Written by: John Shepherd
Unlock premium reporting and in-depth coverage
Subscribe
The US has declared a cyber security national emergency in a bid to protect battery energy storage systems and the wider power infrastructure from Trojan horse-style attacks.
BESS and UPS systems are specifically included in an extensive list of potential cyber warfare targets among bulk-power system electrical equipment (BPSEE) produced abroad — which the US fears are at heightened risk.
The energy systems cyber alert was outlined in an executive order signed by US president Donald Trump on August 26.
The order — covered by the International Emergency Economic Powers Act and the National Emergencies Act — largely prohibits certain foreign-made equipment from being bought or installed in the US, including critical software and digital capabilities.
BPSEE covers a wide range of equipment and installations including power stations, backup power systems and grid-connected inverters.
Trump said energy secretary Chris Wright will now work with cabinet colleagues and others to identify BPSEE that may pose risks and draw up a safeguards action list, with a particular focus on equipment linked to US-designated foreign entities of concern (FEOC).
‘Supply disruption’
“Since my first term, the threat to the US regarding foreign supply of bulk-power system electric equipment has become even more acute,” Trump said.
“The rapid growth of advanced manufacturing, datacentres, artificial intelligence and defence production has increased the nation’s dependence on abundant, reliable electricity and magnified the consequences of a successful attack or supply disruption on the bulk-power system.”
The president’s directive follows a report issued last month by the US Solar Energy Industries Association (SEIA), which warned as solar and energy storage continues to expand, cybersecurity protections become increasingly important to support grid reliability and resilience.
SEIA cited a 2022 ransomware attack against the IT infrastructure of a wind turbine manufacturer in Germany, followed a year later by an attack that saw a third-party service provider lose remote data monitoring capabilities for around 2,000 turbines.
‘New risks loom’
Separately, in 2025, Poland successfully thwarted what officials described as the largest cyberattack on its energy infrastructure in years, SEIA said.
Emerging technologies, including the deployment of advanced artificial intelligence models to optimise energy assets, create new cybersecurity risks and expand the attack surface.
The association revealed it now runs a monthly cybersecurity working group dedicated to sharing latest cybersecurity policy, threat information and defence tactics for solar and energy storage systems.
In the UK, the government confirmed that a power plant was shut down during a cyber attack in July 2026. Reliable media sources reported that the attack was carried out by hackers affiliated to the Iranian regime.
The UK government declined to give details but said the Department for Energy Security and Net Zero and National Cyber Security Centre have since warned power companies to be on their guard.
EU cyber concerns
A white paper published in December 2025, by global consulting firm the Brattle Group and US-based international operational technology cybersecurity specialists Dragos, said experts agreed that US infrastructure security concerns would likely lead to more stringent security measures towards FEOCs.
In terms of the European Union, the white paper said the bloc’s Cyber Resilience Act, which goes into effect in 2027, will certify every product for sale in the EU meets European cybersecurity standards.
However, while experts agreed that consistent, EU-wide policy was the correct method to approach grid cybersecurity, the white paper warned that member states without the same agenda or policies would create a lack of harmonisation among operators on the same grid.
“Diverging rules between European countries create vulnerability to the highly interconnected European power network, resulting in higher regulatory compliance costs for investors and differing levels of cybersecurity implementation in the European internal energy market.”
The white paper said BESS deployment over the next five years is expected to grow at 30% annually in the US, 45% in the EU and 20–25% across Japan, South Korea, Southeast Asia and India.
“As BESS deployment accelerates, it is important that the increasing role of batteries in facilitating efficient clean energy and grid reliability is not undermined by cybersecurity vulnerabilities.
“Conversely, BESS additions with strong cyber protection will contribute to lower levels of vulnerability for the grid as a whole.”
Image credit: Envato