Semperis has released its latest study, which shows that water and electric utilities are at serious risk of disruption from cyber attacks. The study looks at utilities in the US and UK and is titled, The State of Critical Infrastructure Resilience, Evaluating Cyber Threats to Water and Electric Utilities. It shows how nation-state attackers are actively targeting critical national infrastructure.

Chris Inglis, Semperis Strategic Advisor and first U.S. National Cybersecurity Director, said, “Many public utilities likely don’t realise that China has infiltrated their infrastructure.
“For instance, Chinese-sponsored threat actors like Volt Typhoon are known to prefer Living off the Land attacks, which are difficult to detect and can remain dormant, planting backdoors, gathering information or waiting to strike for months or even years.”
Key findings show the scale of the risk
The report’s key findings show the scale of utilities’ risk. 62% admitted to being attacked in the last 12 months, with 80% saying they faced repeated attacks. The US suffered a higher rate of attacks than the UK, 64% vs. 57%. The authors also question why the remaining 38% think they weren’t targeted. This leads the report’s authors to say that all organisations need to adopt an assume-breach model.
Of particular interest is that 59% confirmed that nation-state attackers were behind the attacks. This is an important stat because attribution is typically extremely difficult. There is little detail on where those attributions came from. However, as critical national infrastructure, most utilities will be able to call on national cybersecurity bodies. They will have the resources to make such claims.
Of those countries named, all targeted the UK more than the US. North Korea was the most likely to attack both countries, followed by Russia. Attacks from Iran and China were much lower than the other countries in the US, but China was just as active in the UK as North Korea and Russia.
The stat also threw up some worrying comments. According to the research “experts agree that many more might simply lack the ability to detect stealthier attacks.” That implies that the attacks detected may represent a much smaller percentage than the figures show.
Attacks lead to deliberate data destruction
In 54% of cases where attacks were successful, data was permanently corrupted or destroyed. It is not clear if this was due to a failure to pay a ransom or happened even if a ransom was paid.
There is, however, some good news on data. It seems that 84% were able to restore services within 24 hours. Compared to some of the multi-day, multi-week and multi-month outages, this is a key step forward in terms of resiliency. However, with the increase in legislation around the need for resiliency, there is still more to be done. Customers will want to see restoration within hours and no longer.
Semperis sees identity under direct threat
But perhaps the most worrying statistic is that 82% are believed to have suffered some form of compromise to their primary identity systems. That includes Active Directory, Entra ID and Okta. It seems that US utilities are seeing a higher level of attack against identity but the report offers no insight into why.
Is it the use of outsourced systems? Is this the long tail of earlier attacks where attackers are exploiting previous vulnerabilities that remain unpatched? Are UK systems better maintained or even using older technology that is less visible?
Irrespective of the reason, it highlights the need to move towards zero-trust environments. They deliver a more secure identity approach than role-based systems.
What are the biggest threats?
There were five key categories of threats that Semperis identified through this research. They are:
- Supply chain compromise: Risks to the UK are seen as higher than the US (43% vs 40%). This might be due to more complex supply chains with a much larger number of smaller suppliers.
- Legacy systems: Again the UK (47%) is more at risk than the US (35%). It would have been interesting to have seen some qualitative research from Semperis around this. What type of legacy system? Is this core IT, cybersecurity, IoT or something else?
- Nation-State threats: The US (35%) is marginally more at risk than the UK (34%). However, figures from other industries show a significant uptick in attacks against the UK from nation-state attackers.
- Compromise of Identity Systems: The US (33%) has seen more issues here than the UK (30%). However, as outlined above, there is little detail on why this is.
- Insider threats: The US (31%) is far more likely to suffer from an insider threat than the UK (23%). Once again, details on why are not given, which is very disappointing.
Enterprise Times: What does this mean?
This research presents more numbers, but at just 15 pages, it is not a difficult read. It shows the scale of attacks on utilities and the need to do more to protect them.
We are in an age where critical national infrastructure is a legitimate target for cyber attacks as part of an asymmetrical warfare strategy. Yet, we should not assume that most of those attacks are from nation-state actors.
The rise in hacktivism and attacks from cybersecurity gangs is also on the rise. Some are sponsored by or provided tools by nation-state groups that use them as proxies. As armed conflicts continue to rage around the world, they are also pulling many more groups into the sphere of influence of those nation-state actors. The problem is that attribution is notoriously difficult and, as we’ve seen before, wrong.
Utilities in the US and UK are predominantly privatised. That means that their primary business focus is on the shareholders. This requires them to balance the payment of dividends with spending on the business. This is where government regulators need to look at resiliency as part of their remit and put more pressure on those businesses.
As can be seen here, over a third do not have an assume-breached mentality. That needs to change, and the various utilities need to improve cooperation to create a more secure environment.

















