How Cloud Expansion and AI‑Driven Threats Are Reshaping Cyber Risk in the U.S. Energy Sector
About This Session
The U.S. energy sector is rapidly adopting cloud services, IoT technologies, and integrated IT/OT architectures. Changes that have significantly widened the attack surface. Recent research shows a sharp increase in cloud‑borne intrusions, identity compromise, exploitation of internet‑exposed assets, and phishing campaigns that frequently target high‑value individuals within energy organizations. These pressures are compounded by over‑reliance on a small number of critical vendors and unmanaged assets throughout the supply chain, creating dependencies that attackers increasingly exploit.
At the same time, U.S. critical infrastructure continues to attract interest from both financially motivated groups and nation‑state actors conducting reconnaissance and positioning for future disruption. This includes early‑stage activity that blends cloud identity misuse, low‑signal lateral movement, and OT‑adjacent probing that may not register on traditional tools.
This talk provides a focused look at how these attack patterns are evolving and how detection strategies must adapt. Based on analysis of North American energy sector incident trends based on Darktrace telemetry, the session will break down the behaviors most indicative of early‑stage compromise, outline key telemetry required for high‑fidelity detection in cloud‑enabled environments, and provide practical guidance for identifying subtle attacks before they impact reliability or operations.
At the same time, U.S. critical infrastructure continues to attract interest from both financially motivated groups and nation‑state actors conducting reconnaissance and positioning for future disruption. This includes early‑stage activity that blends cloud identity misuse, low‑signal lateral movement, and OT‑adjacent probing that may not register on traditional tools.
This talk provides a focused look at how these attack patterns are evolving and how detection strategies must adapt. Based on analysis of North American energy sector incident trends based on Darktrace telemetry, the session will break down the behaviors most indicative of early‑stage compromise, outline key telemetry required for high‑fidelity detection in cloud‑enabled environments, and provide practical guidance for identifying subtle attacks before they impact reliability or operations.
Speaker
Dylan Hinz
Associate Principal Cyber Analyst, Darktrace - Darktrace
Dylan Hinz is an Associate Principal Cyber Analyst at Darktrace with more than five years of experience in threat detection, cloud security, and adversary behavior analysis. Dylan contributed to Darktrace’s energy‑sector research, including the 2024–2025 State of Cyber Security in Energy reports, focusing on emerging attack vectors targeting U.S. critical infrastructure. Holding the SANS GRID certification, Dylan specializes in industrial control system defense and the IT/OT intersection. Dylan’s work spans hands‑on investigations, hypotheses‑driven threat hunts, and detection strategy development for complex cloud and hybrid environments. Drawing on real‑world energy‑sector incidents, Dylan advises organizations on threat evolution and how AI‑assisted defense can reduce operational risk.
