
In an increasingly interconnected energy system, the risks from cyber events are moving from the theoretical to the more probable. Cybersecurity expert Ryan Davidson assesses the greatest threats to energy system stability and the practical steps PV and battery storage professionals can take to minimise them.
After two decades working on power resilience, cybersecurity and grid digitalisation, I still oscillate between two honest instincts: we’re exposed and we’re more resilient than we think. That tension is not just mood; it’s a reasonable response to what has changed in the last 10-15 years. Grids have become more software-defined, energy assets are more connected, supply chains are more global, and geopolitical stress is no longer background noise.
Try Premium for just $1
- Full premium access for the first month at only $1
- Converts to an annual rate after 30 days unless cancelled
- Cancel anytime during the trial period
Premium Benefits
- Expert industry analysis and interviews
- Digital access to PV Tech Power journal
- Exclusive event discounts
Or get the full Premium subscription right away
Or continue reading this article for free
For the PV and battery industry, this is not an abstract national security debate. Utility-scale PV, hybrid PV+BESS, standalone BESS and aggregated distributed energy portfolios now participate in services that used to be provided almost exclusively by synchronous machines: voltage control, frequency response, fault ride-through, fast ramping and increasingly “grid-forming” behaviour.
When you connect more PV and storage, you also connect more firmware, remote access paths, third-party monitoring and update mechanisms into the core of power system stability.
So, the central question is not whether the grid is “fragile”. It’s whether a complex, adaptive system designed to survive faults can keep adapting fast enough as the failure modes evolve from physical contingencies into cyber-physical control and coordination risk.
When systems break but don’t collapse
A useful way to calibrate fear is to look at real disruptions where the world briefly looked “stuck” and then wasn’t.
The blockage of the Suez Canal in March 2021 is the supply-chain equivalent of a single-point-of-failure thought experiment. A grounded container ship halted traffic for nearly a week, and the resulting backlog exceeded 400 vessels. Reporting at the time also highlighted the scale of delayed value moving through that corridor. Then the canal reopened, and the backlog was worked down over days rather than months. The shock was real, but so was recovery.
A more recent European example shows the same pattern on the physical side. In January, an arson attack damaged high-voltage cables in southwest Berlin, cutting electricity for several days to around 45,000 households and more than 2,000 businesses. The disruption was serious, politically charged, and widely felt, but it still remained a bounded outage rather than a system-wide collapse.
Cyber incidents against critical infra structure have a similar “massive attention, bounded duration” pattern but with important caveats.
In Ukraine, the 2015 power grid cyberattack remains a milestone because it caused real outages, not just IT disruption. An E-ISAC/SANS analysis describes coordinated attacks against multiple distribution companies, impacting about 225,000 customers, with outages measured in hours and service reportedly restored relatively quickly. Critical services resumed quickly, although recovery of full operational capability took much longer and included constrained operations and manual workarounds.
A follow-on 2016 event targeted a transmission-connected substation and highlighted a different risk: malware modules built to speak industrial protocols (IEC 101/104/61850) and issue breaker commands. It was an explicit bridge from IT compromise into operational control. Similar events now occur routinely, often in parallel with kinetic military operations, but sometimes also in times of increased geopolitical tension, such as in Poland last December, but more on this later.
Now compare these cyber-attacks to a physical emergency. The February 2021 cold-weather crisis in Texas is a documented case where equipment performance, fuel supply disruption and weather drove a very large reliability event. A FERC/NERC joint presentation summarising the investigation notes that ERCOT, the Texan grid operator, averaged ~34,000MW of generation outages for over two consecutive days, and that firm load shed in ERCOT lasted nearly three consecutive days at its worst point. Official reports link 246 deaths to the outage.
The takeaway is not “cyber is less serious.” It is that duration and impact depend on what is attacked or how it fails. Many cyber events to date have produced hours-scale outages (or no generation impact) while extreme weather and fuel/equipment cascades have produced multi-day outages. But digitalisation and automation of the grid are trending deeper into the operational technology, and therefore the potential cyber risk and also the impact of unintentional software errors increase.
The grid is built to be resilient from the ground up
Despite the risks, power grids endure because they were built on the assumption that bad things happen: lines trip, transformers fail, lightning hits, plants disconnect, operators make mistakes. The system stays standing because it has layers of “keep it from getting worse” logic.
When a failure in a component or control system occurs, protective systems are designed to take the affected components out of service and isolate the fault. This is true in your house with your breaker panel as well as at the grid scale. The grid as a whole is designed with ancillary and flexibility services to maintain stable voltage and frequency, and when a region becomes unstable, it can be automatically isolated to limit the spread of the outage.
