Geopolitical tensions are rising, and critical sectors like utilities and power are increasingly in the crosshairs of cybercriminals. The reason is simple: the services they provide are essential, tightly connected to other critical sectors, and any disruption can have direct consequences for national security.
The Swiss Federal Electricity Commission (ElCom) has warned that in extreme cases, a cyberattack could cause a large-scale blackout with serious consequences. This is the point where cybersecurity goes beyond just being an IT issue and it becomes a matter of national security.
This urgency is reflected in the regulatory landscape in Switzerland. Since April 1, 2025, operators of critical infrastructure such as energy or drinking water suppliers must report cyberattacks within 24 hours. The message is clear: utilities need to treat cybersecurity as a top priority.
But the real question is: how can utility operators avoid ever getting to that point? Can the defense tools available today truly secure such a vast and interconnected ecosystem, and most importantly protect society as a whole? The hard truth is no.
Utility operators used to operate their own networks completely detached and isolated from the Internet. This is no longer the case. Apps to charge electric cars, manage solar panels, control heat pumps but also remote operations of critical infrastructures, have introduced new threat vectors and attack surfaces from the Internet against highly critical infrastructure.
Without rethinking the very foundation of these attack vectors, it is hard or even impossible to guarantee the resilience and security of such infrastructure.