Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Human actions remain an important cybersecurity risk for energy systems, but the available evidence does not show that people are a bigger threat than rogue AI, AI-assisted attackers, or non-AI technical attacks. A widely cited human-factor statistic covers breaches across industries, not energy organizations. Energy-specific guidance describes a broader risk picture that includes operational technology, software, supply chains, and physical access.

What the evidence says about humans and energy-sector risk

“Human risk” does not mean that employees are usually malicious. It can include an employee tricked by social engineering, an accidental mistake, or a deliberate insider threat. These are different behaviors and call for different safeguards.

Verizon’s 2024 Data Breach Investigations Report found that 68% of breaches involved a non-malicious human element. That figure describes Verizon’s global breach dataset; it is not an energy-sector sample and does not measure what share of energy-system risk is caused by people. CISA’s insider-threat guidance, in turn, addresses deliberate threats and recommends that organizations involve HR professionals in multidisciplinary threat-management teams. It does not establish that ordinary employees are the dominant threat.

The comparison in the headline therefore remains unproven. The evidence here supports treating human-linked pathways as material, not ranking them first across the energy sector.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What “rogue AI” can mean—and why the distinction matters

“Rogue AI” is too broad to describe a single attack method. In its initial 2024 assessment of AI in the energy sector, the U.S. Department of Energy (DOE) separated several risk categories:

  • Unintentional AI failure: an AI system behaves incorrectly or unreliably, potentially affecting a process that depends on it.
  • Attacks against AI: an adversary targets an AI system or its inputs.
  • Hostile uses of AI: an attacker uses AI as part of malicious activity.
  • AI software supply-chain compromise: a weakness or compromise in software used to build or operate AI introduces risk.

These mechanisms differ from both a worker’s mistake and a malicious insider. DOE’s April 29, 2024 assessment was explicitly an initial, interim assessment; the announcement said an update was expected by the end of that year. The available evidence does not establish whether a later assessment was published, so the 2024 document should not be treated as a final current ranking of threats.

How the main threat paths differ

Energy organizations need to consider more than one kind of actor or system. A useful comparison is the pathway involved, the layer it may affect, and what the cited evidence can establish.

Threat path What it can involve What the evidence establishes
Accidental human involvement A person is deceived by social engineering or makes an error; the affected environment could include corporate IT or systems connected to operations. Verizon’s 2024 figure is global and cross-industry, not energy-specific. It does not quantify the risk to energy operations.
Malicious insider A person with authorized access deliberately misuses it. CISA recommends coordinated threat-management work that can include HR. CISA’s guidance supports a mitigation program; it does not show that insiders are the biggest energy-sector threat.
External attacker using non-AI methods An attacker targets accounts, software vulnerabilities, networks, or operational technology (OT), including industrial control systems (ICS). A joint CISA, FBI, and DOE advisory documents state-sponsored campaigns against U.S. and international energy organizations from 2011 to 2018. Those historical campaigns illustrate attack paths, not their present-day prevalence.
AI-related failure or attack An AI system fails unintentionally, is attacked, is used by a hostile actor, or is affected through its software supply chain. DOE’s initial 2024 assessment catalogs these risk categories but does not rank them against human error, insider activity, or other cyber threats.

The operational context matters. DOE’s electricity-sector guidance is intended for organizations involved in generation, transmission, distribution, and marketing, as well as supporting organizations. NIST’s utility cybersecurity guide describes situational awareness across OT, IT, and physical-access systems. An incident involving an energy organization can therefore raise reliability or operational concerns as well as familiar information-security concerns; a general breach statistic alone cannot describe that exposure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What recent breach figures do—and do not—show

Verizon’s 2026 Data Breach Investigations Report page reports that 31% of breaches started with software vulnerabilities and that mobile social-engineering attacks had a 40% higher click rate than traditional email phishing. The report’s incident window was November 1, 2024, through October 31, 2025. These figures are not energy-sector-specific, and they do not settle whether humans, AI, or another attack path is the largest risk to energy systems.

The figures also use different measures: one describes how breaches started, while the other compares click rates for two forms of social engineering. Neither shares a common denominator with the 68% human-element figure in Verizon’s 2024 report. They should not be combined into a ranking.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why a people-only defense is inadequate

Training can help people recognize deception, but energy-sector guidance calls for layered controls that also address accounts, networks, operational environments, and organizational risk. The joint CISA, FBI, and DOE advisory recommends measures including IT/ICS segmentation, multifactor authentication (MFA), and management of privileged accounts. These controls reduce reliance on a person always making the right choice: segmentation can limit paths between environments, MFA adds a check beyond a password, and privileged-account management constrains powerful access.

DOE’s electricity subsector Cybersecurity Risk Management Process guideline, developed with NIST and NERC and released May 23, 2012, treats cybersecurity as part of enterprise risk management. It frames risk as something organizations manage through informed decisions, rather than something they can eliminate entirely. NIST Special Publication 1800-7, published August 7, 2019, describes a modular example for utility situational awareness across OT, IT, and physical access; NIST says it does not endorse the example products.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Limit pathways: segment IT and ICS environments rather than assuming an office account should reach operational systems.
  • Protect sensitive access: use MFA and manage privileged accounts deliberately.
  • Maintain visibility: consider OT, IT, and physical access together when building situational awareness.
  • Keep assessing and sharing: DOE describes continuous threat and vulnerability assessment and information sharing as parts of energy-sector preparedness.
  • Coordinate insider-risk work: involve relevant functions, including HR where appropriate, instead of treating every employee as a suspect or relying on security-awareness training alone.

DOE reports that current participants in its Cybersecurity Risk Information Sharing Program (CRISP) provide power to over 75 percent of customers in the continental U.S. electricity subsector. That is a program-coverage figure, not a measure of security outcomes or of how frequently human actions cause incidents.

How to read the headline

People can be involved in incidents through mistakes, social engineering, or deliberate insider activity, and energy organizations should mitigate those pathways. But the evidence cited here does not demonstrate that humans are the biggest cybersecurity risk to energy systems—or that rogue AI has displaced other threats. The more defensible conclusion is that human, technical, AI-related, supply-chain, and physical risks need to be assessed together, with controls suited to the systems and consequences involved.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.