Episode 072: CERT Polska maps a 30-site energy intrusion in detail

Episode Description CERT Polska maps a 30-site energy intrusion in detail Poland's national incident response team published a rare, technically granular account of a multi-stage cyberattack that began in December 2025 and compromised roughly thirty energy facilities, including renewable installations and a combined heat-and-power plant. Investigators traced a chain from VPN compromise through private APN abuse to OT network tunneling across segments many operators still treat as isolated — no threat actor was named. Also this week, AWS disclosed it cannot restore customer data from its Bahrain region or one UAE availability zone after war-related destruction of physical infrastructure, making cross-region replication a hard requirement rather than a best practice. U.S. battery storage additions are on track for a record 24 gigawatts in 2026, nearly double last year's pace. Energy defenders and cloud architects alike have concrete, specific findings to act on this week. ...

September 25, 2026

Episode 071: Google Merges Wiz Into Agentic Defense Platform

Episode Description Google Merges Wiz Into Agentic Defense Platform Google Cloud's biggest announcement from Next '26 is Agentic Defense, a unified security platform combining Google Threat Intelligence, Google Security Operations, and the Wiz cloud security stack into a single offering — and the first tangible enterprise product to emerge from the Wiz acquisition. Alongside it, Cloud Fraud Defense launched to classify traffic by humans, bots, and AI agents, addressing the challenge of distinguishing authorized automation from adversarial automation. Separately, EU AI Act enforcement activated on August second with the AI Office already questioning dozens of companies, and the Electrum threat group struck roughly thirty distributed energy sites in Poland in a coordinated cyberattack. Security and compliance leaders have concrete decisions to act on this week. ...

September 21, 2026

Episode 067: Iran-Linked Attack Shuts Down UK Power Plant

Episode Description Iran-Linked Attack Shuts Down UK Power Plant Iran-linked actors caused an operational shutdown at a small UK power plant following a cyberattack disclosed August 23–24, with The Guardian framing the incident as emblematic of vulnerabilities across smaller UK generating facilities. Confirmed physical operational impact is rare in public reporting, and the attack signals geographic expansion beyond the U.S.-focused advisories most operators have relied on. Separately, supply chain attacks now account for 25 percent of significant cloud incidents — up from roughly 10 percent in the second half of 2025 — with a single compromise of the LiteLLM library affecting an estimated 434,000 CI/CD pipelines. Battery storage is breaking deployment records globally while Wood Mackenzie warns the U.S. grid-scale market could contract by nearly 29 percent in 2026 due to tariffs and policy uncertainty. Generation operators should verify PLC and engineering workstation exposure now, and procurement teams should pressure-test storage timelines against near-term policy risk. ...

September 6, 2026

Episode 066: Governance-First AI Firms Cut Errors Five Times Faster

Episode Description Governance-First AI Firms Cut Errors Five Times Faster KPMG's 2026 Global AI in Finance report finds that organizations embedding governance controls from the start reduced errors by thirty-three percent, compared to just six percent for peers that treated governance as an afterthought — and forty-two percent felt confident scaling their deployments versus fourteen percent without embedded controls. The data makes a concrete operational case: governed teams move faster and make fewer mistakes, not fewer. Separately, FERC issued simultaneous show-cause orders to all six major U.S. grid operators over inadequate large-load interconnection rules for data centers, and Microsoft patched a maximum-severity unauthenticated remote code execution flaw in Entra ID that was already being exploited in the wild. Both stories carry immediate action items for infrastructure and security teams this week. ...

August 23, 2026

Episode 064: Volt Typhoon Reframed as Disruption Threat in Energy Grids

Episode Description Volt Typhoon Reframed as Disruption Threat in Energy Grids Multiple credible analyses now argue that China-linked Volt Typhoon operators embedded in U.S. electric, oil, and gas networks are positioned for disruption, not espionage. Ampyx Cyber's January 2026 whitepaper draws a firm line between data theft and disruptive-intent access, placing Volt Typhoon in the latter category, and the International Institute for Strategic Studies ties the capability to potential Indo-Pacific crisis scenarios. CISA's advisory AA24-038A details living-off-the-land techniques and publishes rare eviction guidance, while the Congressional Research Service has now briefed Congress, moving this beyond classified channels. Also this week, AWS disclosed a twenty-eight-hour recovery from a thermal event in Northern Virginia, and NERC filed a wildfire risk report to FERC that repositions wildfire mitigation as a national grid reliability obligation — both stories carry direct implications for infrastructure planners and operators. ...

