Two incidents from 2026 make an uncomfortable point clearly. Iran-linked hackers shut down a power plant in the United Kingdom for four days. Separately, coordinated attacks used AI-generated exploitation scripts against water systems in the United States, at one point affecting water pressure and triggering precautionary boil-water advisories.
Neither succeeded through some dramatic new vulnerability. They succeeded by exploiting weaknesses that had existed for years, the kind every infrastructure operator has heard about in a compliance briefing at some point. What changed is who could exploit them, and how fast.
The real shift: not new holes, just less effort to find them
Diana Kelley, CISO at Noma Security, put it plainly in reporting on these incidents: AI is lowering “the time, cost, and expertise needed to take advantage of weaknesses that already exist.” Margaret Cunningham of Darktrace made a similar point. AI gives attackers more speed and reach, but “it doesn’t erase the problems critical infrastructure organizations have been dealing with for years.”
That combination is the real risk. Attacking a water treatment system or a power distribution network used to require specialized industrial-control-systems knowledge that few criminal groups had. AI-assisted tooling collapses that requirement. The vulnerabilities were already there. The barrier to reaching them just came down.
This isn’t only a “developed world” problem
It’s tempting to read stories about UK power plants and US water utilities as distant. They’re not. Every government agency, utility provider, telecom operator, and financial institution running legacy systems, which describes a lot of infrastructure across Nigeria and the wider region, carries the same underlying exposure: old systems, patchy documentation, and IT governance built for a slower threat environment.
The bureaucratic side makes it worse. Regulatory efforts to modernize infrastructure security keep stalling: funding cuts, legal challenges, competing priorities. Defensive processes move at institutional speed. Attackers, increasingly, do not.
Where governance actually earns its keep
This is why IT project management and governance matter as much as the technical fixes themselves. A vulnerability that’s known but never scheduled for remediation is functionally the same as one nobody found. Closing that gap takes a delivery structure that tracks who owns each risk, what the remediation timeline actually is, and who answers for it when that timeline slips.
GressTech’s IT project management and cybersecurity services exist for exactly that reason: not just identifying what’s wrong, but making sure fixing it doesn’t quietly fall off a to-do list for another two years.
If your infrastructure runs on systems nobody’s fully audited recently, now is the moment. Not after an incident makes the decision for you.
Source: AI is making critical infrastructure easier to attack, Axios
