Cyber Security’s Hidden Risk in Renewable Energy Infrastructure
Every wind farm, solar park and battery site is also a computer - thousands of them, in fact, networked together and scattered across the country. We connect them for the clean power they produce. We rarely stop to think that each one is also a door, and that most of those doors were built by people who never asked who might walk through them.
That is the uncomfortable truth behind Clean Power 2030, and the UK government has now said so out loud. Its Energy Sector Cyber Security Strategy, published by DESNZ, Ofgem, the NCSC and NESO, warns that "if security is not embedded throughout the transformation of the energy sector, adversaries are likely to exploit emerging vulnerabilities and gaps." This is not hypothetical caution: in December 2025, attackers targeted Poland's energy system precisely through its distributed energy resources - the small, dispersed generation and storage assets the strategy names directly.
Why distributed renewables are a different kind of target
A conventional power station is one large, heavily defended site. A renewables-led grid is the opposite: thousands of smaller assets, many of them remotely monitored and controlled, spread across the country and stitched together by software. The strategy puts it plainly - Britain's "energy infrastructure was never designed with rapid digitalisation and decentralisation in mind."
Each turbine, inverter and battery rack is a computer that talks to the outside world. Collectively, they add up to gigawatts of capacity an attacker could try to manipulate at once. The attack surface is no longer a perimeter fence. It is the whole fleet.
Solar farms and the inverter problem
Solar is the clearest illustration. In March 2025, security firm Forescout published its SUN:DOWN research, disclosing "46 new vulnerabilities across three of the world's 10 leading solar inverter vendors" - Sungrow, Growatt and SMA. More tellingly, of 93 previously disclosed solar vulnerabilities, "80% were classified as high or critical severity."
Inverters are the brains of a solar installation: they convert DC to AC and manage how the array behaves on the grid. Forescout found flaws allowing cloud-based takeover and remote code execution. As the firm warned, attackers could "manipulate power generation at scale and trigger coordinated load-changing attacks to destabilise the grid - potentially leading to emergency power measures, grid disconnections, or even blackouts." All vendors patched the issues, but the lesson stands: the cleverness is in the software, and so is the risk.
Battery storage: fast, flexible, and exposed
Battery energy storage is the flexibility that makes a renewables-heavy grid work, soaking up surplus wind and solar and releasing it on demand. That same centrality makes it a prize. A December 2025 white paper from the Brattle Group and Dragos, reported by Cybersecurity Dive, found utility-scale BESS "facing heightened risks of attack from nation-state and criminal threat groups."
The economics sharpen the point. The report calculated that a single 100MW outage lasting four hours "could cost up to $1.2 million in revenue," while a larger event affecting 100,000 customers could run to $39 million. As Dragos's Phil Tonkin put it, batteries' growing role in enabling solar and wind "makes them an attractive target." With BESS deployments expected to grow 20-45% over five years, that exposure is compounding.
SCADA and OT: the layer nobody sees until it breaks
Behind all of this sits the control layer: SCADA and the wider world of Operational Technology - the systems that actually open and close breakers, adjust turbine pitch and dispatch a battery.
OT is where renewables security gets genuinely hard. These systems were engineered for safety and uptime over decades, often long before constant internet connectivity. They speak industrial protocols with little built-in authentication, run on hardware that cannot simply be rebooted for a patch, and were historically air-gapped - a separation that digitalisation has quietly erased. An attacker in the OT layer is not stealing data; they are touching the physical grid. The same Brattle/Dragos work notes 18 threat groups tracked as targeting electrical infrastructure, including state-linked actors that "live off the land" inside control networks to stay hidden.
The talent gap underneath the risk
Here is the part the headlines miss. You cannot defend OT with an IT security team alone, and you cannot run a wind farm's controls safely with engineers who have never thought about adversaries. The UK strategy names this directly: the country "faces a significant shortage of professionals that have the required combination of cyber and engineering skills, with an insufficient number of security-cleared industry staff."
It is an explicit objective of the four-year plan to build capability "specifically related to bridging the gap between OT engineering and cyber." That is a workforce problem before it is a technology problem. People who understand both an inverter's firmware and an attacker's playbook - who can read a SCADA architecture and a threat model - are genuinely rare, and demand for them is about to rise sharply as the Cyber Security and Resilience Bill widens regulatory scope across the sector.
Cyber security is no longer a bolt-on to renewable energy infrastructure - it is part of the asset. For developers, asset owners and O&M providers, the strategic question is not only how to secure the fleet, but who will do it. The convergence of energy OT and cyber security is creating a category of specialist that barely existed five years ago, and the organisations that hire ahead of the curve will be the ones still generating, and earning, when the next incident lands.
At Gaia, securing renewables talent is our whole focus - including a dedicated cyber security division built for clean energy. If you are planning the people behind your next project's defences, we would welcome the conversation.
Sources
Energy sector cyber security strategy - DESNZ, Ofgem, NCSC & NESO - 28 May 2026 - https://www.gov.uk/government/publications/energy-sector-cyber-security-strategy/energy-sector-cyber-security-strategy
Verified quote: if security is not embedded throughout the transformation of the energy sector, adversaries are likely to exploit emerging vulnerabilities and gaps.
Grid-scale battery energy storage systems face heightened risk of cyberattack - Cybersecurity Dive (reporting Brattle Group & Dragos) - 11 December 2025 - https://www.cybersecuritydive.com/news/battery-energy-storage-systems-risk-cyberattack/807675/
Verified quote: facing heightened risks of attack from nation-state and criminal threat groups; a 100MW outage could cost up to $1.2 million in revenue.
Forescout Vedere Labs uncovers severe systemic security risks in global solar power infrastructure (SUN:DOWN) - Forescout - 27 March 2025 - https://www.forescout.com/press-releases/forescout-vedere-labs-uncovers-severe-systemic-security-risks-in-global-solar-power-infrastructure/
Verified quote: 46 new vulnerabilities across three of the world's 10 leading solar inverter vendors.
More Assets
Clarity In The Search
What sectors do you recruit for?
What types of roles can you help us fill?
How quickly can you provide suitable candidates?
Do you recruit permanent, contract or temporary staff?
Can you support projects across the UK and internationally?
How do you assess candidate quality?
What makes your recruitment consultancy different?
Can you help with difficult-to-fill or niche positions?
Do you provide recruitment support for major project mobilisation?
How do we get started?







