Energy, manufacturing and utility operators are wiring decades-old plants into modern networks just as attackers gain machine-speed tooling, and critical infrastructure cybersecurity is where that mismatch bites hardest. Awareness of the risk is widespread, but action in many sectors is still lagging.
That gap is now the central problem for security leaders at industrial companies, where AI is being adopted to operate plant and grid systems faster than it is being secured. The next phase of defense will be built around people and software working in tandem, according to David Cooper (pictured, left), Americas cybersecurity growth leader at Ernst & Young Global Ltd.
“There’s a recognition that the future of cybersecurity is humans and agents operating at a speed we’ve never seen,” Cooper said. “What we heard from George Kurtz and Jensen and all the group in the keynote was all focused on how do we help defenders accelerate and get parity with the attackers. That’s where all of our clients are looking and that’s where they need to go.”
Cooper and Payal Thakkar (right), Americas industrials and energy cybersecurity leader at EY, spoke with theCUBE’s Dave Vellante and Rebecca Knight at Fal.Con, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. (* Disclosure below.)
Critical infrastructure cybersecurity meets an expanding attack surface
Oil fields, rigs and utility plants that ran unconnected for decades are being tied into operational technology networks, and agentic AI is widening the attack surface as that buildout accelerates. Spending on modernization is global and heavy, but security investment has not kept pace, Thakkar noted.
“They are getting more and more connected into devices that were just not meant to be connected before,” Thakkar said. “That’s where the interesting part for cyber is. It’s not just, hey, we need to put a layer of AI. How we think about cybersecurity for those devices has to change.”
EY’s own research found the share of organizations dedicating at least a quarter of their cybersecurity budget to AI is set to roughly quintuple — from 9% today to 48% in two years — as security leaders invest more heavily in AI and agentic defenses against AI-enabled threats, yet critical infrastructure cybersecurity teams still cannot find people fluent in both disciplines.
“Agentic AI is not replacing security operators,” Cooper said. “The human beings that are operating in these defenses, they are changing what they do. The nature of their work is changing, but the jobs are not going anywhere, and we’re still seeing a lot of our clients struggle to get the right talent for those new jobs.”
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Fal.Con:
(* Disclosure: TheCUBE is a paid media partner for the Fal.Con event. Neither CrowdStrike, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)





