OT Cyberattacks: Energy Sector Faces $329 Billion in Risks

A Dragos report reveals the scale of cyber vulnerabilities in global energy infrastructures. Potential losses reach historic highs.

Share:

Comprehensive energy news coverage, updated nonstop

Annual subscription

8.25£/month*

*billed annually at 99£/year for the first year then 149,00£/year ​

Unlimited access • Archives included • Professional invoice

OTHER ACCESS OPTIONS

Monthly subscription

Unlimited access • Archives included

5.2£/month*
then 14.90£ per month thereafter

FREE ACCOUNT

3 articles offered per month

FREE

*Prices are excluding VAT, which may vary depending on your location or professional status

Since 2021: 35,000 articles • 150+ analyses per week

The global energy sector faces an unprecedented cyber threat that could generate up to $329.5 billion in losses in an extreme scenario. This estimate comes from the 2025 OT Security Financial Risk Report published by Dragos Inc., the global leader in cybersecurity for operational technology (OT) environments. The study, conducted by Marsh McLennan’s Cyber Risk Intelligence Center, represents the first statistical analysis quantifying the financial risks of OT cyber incidents. Indirect losses, often overlooked in traditional models, affect up to 70% of OT-related breaches, with $172.4 billion attributed to business interruptions alone.

Critical vulnerabilities exploited at scale

Recent incidents confirm the severity of these financial projections. The ransomware attack against Halliburton in August 2024 generated $35 million in direct losses and forced the partial shutdown of systems at this $23 billion valued company. RansomHub, the group allegedly responsible for this cyberattack, demonstrated malicious actors’ ability to paralyze global oil giants. In January 2024, the FrostyGoop malware struck a Ukrainian municipal energy company, depriving more than 600 apartment buildings of heating for two days during sub-zero temperatures. This attack illustrates how Modbus TCP industrial control systems can be compromised with immediate physical consequences for civilian populations.

American water infrastructures have become prime targets for state-sponsored groups. The Cyber Army of Russia Reborn (CARR), linked to the Russian GRU military intelligence’s Sandworm group, caused a water tank overflow in Muleshoe, Texas in January 2024. The intrusion was facilitated by a password unchanged for ten years, revealing basic negligence in critical infrastructure security. The cities of Abernathy, Hale Center, and Lockney suffered similar attacks, demonstrating a coordinated campaign against American water distribution systems.

A geopolitical escalation with major economic consequences

Analysis of 2024 data reveals a qualitative transformation in OT cyber threats. While the number of attacks increased only marginally, from 72 in 2023 to 76 in 2024, the physical impact exploded with 1,015 disrupted sites versus 412 the previous year, a 146% increase. Nation-state attacks with physical consequences tripled, driven by Chinese, Russian, and Iranian campaigns. Three new malware strains specific to industrial control systems (ICS) were discovered in 2024, equaling half the total discovered during the previous fourteen years.

The Forescout report reveals that industrial automation protocols have become preferred attack vectors. Attacks on these protocols climbed from 71% to 79% between 2023 and 2024, with Modbus dominating at 40% of incidents, followed by Ethernet/IP at 28%. Threat actors increased their presence by 93% in the energy sector, 71% in manufacturing, and 55% in healthcare. This exponential progression is accompanied by increased sophistication in attack methods and unprecedented physical disruption capability.

Quantified security controls to reduce exposure

The Dragos report identifies three priority OT cybersecurity controls with their potential for financial risk reduction. Incident response planning enables average risk reduction up to 18.5%. Defensible architecture can reduce exposure by 17.09%, while ICS network visibility and monitoring offer protection up to 16.47%. These percentages, based on tens of thousands of simulations and a decade of breach data, provide executives with concrete metrics to justify OT cybersecurity investments.

Regulatory implications intensify with the European NIS2 and CER directives coming into force in late 2024, imposing cybersecurity measures on more than 400,000 companies. In the United States, the Transportation Security Administration (TSA) issued binding directives for the pipeline sector following the 2021 Colonial Pipeline attack that disrupted 45% of the East Coast’s fuel supply. Energy companies must now quantify their cyber risks to meet Securities and Exchange Commission (SEC) reporting requirements, notably the 8-K rule on cyber incident disclosure. This regulatory evolution transforms OT cybersecurity from a technical cost center into a financially measurable strategic imperative, redefining investment priorities for the global energy sector.

Texas-based energy solutions provider VoltaGrid secures record mixed financing to expand its decentralised power generation portfolio, primarily targeting hyperscale data centres.
Kuwait's IMCC and Egypt's Maridive have formalised a joint venture based in Abu Dhabi to expand integrated offshore marine operations regionally and internationally.
In New York, Chevron outlines its long-term vision following the Hess integration, focusing on financial stability, spending reduction, and record production to consolidate investor confidence.
Facing surging computing needs, US tech leaders are hitting an energy wall that slows down data centre construction and revives demand for gas and coal.
NextNRG's monthly revenue reached $7.39mn in October, more than doubling year-over-year, driven by the expansion of its technology platforms and energy services across the United States.
The Canadian group posted record Q3 EBITDA, sanctioned $3bn worth of projects, and confirmed its full-year financial outlook despite a drop in net income.
OMS Energy is accelerating investments in artificial intelligence and robotics to position itself in the growing pipeline inspection and maintenance sector, a strategic segment with higher margins than traditional equipment manufacturing.
Duke Energy is set to release its third-quarter results on November 7, with earnings forecasts pointing upward, supported by strong electricity demand, new rate structures and infrastructure investments.
Engie maintains its 2025 earnings guidance despite falling energy prices and weaker hydro output, relying on its performance plan and a stronger expected fourth quarter.
The funding round led by Trident Ridge and Pelion Ventures will allow Creekstone Energy to launch construction of its hybrid-generation site designed for AI-optimised data centres.
The US group reported a $877mn operating loss for fiscal year 2025, impacted by $3.7bn in charges related to project exits and restructuring.
SLB has unveiled Tela, an agentic artificial intelligence technology designed to automate upstream processes and enhance operational efficiency at scale.
Gibson Energy reported record volumes in Canada and the United States, supported by the commissioning of key infrastructure and a cost reduction strategy.
Norwegian provider TGS will mobilise its marine seismic resources for at least 18 months for Chevron under a three-year capacity agreement covering exploration and development projects.
Eversource Energy rebounded in the third quarter with a net profit of $367.5mn, driven by revenue increases in electric distribution and a sharp reduction in offshore wind-related losses.
Ameresco posted a 5% increase in quarterly revenue, supported by stronger project execution and sustained demand for energy infrastructure solutions.
US-based Primoris posted record quarterly revenue of $2.18bn, driven by strong momentum in its Energy and Utilities segments, and raised its earnings guidance for the full year 2025.
Energy group Constellation proposes a massive investment in electricity generation and storage, with a planned capacity of 5,800 megawatts to meet rising energy demand in Maryland.
Danish firm Aegir Insights extends its Aegir Quant™ platform to onshore wind, solar, storage and hybrid assets, strengthening its investment intelligence offering for developers and investors.
TotalEnergies has released its Energy Outlook 2025 report, outlining three scenarios for the global energy system’s evolution and the economic implications of consumption and production trends through 2050.

All the latest energy news, all the time

Annual subscription

8.25£/month*

*billed annually at 99£/year for the first year then 149,00£/year ​

Unlimited access - Archives included - Pro invoice

Monthly subscription

Unlimited access • Archives included

5.2£/month*
then 14.90£ per month thereafter

*Prices shown are exclusive of VAT, which may vary according to your location or professional status.

Since 2021: 30,000 articles - +150 analyses/week.