shifts mean organizations must urgently invest in robust failure containment and user-validated explainable AI to ensure automated speed doesn't compromise critical safety. ...

November 2, 2025