Energy Sector's OT Cybersecurity Talent Gap Widens as Experts Retire
The energy sector faces a critical shortage of Operational Technology (OT) cybersecurity talent, with retiring experts leaving critical infrastructure vulnerable to prolonged disruptions.

The energy sector is grappling with a severe shortage of Operational Technology (OT) cybersecurity talent, a crisis exacerbated by the impending retirement of experienced professionals. This skills gap leaves critical infrastructure, such as chemical plants and refineries, increasingly vulnerable to sophisticated cyberattacks that can lead to extended operational downtime and significant supply chain disruptions. A recent ransomware incident at a chemical plant, initially thought to be contained, resulted in weeks of paralysis due to encrypted systems, demonstrating the profound impact such attacks can have.
Experts like Marco Ayala, technical director for global energy at ABS Consulting, emphasize that cybersecurity in OT environments is fundamentally an engineering problem, directly impacting paramount concerns of reliability, uptime, and safety. The financial stakes are immense, with cyberattacks on U.S. utility companies surging by nearly 70 percent in a single year. Industry estimates from Dragos and Marsh McLennan place potential global OT cyber losses across all sectors at a staggering $329.5 billion, while Waterfall Security reported a 146 percent year-over-year increase in OT sites experiencing attacks with physical consequences.
Despite the escalating risks, cybersecurity budgets within the energy sector often prioritize enterprise IT tools over OT security, with OT security typically receiving only about 20 percent of the allocated funds. This imbalance becomes particularly problematic during recovery operations, where existing plans frequently falter. Shankar Somasundaram, CEO of Asimily, highlights that recovery plans often assume the availability of engineers who possess intimate knowledge of system configurations, knowledge that may be lost with retiring staff.
"I’ve seen plants with a backup of a controller, but the engineer who knew why it was configured the way it was is long gone," Somasundaram explained. "So the backup is restoring a state no one can confirm is actually still correct. Plants end up reverse-engineering their own process under immense pressure (mid-outage!), which is the worst possible time to learn how your plant functions."
Furthermore, the reliance on original equipment manufacturers (OEMs) or integrators for critical system restoration introduces another layer of constraint. The assumption that a quick phone call can resolve issues is often shattered by the reality of waiting weeks for physical on-site support. This dependency can significantly prolong recovery times, turning a manageable incident into a protracted crisis.
The entry points for attackers often lie in less scrutinized areas, such as Internet of Things (IoT) devices. While core OT devices may be well-protected, facility cameras, sensors, and building management systems are frequently treated as afterthoughts. However, these devices can serve as effective launchpads into the broader plant network, often because they are not monitored as closely as critical operational systems.
Ayala also points to the accumulation of temporary workarounds, unlocked panels, and long-standing "temporary" network connections as common blind spots. These physical and network security oversights, often overlooked due to a lack of recent incidents, represent significant vulnerabilities. When confronted, plant staff may dismiss these issues, but Ayala counters that the absence of a cyber event thus far is not proof of safety, but rather evidence that the site has not yet been seriously tested.
The convergence of OT and IT security challenges, coupled with a shrinking pool of experienced OT cybersecurity professionals, creates a precarious situation for the energy sector. Addressing this requires a strategic shift towards prioritizing OT security, robust training and knowledge transfer programs, and a comprehensive understanding of all connected assets, including those often relegated to the periphery.