KROLL-保障低碳人工智能(英)-2025_9页_2mb
报告摘要
Securing Low-Carbon AI: Critical Infrastructure Resilience
Executive Summary
The growing demand for AI, coupled with global net-zero ambitions, is driving investment in low-carbon energy sources like nuclear, renewables, and battery storage. However, this transition increases the attractiveness of critical infrastructure (power grids, data centers, energy assets) to hybrid warfare, sabotage, and cyber-physical threats. The challenge is balancing climate goals with security resilience, ensuring infrastructure can withstand high-impact, low-probability attacks.
Key Challenges
-
Energy Concentration Risks: Data centers (e.g., in London, Dublin, Virginia) consume significant electricity (projected to rise from 4-9.1% in the U.S. to 30% by 2030 in Ireland). High geographical clustering exacerbates vulnerability during targeted disruptions.
-
Nuclear Energy Security:
- SMRs & Large Reactors: Nuclear provides reliable low-carbon power but faces security challenges (e.g., legacy issues in older plants, sabotage risks). Security is stringent but costly; however, passive safety features in SMRs may reduce risks.
- Public Perception: Fear of attacks on nuclear sites could hinder deployment.
-
Renewables Vulnerabilities:
- Wind/solar assets are scattered but controlled via vulnerable operational technology (OT).
- Supply chain risks (e.g., "kill switches" in solar farms).
-
Grid & Substation Threats:
- Attacks on transmission infrastructure (e.g., fire at London’s North Hyde substation) or interconnectors can cause cascading failures.
- Maritime sabotage targeting undersea cables and pipelines persists.
-
Systemic Risk Complexity:
- Risks span cyber, physical, and hybrid domains.
- Regulators lag in addressing evolving threats beyond traditional compliance (e.g., NIS2, CER).
-
Hybrid Warfare: State-sponsored sub-threshold attacks (gray zone activities) target infrastructure without triggering declared war, making attribution and response harder.
Regulatory & Governmental Responses
- Legislation: EU’s Critical Entities Resilience Directive (CER) and UK’s Cybersecurity Resilience Bill (2025) strengthen security requirements.
- Defense Collaboration: UK’s Strategic Defence Review (SDR 2025) calls for military-integrator partnerships and funding for dedicated CNI protection units.
- Cross-Sector Coordination: Public-private collaboration, resilience scenario planning, and risk modeling (e.g., probabilistic risk assessment) are emphasized.
Recommendations for Operators
-
Holistic Risk Management:
- Adopt continuous threat/risk assessment integrating cyber and physical domains.
- Invest in scenario planning to address plausible high-impact scenarios.
-
Physical & Cyber Resilience:
- Use grid quantification techniques and OT security for critical systems.
- Design redundancy and separation (e.g., interconnectors, geographically dispersed data centers).
-
Systemic Risk Prevention:
- Enhance coordination between energy and digital infrastructure operators.
- Address supply chain vulnerabilities and national coordination gaps.
-
Policy Advocacy:
- Support new legislation for CNI protection (e.g., UK’s planned CNI legislation by 2029).
- Clarify governmental priorities through threat registers (e.g., UK’s National Risk Register).
Forward-Looking Strategies
- AI-Enhanced Security: Leverage AI for threat detection and predictive risk modeling, but manage its own computational and resilience demands.
- Emerging Tech Balance: Secure SMR and offshore hybrid assets (OHAs) to decarbonize grids, while ensuring their resilience against sabotage.
- Public-Private Alliance: Strengthen partnerships for intelligence sharing, emergency response, and joint infrastructure planning.
试读结束,高清完整版pdf/doc/ppt,请点下载