A concrete example is the Iberian Peninsula blackout of April 2025. It has become a modern reference point because it shows both the resilience of the grid and the complexity of the transition now underway. ENTSO-E’s final report did not reduce the event to a simple “renewables caused the blackout” narrative.
Instead, it identified a combination of interacting factors, including oscillations, gaps in voltage and reactive power control, differences in voltage regulation practices, rapid output reductions and generator disconnections in Spain and uneven stabilisation capabilities.
That matters for the PV and battery industry because it highlights a broader point: as power systems become more inverter-dominated, resilience increasingly depends on how fast, distributed, software-driven assets behave together under stress, not just whether individual components remain online.
This matters for PV and BESS because resilience is not only about preventing events, it is also about how the system behaves during the failure: whether assets revert to a safe state, whether control loops remain stable during abnormal conditions and whether operators can regain trustworthy control and situational awareness quickly.

The transition to inverter-based resources is creating new failure modes
One of the clearest signs that the risk landscape is changing is that some of the most important grid events involving inverter-based resources are not caused by traditional faults at all, but by control interactions, tuning issues, and correlated responses across fleets of devices.
In a September 2025 “Lessons Learned” bulletin, NERC describes three oscillation events during commissioning of hybrid PV+BESS sites, all caused by controller integration and feedback logic failures. In the most severe case, a +200MW discharge setpoint triggered 17 minutes of oscillation, with the plant swinging from +275MW discharging to -138MW charging until operators switched the controller to local mode.
NERC traced the events to issues such as invalid NaN values in metering compensation logic, non-standard PLC and inverter restart behaviour after software updates, and unstable feedback caused by switching between battery-only and combined PV+BESS meter signals.
The bulletin’s core message is that routine software, controls and commissioning errors in inverter-based resources can now create interconnection-wide reliability events. Similar non-public events have also occurred in Europe, leading to the loss of HVDC interconnectors.
Australia offers an equally important public example. AEMO has documented persistent oscillation problems in the West Murray Zone, an inverter-based-resource heavy, low-system-strength area with large concentrations of solar and wind generation. AEMO says these oscillations were first observed in 2019, with further intermittent oscillations identified after a line trip on 20 August 2020. In 2020, AEMO said five West Murray solar farms were only able to have constraints lifted after the successful testing of new tuned inverter settings.
Because grid behaviour is more heavily influenced by software, we start to worry about software-driven common-cause failures. A public example can be found in North America. In its report on the 2021 California solar PV disturbances, NERC found that multiple facilities experienced similar protection-related responses during grid disturbances, and that some issues were more pronounced for one inverter manufacturer, particularly in older models.
NERC also recommended proactive settings updates across existing facilities that might be vulnerable to the same behaviour. Other similar concerns include sudden and simultaneous shutdown of plants in response to negative pricing signals. It is not just whether one plant misbehaves, but whether large numbers of devices sharing similar firmware, settings, or control logic will respond in the same way at the same time.
The cyber relevance is straightforward. If unintentional controller interactions, shared tuning assumptions, or common protection settings can already produce oscillations and widespread misresponse, then an attacker may not need to “turn a plant off” to create disruption.
A more plausible concern is the deliberate manipulation of shared control logic, plant controller setpoints, measurement feedback, or firmware behaviour across many similar devices. In a highly digitised PV and BESS fleet, the real risk is not only outage—it is loss of control integrity at scale. This scenario is highlighted in the DNV report
Solutions for PV Cyber Risks to Grid Stability, commissioned by SolarPower Europe, as it requires less compromised capacity to have an impact on grid stability.
Two implications follow for PV/BESS practitioners.
First, modern grid events are increasingly control-driven. The “root cause” might be an algorithm, a mismatch between intended and actual feedback signals, an update procedure that restarts inverters unexpectedly, or a latent bug that only appears under certain dispatch or topology conditions.
Second, cybersecurity is shifting from “prevent outages” to “preserve control integrity”. The security objective is no longer just confidentiality of data or uptime of servers; it is ensuring that control loops and protection coordination can’t be coerced into unsafe operating regions at scale.
Cyber risk is now visibly inside renewable plants, not just around them
The most useful evidence here is not a hypothetical red-team story; it is the public reporting of real compromises affecting renewable facilities.
In late 2025, CERT Polska reported an “attack on renewable energy plants” in Poland targeting at least 30 wind and solar farms. The documented outcome was loss of communication between facilities and DSOs, however generation remained intact.
From the perspective of the transmission system operator Polskie Sieci Elektroenergetyczne, the attack did not impact the stability of the national power system during the period. But CERT Polska explicitly notes that the attacker’s level of access created a risk of disruption in generation at affected facilities, even if the aggregate loss would not have threatened system stability at that time.
