OTSecurity

Centrii warns nation-state access and renewable supply-chain risks raise energy sector financial exposure


New analysis from Centrii identified that cyber risk in the energy sector is increasingly becoming a financial and geopolitical concern as nation-state activity, ransomware and renewable-energy supply-chain risks converge. In an Oct. 1 analysis, the company said state-linked actors are increasingly positioning themselves inside energy infrastructure for potential future disruption, while criminal ransomware attacks are creating measurable financial exposure for utilities. 

“Over the past several months, nation-state activity, criminal ransomware, and a supply chain crisis have converged into something that looks less like a security problem and more like a portfolio risk,” Centrii detailed in its most recent analysis. “If you sit on a board, manage a fund, or run risk for a utility or an IPP, this is now your problem too, not just your CISO’s.”

Centrii pointed to Volt Typhoon’s reported footholds in U.S. critical infrastructure and an updated U.S. advisory on Iranian-affiliated actors exploiting internet-facing programmable logic controllers, alongside reported Russian-attributed sabotage activity in Europe. The analysis also highlighted growing cybersecurity concerns around renewable-energy supply chains, particularly grid-connected solar inverters and battery systems. 

It noted that the most consequential shift in the threat landscape this year is not a specific breach, despite the serious nature of those attacks. But rather the change in intent, wherein security agencies and researchers now describe multiple state-linked actors as pre-positioning inside energy infrastructure rather than simply gathering intelligence. 

“A China-linked group publicly known as Volt Typhoon has maintained footholds inside US critical infrastructure networks for years, using legitimate administrative tools rather than malware, making it much harder to detect,” the post observed. “US agencies have found no confirmed evidence that the group has been fully removed. The consistent assessment across investigators is that this activity is meant to enable disruption of US energy, water, and communications systems during a future crisis, not to steal data today.” 

A recently updated joint advisory from U.S. federal agencies describes ongoing exploitation of internet-facing programmable logic controllers by Iranian-affiliated actors, with energy sector systems named specifically among the affected deployments. 

In Europe, the activity has moved beyond cyber intrusion into physical sabotage. Reported incidents include a plot to disable undersea cables using submersible technology, and a drone sabotage attempt at a European airport involving military-grade explosives, both attributed to Russia by Western officials. Independent industry threat assessments have separately flagged that distributed renewable and grid-edge assets, the fastest-growing part of the generation mix, carry weaker security governance than traditional generation, and represent a growing share of the exposure. 

None of this requires a successful attack to matter financially. Pre-positioned access inside a network is already a portfolio risk the moment an insurer, a lender, or an investment committee asks whether it can be ruled out. 

Centrii also touched upon how renewable supply chains are now being treated as a national security issue. A large majority of solar inverters installed across Europe come from a small number of Chinese manufacturers, and inverters are the component that links solar and storage assets to the grid. Researchers have publicly disclosed flaws in widely deployed inverters that could let a nearby attacker shut units down, change their output, or push unauthorized firmware using only an intercepted serial number. Investigators have also reported undocumented cellular hardware in inverters and batteries from several Chinese suppliers, capable of bypassing the firewalls utilities use to block outside access.

Regulators on both sides of the Atlantic see this as a structural risk rather than a single-vendor problem. The European Commission has restricted EU funding for renewable projects that use inverters from a list of high-risk suppliers, warning that a coordinated remote shutdown could cause blackouts across several member states. In the US, a new executive order declares a national emergency over the bulk-power system and restricts transactions involving foreign-linked equipment, including grid-connected inverters, battery storage, and industrial control systems, even for equipment already under contract. For anyone acquiring renewable or storage assets, unknown inverter provenance is now a financial and regulatory exposure that needs to be priced into the deal.

“State-linked pre-positioning gets the headlines, but criminal ransomware is doing the most measurable financial damage right now,” Centrii reported. “Utility sector ransomware incidents rose sharply in the first quarter of 2026 compared with prior months, spread across more than a dozen countries. Broader industry analysis has found that energy, oil, and utilities organizations face ransomware at a materially higher rate than the average across other sectors, with most of those incidents resulting in encrypted operational data.”

