The Grid That Cried Wolf: Why the Next Blackout Won’t Be an Accident
- By Winston Thomas
- May 04, 2025

When Spain and Portugal plunged into darkness on April 28, 2025, panic erupted as public services ground to a halt. While authorities denied a cyberattack, the blackout ignited global concern about critical infrastructure vulnerability. The incident — still under investigation — has sparked fierce debate between renewable energy critics and those pointing to system disconnects.
The stakes couldn’t be higher. As IT and operational technology (OT) increasingly converge, it creates perfect conditions for sophisticated attacks.
When digital meets physical
For decades, critical infrastructure systems operated in isolation from IT networks. That era has ended. IT systems offer visibility and manageability that OT networks do not. But this convergence creates fundamental vulnerabilities because OT systems prioritize reliability, not security. And now IT attacks are spreading into OT networks.
“We started to see that OT networks, which were typically air-gapped, would be connected to IT networks and now posed a possible threat to those types of critical infrastructures that normally would be isolated from the internet,” explains Joe Sarno, executive vice president of international sales at Fortinet, who has tracked OT security evolution for over a decade.
The problem is that many industrial control systems run on obsolete technology — Windows NT machines abandoned by Microsoft years ago still control critical infrastructure. This creates an immediate blind spot for security teams who may be operating without visibility into these sprawling, decades-old networks.
As OT vulnerabilities multiply, AI has supercharged cyberattacks. “AI is both a risk but also an opportunity for cybersecurity,” Sarno notes. “Attackers are actually leveraging AI to automate... and create deep, baked phishing attacks.”
Most alarming are what Sarno describes as “self-evolving malware attacks” — “extremely sophisticated malware that actually can change their form and their vectors to attack different areas of the networks.”
Research shows attackers now exploit vulnerabilities faster than ever. Last year alone saw approximately 70,000 vulnerabilities across 2,000 vendors, with AI accelerating the exploitation lifecycle and rendering traditional defenses obsolete.
The democratization of cybercrime compounds these threats. “We’ve practically democratized cybercrime because even low-skilled attackers... can now have access to sophisticated attack tools,” says Sarno, referring to the booming Cybercrime-as-a-Service (CaaS) economy.
Critical infrastructure in the crosshairs
Critical infrastructure has become a battleground where state-sponsored actors and criminal organizations leverage these converging vulnerabilities. The stakes far exceed traditional IT breaches — physical infrastructure, essential services, and human lives hang in the balance.
“Blocking a hospital with patients is extremely more devastating than any data that I haven't got access to for a few hours or a day,” Sarno explains. “My email is less important to a patient who is on a machine in the hospital.”

Solving critical infrastructure is not as easy as deploying rings of firewalls or unplugging from IT systems. One of the greatest challenges in addressing these threats is cultural. IT and OT teams operate with fundamentally different priorities, languages, and security approaches. “These are two different languages, and not always do the two areas get on well together,” Sarno acknowledges.
Yet, organizations have no choice and are now forcibly bridging this divide. “We’re even seeing CISOs managing both IT and OT environments,” Sarno observes. “The CISO role was separated [from OT], but now [they] are converging.”
With human analysts overwhelmed by AI-powered threats from IT and OT fronts, defensive AI has become crucial. “AI defense is not optional. It’s essential nowadays for organizations to be able to contain the problems,” Sarno emphasizes.
Security platforms now process “trillions and trillions of security events on a daily basis,” leveraging AI to automate threat detection, illuminate previously invisible OT environments, and implement protective measures at machine speed.
“We use AI within security operations to mitigate and detect, and contain those threats in seconds instead of days that we would need with human intervention,” Sarno notes.
Micro-segmentation has also become essential in both environments to prevent lateral movement across networks. “The segmentation is one of the main tactics that we put into place when building and protecting OT networks,” says Sarno.
Meanwhile, for unpatchable legacy systems, virtual patching provides critical protection. Additionally, deception technologies have emerged as vital OT defenses, luring attackers into fake environments to analyze their tactics without risking critical systems.
“Having sandboxing for OT environments and deception technologies that lure attackers into fake environments... is pretty interesting and very well appreciated from our customers,” Sarno explains.
Preparing for the inevitable
The biggest challenge for IT-OT security is the global skills shortage. IT security already faces a major skills challenge, but finding professionals who understand both worlds can be a nightmare. This is where Sarno sees industry-academic partnerships becoming a major factor, but these won’t plug the gap anytime soon.
So, the most pragmatic security stance today is accepting that breaches will occur. “Organizations should assume that they will be attacked. So investing in proactive resilience strategies is a good method and strategy to mitigate these impacts,” Sarno advises.
Critical infrastructure digitization is accelerating. But IT-OT security convergence demands not just technical solutions but organizational and cultural transformation. As the line between digital and physical security blurs, it requires a fundamental rethinking of how we protect our most essential systems. And the cybercriminals aren’t waiting.
Image credit: iStockphoto/Francisco Javier Ortiz Marzo
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.