This is the uncomfortable middle ground engineers should pay attention to. Operational stability can remain intact while adversaries demonstrate they can penetrate and manipulate plant operational technology infrastructure. The attackers were in the substation network, which in this case may have been isolated from the plant controller.
If access to the plant network is possible, the consequences extend beyond opening breakers or cutting off communication. For several reasons, once you have access to a plant network, it is often trivial to login to control and protection applications with default credentials via available web interface, giving the user full access to the control functions of the plant.
The CERT report provides details that translate almost directly into actionable controls for PV and BESS portfolios:
- The attack affected the grid connection point substation, and just as with most PV and BESS plants, such substations are typically unmanned and remotely managed.
- In each affected facility, a poorly configured FortiGate device served as a virtual private network (VPN) concentrator/ firewall. VPN interfaces were exposed to the internet and allowed authentication without MFA and in many instances shared and reused credentials were in use.
- After gaining access to the internal substation network, the attacker conducted reconnaissance and then executed destructive actions against accessible devices, including controller firmware damage, deletion of system files, and damaging to the RTUs which cut communication with the DSO and disabled remote control.
Put bluntly: remote access is operationally convenient and commercially normal but can be a first-class threat path when implemented incorrectly. Industry bodies are now acknowledging that this is not only an OT cybersecurity concern, but a grid-stability concern.
SolarPower Europe has argued for an EU-wide baseline for PV cybersecurity, regulators are working behind the scenes to better understand the problem to improve regulation, ENTSO-E is considering such scenarios in their risk assessment under the Network Code for Cyber Security and many industry stakeholders are taking a proactive approach to improve cyber security and software development and deployment processes.
Supply chain risk is bigger than “China versus not China”
It is true that PV and battery supply chains are highly concentrated—and that this creates strategic risk. One that, at an EU level, for energy security reasons, should not be ignored. But the engineer’s version of the argument is not “country X bad.”
Regarding PV, the International Energy Agency has documented that China’s share across the major manufacturing stages of solar panels exceeds 80% (polysilicon, ingots, wafers, cells, modules). In the IEA’s framing, the world is “almost completely” reliant on China for key building blocks through at least the mid-2020s given capacity under construction.
Additionally, the analysis in the SolarPower Europe report shows nearly 50% of inverters in Europe come from only two Chinese manufacturers.
On batteries, concentration can be even sharper depending on chemistry. The IEA notes that the LFP supply chain is particularly concentrated in China, with over 98% of LFP cathode material and LFP battery cells produced there (contrasted with nickel-based supply chains that are less concentrated).
Separately, IEA analysis of EV battery supply chain sustainability notes that China has accounted for more than three-quarters of battery cell production (with large shares of key components such as cathodes).
These are real concentration risks. Yet supply chain exposure in PV+BESS projects is not limited to modules and cells:
- Inverters, plant controllers, BMS/EMS platforms and remote monitoring systems embed software supply chains and update channels.
- Cloud dependencies and managed services can become de facto single points of operational dependency even if hardware is multi-sourced.
- “Common mode” vulnerabilities (a shared VPN configuration pattern, shared default credentials, shared device exposure patterns) can create correlated failure risk across a fleet that looks diversified on paper.
So, the more precise statement is: risk is driven by concentration, transparency and control—not geography alone.
That framing is consistent with mainstream cybersecurity supply-chain risk management guidance. NIST Special Publication 800-161 Rev. 1 describes cybersecurity supply chain risk management as identifying, assessing and mitigating risks throughout the supply chain at multiple levels (enterprise, mission/business process, system), integrating C-SCRM into broader risk management rather than treating it as procurement paperwork.
For grid operators and asset owners in Europe, supply chain risk is also formalised in NIS2 requirements (e.g., vendor and procurement risk management expectations). But even for organisations outside that compliance boundary, the underlying logic is transferable: if a supplier can influence your system via updates, remote access, or hidden dependencies, then vendor assurance must extend beyond “where it was made”.
What’s changing and what PV and battery professionals can do now

The system is not standing still—regulators, transmission system operators and industry groups are actively tightening expectations because they are watching the same trendlines.
The number of cybersecurity regulations in the EU is expanding. We now have more than just NIS2, but also the CRA, CER, NCCS, CSA and so on. A list of acronyms that could make your head spin. And each one tacks on more things for organisations to consider. But at the end of the day, good cyber hygiene across the organisation gets you 80% of the way there. Most cyber regulation is written as outcome-based, with controls chosen by risk-informed decisions.
So, for PV and battery professionals (EPCs, asset owners, integrators, OEMs, O&M teams), the “practical” move is to treat cyber and supply chain security as engineering requirements, not just IT checkboxes. Cybersecurity is more a process than a destination, measured by maturity levels determined by the level of structure and detail included in the various required processes. And for each process, there is a mountain of guidance to accompany it. But if you are just starting out, there are some areas that offer more value for limited resources.
