What is cybersecurity?
Key pillars of cybersecurity at Iberdrola
Today's society relies on the Internet for all the activities it undertakes during the day, from work to leisure, from finance to storing personal data or to communicating with others. The role of cybersecurity is growing in parallel with the concern for protecting our digital data. Find out about its importance, how we defend ourselves against cyber attacks at Iberdrola and our tips to prevent them.

In a world increasingly reliant on the Internet, the need to prevent online scams and maintain cyber security is becoming more prominent. Any individual or company, regardless of size, is a potential target for cyber attack. Internet users leave a trail of digital information and businesses have key assets that criminals may seek to exploit. Sometimes it is money or financial information, sometimes it is personal data, and sometimes it is even infrastructure.
Knowing the importance of cybersecurity and the types of cyber attacks can help you better understand the risks and find ways to prevent and deal with them.
Definition and scope of cybersecurity
Cybersecurity is the set of capabilities, technologies, standards, processes and best practices designed to protect the cyberinfrastructure against attacks, damage or unauthorised access. Cybersecurity is the ability to prevent, identify, detect, respond to and mitigate or eliminate deficiencies, vulnerabilities, attacks and internal and external threats that may pose a risk to the Company's cyberinfrastructure, with the aim of eliminating or minimising damages of any kind that may be caused to the company.
Like a barrier, cybersecurity slows or minimises attacks. "A robust cybersecurity strategy can provide a good security posture against malicious attacks designed to access, alter, delete, destroy or extort an organisation's or user's systems and sensitive data," notes TechTarget. Cybersecurity is also critical to prevent attacks aimed at disabling or disrupting the operation of a system or device.
With an increasing number of users, devices, technologies and programmes, along with the growing deployment of data – much of which is sensitive or confidential – the importance of cybersecurity continues to grow. In addition, the growing volume and sophistication of digital scams further exacerbates the problem. While these attacks can affect different levels —for instance, governments, businesses or institutions— the key is to pay special attention to the role of humans. In fact, according to cybersecurity company Proofpoint, "more than 99 % of cyber attacks require human interaction".
In this context it is essential to distinguish between Information Technology (IT) and Operational Technology (OT) environments.
- IT cybersecurity focuses on protecting the systems that manage corporate information, such as applications, networks, data and devices used for processing and storing information;
- OT cybersecurity aims to protect the systems that control and monitor the company's critical physical and operational processes.
In an energy company such as Iberdrola, these two areas are increasingly interconnected, making it essential to ensure comprehensive protection that safeguards both the confidentiality, integrity and availability of information and the continuity and security of operations.
The most common cyber threats
Cybersecurity works to prevent and minimise online threats. However, cyber attacks are becoming increasingly sophisticated and stealthy in order to circumvent the defence barriers of computer systems. These are the most common threats facing cybersecurity today:
Malicious software
'Malware' is a contraction of 'malicious software' designed to damage or infiltrate systems without the user's knowledge. It often appears when a dangerous link or email attachment is clicked. Some of them are the following:
-
Worms
They spread from one device to another without human intervention, exploiting vulnerabilities.
-
Trojans
They are used to hide other malware. It infiltrates a victim's device by presenting itself as legitimate software and allows attackers to gain unauthorised access.
-
Ransomware
It blocks or denies access to a device and its files until the user pays a ransom to the hacker.
-
Spyware
Collects information from a device or network to send to the attacker.
Distributed Denial of Service ( DDoS ) attack
Prevents users from accessing information, services and other resources. This type of attack occurs by overloading or flooding a target machine with requests to the point where normal traffic cannot be processed and, as a result, causes a denial of service to legitimate users.
Social engineering attack
Different techniques and mechanisms by which the attacker uses a human emotion - often fear or a sense of urgency - to convince the user to perform an action, such as providing personal information that can be used later or sending money. These include phishing, vishing and smishing.
Disinformation
Based on creating or disseminating false or misleading information to manipulate public opinion. The aim is to have a negative impact on the target audience in order to create a negative view of certain facts or the image of certain entities through manipulation of information.
Supply chain attacks
Cyber criminals can compromise service providers or software vendors to infiltrate the networks of their customers, who become their victims.
Source: European Union Agency for Cybersecurity (ENISA), Cisco.
