The findings are part of DNV’s report, Energy Cyber Priority 2023: Closing the gap between awareness and action. It included a survey with 601 energy professionals between February and March 2023 across Europe, Asia, Middle East, Africa, North America, and Latin America.
The report found that 77% of organisations consider cybersecurity a business risk, and 64% say their infrastructure is more vulnerable than ever. However, only 36% of organisations are confident they have made sufficient investments in securing their technology.
Geopolitical uncertainty was also a major driver for energy professionals in reckoning with the vulnerability of their operational technology. The report found that 78% cited the geopolitical landscape for their growing awareness of cybersecurity.
“Just as governments and energy companies know they need to transition faster to meet the targets of the Paris Agreement, they also know they need to urgently step up action on cyber security,” said Ditlev Engel, CEO, Energy Systems at DNV.
“And the two are connected – safety and security are enablers of the clean energy technologies that need to be deployed and operated at scale in the coming decades.”
The energy sector saw 24% of all cyber-attacks in the UK in 2021 according to an IBM report, more than the financial or manufacturing sector.
The energy sector is a traditionally ‘easy’ target for hackers due to it being heavily reliant in distributed, complex networks, giving it a larger attack surface for malicious actors. Cyber-attacks on the energy sector can be devastating and cause ripple effects into other sectors.
DNV’s report calls for stricter cybersecurity measures for the sector. Examples include the EU’s new national law to be set into place by 2024 which will see essential services such as energy organisations face tougher regulation on the security of their network systems.
Additionally, the US Department of Energy is developing a bi-partisan plan to sauce standards in creating a cyber-informed engineering strategy.
Recommended
- Rural Scotland Beset by the Slowest Broadband Speeds in the UK
- Cyber Attack Targets UK HR Provider — BBC, Boots, British Airways Impacted
- UK at Risk of Losing Position as Tech Leader, Warns techUK
Nearly half (49%) of survey respondents cited government regulation as a top three driver in increasing organisational budgets for cybersecurity. However, Jalal Bouhdada, Global Segment Director, Cyber Security at DNV says companies should seek to go deeper than merely hitting the marks of government regulations.
“Compliance doesn’t guarantee security,” he says. “It takes the right mindset, company culture, and access skills to ensure regulation-driven investment translates into greater cyber resilience.”
To read the report, click here.





