By Frank Balonis, Field CISO, Kiteworks
New survey research points to a paradox that should concern every utility security leader: energy and utilities posted the strongest combined governance maturity of any industry measured this year, and the sector's data keeps walking out the door anyway.
The finding comes from a 2026 annual industry study, the fifth of its kind, based on responses from more than 450 security, compliance, and IT professionals across ten industries. Energy and utilities recorded the second-highest data security maturity of any sector, behind only financial services, and the highest AI governance maturity measured anywhere. On a composite readiness index combining both, the sector led every other industry. Decades of operational technology security requirements built a discipline most industries are only beginning to develop.
So why did the same 12 months bring a $35 million ransomware loss at a major energy services company, hundreds of gigabytes of confirmed data theft from energy firms, and a utility engineering subcontractor's data offered for sale on a criminal marketplace, in a year when Verizon found espionage behind 71% of utility breaches?
The research points to an answer: maturity in aggregate hides gaps in evidence. Ask an organization whether it has strong governance and it can say yes truthfully. Ask it to prove what happened to a specific piece of data, and the picture changes. The survey found that half of organizations cannot produce a complete data access audit record within one business day, and 10% cannot produce one at all. Sixty-seven percent lack tamper-evident audit trails, the specific form of logging that lets an investigator confirm records were not altered after the fact. Seventy percent have no AI kill switch deployed. When a regulator or a federal cyber authority comes asking within hours of a breach going public, these are the artifacts they ask for, and most organizations cannot hand them over.
The vendor dimension is weaker still. The same research found 27% of organizations have either never evaluated whether their AI vendors use organizational data for model training or rely entirely on paper attestations with no technical verification behind them. Every utility professional reading this knows how concentrated the OT supply chain is. When a handful of specialized vendors sit behind your switchgear, inverters, substation controllers, and SCADA software, and third-party involvement in breaches has climbed to 48% of confirmed cases per Verizon, an unverified attestation is not due diligence. It is hope with a signature on it.
Here is the number I keep coming back to, and the one I would put in front of a board: spending showed almost no relationship with control deployment. High-spending organizations in the survey scored barely half a point above the full sample average on maturity. The reflex after every incident is a new policy and another training cycle. The data says the organizations that actually closed the gap did something else. They built classification that enforces downstream controls instead of just labeling data. They extended logging to every channel carrying sensitive data, including AI systems. And they tested their kill switches and access revocation before an incident forced the question.
For this community, the regulatory stakes are concrete. NERC CIP applies to bulk electric system assets today. IEC 62443 remains the OT reference architecture. Operators with European exposure add NIS2 notification timelines and EU AI Act logging and oversight obligations. Every one of these frameworks converges on the same demand: continuous, technically verifiable evidence, not policies in a folder.
Energy and utilities earned its lead honestly. But a benchmark is not a defense, and the past year proved the difference. My question for the utility professionals here: if an investigator asked tomorrow morning, how long would it take your organization to produce a complete, tamper-evident record of who accessed a specific dataset? I suspect the honest answers would tell us more than any maturity index.