Cyber Risk Report

Live Wire — Energy Sector Cyber Exposure & Supply Chain Intelligence

Based on ThingsRecon scans of 5 energy organisations across the UK, Netherlands, Belgium & Luxembourg ·

24,085
Internet-facing assets discovered
Across 5 scanned organisations
1,714
Supplier connections mapped
script · cert · ASN · DNS · header
111
Fix Now priorities
Requiring immediate action
4/5
Suppliers common to all 5 orgs
Microsoft · Google · GitHub · jQuery

Why energy sector attack surfaces demand continuous monitoring

Energy companies operate at the intersection of critical infrastructure and highly digitalised customer operations. They manage smart meter networks, online energy portals, grid management dashboards, B2B trading platforms, and increasingly complex IT/OT integrations — all of which create an external attack surface that attackers scan continuously. The consequences of a successful attack extend beyond financial loss: energy disruption affects homes, hospitals, industry, and national security.

Yet the external attack surface — everything visible from the public internet — is rarely mapped with the same rigour applied to internal OT security. Subdomains, supplier scripts, DNS records, and cloud-hosted energy management interfaces change constantly, often without security team oversight. ThingsRecon maps this surface agentlessly, from public data alone, revealing the suppliers, vulnerable components, and DNS misconfigurations that standard security tooling misses.

This report draws on simultaneous scans of five energy organisations across the UK, Netherlands, Belgium, and Luxembourg — spanning oil and gas operators, green energy retailers, large utilities, regional energy suppliers, and energy services companies. The findings reveal a sector where external hygiene lags well behind operational security investments, and where four common technology suppliers are embedded in every organisation's digital estate.

All organisations in this report are anonymised. Technology suppliers and infrastructure providers are named as they appear on the external attack surface.

Sector Benchmark

How do energy organisations compare?

ThingsRecon scanned five energy organisations simultaneously — from a small North Sea operator to one of Belgium's largest energy utilities. All five received an overall score of C, masking significant variation in individual risk indicators. The two standout findings: a DNS F rating at a regional energy supplier (the most alarming single indicator across all organisations) and a Header D rating at the largest utility, which operates the most complex and supplier-rich external estate.

Organisation
Assets
Suppliers
Fix Now
Fix Soon
Score
Weak indicators
Company AOil & gas operator · UK
1,386
30
1
4
C
Headers C · DNS C · Software C · SSL C
Company BGreen energy retailer · NL
7,060
192
45
37
C
Headers C · App C · Software C
Company CEnergy utility · BE
12,639
217
60
215
C
Headers D · App C · Software C · SSL C
Company DEnergy supplier · LU
386
18
2
3
C
DNS F · Software C · Headers B
Company EEnergy services · UK
2,614
57
3
23
C
Headers C · Domain C · Software C
Sector-wide Risk Patterns

Structural vulnerabilities across the energy digital estate

The patterns below appear consistently across energy organisations regardless of size, country, or sub-sector. They reflect the accumulated technical debt of organisations that have expanded digital customer services rapidly without equivalent investment in external security hygiene.

