Security measures for energy production plants were formerly focused on the physical security of the plant, including considerations for the perimeter and reliable procedures. The Stuxnet worm demonstrated in 2010 that even if a system is protected and cannot be accessed by external attackers, it can be hacked. SCADA systems may be closed, but they are based on elements that can be affected by cybercrime. To create a problem for an enterprise focused on producing energy, it is not necessary to compromise the SCADA, but it could be enough to attack the customer relationship management system.”]
Source: https://securityintelligence.com/should-the-energy-production-industry-consider-cybersecurity/

