Domki 14, 31-519 Kraków,
Poland
A battery storage system is not only an electrical asset. It is also a connected control system and that is where the cybersecurity risk begins.
Modern BESS projects depend on multiple digital and operational layers: EMS, BMS, PCS, SCADA, remote access, vendor monitoring, grid interfaces and market communication systems. Each of these layers adds value because it helps the asset operate, communicate, optimize and respond to market signals. But each layer can also create exposure.
The risk is not simply that someone hacks a battery. That sounds too narrow and almost unrealistic.
The real risk is operational.
A cyber or control-system weakness can lead to wrong commands, manipulated setpoints, loss of visibility, unauthorized remote access, communication failure, grid non-compliance or downtime during the hours when the asset should be earning revenue.
For an investor, owner or operator, this is not just an IT issue. It affects availability, insurance, regulatory compliance, revenue stability, lender confidence and reputation. A storage asset that cannot operate securely is not fully bankable, no matter how strong the battery specification looks on paper.
This is becoming more important in Europe as cybersecurity expectations for energy and critical infrastructure continue to rise. Regulation, lender scrutiny and operational risk management are all moving in the same direction: connected energy assets must be designed with resilience in mind from the beginning.
That means BESS cybersecurity should not be treated as a late-stage checklist. It should be considered during project design, procurement, EPC contracting and O&M planning.
The key questions are practical:
Who has remote access to the system?
How is that access approved, monitored and logged?
Is the OT network properly segmented?
How are vendor connections controlled?
Can unauthorized physical or digital changes be detected?
What happens if communication with the EMS is lost?
Is there a clear incident response procedure?
Are cybersecurity requirements included in EPC, supplier and O&M contracts?
The dangerous assumption is: The supplier will handle it. Maybe they will handle part of it.
But project owners, investors and operators cannot outsource responsibility completely. They still need to understand how the system is protected, who controls access, how incidents are managed and what happens if something goes wrong.
A battery storage system is part of energy infrastructure and energy infrastructure must be resilient not only electrically, but also digitally and operationally.