IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Battery energy storage: 6 security questions operators should be asking

Battery energy storage: 6 security questions operators should be asking

Tue, 29th Sep 2026 (Today)
Rafael Narezzi
RAFAEL NAREZZI CEO and Co-founder Centrii

Battery Energy Storage Systems (BESS) play a critical role in grid stability and renewable energy utilisation. But as these infrastructures become more sophisticated, the risk of cyberattacks grows, potentially compromising operations, safety and energy reliability.

In Centrii's recently published GRIDLOCK report, using risk modelling to analyse what an attack on BESS would cost the grid, it put the chance of a major coordinated attack on the UK's battery storage fleet at 92% within the next five years. The estimated financial cost is between £2 billion and £10 billion. 

But what's interesting from our analysis is that the probability of an attack falls as the security investment and enhancements increase. For example, under voluntary improvements adopted gradually and unevenly across the sector, the probability falls to 78%. With mandatory IEC 62443 certification and attack-readiness drills, it fall to just 61%.

BESS are not passive assets. They are software-controlled, grid-interactive systems that directly influence frequency, load balancing and stability. The integration of IT and OT in energy storage systems increases their vulnerability.

As more countries shift toward long-duration energy storage, these systems could face more frequent attacks. The issue is whether operators and asset owners are prioritising security. These are the questions every operator should be asking:

1. Do I have visibility into my distributed assets?

When operators lose visibility into distributed assets, whether that's down to communication failures, misconfigurations, or malicious interference, the response becomes reactive rather than coordinated.

Unlike centralised generation, battery assets are often remote and dispersed, and heavily dependent on real-time telemetry. Last year's attacks on Poland's power grid show just how threat actors understand how to manipulate remote locations simultaneously to destabilise critical power networks. 

Without continuous, validated visibility into operational states, operators are managing blind.

2. What happens if dispatch signals are manipulated?

Battery systems do not just store energy; they respond to it. Charging and discharging decisions are driven by automated signals tied to grid frequency, market conditions, and control system inputs. If signals are altered, delayed, or spoofed, the behaviour of the battery changes accordingly.

A coordinated manipulation of dispatch signals could cause batteries to discharge during peak stress or charge when supply is already constrained. At scale, this could become a major grid stability event.

3. How secure is my remote access infrastructure?

Remote access is critical to today's energy operations. But it's also one of the most consistently exploited pathways into operational environments.

The challenge is not just whether remote access exists, but whether it is continuously monitored, authenticated and segmented.

One example of a UK battery facility revealed remote connectivity and VPN management as key vulnerabilities before security improvements were made. Without robust controls these pathways could directly access systems responsible for charging discharging and grid interaction.

Remote access must be treated as a critical control point, or it becomes an attacker's shortcut.

4. Are my OT systems designed for today's threat environment?

Many battery installations rely on industrial control systems (ICS) originally designed for isolated environments. But in today's environment, SCADA platforms, battery management systems and programmable logic controllers are connected to external networks. While this enables efficiency and scalability, it also exposes them.

Advisories by CISA in the US have highlighted vulnerabilities in widely used ICS components, including unauthorised command execution, denial-of-service conditions, or system manipulation.

In the UK BESS example, outdated firewalls, irregular patching and poor segmentation led to exploitable conditions within the operational environment. 

5. Is cybersecurity being managed at the speed of deployment?

The simple fact is that battery storage is being deployed faster than many operators can secure it. According to the IEA, global energy storage capacity is expected to grow more than six-fold by 2030. As growth accelerates, it creates a gap between what is operationally critical and what is operationally secured.

In practice, this gap shows up in incomplete asset inventories, delayed patch cycles and limited monitoring of newly deployed systems. When basic vulnerabilities exist, attackers will always sense an opportunity.

6. Do I understand how cyber risk translates into financial impact?

Cybersecurity in energy is often framed as a data protection issue. In BESS environments, it is an operational and financial issue.

The GRIDLOCK report backs this up. It estimates that bringing the UK's battery storage infrastructure up to IEC 62443 Security Level 2 – the standard the modelling shows meaningfully reduces attack probability – would cost between £400m and £1bn across the national fleet. This is a return on proactive security investment of roughly 5x to 25x.

The earliest likely attack window also changes, from 2027–28 under a baseline posture to 2029–31 under the most rigorous one. What's clear is that security investment reduces risk, but also buys time

The grid is becoming far more distributed, connected and automated – and BESS is at the heart of this energy transformation. Distributed control without distributed visibility creates fragility rather than resilience.

For operators the question is not whether cybersecurity matters, but why it matters.