The digital threat landscape is described as being persistently elevated in the power and petroleum sector. The measures are based on KraftCERT's 2026 threat assessment and encompass prevention, identification and response with respect to cyber incidents.
KraftCERT specifically points to the increased use of artificial intelligence in phishing attacks and the misuse of legitimate tools as key challenges going forward. Among the most important measures recommended are the use of phishing-resistant multi-factor authentication and reducing unnecessary software and tools at endpoints. The package of measures also emphasises the need for training and exercises based on cyber scenarios.
To improve the ability to detect anomalies and attacks, it is recommended that exposed interfaces, outbound network traffic and endpoints be monitored. Vulnerability scans should also be performed regularly. Measures that help identify unwanted activity at an early stage are important for limiting the consequences of any cyber incident.
KraftCERT also stresses the importance of integration with other emergency preparedness measures within the enterprises. Enterprises should have established procedures for dealing with ransomware attacks, in addition to planned preparedness measures, and conduct regular drills for relevant cyber incidents. Appropriate training and exercises will make the organisation better equipped to handle serious incidents when they occur.
The Norwegian Ocean Industry Authority (Havtil) urges enterprises to assess the measures in light of their own risk profile and to use the package of measures as a resource in their efforts to enhance their digital security and resilience.