Table of Contents
“We are at perhaps the most dangerous time I can recall as far as the risk to utility infrastructure and everything that helps power the United States,” Scott Aaronson said
That was the throughline of a recent webinar VanishID co-hosted with Carahsoft, featuring Scott Aaronson, Founder and Principal at Aaronson Resilience Advisors, and Tommy Hoschouer, Head of Public Sector at VanishID. Aaronson has spent roughly 20 years in government and alongside utilities preparing for and responding to all hazards. His read on this moment was blunt.
The attack surface walked out of the substation
Security teams in the energy sector have spent years hardening control systems and fence lines. Aaronson’s point is that cyber and physical risk stopped being separate problems a while ago, and that the seam between them is a person.
“A cyber attack today is going to have physical impact. A physical attack today on infrastructure is going to have cyber impact. The enabler of both of those types of risk, those types of threat, are people,” he said.
The opposition to grid buildout isn’t fringe anymore. As Aaronson put it, it’s mainstream, it’s getting violent, and it’s getting easier. Utility executives get named by activists and angry customers. So do state and local officials sitting on approval boards.
What makes energy different from most industries is proximity. Utility leaders and field crews live in the communities they serve. They shop where their customers shop. After Hurricane Beryl, Aaronson noted, line workers restoring power were targeted by frustrated customers while doing the job.
The shift inside boardrooms tracks with that. Aaronson said that 12 to 15 years ago he could count exactly one utility CEO with an executive protection detail. After the UnitedHealthcare CEO shooting:
“I think the last time I was at an Edison Electric Institute board meeting, there were at least two dozen CEOs who had their own executive protection. Boards are looking at this as a mandate,” he said.
Government officials are living the same problem
Tommy Hoschouer spent time this year at conferences like the National Association of Counties and the National Conference of State Legislatures. Data centers dominate the main stage, and the people inside those approval processes are feeling it.
“I can tell you firsthand, they are petrified and scared of these data centers coming into their state, coming into their counties, and coming into their cities because of all of the threats and harassment that come with it,” Hoschouer said.
He recounted a moment from an AI and cybersecurity session where a committee member stood up and said it was the first time they’d seen both political parties come together in their hatred for one organization and its data centers.

Three data points and one click
The reason a frustrated stranger can now act like a trained investigator is that the research is free and the results are organized. Hoschouer demonstrated this live using FamilyTreeNow, a site the head of court security in his home state of Utah uses to check how exposed local judges are.
Using only a first name, last name, and state, he pulled up someone’s record: a map of the house, the home address, a cell phone number, relatives, property values, and an employer. The site bills itself as genealogy. Its sponsors are data brokers.
“This is what they can get with three data points and one click,” he said.
He then described what happens next, drawn from cases he hears about regularly. Someone takes the address, drops it into Zillow or Homes.com, finds listing photos from when the house was on the market, and sends a text at 11 at night with a screenshot of the master bedroom: “I know where your head hits the pillow”.
Family members are the part most programs miss entirely.
“Family members are part of your attack surface, unfortunately. They will use them to find you,” Hoschouer said.
Aaronson reinforced the point from the cyber side. Years ago, only a sophisticated adversary could write a message convincing enough to look like it came from an executive’s kid. That’s no longer a specialist skill.
“The ability for information to be operationalized by increasingly less sophisticated threat actors really scares me,” Aaronson said.
None of this is off-book behavior. What Hoschouer demonstrated has a name in the MITRE ATT&CK framework: T1589, Gather Victim Identity Information, which sits under Reconnaissance, the first tactic in the chain.
Its sub-techniques cover employee names, email addresses, and credentials, and ATT&CK describes adversaries collecting them from social media, victim-owned sites, and leaked data long before any attempt at access. The part security leaders should sit with is the mitigation. ATT&CK lists exactly one, M1056 Pre-compromise, and its own language is candid: this “cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses.” The guidance is to minimize the sensitive data available to external parties. A framework built on detection is telling you that on this one, detection isn’t the lever. Shrinking what’s findable is.
“Too low profile” has a short shelf life
An attendee asked what to tell a security leader who believes their executive team isn’t prominent enough to be a target. Aaronson’s answer:
“That’s true until it isn’t … your job as a security professional, whether chief security officer or something like that, is to look around corners.”
Hoschouer brought a fresher data point. An energy organization VanishID met with the day before the webinar is now seeing threats reach frontline managers, and is worried about nearly every employee because of what AI makes possible.
“The attacks are not centralized, they’re not targeted as much. They can go at every single employee,” Hoschouer said.
The logic is straightforward. A frontline manager still has system access, and once an attacker is in, they go further. AI removes the cost of researching and writing a convincing lure at volume, so the old assumption that attackers only bother with the top of the org chart no longer holds.
What to do in the next 30 days
Asked what a CISO at a mid-sized organization should do first, Aaronson didn’t reach for a new tool.
“Learn my exposure…just see where my attack surface is, where my exposure is. Because that’s going to be illuminating.”
Three countermeasures came out of the session:
- Run a data broker audit. Start with a free search on your own executives and see what comes back. It’s usually worse than people expect.
- Review social accounts and apps. Hoschouer’s example was a county judge whose public Strava showed the same route, same start point, and same 5:30 a.m. window three days a week. Location-sharing apps have burned military personnel the same way.
- Get a personal threat assessment. If someone is actively being threatened or harassed, bring in people who do this work daily rather than handing executives a homework assignment.
Aaronson closed on a basic tenet of security that applies cleanly here:
“You can’t protect what you don’t know needs protection.”
Exposed personal information is what turns public anger into a targeted attack, and it’s one of the few parts of this problem a security team can actually shrink. That’s the work of external identity security: finding what’s exposed about your people and their families, and removing it continuously.
Request a complimentary risk analysis with VanishID, or download the full webinar here.