tech_surveillance708 wordsRead on Arc Codex

Cyber attack on battery energy storage systems could trigger blackout, report finds

A successful cyber attack against 29% of the UK’s battery energy storage systems (BESS) – approximately 400 units – could trigger a national blackout, according to a report from cybersecurity firm Centrii. Published yesterday (2 September), the report, titled Battery Energy Storage Systems — A Monte Carlo Risk Assessment, says: “BESS are critical to modern grid stability, providing frequency regulation for renewable energy integration. However, cloud-controlled BESS architectures create novel attack surfaces that enable coordinated cyber-physical attacks. “This paper introduces Gridlock, a threat scenario where adversaries compromise multiple BESS units to execute grid-scale Distributed Denial of Service (DDoS) attacks using energy as the weapon. “Unlike traditional DDoS attacks targeting network bandwidth, Gridlock manipulates physical power flows to destabilise grid frequency, triggering cascading blackouts.” It adds: “We validate technical feasibility through analysis of recent academic research demonstrating that load-altering attacks using 11 to 21 compromised 2MW BESS units can destabilise regional grids. “Monte Carlo simulations (10,000 iterations) across three security postures show a 92% probability of a major Gridlock attack by 2031 under current conditions, reducing to 61% with aggressive IEC 62443 compliance.” Under its UK case study, the report said: “UK National Grid operates 6.8 GW of BESS capacity (79% concentrated in England), consisting of approximately 1,400 individual units. “Gridlock attack requirements show that compromising 29% of BESS (400 units) triggers a national blackout, affecting 67M people with £2bn-£10bn economic damage. “Great Britain faces heightened vulnerability due to lack of grid isolation (single national grid) and concentrated geographic deployment (79% in England).” Centrii co-founder and CEO Rafael Narezzi said: “A coordinated attack does not need to stop generation to cause a blackout. “It only needs to desynchronise the balancing layer, forcing batteries to charge or discharge together, or delaying how they respond to grid signals. Neither action damages a battery. “The effect is closer to a distributed denial-of-service attack than a conventional outage – instead of overwhelming a website with traffic, it overwhelms the grid’s ability to stay in balance, using energy itself as the disruptive force. The modelled result is a cascading blackout that unfolds in under two minutes.” He added: “Every board I speak to already accepts that cyber risk exists. What they haven’t had is a definitive assessment that helps them to reach the right figure. “Security spending in operational technology is rarely treated as return-generating, because its value shows up in an event that does not happen. This modelling makes that value visible and measurable. “Based on these figures, protecting battery storage is one of the highest-return decisions available anywhere in the business, but it’s also one of the least discussed at board level.” A government spokesperson told NCE: “The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards. “We are alive to growing cyber security threats and are driving legislation through parliament to introduce new powers to tackle threats to our national security.” Energy Storage Association (ESA) UK operations and strategy director John Southern told NCE: “The ESA welcomes efforts to raise awareness of cyber security risks affecting battery energy storage systems and agrees that cyber resilience must be a significant priority for the sector. “The Gridlock report presents modelled (noted in the report) scenarios based on several assumptions regarding attacker capability and the successful coordination of attacks across a large proportion of the UK’s highly diverse BESS fleet. “It is worth highlighting the work already underway across industry, government and the Smart Secure Electricity Systems workstreams (SSES) to address these risks.” He added: “Through our own IOT (Internet of Things) and Cyber security working group, industry participants are actively working with SSES, DESNZ (Department for Energy Security and Net Zero) and other stakeholders to accelerate the implementation of appropriate safeguards, improve cyber resilience and strengthen operational security across the sector. “We recognise the potential severity of cyber threats to critical infrastructure, but it is equally important to recognise the mitigation measures already being developed and deployed. “Our focus remains on ensuring that the rapid growth of energy storage is matched by robust and proportionate security measures that maintain confidence in the resilience of the UK’s energy system.” Have your say or a new account to join the discussion.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.