insight / 1 February 2026
The Defender's Terrain
The AI and cybersecurity debate has settled into a comfortable but misleading equilibrium. Both camps miss the structural asymmetries AI amplifies.
The debate about artificial intelligence and cybersecurity has settled into a comfortable but misleading equilibrium. The optimists argue that AI will help defenders as much as attackers—better detection, faster response, smarter prioritisation. The pessimists warn of AI-powered attacks outpacing human defenders. Both camps miss what actually matters: the structural asymmetries that AI amplifies, and the one lever that could genuinely shift the balance.
A year ago, the conventional wisdom held that AI assistance would “net out”—attackers would get smarter tools, defenders would get smarter tools, and the underlying dynamic would remain unchanged. That analysis was always superficial, and the electricity sector is now learning why. The problem is not that defenders lack access to AI. The problem is that the game itself favours offence, and AI makes that imbalance worse.
Consider the fundamental asymmetry. A grid operator must protect every substation, every SCADA link, every telemechanics controller, every vendor remote access pathway. An attacker needs to find one weakness. This has always been true, but AI changes the economics dramatically. An adversary can now run thousands of AI instances probing for vulnerabilities around the clock. They face no fatigue, no shift changes, no compliance burden, no change management process. The attacker’s AI fails cheaply and iterates quickly. The defender’s AI must be right everywhere, all the time, while operating within the constraints of a regulated environment where false positives disrupt operations and unexplained actions fail audits.
There is a deeper constraint asymmetry that rarely surfaces in discussions of AI security. The major AI providers—Anthropic, OpenAI, Google—spend substantial resources preventing their models from assisting with attacks. Anthropic reports dedicating roughly five percent of inference costs to safety classifiers. This is responsible, but it creates an odd dynamic. Defenders using commercial AI tools pay that safety tax. Adversaries using unconstrained open-source models, or jailbroken instances of commercial models, do not. The tools designed to secure critical infrastructure are handicapped in ways the tools used to attack it are not.
The electricity sector faces particular challenges. Operational technology environments run on asset lifecycles measured in decades. A substation commissioned in 2010 cannot be meaningfully defended with 2026 AI capabilities—it lacks the instrumentation, the connectivity, the architectural flexibility. Meanwhile, attackers probe these legacy systems with the latest techniques. The Poland attacks in December demonstrated this precisely: adversaries using Industroyer derivatives—malware with a decade of evolution behind it—targeted telemechanics controllers that many operators had never considered part of their security perimeter. The attackers iterate faster than the infrastructure can adapt.
What, then, can actually shift the balance? The usual answers are necessary but insufficient. Shared threat intelligence helps, but mostly at the indicator level—hashes, IPs, domains—rather than at the level of tactics and techniques that truly matter. Collective defence is valuable, but coordination across competing utilities is slow and constrained by commercial sensitivities. Better detection is essential, but detection is inherently reactive. None of these approaches address the structural advantages that attackers enjoy.
The genuinely novel opportunity lies in terrain manipulation. Defenders control something attackers do not: the environment itself. A grid operator knows which substations are real. An attacker probing from outside must discover this through reconnaissance. In a traditional security model, defenders try to prevent that reconnaissance or detect it when it happens. In a terrain-manipulation model, defenders actively corrupt the attacker’s understanding of the environment.
What does this look like practically? Consider an AI system generating synthetic substations—complete with realistic SCADA interfaces, plausible DNP3 traffic patterns, believable operator activity, and detailed documentation. These honeypots consume attacker reconnaissance time. They inject false positives into attacker targeting. They create uncertainty about which assets are real and which are decoys. When an attacker compromises a synthetic substation, defenders learn their techniques in a controlled environment without risking real assets.
This is not a new concept. Deception technologies have existed for decades. But they have never achieved scale for a simple reason: maintaining realistic deceptions is labour-intensive. A honeypot that looks fake is worse than useless—it signals to attackers that defences are unsophisticated. Creating and maintaining convincing deceptions for an environment as complex as electricity grid operations was prohibitively expensive. AI changes that calculus. A system that can generate realistic OT traffic, simulate operator behaviour, and adapt to attacker probing can create and maintain deceptions at scale that would have required dedicated teams.
The strategic logic is compelling. Traditional security economics favour attackers because they can probe many targets cheaply while defenders must protect everything. Deception at scale reverses this. Every hour an attacker spends mapping a fake substation network is an hour not spent compromising real assets. Every false trail followed represents wasted adversary resources. Every technique revealed against a honeypot is a technique neutralised before it reaches production systems. The goal is not to make attacks impossible—that has never been achievable—but to make reconnaissance expensive and targeting uncertain.
There are practical obstacles to address. Regulatory frameworks for electricity may not contemplate intentionally deceptive elements in grid operations. Integration with existing security operations centres requires new playbooks. The line between deception and operational confusion must be carefully managed—defenders must know which assets are real even as attackers cannot. These are engineering and governance problems, not fundamental barriers. Organisations that solve them gain a genuine asymmetric advantage.
The electricity sector is navigating an uncomfortable transition. The clean energy revolution has multiplied attack surfaces. Nation-state adversaries have demonstrated willingness and capability to probe grid infrastructure. AI amplifies the structural advantages that attackers already enjoyed. In this environment, the traditional defensive playbook—detect, respond, patch, repeat—is necessary but not sufficient. The organisations that gain genuine strategic advantage will be those that reshape the terrain itself, making the environment hostile to attackers rather than merely monitored.
Draft - February 2026