DNS Infrastructure
Critical
One organisation received an F — the worst possible DNS rating. DNS C ratings appear across two additional organisations. Energy companies manage complex DNS estates spanning customer portals, smart meter APIs, trading platforms, and partner integrations. Dangling DNS records and DNSSEC failures in this context expose energy-critical web services to subdomain takeover and traffic hijacking. Under NIS2, DNS infrastructure security is a mandatory element of risk management for essential entities.
HTTP Security Headers
High
4 of 5 organisations received C or D ratings for HTTP security headers. The largest utility — with 12,639 assets and 217 supplier connections — scored D, meaning its entire external estate lacks adequate Content-Security-Policy and HSTS controls. Customer account portals, smart meter dashboards, and energy trading interfaces without these controls are directly exposed to clickjacking, script injection, and cross-site scripting attacks.
Software Supply Chain
High
All five organisations show C-rated software risk. Outdated JavaScript libraries — particularly jQuery and related frameworks — appear in all five organisations' external estates. In energy sector web portals and customer-facing applications, unpatched JS libraries with known CVEs provide the initial entry point for supply chain attacks: a compromised or vulnerable script on an energy customer portal can harvest credentials or redirect payment data without any network intrusion.
Supplier Concentration
High
Four technology suppliers — Microsoft, Google, GitHub, and the OpenJS Foundation / jQuery — appear in all five energy organisations. Microsoft and Google are present at high digital proximity (avg 58% and 52% respectively), meaning their infrastructure sits deep within the critical customer-facing estate. A supply chain attack on any of these four suppliers has simultaneous impact across the entire sector — exactly the vector NIS2 Article 21(2)(d) demands energy essential entities to assess.
Application Security
Medium
The two largest organisations both scored C on application risk, with Fix Now application findings present in both. Customer-facing energy portals — where users manage accounts, view consumption, and set up direct debits — show authentication and configuration weaknesses that directly expose consumer data. The largest utility has 60 Fix Now items, of which a significant portion are application-level findings.
SSL/TLS Configuration
Medium
Three organisations have C-rated SSL service risk, with Fix Now SSL findings across two of them. Energy portals transmit consumer payment data and account credentials over TLS — weak cipher configurations and certificate mismanagement create man-in-the-middle exposure on exactly the sessions that carry the most sensitive customer data.
Domain & Certificate Hygiene
Medium
Domain risk indicators appear across multiple organisations, with one energy services company showing a C-rated domain risk and another showing B-rated certificate risk. Energy companies typically manage large domain portfolios spanning trading platforms, customer portals, partner APIs, and legacy service domains — certificate expiries and misconfigured records accumulate over time and create attack surface that is invisible to perimeter tools.
Sector verdict: The energy sector's digital attack surface is defined by rapid expansion of customer-facing digital services layered on top of infrastructure that was not designed with security hygiene in mind. The result is 111 Fix Now items across five organisations, a DNS F rating at one energy supplier, and 282 Fix Soon items requiring structured remediation programmes. NIS2 mandates continuous monitoring of the external attack surface for energy essential entities — and the data shows this monitoring gap is real.
NIS2 Directive — Energy Sector Obligations

Energy operators (electricity, gas, oil) are classified as essential entities under NIS2 Annex I. This triggers mandatory obligations under Article 21: risk analysis and security of information systems, supply chain security (Article 21.2.d), vulnerability handling, use of cryptography, and incident reporting within 24 hours (Article 23). UK energy operators face equivalent obligations under the Network and Information Systems (NIS) Regulations and OFGEM's cybersecurity guidance. ThingsRecon provides the continuous outside-in visibility that Article 21 compliance and regulatory audit evidence requires.

Why Energy Needs This

Discovery. Prioritisation. Monitoring.

Energy organisations manage digital estates that span customer portals, smart meter APIs, trading platforms, partner integrations, and OT-adjacent web interfaces — all growing continuously. ThingsRecon maps every publicly visible asset and supplier connection from a single seed domain, with no agents required and no access to internal systems.

01

Continuous Discovery

Energy digital estates expand constantly — new customer portals, smart home integrations, B2B energy trading APIs, and partner platforms. ThingsRecon discovers every subdomain, cloud-hosted service, and third-party script continuously, including DNS records that have become dangling or misconfigured as infrastructure evolves over time.

02

Risk Prioritisation

With 111 Fix Now items across five organisations, energy security teams cannot address everything simultaneously. ThingsRecon scores every finding by exploitability and proximity to business-critical assets — enabling teams to act on the DNS F, the vulnerable customer portal libraries, and the SSL misconfigurations before less critical hygiene issues.