SEE INFOGRAPHIC: The most common cyber threats? [PDF]
The most common cyber threats. Cybersecurity seeks to prevent and minimise online threats, which are becoming increasingly sophisticated and stealthy. Among the most common are malicious programmes, or malware, designed to damage or infiltrate systems: worms spread between devices by exploiting vulnerabilities; Trojans disguise themselves as legitimate software to gain unauthorised access; ransomware blocks access to a device or files and demands a ransom; and spyware collects information to send to the attacker.Also of note are denial-of-service (DDoS) attacks, which overwhelm a system and prevent access to information or services; social engineering, which manipulates people through deceptive tactics such as phishing, vishing or smishing; disinformation, which spreads false or misleading content to influence public opinion; and supply chain attacks, which compromise service or software providers to gain access to their customers' networks.
Why it is key in an electrified and digital world
The consolidation of a more electrified and connected energy model entails a profound transformation of infrastructure. Smart grids, storage systems, distributed renewable generation and electric mobility incorporate digital technologies that enable energy to be managed more efficiently and flexibly.
This evolution requires strengthening the protection of infrastructure that is increasingly critical to society.
The protection of energy infrastructure
Energy infrastructure forms part of the essential services that enable households, businesses and industries to function. Ensuring its availability and security requires anticipating new threats through advanced monitoring, analysis and response capabilities.
Cybersecurity helps to:
Artificial intelligence and cybersecurity: opportunity and challenge
Artificial intelligence is transforming the way organisations detect, analyse and respond to digital threats. Its ability to process large volumes of information enables it to identify anomalous patterns, anticipate risks and improve response times to potential incidents.
At the same time, AI also poses new security challenges. Cybercriminals can use these technologies to develop more sophisticated attacks, automate malicious processes or create new forms of social engineering. Therefore, the responsible development of artificial intelligence must be accompanied by governance measures, data protection and security controls that ensure the reliable use of this technology.
A recent example occurred in Hong Kong where, according to the local police, an employee of a company transferred approximately $25 million after taking part in a fake video call in which cybercriminals used artificial intelligence to impersonate the chief financial officer and other colleagues. It is because of cases such as these that campaigns and technologies are being developed to streamline tasks such as system recognition, vulnerability scanning and the detection of unauthorised access attempts. For example: the campaign identified by the National Cybersecurity Institute (INCIBE) in Spain, in which an artificial intelligence-based tool called CyberStrikeAI was used to automate various stages of an attack on corporate security devices.
Innovation and the future of cybersecurity in the energy industry
Cybersecurity is crucial in the energy industry due to the increasing interconnectedness of systems and dependence on technology. Smart grids, industrial control systems and other internet-enabled devices are already an essential part of the industry, bringing efficiency and control. However, these developments require closer security scrutiny to avoid exposure to vulnerabilities exploited by attackers or hackers.
Some expected innovations or trends in cybersecurity in the energy industry are the following:
- Integration of emerging technologies. The adoption of technologies such as the internet of things (IoT), artificial intelligence (AI) and machine learning can help early detection of security breaches and optimise responses.
- Blockchain. This technology is being explored to improve transaction security and data management in the energy supply chain. It provides an immutable record that helps prevent fraud and attacks. At Iberdrola, we have become the first company to use blockchain to certify participation in the General Shareholders' Meeting.
- Cloud security. With the proliferation of cloud services, robust security measures and encryption techniques are expected to be implemented to protect stored and transmitted data, as well as agreements with strong vendors that provide secure technologies and services.
- Response automation. The goal would be to achieve threat response automation. Systems capable of identifying, analysing and responding on the spot could help minimise the impact of attacks and reaction time.
- Training and awareness. To cope with the increasing sophistication of attacks, continuous training of staff at all levels of the company in cybersecurity and awareness of best practices will be critical.
- Collaboration. Training and technical support between energy industry entities, government agencies and cybersecurity companies will be key to sharing knowledge in the face of cyber-attacks.
- Legislation. Regulations and standards relating to cybersecurity in the energy sector are likely to increase to ensure the protection of critical infrastructure assets.
How to report cyber attacks
At Iberdrola, we have developed the vulnerabilities mailbox, a contact platform for reporting possible security incidents on our websites. Through this form, we can receive comments from a security researchers community that contribute to securing the products and services for all of the Group's companies. Once we have been alerted, we will investigate and resolve any vulnerabilities detected on our platforms.
The information required for alerting about attacks or incidents are the affected web page or site, a brief description of the vulnerability, steps to reproduce it and documentation that can illustrate the problem.
Tips for users to avoid data harvesting
Cybersecurity starts with our own online activity. Here are some tips to keep your data safe:









