GlobalData is warning energy companies to harden cybersecurity before supply risks translate into operational disruption.
Its latest strategic intelligence points to a sector under pressure from digitalisation, IT/OT convergence, third-party exposure and geopolitical tensions, all of which widen the attack surface for critical national infrastructure.
Supply risk rises
For CISOs and energy leaders, the core concern is that an attack on one part of the value chain can ripple across operations. GlobalData said third-party vulnerabilities are a major risk because shared vendor software and outsourced services can spread compromise into both IT and OT environments, even where internal defences are strong.
Ravindra Puranik, Oil and Gas analyst at GlobalData, said energy companies depend on extensive third-party ecosystems and that supplier weaknesses can cascade into client organisations. He called for stronger vendor governance through continuous monitoring, segmentation, least privilege, audits and joint incident response.
OT and geopolitics
The report also flags the convergence of legacy assets with modern grid technologies as a structural issue. As utilities and operators connect operational technology with information technology, more entry points are created for attackers, while generative AI is making attacks faster and more sophisticated, shrinking defenders’ response windows.
That mix is especially sensitive in critical infrastructure, where disruption can affect national stability as well as revenues.
GlobalData argued that cyber espionage rises alongside geopolitical uncertainty, making resilient cybersecurity programmes a strategic necessity rather than a technical add-on.
What operators should do
Puranik said oil and gas firms should invest in specialised cybersecurity services with continuous monitoring, rapid response and expert validation, while equipment and oilfield service providers should add product-focused security services such as secure development support and security audits.
He said cybersecurity is integral across the oil and gas value chain for securing data, protecting asset integrity and preventing financial losses.
For operations teams, the message is clear: security controls now have to work across the full stack, from vendor software and cloud services to plant-floor systems and remote access. That means tighter supplier due diligence, stronger segmentation between IT and OT, and a more disciplined incident response posture.
Why it matters
The report is timely because energy infrastructure remains a high-value target for ransomware, espionage and disruption, and the sector’s digital transformation is expanding the number of ways attackers can get in.
For CISOs and CIOs, the operational takeaway is that resilience increasingly depends on seeing cyber risk as a supply-chain and continuity issue, not only a perimeter defence problem.