03

Supply Chain Monitoring

Four technology suppliers appear in every energy organisation scanned. ThingsRecon monitors every supplier connection for changes — new scripts, certificate rotations, CDN routing changes, unexpected subdomain appearances — the moment they occur on the external surface, before they become incidents reportable under NIS2 Article 23.

Supply Chain Intelligence

The suppliers inside every energy digital estate

ThingsRecon maps the technical supply chain — every third-party component detected on the external attack surface via scripts, certificates, DNS, ASN routing, and HTTP headers. These are the suppliers that standard TPRM questionnaires miss because they were never deliberately onboarded: they arrived embedded in platforms, CMS themes, analytics tooling, and acquired infrastructure. In the energy sector, where IT/OT convergence means web-based energy management interfaces increasingly talk to operational systems, the risk profile of this invisible supply chain is elevated significantly.

Sector-wide supplier connections
1,714 connections mapped
Across 5 energy organisations — detected via script, cert, ASN, DNS, and header vectors. The large majority are undeclared in any TPRM register.
Universal suppliers (all 5 orgs)
4 in every estate
Microsoft, Google, GitHub, and OpenJS Foundation / jQuery each appear in all 5 energy organisations — a shared, sector-wide dependency that NIS2 Article 21 supply chain obligations directly address.
Fix Now items — largest utility
60 Company C alone
The largest energy utility in this benchmark has 60 Fix Now and 215 Fix Soon items — by far the highest priority count across all organisations, driven by its sprawling 12,639-asset external estate.
Highest supplier proximity
71% Microsoft (Company B)
Microsoft achieves 71% digital proximity at the green energy retailer — the highest of any supplier across any organisation — reflecting deep Azure and M365 integration in its customer platform.
Supplier
Avg proximity
Connection vector
In
Found in
Microsoft Corporationmicrosoft.com · azure.com
58%
script · header · ASN
5 / 5
Company A, B, C, D, E
Google LLCgoogle.com
52%
script · header · dns
5 / 5
Company A, B, C, D, E
OpenJS Foundation / jQueryjquery.com · code.jquery.com
34%
script
5 / 5
Company A, B, C, D, E
GitHub Inc.github.com · githubusercontent.com
30%
script · header
5 / 5
Company A, B, C, D, E
Amazon Technologies, Inc.amazon.com · aws.com
52%
ASN · cert · dns
4 / 5
Company B, C, D, E
Critical Supplier Spotlight
Microsoft Corporation
microsoft.com · azure.com · office365.com | Avg proximity 58% · Max 71%
Found in
All 5 scanned energy organisations
Digital proximity
71% max Highest proximity in Company B
Connection vectors
JavaScript scripts · response headers · ASN routing · DNS
Energy risk profile
IT/OT boundary Identity dependency

Microsoft is the most deeply embedded technology supplier across every energy organisation in this benchmark. At 71% digital proximity in one organisation, Microsoft infrastructure is woven into the heart of the customer-facing digital estate. In practice, this means Azure Active Directory controls identity for every customer-facing and internal application, Microsoft 365 handles all staff communications including operational alerts, and Azure hosts energy management workloads and customer data platforms. For energy operators with IT/OT integration, Azure-hosted dashboards and Teams-based operational communications create a dependency chain where a misconfigured Entra ID application registration, an overpermissioned OAuth scope, or an undeclared Azure-hosted service can provide attackers with a path from the public internet toward operational technology environments. Under NIS2 Article 21(2)(d), energy essential entities must specifically assess ICT supply chain security — and Microsoft, as the universal IT infrastructure provider across this sector, is the highest-priority supplier to map and continuously monitor.

