Research from Centrii warns that a coordinated cyberattack on the U.K.’s battery energy storage infrastructure poses a nationwide grid threat costing up to US$10 billion. The GRIDLOCK scenario demonstrates how compromising just 29% of national battery storage capacity could trigger an outage affecting 67 million people, as cloud-connected BESS fleets create new attack surfaces for grid-scale disruption.
In a report titled ‘GRIDLOCK: What a Coordinated Battery Attack Would Cost the Grid,’ Rafael Narezzi, CEO and co-founder at Centrii, presents findings from a Monte Carlo risk assessment running 10,000 simulations across three industry security postures. The analysis quantifies the probability and financial impact of coordinated attacks on battery storage through 2031, showing a 92% probability of a major attack under today’s industry-average security posture, falling to 61% with mandatory IEC 62443 certification in place.
“In Texas, compromising just 5.4% of ERCOT’s battery fleet (1,500 units) is enough to affect 30 million people, with an estimated $12B–$65B in economic damage,” he identified. “In the GB, compromising 29% of national BESS capacity (400 units) is enough to trigger a national-scale blackout affecting 67 million people, with an estimated £2B–£10B in economic damage. Securing that infrastructure is dramatically cheaper than the alternative: our analysis shows a 15x–80x return on proactive security investment relative to the cost of an attack.”
Underlining that battery storage exists to balance the grid, Narezzi pointed out that wind and solar generation rise and fall with the weather; batteries absorb the excess and release it back when generation dips, keeping the grid’s frequency stable. “Its role is like a voltage regulator protecting a piece of sensitive electronics — without it, supply and demand drift out of sync, and the system becomes unstable. Increasingly, that balancing function is managed remotely, through cloud-based control platforms that operate thousands of battery units across a portfolio or a national grid.”
He recognized that connectivity is what makes modern BESS fleets efficient to operate at scale, and it’s also what creates a new kind of exposure. “A coordinated attack on battery storage doesn’t need to stop power generation to cause a blackout. It only needs to desynchronize the balancing layer — forcing batteries to charge or discharge in a coordinated, disruptive pattern. The effect is closer to a distributed denial-of-service attack than a conventional power outage: instead of overwhelming a website with traffic, the attack overwhelms the grid’s ability to stay in balance, using energy itself as the disruptive force.”
The GRIDLOCK report notes that in the past year, two events have shown how plausible and how difficult to detect a coordinated disruption of grid balancing infrastructure already is.
Last December, in Poland, state-sponsored actors attempted to destabilize regional grid infrastructure by rapidly cycling wind turbine output on and off. Not by damaging equipment, but by manipulating output in a way designed to push grid frequency out of balance. The attempt was contained, but it demonstrated a working blueprint: an adversary does not need to stop generation to threaten grid stability. Disrupting the balance is enough.
Before that, on April 28, last year, in Spain and Portugal at 12:33 CEST, a small number of large solar and wind sites stopped producing at the peak of the day, together shedding 2.5 GW of generation in under 20 seconds, enough to collapse the Iberian grid. The outage lasted roughly 10 hours, and as long as 20 hours in some areas.
Narezzi mentioned that two aspects of the official record are worth noting. First, the affected sites have no usable operational logs from the moment of failure. Investigators cannot reconstruct what the control systems saw or decided in that window. Second, when the documented grid conditions are re-run in simulation, they do not reproduce a blackout. Sources believe something happened at those sites that isn’t captured in the official account.
He noted that Spanish and Portuguese authorities attributed the outage to a technical fault, not a cyberattack. “What the Iberian blackout demonstrates is narrower, and arguably more important for risk purposes: a small number of large renewable sites can take a national grid offline in under 20 seconds, through a failure mode that official investigators — using the complete forensic record available to them — have not been able to fully explain or reproduce.”
To understand what’s being measured in the Centrii report, it helps to walk through how a coordinated attack on battery storage would unfold. Battery fleets are increasingly managed through cloud-based control platforms that issue charge and discharge commands to thousands of units at once, creating access points through weak remote access credentials, outdated firmware, or supply chain vulnerabilities in inverters, optimizers, and battery management components. Once access is established, an attacker can synchronize commands across many units simultaneously, instructing them to charge or discharge together or introducing delays into how they respond to grid signals. While neither action damages individual batteries, both can disrupt the grid by manipulating electrical frequency.
Electrical grids operate within a narrow frequency band, and any significant deviation creates unsustainable imbalances between supply and demand. A synchronized flood or drain of power across a large battery fleet pushes frequency outside safe operating limits, as does introducing even a few seconds of delay into battery response times, effectively transforming a system designed to stabilize the grid into one that amplifies instability. Once frequency deviation crosses a critical threshold, protective relays, safety mechanisms built to prevent equipment damage, begin tripping automatically. While this isolation function prevents physical damage, sequential relay trips at scale cascade into a blackout, unfolding in under two minutes from the attack’s start.
The scale required for such an attack is smaller than most portfolio owners assume. Academic modeling validates that compromising a relatively modest share of a region’s total battery capacity, well under a majority, is sufficient to push grid frequency outside safe limits, following the same logic as traditional denial-of-service attacks: many compromised endpoints coordinated to overwhelm a single system at once.
