Cybersecurity and energy, a binomial that is consolidated

Few industries combine such a high level of digitalization with such direct social responsibility as the energy sector. Gas, electricity and water networks sustain the daily lives of millions of people. For this reason, more and more companies in the sector are placing cybersecurity at the center of their corporate strategy.

Distributors, international organizations and experts agree that the answer is to integrate cybersecurity into the culture and processes of the entire value chain. A good example of this approach are the cybersecurity conferences that some energy distributors have begun to organize with their teams and collaborating companies. In meetings of this type – such as those recently promoted by Nedgia, the Naturgy group’s gas distributor – they seek more than just updating protocols, they are, according to the company, about building a shared culture of digital risk management.

The central idea that usually guides these forums is clear, cybersecurity is not a one-time project, but a structural part of the way an energy company operates and provides service. Any incident in its systems can have a direct impact on the networks, supply and the territory it serves, which reinforces the need for a shared and coordinated vision between all actors in the ecosystem.

In the case of Nedgia, this vision has been translated into five principles that guide daily action, which in the opinion of the energy company translate into “the five Cs”, raise awareness, communicate, care, continue and comply. Five axes that well summarize the spirit with which the sector approaches cybersecurity today, as a combination of organizational culture, solid processes and individual and collective responsibility.

A strategic risk

Cybersecurity, in the opinion of Nedgia representatives, is today a strategic company risk. The combination of investments, technical protection and surveillance measures, together with the continuous training and awareness of the teams, is key in a context in which it is advisable to never take for granted that the systems are secure. This is also remembered by the European Union Agency for Cybersecurity (ENISA), which in its Threat Landscape 2025 report places digital infrastructures and services among the sectors most monitored by European authorities, in an ecosystem of constantly evolving threats.

The supply chain deserves special attention, a critical element in the digital ecosystem. Suppliers and collaborators are part of the operating environment and must protect access, identities and devices with the same level of demand as the company itself. Cybersecurity, in this sense, is also a “partnership” relationship based on trust and co-responsibility.

Supply chain protection is not only a good practice, but a regulatory and strategic obligation for companies providing essential services. Supervising, training and coordinating the ecosystem is key to continue advancing in the prevention of risks such as the theft of information, the unavailability of outsourced processes or the spread of incidents. Along these lines, Fortinet’s 2026 Energy Cybersecurity Outlook report highlights the importance of continuing to close the gap between the maturity of operational technology systems and information technology systems, one of the areas of improvement that the sector has already identified.

For an entity providing essential services, like Nedgia, the availability of critical assets is non-negotiable. Industry data confirms that a significant portion of incidents originate from third parties, making supply chain protection a strategic priority.

Challenges and priorities

The energy sector is already identifying the main challenges that will mark its cybersecurity agenda in the coming years, the intensive use of artificial intelligence to design and also to anticipate more sophisticated attacks, the secure management of identities and accesses, the governance of AI in projects and processes, and the need to balance digitalization, agility and control. The International Energy Agency (IEA) emphasizes that the transition towards renewable sources, supported by highly digitalized systems such as wind, solar parks or smart grids, makes it even more necessary to advance in parallel in the strength of digital defenses.

In this context, for Nedgia the progress made in areas such as identity management, strengthening supply chain governance or the development of business continuity plans mark a solid foundation. Looking to the future, the priorities are to integrate cybersecurity from the design, eliminate unnecessary access, standardize connection models and truly test operational resilience.