Moreover, the financial pattern is consistent. Attackers know that recovery costs in the energy sector run well into the millions per incident, and organizations without tested recovery processes for OT environments specifically tend to take far longer to restore service than their IT-only counterparts. That’s leverage.  

Regulation, especially for renewables, has lagged the threat landscape for years, but it is now catching up. NIS2, the EU’s cybersecurity directive, has moved from transposition into active enforcement, with member state authorities running audit programs aimed specifically at the energy sector and imposing real fines rather than warnings. The EU’s Critical Entities Resilience Directive, NIS2’s physical counterpart, required member states to formally designate critical entities by mid-2026, including electricity, storage, and demand response operators. Once designated, those entities have a defined window to meet the full set of requirements, which cover supply chain dependencies, incident handling, and continuity planning, not just cyber controls.

In the U.S., NERC CIP-015 is lowering the capacity threshold that triggers mandatory internal network monitoring. This pulls a much larger share of solar, wind, and storage assets into scope just as inverter-based resources become the fastest-growing part of the grid. TSA’s pipeline security directives extend a comparable monitoring and reporting obligation to midstream oil and gas operators. The executive order restricting foreign-linked grid equipment serves as a compliance answer to the supply chain problem, since it is intended to address what gets installed before it becomes a monitoring burden after the fact.

“Together, these frameworks are pushing the industry away from static, point-in-time compliance documents and toward continuous, timely evidence about monitoring, governance, and incident response,” according to Centrii. “At their core, these frameworks are effective security measures that protect lives and keep operators sustainable over the long run, not just compliance checkboxes. The evidence they require also lets companies prove that resilience continuously, rather than once a year at audit time.”

Centrii said that the insurance market will soon become one of the more effective enforcement mechanisms. Global cyber insurance premiums have risen sharply, and underwriters have shifted from questionnaire-based applications to technical audits of an applicant’s environment. For energy and utility operators specifically, that increasingly means demonstrable, dated evidence of OT monitoring controls, not a vendor attestation, before a policy renews at a reasonable rate. 

“This closes the loop,” it added. “Regulators set the requirement, but enforcement was slow and inconsistent. Insurers now sit on the other side of the same requirement with a much faster feedback mechanism: your premium, your deductible, and in some cases whether you can get coverage at all.”

Taken together, the shape of the problem is clear. Nation-state actors are positioning for disruption, not just intelligence collection. The renewable supply chain behind the energy transition carries a vendor risk that did not exist in this form five years ago. And criminal ransomware crews have learned that utilities will pay when the leverage is right. Regulators, insurers, and investment committees- the three groups with the power to force a response- are now asking the same question at the same time: can an operator prove, continuously and with evidence, that it has visibility into its own operational environment and controls in place to protect it?

“Operators that can answer that question with real, current evidence are turning a compliance cost into a credential with lenders, insurers, and acquirers,” Centrii wrote in its analysis. “Operators that cannot will find out how expensive that gap is at the worst possible moment, whether that’s a renewal letter, an audit finding, or a disruption that reaches the board before the security team has finished writing the incident report.”

In September, Centrii’s GRIDLOCK report modeled the risk of a coordinated cyberattack on UK battery energy storage. Batteries help keep the grid’s frequency stable, and that balancing is increasingly managed through cloud platforms controlling thousands of units at once. The report argues an attacker would not need to halt generation to cause a blackout, only to push batteries into synchronized charge and discharge patterns. 

A Monte Carlo analysis of 10,000 simulations puts the probability of a major attack by 2031 at 92% under current industry practices, falling to 61% with mandatory IEC 62443 certification. Compromising 29% of Great Britain’s battery capacity, around 400 units, could cause a blackout affecting 67 million people and £2B to £10B in damage. The report cites Poland, where state-sponsored actors tried to destabilize the grid by cycling wind turbine output, and the Iberian blackout, where a few large sites shed 2.5 GW in under 20 seconds, as signs of how plausible such disruption is. It estimates that bringing GB battery storage to IEC 62443 Security Level 2 would cost £400M to £1B, a 5x to 25x return against a single attack.



Source link