Cybersecurity in the global power sector has reached an inflection point. While renewable energy capacity accelerates, so do the attacks targeting the infrastructure that supports it.
Europe alone experienced 48 successful cyberattacks on energy infrastructure in 2022, and the trend has only intensified since then. Globally, the energy sector now faces an estimated $329.5 billion in potential economic losses linked to OT cyber incidents, with disrupted sites increasing by 146% year-over-year.
These numbers paint a concrete picture: the threat landscape is growing faster than defenses. And the most alarming signals comes not from attackers, but from the industry itself.
An increasingly hostile threat landscape
According to power-sector professionals, the most critical emerging threats for power and renewable operators in the next 5 years include:
- IT–OT convergence challenges, significantly expanding the attack surface
- Data leakage and manipulation, especially impacting SCADA, EMS, and PPC systems
- Supply chain attacks and compromised vendor products, one of the fastest-growing attack vectors
- Compromise of distributed energy resources (DERs) — already a concern for aggregators and grid operators
- AI-driven cyberattacks capable of generating ICS-specific payloads
- Insider threats, both malicious and accidental
- Geopolitical hybrid threats increasingly targeting critical infrastructure
- Social engineering (phishing, baiting) aimed at O&M or remote-access teams
- DoS/DDoS attacks affecting gateways, telemetry, and data acquisition
This reveals a crucial insight: operators know that threats are evolving faster than their protections. The sector itself acknowledges that emerging risks are outpacing current capabilities – especially in OT.
Real incidents show what can go wrong
Recent history offers clear evidence that cyberattacks against energy systems are no longer hypothetical.
Industroyer / CrashOverride (Ukraine, 2016)
A malware engineered specifically to exploit substation automation protocols, causing power outages for tens of thousands. This attack demonstrated that adversaries can weaponize ICS protocols.
Triton (2017)
A malware targeting safety-instrumented systems (SIS), capable of overriding protection mechanisms. This was one of the most dangerous ICS-targeted attacks ever recorded.
2022–2024 attacks on renewable and distributed energy systems
Multiple incidents involved:
- ransomware on solar/DER aggregators
- exploitation of inverter management interfaces
- manipulation of telemetry from distributed DERs
- remote-access abuse on SCADA-connected gateways
These cases highlight an uncomfortable truth: the distributed, multi-vendor, remotely accessible architecture of renewables makes them a prime target.
Passive cybersecurity is no longer viable.
Why renewable operators remain under-protected
Despite rising awareness, the renewable energy sector — solar, wind, hydro, BESS, and hybrid grid-interactive systems — remains structurally under-protected. The reasons are systemic and deeply linked to how the industry has historically approached cybersecurity.
1. A passive, reactive cybersecurity mindset
Too many renewable operators still treat OT cybersecurity as:
- something to prepare only before audits
- something handled by EPC contractors at commissioning
- something solved by “good IT hygiene”
- something to worry about only after an incident
This mindset leaves organizations dangerously exposed, particularly considering the inherently distributed nature of renewable assets.
2. Overreliance on traditional IT controls
IT tools — firewalls, VPNs, endpoint protection — are necessary but insufficient. Many operators assume IT compliance (ISO 27001) is a proxy for OT security maturity, overlooking:
- insecure, decades-old industrial protocols (IEC-104, Modbus, DNP3)
- uncontrolled OEM remote access tunnels
- outdated and unpatched firmware
- limited segmentation
- absence of asset-criticality mapping
- no real risk scoring tied to operational impact
This mismatch creates blind spots that attackers can easily exploit.
3. Lack of OT asset visibility
A surprising number of operators cannot answer essential questions such as:
- What firmware versions are running across inverter or turbine fleets?
- Which devices allow vendor remote access?
- Which OT assets communicate externally?
- Which anomalous behaviors represent physical process deviations?
Without visibility, there is no security — only assumptions.
4. Fragmented governance across plants, vendors, and systems
Every plant is a patchwork of:
- different OEM technologies
- different SCADA systems
- different network architectures
- different access policies
The result is an inconsistent, non-standardized security baseline across the entire fleet.
5. Insufficient monitoring of operational anomalies
IT SOCs monitor logs. OT SOCs must monitor physical behavior.
Most renewable operators still lack detection capabilities for:
- unexpected inverter derating
- unauthorized setpoint or mode changes
- turbine pitch anomalies
- PPC or EMS deviations
- redundant link failures across substations or SCADA paths
Operational anomalies often precede or reveal cyber incidents — but without OT-first monitoring, they go unnoticed.
The threat is growing faster than defenses
According to the 2025 CLUSIT analysis, cyberattacks targeting energy and utilities increased by almost 40% year-over-year, making it one of the most targeted sectors worldwide.
Meanwhile, renewables continue to expand their digital footprint:
- more OEM remote access
- more cloud-connected PPC/EMS systems
- more DER aggregation
- more IT–OT convergence
Yet many companies still rely on:
- infrequent or inconsistent risk assessments
- manual spreadsheets for governance
- outdated firmware
- minimal segmentation
- no OT-native monitoring
This creates a dangerous gap between the complexity of operations and the maturity of defenses. Operators simply cannot detect, prioritize, or mitigate cyber risks at the speed required.
What needs to change today
To move from passive to proactive, renewable operators must embrace three fundamental pillars.
1. OT-native continuous monitoring (SOC OT-first)
Monitoring must extend beyond IT logs to include:
- industrial protocols
- remote access behavior
- setpoint manipulation
- configuration changes
- operational deviations affecting turbines, inverters, substations, BESS
- anomalous DER behaviors
2. Unified OT governance (GRC) connected to real operational data
This includes:
- regulatory and framework mapping (IEC 62443, NIS2, ISO 27001)
- continuous evidence collection
- asset criticality-based risk scoring
- standardized controls across all plants and technologies
3. Supply chain and vendor access governance
OEM access should always be:
- authenticated
- logged
- monitored
- time-restricted
- governed by explicit security requirements
Given how frequently OEMs access remote assets for maintenance, this is now non-negotiable.
How BaxEnergy supports energy operators to secure their plants
Cybersecurity in the power sector — and especially across renewable energy fleets — is not sufficient in 2025.
As cyber threats shift from traditional IT vectors to operational assets, operators need solutions capable of providing both structured governance and continuous OT security monitoring.
BaxEnergy supports this transition with an approach designed to secure critical infrastructures end-to-end: from risk identification and compliance management to real-time detection of cyber-physical anomalies.
By integrating structured governance with real-time cyber-physical monitoring, BaxEnergy helps energy companies move from reactive, IT-centric protection to a proactive, OT-native cybersecurity strategy – a necessity for the operational realities of 2025 and beyond.
Learn more about our cybersecurity solutions here: Cybersecurity as a Service
About BaxEnergy
BaxEnergy, a Yokogawa company, is a global full-service partner of energy companies and industrial operators providing end-to-end digital solutions for asset performance management, grid control, and cybersecurity. BaxEnergy’s solutions are able to optimize the operations of utilities and IPPs who manage cross-technology and cross-manufacturer portfolios, including wind, solar, hydro, geothermal, combined cycle, BESS and green hydrogen. The company currently monitors and manages more than 140 GW of renewable energy in 50+ countries.
Learn more here: www.baxenergy.com