Human intent, machine speed: the potent new cyber threat facing critical infrastructure
© Shutterstock
Malicious bots currently account for a third of all web traffic. Now, hackers are targeting these ‘bad’ bots at vulnerable critical infrastructure systems…
Everyone remembers the famous 'swordsman' scene from Indiana Jones and the Lost Ark. Indy faces off against a warrior who performs an elaborate pre-fight ritual with his sword. A bored-looking Indy draws his gun and shoots him. Battle over.
Is there a metaphor here for the fight taking place between cybersecurity teams in the critical infrastructure (CI) space and their attackers? Could be.
We might think of chief information security officers (CISOs) as the swordsman technician – developing complex defences that have to be tested and deployed, and maybe even cleared with a regulator. Then along come cyber criminals with no such operational constraints. They simply take aim and fire.
And now, the gap between the two sides is growing even wider. Why? Because the hackers have machine help. They are sending in malicious AI-enhanced bots to do the work for them. With their automated scripts, these robotic agents can probe thousands of CI assets simultaneously and on a massive scale.
Bad bots are on the march
The challenge of ‘human-speed defence vs machine-speed attacks’ is one facing cybersecurity teams in every industrial sector. Today, bad’ bots account for 32 percent of all internet activity. It's also getting easier for criminals to access this malicious agentic tech. Cybercrime-as-a-service, offered via the dark web, gives any non-technical cybercriminal the ability to commit sophisticated attacks. With a simple subscription, they can perform credential stuffing, automated scraping, form-jacking, API data exploitation and more to order.
In short, AI-enhanced bots are doing work that previously required skilled human know-how.
So, is the CI space more vulnerable to AI-powered bot attacks than other verticals? The evidence contained in Thales's report suggests it might be. It says the sector is actively embracing digital transformation (DT). As a result, CI organisations are now highly connected. They’re managing vast data resources in real time, and shifting rapidly to cloud-based models (see below.)
The two sides of digital transformation
On the upside, this DT innovation is delivering dramatic improvements in areas such as customer service, the user experience, safety, operating efficiency and return on investment. It is accelerating environmental progress too – reducing CO2 emissions and enabling better use of scarce natural resources.
The regrettable downside of DT is its impact on security. The new cloud models and remotely connected IoT devices give automated attackers the opportunity to probe the attack surface at scale. In CI, four specific factors are accelerating this exposure:
- The fusion of legacy OT systems with new cloud-native environments
- The creation of digital twins that replicate physical assets, using data supplied by permanently connected IoT sensors
- Hybrid environments that combine on-premises and cloud resources
- Legacy CI assets spread across different physical locations (thanks to M&A activity).
The threat is real – and potentially ruinous
Real-life attacks are already happening. In July 2026, The US Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) stated that water utility companies in seven states had reported incidents in the space of just a few days, and that some of the activity degraded water operations. It described how cyber attackers had targeted remote Programmable Logic Controllers (PLCs) to change IP addresses and re-set passwords.
The impact of cyber crime like this can be ruinous in a sector as strategically important to wider society as CI. According to an IBM-Ponemon Institute Report, the average cost of an attack in the energy sector in 2025 was predicted to be $4.83 million. Another report estimates a cyber attack against the US power grid could cost the US economy more than $1trn and leave 93 million people without power. And don’t forget identity theft, since many CI organisations store the personal data of millions of customers and end users.
Causes for concern?
Of course, CI security teams are working hard to address the new bot-enabled cyber threats. Industry data suggests they are making progress too. In 2021, 37 percent said they had experienced a data breach in the previous 12 months. By 2025, this figure had dropped to 15 percent.
But even if the volume of incidents has fallen, it seems that the underlying fear of future attacks has not. According to the Thales report, CI leaders remain acutely aware of their organisational vulnerability. It reveals that 22 percent of CI execs say they have “little or no confidence in identifying where their data is stored” while 79 percent believe that some of their OT devices are internet-exposed.
Falling data breaches and rising concerns? How can both realities be true? Maybe because they're not reflecting the same thing. The reported decline in breaches reflects the strength of CI organisations in terms of their security strategy and regulatory compliance. The worry about exposure reflects the ongoing fear that attackers can still get in.
Man and machine – the hybrid menace
The takeaway is clear. CI organisations need a strong technical foundation to secure the applications, data and identity credentials that reside on their increasingly connected ecosystems. Regulations, standards and frameworks provide a good foundation for this protection. But they should be the product of an effective cybersecurity strategy – not the driver. Compliance can only demonstrate that requirements have been met. It does not necessarily reflect what an attacker can see.
In the world of machine automation, it seems certain that the cyber threat to CI will proliferate. Bots will attack in swarms. They will probe defences and adapt their tactics. The agentic danger is real and serious. But we should always remember that a bot is only ever acting on a prompt written by a human. The combination of man and machine is the real threat. For CI leaders, it’s time to stop thinking about the attacker as a person. Instead, they must consider a hybrid enemy – one that can attack at a scale and speed no purely manual defence can ever match.
How the critical infrastructure space is going digital
The critical infrastructure sector is scaling up its investment in digital transformation to make its operations more efficient – and its customer service more user-friendly. Industry data reflects the speed and scale of this transition. Highlights include:
- Utilities are projected to invest $129 billion in the Internet of Things by 20321
- The energy sector will increase its spending on big data by 69 percent by 2029
- 49 percent of CI organisations have fully embraced cloud-native architectures, including energy and industrial sectors where OT is critical
- 16 percent of all user access to CI organisations now comes via websites, apps, and AI-enabled chatbots
- 26 percent of CI organisations plan to integrate AI into their core products in the next 12 months.