Attack vector: Misconfigured Azure Entra ID app → overpermissive OAuth token → lateral access to M365 operational communications → harvested credentials for energy management platform → OT-adjacent access
Energy sector attack path — DNS misconfiguration to operational disruption
1
Entry point
DNS F-rated infrastructure exploited — dangling subdomain taken over, malicious content served from hijacked energy domain
Entry
No authentication required — public DNS record pointing to uncontrolled infrastructure
2
Pivot
Phishing campaign served from trusted energy domain → operational staff credentials harvested → account takeover
Pivot
Trusted sender domain bypasses email security controls
3
Impact
Access to energy management platform — operational disruption, customer data exfiltration, or ransomware deployment
Impact
Why this matters for energy: A DNS F rating indicates publicly visible infrastructure that attackers can exploit without any internal access. The attack does not require sophisticated tooling — only a dangling DNS record pointing to unclaimed cloud storage or an expired subdomain. ThingsRecon identifies every DNS misconfiguration on the external estate, maps it to the applications and services it affects, and monitors for changes continuously — so energy security teams know about DNS risks before attackers do.
Sector Findings

Aggregated risk signals across all scanned organisations

The following findings reflect patterns observed across all five energy organisations. Individual organisation-level findings with full asset detail are available through a full ThingsRecon engagement.

111
Fix Now
282
Fix Soon
60
Monitor
302
Track
  • Fix Now
    DNS F rating at an energy supplier — immediate remediation required. The most alarming single finding across all five energy organisations. An F-rated DNS estate indicates dangling DNS records, DNSSEC failures, or misconfigurations that leave externally accessible energy services — customer portals, billing systems, B2B APIs — open to subdomain takeover and traffic interception. This is the highest-priority finding in the energy sector benchmark and requires immediate attention before an attacker discovers it first.
  • Fix Now
    Software vulnerability Fix Now items across all five organisations. Outdated JavaScript libraries with publicly disclosed CVEs are present on externally accessible energy web applications in every organisation. The largest utility has 24 software Fix Now items alone. In energy portals that handle account management, consumption data, and payment processing, a known-vulnerable library provides the initial entry point for supply chain attacks without any network intrusion.
  • Fix Now
    SSL service Fix Now findings across multiple organisations. Weak TLS configurations and SSL mismanagement on customer-facing energy portals create man-in-the-middle exposure on exactly the sessions that carry payment data and authentication tokens. The largest utility has 10 SSL-related Fix Now items — a significant concentration of TLS risk for a customer-facing energy platform.
  • Fix Soon
    Header D rating at the sector's largest energy utility. 12,639 assets and 217 supplier connections, with D-rated HTTP security headers across the external estate. Missing Content-Security-Policy on energy portals that load jQuery scripts, Google Analytics, and GitHub-hosted libraries creates direct cross-site scripting exposure on customer-facing applications managing energy accounts, direct debits, and consumption data.
  • Fix Soon
    282 Fix Soon items across the sector — structured remediation programme required. The largest utility alone has 215 Fix Soon items — cookie security failures, application misconfigurations, and certificate issues that require a prioritised, tracked remediation programme. At this scale, ad-hoc remediation is insufficient: continuous monitoring with a Fix Now / Fix Soon priority framework is required to make measurable progress against the backlog.
  • Monitor
    Four universal suppliers not tracked in TPRM programmes. Microsoft, Google, GitHub, and OpenJS Foundation / jQuery are present in every energy organisation's external estate — yet the technical connections that create this dependency (CDN-loaded scripts, OAuth redirects, ASN routing) are rarely captured in formal supply chain risk registers. ThingsRecon maps and monitors these connections continuously, alerting when new versions, new domains, or new certificate authorities are introduced without security team oversight.
Get the full picture

Your organisation's exposure — mapped in 48 hours

This sector report shows the patterns. A ThingsRecon scan of your organisation shows exactly which DNS records are dangling, which suppliers are in your estate, and which of your 111 sector Fix Now equivalents apply to you — with the NIS2 evidence pack your compliance team needs.

✦ Full external asset inventory ✦ DNS misconfiguration detection ✦ Every supplier scored ✦ Fix Now / Fix Soon list ✦ NIS2 Art. 21 evidence ✦ IT/OT supplier mapping ✦ Continuous monitoring
Request a PoC scan