August 9, 2026

Episode 055: FERC pushes public disclosure for grid cyber violators

Episode Description FERC pushes public disclosure for grid cyber violators Federal energy regulators are advancing a joint proposal to publicly name utility companies that violate grid cybersecurity standards, ending over a decade of enforcement anonymity. Under the proposed framework, violators facing statutory civil penalties of up to one million dollars per day will also contend with severe reputational exposure. While the utility industry has raised concerns about providing actionable intelligence to potential adversaries, regulators explicitly separated entity identities from sensitive technical vulnerabilities. Compliance teams must immediately prepare for a new era of grid enforcement where cyber failures carry public accountability stakes similar to data breach notifications in other critical sectors. ...

June 21, 2026

Episode 046: Mythos and the Utility Industry: Detection Without a Patch Path

Mythos and the Utility Industry: Detection Without a Patch Path Special edition — June 6, 2026 Anthropic has built a frontier model that can find and chain industrial-grade vulnerabilities, and stood up Project Glasswing — now around one hundred fifty organizations across critical infrastructure — to gate its use. The detectors and hyperscalers are inside the consortium. The equipment OEMs whose firmware is the actual attack surface for the bulk electric system — SEL, ABB, Siemens, Schneider Electric, GE Vernova — are, with a single Hitachi-shaped exception, conspicuously silent. This episode argues the load-bearing question for the grid is not who has access to Mythos; it is what happens between a Mythos finding and a patched protective relay, and the corpus says that pipeline has not been built. ...

June 6, 2026

Episode 042: CISA redefines zero trust for industrial networks

Episode Description CISA redefines zero trust for industrial networks CISA just delivered a definitive zero trust roadmap engineered specifically for operational technology that abandons disruptive IT playbooks in favor of passive discovery. This guidance arrives as utilities execute massive risk mitigation efforts, such as PG and E locking in a nearly nineteen billion dollar wildfire plan after reporting a seventy-five percent reduction in reportable ignitions. In response to compounding industry threats, federal energy regulators are simultaneously stepping up enforcement by attaching heavy disgorgement orders to standard compliance penalties. You must master these new architectural standards to secure critical infrastructure without tripping physical safety systems or facing substantial financial clawbacks. ...

May 31, 2026

Episode 040: NIST formalizes identity standards for autonomous AI

Episode Description NIST formalizes identity standards for autonomous AI The National Institute of Standards and Technology has established the first federal standards initiative for autonomous AI agents. The agency's concept paper explicitly recommends treating software agents as first-class enterprise identities subject to the exact same access controls, provenance, and audit trails as human employees. In response to this regulatory signal, cloud providers are already aligning by offering managed orchestration environments that bring AI workflows inside established compliance boundaries. As organizations push automated operations into production, adopting these guardrails ensures security teams can continuously authorize and track exactly what an agent executes. ...

May 17, 2026

Episode 035: Congress unveils energy cyber bill as grid attacks surge

Episode Description Congress unveils energy cyber bill as grid attacks surge Congress advanced the Energy Threat Analysis Center Act to explicitly combat threat actors like Volt Typhoon targeting American power grids. This legislation follows a 70 percent surge in utility cyberattacks, with over 3,300 industrial organizations compromised last year and average recovery costs surpassing $3.12 million. In response, the Department of Defense issued specialized Zero Trust guidance, while utilities like PG and E launched multibillion-dollar, AI-driven mitigation plans to harden infrastructure. Because hardware procurement and grid upgrades lock in your risk profile for decades, integrating these defenses now is a strict financial imperative to prevent costly operational downtime. ...

April 12, 2026