Secure remote access by design. Remote access is no longer a convenience layered onto operations; it is part of how plants are maintained, tuned, updated, and supported. That also makes it one of the most attractive and repeatedly exploited paths into operational technology. For PV and BESS assets, this means moving well beyond basic VPN access and treating remote connectivity as a controlled engineering function: no unnecessary direct internet exposure, strong multifactor authentication, brokered vendor access, time-bounded sessions and comprehensive logging.
Improve network and access controls
Once an attacker gets a foothold, the real question is whether that foothold can become plant-wide or fleet-wide control. Strong network segmentation and access control are what prevent that escalation. In practice, corporate IT, engineering workstations, vendor connections, plant control networks, and critical protective or substation interfaces should not sit in the same flat environment. Within a remote plant network, having separate networks for CCTV, substation, and plant control with restrictive firewall rules is a great starting point.
Access inside the environment should also be tightly governed through role-based access control, least privilege principles, and strong authentication between zones, so that users and systems can reach only the functions they genuinely need. In practice, this is having unique logins for individuals and mapping their account to a set of allowed functions. Such as not allowing IT to make changes to controller logic and not letting engineering create new user accounts.
Create real network visibility and detection
Many operators understand in theory that visibility matters, but in practice they remain partially blind inside their own plant networks. Asset inventories are incomplete, logs are thin, abnormal behaviour is hard to distinguish from normal plant variability and controller or protocol anomalies may go unnoticed until operations are already affected. For PV and battery systems, this visibility has to extend beyond traditional IT telemetry into plant communications, controller behaviour, engineering changes and unusual interactions between devices. Intrusion detection products specific to OT environments are cost-effective and can still provide visibility and detection, even at smaller remote facilities.
Train engineering and operations teams on cyber-physical risk
In software driven energy systems, risk is not created only by malicious actors. It is also created by misunderstood control interactions, poor assumptions about restart behaviour, weak validation of updates and a lack of appreciation for how local changes can produce system-level effects. The people configuring plant controllers, inverter settings, remote access paths, protection interfaces and firmware updates therefore need more than general cybersecurity awareness.
They need OT-specific training that helps them understand how cyber compromise, configuration error and unstable control logic can all lead to the same operational consequence: loss of control integrity. If the industry wants to avoid software-driven instability, engineers and operators need to see cybersecurity and digital reliability as part of system behaviour, not as someone else’s compliance problem.
Strengthen supply chain and secure development requirements
Supply chain security cannot stop at country of origin or vendor reputation, it has to include confidence in how software and firmware are designed, tested, updated and maintained. In practice, that means requiring vendors to demonstrate disciplined development practices, change control, vulnerability disclosure, support lifecycles and transparency around updates and remote dependencies.
The EU Cyber Resilience Act will improve vendor security across the board, but this won’t relieve the burden of performing vendor due diligence reviews. The risk is not just malicious intent, and not all issues begin with malware. They begin with weak validation, unsafe deployment practices and software or control logic errors that only appear under real operating conditions. Secure development therefore needs to be treated as a resilience issue, not just a procurement checkbox. If a supplier can introduce instability through poor engineering, then product quality and cybersecurity are inseparable.
Rehearse incident response and recovery
Even well-designed systems and well-managed suppliers will not prevent every failure, which is why response and recovery have to be treated as engineering disciplines in their own right. Operators should know in advance how to isolate remote access, how to fall back to safe modes, how to restore known-good configurations, how to coordinate with OEMs and grid operators and how to recover without improvising under pressure. That preparation needs to be tested, not assumed.
In the end, resilience depends not just on keeping bad things out, but on ensuring that when something still goes wrong, the organisation can contain it quickly, restore trustworthy control, and keep a serious incident from becoming a wider crisis.
Once the essentials are in place, the maturity of the programme can be improved and made compliance-ready by aligning with emerging baselines rather than improvising. SolarPower Europe’s cybersecurity baseline work and ongoing regulatory action signal a move towards harmonised requirements, indicating that industry “best practice” is converging.
If you build your fleets to meet the direction regulators and TSOs are already moving, you reduce rework risk and, more importantly, you reduce the probability that your fleet becomes the common-mode failure nobody intended.
Viewed through that lens, the most honest answer to “how exposed are we?” is not that much, but only if we stop treating cybersecurity and supply chain as a political argument and start treating them as control-system engineering for a digitised grid. The grid’s historical resilience is real. The new failure modes are real, too. And the PV+BESS industry is at the centre of a future stable and resilient grid.