Energy Digital August 2026 | Page 80

TECH & AI

“ ORGANISATIONS ARE OFTEN TRYING TO HANDLE THESE CYBER THREATS THEMSELVES WITHOUT THE CORRECT KNOWLEDGE”

Warren O’ Driscoll Head of Security Practice, Services & Solutions for the UK & Ireland NTT DATA
The double threat of IT / OT convergence and AI-powered cyberattacks has expanded the attack surface, while also widening that gap between physical engineering teams out in the field, IT teams back in the office, and the cybersecurity teams engaged when it goes wrong. For critical infrastructure providers like energy and utilities firms, combination makes the current threat landscape particularly challenging.
Q. IF 90 % OF BOARDS SAY CYBER IS A PRIORITY, WHY IS PROGRESS STILL SLOW?

» Organisations are often trying to handle these cyber threats themselves without the correct knowledge or subject matter expertise, which ends up with them spinning their wheels.

Boards will acknowledge that cyber is important, because it absolutely is. But with technologies like AI developing so quickly, a lot of the risks and attacks hitting businesses today are things they’ ve never faced before. That means it ends up taking a lot longer to move cybersecurity forwards within the business. The combination of lack of knowledge and lack of communication can lead to reputational damage that affects a business for a long time.
Q. WHY IS SUPPLY CHAIN CYBER RISK SUCH A CRITICAL ISSUE FOR THE SECTOR?

» Ultimately, it’ s because there’ s an implicit trust in upstream suppliers. Just because a supplier is a major tech firm with a well-known name, people default to the assumption that it’ s trustworthy. But that rarely involves any actual validation of how hardened that supplier’ s security posture is.

Popular suppliers upstream in the software supply chain are increasingly becoming targets for cyberattacks, and with our reliance on such technology giants only growing, businesses really need to take a closer look at where their data and software are coming from.
You can’ t run a business without third parties, but organisations need to get much more clinical about understanding what it is that they’ re bringing into their organisations, as well as the potential impacts that could arise if it turns out that they are compromised.
80 August 2026