Post - Blog

The best-governed sector in recent survey keeps losing data anyway

  • 10 days ago (2026-08-18)
  • Junior Isles
Cyber security 10
Frank Balonis

Frank Balonis , Field CISO at Kiteworks

EU-PVSEC 2026
More info

EU-PVSEC 2026

In the same 12-month window, the threat actor Sarcoma exfiltrated 498 GB of data from a Gulf petrochemical services firm, and Akira stole 163 GB from a Pacific energy company. Both were confirmed data theft, not system disruption. Halliburton, hit separately by a RansomHub ransomware attack, disclosed a $35 million loss. None of these were physical-safety incidents; they were failures to protect the sensitive data and systems that energy and utilities companies depend on.

That is not a run of bad luck. It is the sharpest evidence yet of a pattern building across energy and utilities for two years. Verizon's 2026 Data Breach Investigations Report recorded 638 incidents in the utilities sector and 597 with confirmed data disclosure, with system intrusion, basic web application attacks, and social engineering accounting for 94% of utility breaches.

External actors were behind 97% of those breaches, and an espionage motive was present in 71% of cases, a share far higher than almost any commercial industry. None of this is theoretical. It is the operating environment utility CISOs now manage week to week.

The third-party version of this problem is not hypothetical either. A Florida-based engineering firm serving Tampa Electric, Duke Energy Florida, and American Electric Power was breached, with the attacker offering roughly 139 GB of the firm's engineering data for sale. Verizon separately found that third-party involvement in breaches rose 60% year on year across all industries, reaching 48% of confirmed cases – a trend energy and utilities is structurally more exposed to than most sectors, given its dependence on a small number of specialised operational technology vendors for switchgear, inverters, substation controllers and SCADA software.

What makes this uncomfortable reading for the sector is that energy and utilities is not the laggard here. It is, on paper, the leader.

Kiteworks' Data Security and Compliance Risk: 2026 Annual Survey Report measured security and AI governance maturity across more than 450 organisations in ten industries. Energy and utilities organisations recorded the second-highest Data Security Maturity Score of any sector, behind only financial services, and the highest AI Governance Maturity Score of any sector measured. The report attributes this to operational technology security requirements that already demand the kind of control deployment other industries are only beginning to adopt. On a composite readiness index combining both scores, energy and utilities led every other sector in the survey.

Leading the pack, however, is not the same as being ready. The same survey found that 70% of organisations, across all sectors, have not deployed an AI kill switch at all. Sixty-seven percent lack tamper-evident audit trails, the specific evidence type investigators and auditors examine to confirm records have not been altered after the fact.

Half cannot produce a complete data access audit record within one business day, and 10% admit they cannot produce one at all. These are not abstract governance gaps. They are the exact evidence an energy regulator, or a national cyber authority investigating a breach, would ask for within hours of it becoming public.

Vendor governance is just as thin. The survey also found that 27% of organisations have either never evaluated whether their AI vendors use organisational data for model training, or rely solely on paper attestations with no technical verification behind them. Attestation is not evidence, and it does not hold up well against a vendor ecosystem where IBM has recorded a nearly fourfold rise in major supply-chain incidents over five years, and against a subcontractor whose engineering data is already on a criminal marketplace.

The instinct in response is usually another policy or another round of training. The survey data argues against both. Cybersecurity spending has almost no relationship with actual control deployment: high-spending organisations scored barely half a point higher on maturity than the full sample average. What separated the small minority that had genuinely closed the gap was architecture, not budget – classification that enforces downstream controls rather than just labelling data, logging that reaches every channel carrying sensitive information including AI systems, and kill switches and access revocation tested before an incident forces the question.

For UK and European operators, the regulatory clock is already running rather than approaching. NIS2's incident notification timelines and the EU AI Act's logging and human oversight obligations for high-risk systems are enforceable now, and UK operators with EU exposure, or those benchmarked against NIS2 by the National Cyber Security Centre, face the same expectation in substance if not always in statute. IEC 62443 remains the reference architecture for OT security, and operators with North American assets carry NERC CIP obligations on top.

None of these frameworks are satisfied by a policy sitting in a governance folder. They are satisfied by continuous, technically verifiable evidence: the same evidence most organisations in the survey still cannot produce inside a working day.

Energy and utilities earned its lead in this year's data honestly, through operational technology security requirements that forced discipline other sectors have avoided. But RansomHub did not check Halliburton's maturity score before taking $35 million, and the actor selling a subcontractor's engineering data did not check Duke Energy Florida's audit trail policy first. Leading a maturity index and stopping the next data breach are two different achievements. Right now, only one of them is proven.