Energy and utilities

Protect the systems that keep power and water flowing.

In energy and water, a cyber incident can reach the systems that control physical supply. We help operators keep corporate IT and operational technology apart, meet NIS2, the UK NIS Regulations, and sector rules for each regulated entity, and introduce AI into operations under human control.

Situations we help with

Across electricity generation, transmission, and distribution; gas and hydrogen; water and waste water; and district heating and renewables.

  • Operational technology and corporate IT share network paths, and nobody can say with confidence how far an intrusion in one could reach the other.
  • Your regulator expects a Cyber Assessment Framework assessment, and the evidence behind several outcomes is thin or out of date.
  • Group entities operate in several Member States, and the NIS2 position of each has not been confirmed.
  • Remote access for suppliers and maintenance contractors has grown without a single view of who can reach which control systems.
  • Teams want to use AI for forecasting or maintenance, and there is no agreed rule for when a person must approve what it recommends.

The challenges

Operational technology meets corporate IT

Control systems that run generation, networks, and treatment were designed for reliability, and connecting them to corporate networks and the cloud can carry risk into physical processes. Changes need planning around safety and operating constraints.

Long-lived assets and legacy systems

Equipment can stay in service for decades, so some systems cannot be patched quickly or replaced without major outages. Protection then depends on separation, monitoring, and controlled access.

Suppliers and remote access

Vendors, integrators, and maintenance contractors can need remote access to control systems, and each connection is a route in unless it is governed.

Overlapping regulation

Operators can face NIS2 or the UK NIS Regulations, sector rules such as the EU network code on cybersecurity for electricity, and their regulator's own assessment approach, each with its own evidence expectations.

The International Energy Agency reported that weekly cyberattacks on utilities worldwide more than doubled between 2020 and 2022.

Source: International Energy Agency, 2023

AI in energy and utilities

Demand and generation forecasting

The value
Better balancing of supply, demand, and storage.
What needs governing
Forecasts that drive operational decisions without validation, and no clear owner when a model drifts.

Predictive maintenance

The value
Fewer unplanned outages and better use of field teams.
What needs governing
Models that need data from control systems, opening new connections into operational technology.

Network and customer operations

The value
Faster handling of faults, enquiries, and switching.
What needs governing
Recommendations acted on without human approval, and customer data used outside agreed purposes.

AI Factory Design sets the rules for data access, approval, and human control across these uses, so AI can move from pilots into operations without opening new routes into control systems. It is part of our AI Governance and Transformation practice.

Regulation that may apply

NIS2 (EU)

Applies to
Energy (electricity, district heating and cooling, oil, gas, and hydrogen), drinking water, and waste water are sectors of high criticality, where entities meet the size thresholds in each Member State's law.
What it asks
The management body approves the cybersecurity risk management measures, oversees their implementation, and undergoes training. A significant incident requires an early warning to the CSIRT or competent authority without undue delay and within 24 hours of becoming aware.
Timing
Applies through national law. The transposition deadline was 17 October 2024, and Member States have adopted their laws at different times.

UK NIS Regulations

Applies to
Operators of essential services in UK electricity, oil, gas, and drinking water that meet the designation thresholds.
What it asks
Appropriate and proportionate security measures, which sector regulators assess using the Cyber Assessment Framework, and notification of a NIS incident no later than 72 hours after becoming aware of it.
Timing
In force since May 2018. The Cyber Security and Resilience Bill, introduced to Parliament in November 2025, would update the regime.

EU network code on cybersecurity (electricity)

Applies to
Electricity undertakings identified as high-impact or critical-impact entities for cross-border electricity flows.
What it asks
Common minimum cybersecurity requirements, risk assessment, monitoring, reporting, and crisis management for cross-border electricity flows.
Timing
Adopted in March 2024 as Delegated Regulation (EU) 2024/1366 and in force since June 2024, with obligations phased in over the following years.

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.