The Monte Carlo model quantifies this scenario not to determine whether the mechanism works, which has already been validated in peer-reviewed simulation, but to assess how likely someone is to use it and what consequences would result.
The findings in the GRIDLOCK report are not a conventional forecast, as no one can predict exactly when or where a coordinated attack on battery storage might occur. Instead, this analysis employs a Monte Carlo simulation, a modeling technique that runs a scenario tens of thousands of times while varying underlying conditions within realistic bounds to produce a probability distribution rather than a single prediction. This same class of technique is well established in financial risk modeling, insurance underwriting, and climate forecasting, wherever the central question is ‘how likely’ rather than ‘if.’
For this analysis, the model was run 10,000 times across three industry security postures. The baseline scenario reflects current, industry-average security practices with no meaningful improvement over time. The moderate scenario assumes voluntary security enhancements adopted gradually and unevenly across the industry. The aggressive scenario reflects mandatory IEC 62443 certification and regular attack-readiness drills adopted consistently. Each simulation incorporated realistic variables including the pace at which attackers are likely to improve their capabilities, the expected growth trajectory of battery storage capacity, and a range of realistic success rates for different attack vectors such as cloud platforms, remote access tools, and hardware supply chains.
Rather than relying on single assumptions for each variable, the model draws from a plausible range each time it runs. This approach allows 10,000 iterations to produce a meaningful probability distribution instead of one fixed answer, providing insight into how different security investments affect the likelihood and consequences of coordinated battery storage attacks.
The GRIDLOCK report also quantifies the alternative and examines the cost to close risk gaps and how that cost compares to an attack’s price. Bringing GB battery storage to IEC 62443 Security Level 2, which has been shown to meaningfully reduce attack probability, costs an estimated £400M to £1B. A single major GRIDLOCK class attack costs £2B to £10B, yielding a 5x to 25x return on security investment. Even in conservative comparisons, prevention costs a fraction of recovery.
Securing the ERCOT battery fleet to the same standard costs $800M to $2.8B, compared to a single attack cost of $12B to $65B, producing a 15x to 80x return on investment in the most severe scenarios. This pattern holds across all market sizes. Proactive security costs hundreds of millions; a successful attack costs billions. For portfolio owners and investors, this is not a marginal risk decision but one of the highest return investments available in battery storage portfolios.
This inverts how OT security is typically perceived. Its value is rarely framed as return-generating because it’s measured in events that, if the investment works, never occur. This report makes that value visible. The return isn’t hypothetical or close; it’s calculable.
Narezzi said that the findings in the GRIDLOCK report “point to a clear conclusion: the cost of prevention is a fraction of the cost of an event, and the technology to close this gap already exists. What’s missing isn’t capability. It’s urgency and adoption.”
For regulators and standards bodies, the case for mandatory action is direct: require IEC 62443 Security Level 2 certification for grid-connected battery storage on a defined timeline, extend existing frameworks like NERC CIP and NIS2 to explicitly cover BESS-specific controls, and introduce supply chain security requirements for battery hardware and firmware given how concentrated global manufacturing is today. Regular, mandated attack-readiness drills, modeled on the exercises already common in aviation and financial services, would meaningfully shorten the gap between a vulnerability being discovered and being fixed.
For asset owners, operators, and investors, the responsibility doesn’t wait for regulation to catch up. The practical priorities are consistent regardless of geography: isolate battery control systems from general corporate IT networks, require multi-factor authentication on every remote access point into cloud control platforms, keep firmware current and verified, and build redundancy into frequency measurement so no single sensor or feed becomes a point of failure. None of these are novel security concepts, but are the same fundamentals that have hardened other categories of critical infrastructure. Battery storage has simply outpaced their adoption.
“Every finding in this report traces back to one underlying shift: as more of the grid’s balancing capacity moves into cloud-controlled battery systems, more of the grid’s stability depends on who controls that software layer — not who owns the physical asset beneath it,” Narezzi wrote. “That’s the real question this report raises, beyond probability and cost. If a remote vendor portal, a compromised credential, or a piece of unpatched firmware can influence the frequency of a national grid, then operational control of that grid is no longer fully defined by ownership. It’s defined by whoever controls the systems in between.”
He added that the report has modeled the probability of that control being taken (92% by 2031 under current industry conditions, falling meaningfully with proactive investment) and the financial exposure that follows. “What it can’t model is timing with certainty. The conditions for a major attack on battery storage already exist today, and every year of delay in closing this gap is a year the probability compounds rather than resets. The question for every asset owner, investor, and risk leader reading this isn’t whether a coordinated attack on battery storage is possible.”
“The research in this report (and the events already unfolding in Poland and Iberia) settle that question,” Narezzi observed. “The real question is whether the industry closes this gap before the first attack, or after. For organizations ready to understand their own exposure (by asset, by portfolio, or across an entire fleet), Centrii’s platform translates this same class of risk into board-ready financial terms, specific to your infrastructure.”


