High Risk Of Battery Storage Cyber Attacks Highlights Grid’s Growing DER Security Challenge

Blog
Digital Grid Technologies
09 Oct, 2026

As battery energy storage systems (BESSs) become increasingly important to grid operations, their digital connectivity is creating a new category of systemic risk. A September 2026 study from risk assessment firm Centrii estimates a 92% probability of a major coordinated cyberattack on BESS infrastructure by 2031 under current industry security practices. The probability falls to 78% under moderate security improvements and 61% under the study’s most rigorous scenario, which assumes mandatory IEC 62443 compliance and regular attack-readiness exercises.

The scenario modelled is particularly concerning because it goes beyond the conventional theft or disruption of data. The study considers a coordinated cyber-physical attack in which compromised batteries are instructed to charge and discharge simultaneously, using their physical grid capabilities to destabilize frequency. In Texas, for example, the study estimates that compromising just 1,500 BESS units (5.4% of assets) could be sufficient to disrupt power to as many as 30 million people, with potential economic damage of $12 to $65 billion.

The bigger issue, however, extends well beyond batteries. Power systems are shifting from relatively centralized architectures towards increasingly distributed environments incorporating utility-scale storage and renewables, rooftop solar, EV chargers, heat pumps, flexible industrial loads and other distributed energy resources (DERs). Many of these assets sit outside traditional utility operational technology environments and can be owned by consumers or third parties, while relying on internet connectivity, remote software and cloud platforms. The North American Electric Reliability Corporation (NERC) has previously highlighted precisely this transition, noting that DERs and BTM resources are increasingly connected to the internet as electricity systems digitize.

At the same time, utilities increasingly want to do more than simply observe these resources. DERMS, virtual power plants, aggregators and flexibility platforms are enabling information and control signals to travel between grid operators, software platforms and individual devices. This is fundamental to using DERs for congestion management, demand response, frequency support and other grid services, but it also expands the electricity system's digital attack surface.

This creates an important tension for grid operators

The more valuable DERs become to grid operations, the more consequential their cybersecurity becomes. A compromised residential battery or EV charger has limited system significance in isolation. Thousands of devices responding simultaneously to malicious instructions are a different proposition. Cybersecurity therefore needs to account not only for the vulnerability of individual endpoints but also for the potential consequences of aggregating control over them. The challenge is particularly acute as future grids could contain orders of magnitude more connected devices, many customer-owned, operating autonomously, and using hardware and software from increasingly complex supply chains.

Utilities should therefore treat cybersecurity as an architectural requirement of DER orchestration rather than a layer added after assets have been connected. Authentication and access control, communications and data integrity, malware detection, network monitoring, and behavioural anomaly detection all become important when operational decisions depend upon information reaching down to asset level.

Regulators are also beginning to recognize that electricity cybersecurity cannot stop at conventional utility IT and OT boundaries. The EU's network code on cybersecurity establishes sector-specific requirements around cyber risk assessment, minimum controls, monitoring, reporting and crisis management for entities whose digital processes can materially affect cross-border electricity flows. But technology development is moving quickly, and the proliferation of DER endpoints raises the question of how consistently protection can extend across utilities, aggregators, technology vendors and consumers. 

Discover more Digital Grid Technologies content
See More