Logo
FrontierNews.ai

The U.S. Energy Sector Is Getting a New AI-Powered Defense Against Cyberattacks

The U.S. Department of Energy has selected three innovative startups to develop cutting-edge AI and automation tools designed to defend the nation's energy infrastructure against evolving cyber threats. The awards, announced on September 15, are part of the Securing ENergy Technology ResiliencY (SENTRY) initiative, which aligns with efforts to enhance the security and resilience of critical U.S. energy systems.

What Are the Three Winning Technologies?

The DOE's Office of Cybersecurity, Energy Security, and Emergency Response (CESER) selected Frenos, Raptor Dynamix, and Bastazo to receive SENTRY funding. Each company is tackling a different dimension of energy sector vulnerability.

  • Frenos' Adversary Emulation Framework: Frenos is developing an automated system that uses adversarial AI to simulate realistic attacks on energy infrastructure. The framework translates generic threat intelligence into energy-specific attack scenarios, executes them across substations and distributed energy resources (DER) systems, and provides prioritized guidance on how to fix vulnerabilities before attackers exploit them.
  • Raptor Dynamix's Counter-Drone System: Grid Guardian is a cost-effective unmanned aircraft system (UAS) designed to detect, classify, and defeat drones threatening critical energy infrastructure. Once a threat is confirmed, the system uses layered mitigation options, including directional radio frequency disruption and an autonomous interceptor drone, all coordinated through a single command interface for utility operators.
  • Bastazo's Risk Quantification Framework: The Cyber-Informed Engineering Risk Quantification Framework (CIE-RQF) connects an organization's cybersecurity posture to measurable operational impacts using AI-driven analytics. It combines industry standards with attack-path analysis and reliability indicators to generate actionable, utility-specific risk insights that guide strategic investment and remediation planning.

Why Does Energy Infrastructure Need This Protection Now?

Energy infrastructure faces a dual challenge. Attackers are increasingly using AI to accelerate reconnaissance, vulnerability discovery, and credential theft, while defenders struggle to keep pace with the volume and speed of threats. The SENTRY initiative addresses critical gaps in industrial control system (ICS) cybersecurity, decentralized asset management, and counter-drone capabilities.

The timing is particularly urgent because AI is fundamentally changing how cyberattacks unfold. According to recent threat intelligence research, adversaries have progressed from basic AI prompting toward agentic AI workflows, where AI systems can autonomously plan, build, and execute multi-stage attacks. In one documented case from the second quarter of 2026, a threat actor compromised a cloud resource and then planned, built, and executed an AI-enabled credential-harvesting campaign in less than six hours.

How Is AI Changing Both Attack and Defense?

AI threat intelligence now operates on two fronts. Defenders can use AI to collect, correlate, summarize, and operationalize threat intelligence faster than ever before. At the same time, adversaries increasingly use AI to accelerate parts of the attack lifecycle, from initial reconnaissance through malware development.

The challenge for security teams is not simply processing more information, but connecting threat signals with actual business risk. A critical vulnerability on a low-value test system creates far less risk than the same vulnerability on a system containing millions of sensitive customer records. This is where AI-driven risk quantification becomes essential. By connecting threat context with data context, organizations can prioritize which vulnerabilities actually matter to their operations and business continuity.

Another critical development is the emergence of AI agents in attack workflows. Unlike traditional malware that follows a predetermined script, AI agents can investigate signals, gather context, and recommend actions, potentially participating in response workflows with minimal human oversight. This speed advantage cuts both ways: it can help defenders respond faster, but it also means security teams must carefully govern what access and authority those AI systems have.

What Practical Steps Can Energy Organizations Take?

While the SENTRY-funded technologies represent cutting-edge defenses, energy organizations can begin strengthening their posture immediately by implementing several foundational practices:

  • Threat Intelligence Integration: Connect security findings with sensitive data, access, identity, exposure, ownership, and activity so teams can prioritize risks with the greatest potential business impact rather than treating all threats equally.
  • Adversarial Simulation: Conduct regular adversary emulation exercises that translate generic threat intelligence into sector-specific attack scenarios, allowing teams to validate defenses and identify remediation priorities before real attackers strike.
  • Risk Quantification Discipline: Move beyond generic severity ratings to connect cybersecurity posture with measurable operational impacts, using frameworks that combine industry standards with attack-path analysis and reliability metrics specific to your infrastructure.

What Role Does Human Judgment Still Play?

Despite AI's growing capabilities, human oversight remains essential. AI can accelerate analysis and automate routine tasks, but consequential security decisions require reliable evidence, appropriate authorization, and human judgment. Security teams should treat AI-generated summaries and recommendations as analytical aids rather than unquestioned ground truth.

The SENTRY initiative is managed by ConnectWerx in partnership with DOE and made possible through an innovative Partnership Intermediary Agreement (PIA) set up by the DOE's Office of Technology Commercialization (OTC). This collaborative approach reflects a broader recognition that defending critical infrastructure requires coordination between government agencies, private sector innovators, and energy utilities themselves.

As AI continues to reshape both attack and defense capabilities, the energy sector's ability to adopt these new tools quickly may determine whether critical infrastructure remains resilient or becomes increasingly vulnerable to the next generation of AI-powered threats.