Ilyass MotyaIlyass Motya
Batteries exist to keep the grid stable. That makes them the target.
Back to blog

Batteries exist to keep the grid stable. That makes them the target.

· By Ilyass Motya

Source: Industrial Cyber — Centrii, 'GRIDLOCK: What a Coordinated Battery Attack Would Cost the Grid'

The balancing layer is the attack surface

Battery storage exists to absorb excess generation and release it when generation dips, keeping grid frequency inside a narrow band. Increasingly, that balancing is managed remotely through cloud platforms that issue charge and discharge commands to thousands of units at once. A coordinated attack does not need to stop generation. It needs to desynchronize the balancing layer: force batteries to charge or discharge in a coordinated, disruptive pattern.

Centrii's Monte Carlo modeling — 10,000 simulations across three security postures — puts a 92% probability of a major attack by 2031 under today's industry-average posture. The ERP numbers: in Great Britain, compromising 29% of national battery capacity (about 400 units) could trigger an outage affecting 67 million people. The counterfactual is the point: bringing GB storage to IEC 62443 Security Level 2 costs an estimated £400M to £1B, against an estimated £2B–£10B per attack.

OT security engineer commissioning industrial control equipment on the plant floor

Two rehearsals already ran

Poland showed the script last December: state-sponsored actors rapidly cycled wind turbine output on and off to push grid frequency out of balance — contained, but a working blueprint. The April 28 Iberia event showed consequences: a small number of large solar and wind sites shed 2.5 GW in under 20 seconds, collapsing the Iberian grid for roughly 10 hours. Authorities called it a technical fault. The report notes two facts from the official record: those sites have no usable operational logs from the moment of failure, and re-running the documented grid conditions does not reproduce the blackout.

Neither event proved it was a cyberattack. Together they prove the mechanism is not theoretical.

The asset-owner checklist is the same one

None of the recommended fixes are new: isolate control systems from general corporate IT, require multi-factor authentication on every remote access point into cloud control platforms, keep firmware current and verified, and build redundancy into frequency measurement so no single feed is a point of failure.

What is new is the stakes of skipping them. When a stray vendor portal can influence the frequency of a national grid, operational control is no longer defined by who owns the asset — it is defined by whoever controls the systems in between. The technology to close the gap already exists. The urgency, in most portfolios, has not caught up yet.

Next up