New risk analysis indicates a 92% probability of a major cyber attack on BESS systems in the next five years — triggering “cascading blackouts” and billions of dollars in economic damage in the US and UK alone.
The ‘Gridlock’ report, by security firm Centrii, warns an ‘attack window’ could come as early as 2027-28 without investment to boost infrastructure security.
Centrii’s August 28 report came just days after Batteries International reported the US had declared a cyber security national emergency in a bid to protect battery energy storage systems and the wider power infrastructure from Trojan horse-style attacks.
The report, ‘Gridlock: What a coordinated battery attack would cost the grid’, uses a Monte Carlo risk analysis methodology of 10,000 simulations across three industry security postures — baseline, moderate and aggressive — and quantifies the probability and financial cost of a coordinated attack on BESS between now and 2031.
Monte Carlo simulation is a method of modelling the probability of a number of outcomes in processes that involve a degree of uncertainty. According to Gridlock’s findings, under industry-average security practices, the effects of an attack in the UK are more concentrated than in the US.
Financial damage
The modelling finds that compromising 29% of national capacity (around 400 units) could be sufficient to trigger a nationwide outage affecting 67 million people — effectively the entire population. A single major attack is estimated to cost between £2 billion ($2.7 billion) and £10 billion in financial damage.
Research also models a coordinated cyber attack in the US on the battery fleet supporting the grid in Texas, resulting in an estimated $12 billion to $65 billion in economic damage.
By comparison, bringing the Electric Reliability Council of Texas (ERCOT) battery fleet to meet standards for operational technology in automation and control systems (IEC 62443 Security Level 2) is estimated to cost between $800 million and $2.8 billion, according to Centrii.
Compromising 5.4% of the ERCOT battery fleet, around 1,500 units, could be enough to destabilise the Texas grid, potentially affecting 30 million people, the report claimed.
Centrii, founded in 2022, helps energy infrastructure owners assess cyber and operational risk across critical energy environments.
‘Disruptive force’
Co-founder and CEO Rafael Narezzi said a coordinated attack does not need to stop generation to cause a blackout.
“It only needs to desynchronise the balancing layer, forcing batteries to charge or discharge together, or delaying how they respond to grid signals. Neither action damages a battery.
“The effect is closer to a distributed denial-of-service attack than a conventional outage — instead of overwhelming a website with traffic, it overwhelms the grid’s ability to stay in balance, using energy itself as the disruptive force. The modelled result is a cascading blackout that unfolds in under two minutes.”
Narezzi said companies he speaks to already accept that cyber risks exist but have no definitive assessment to help them calculate levels of security investment.
“Security spending in operational technology is rarely treated as return-generating, because its value shows up in an event that does not happen.”
Modelling in the report makes that value visible and measurable — and shows protecting battery storage is one of the highest-return decisions available anywhere in the business, but it’s also one of the least discussed at board level.
The Gridlock report and underlying peer-reviewed research paper are online.
Photo: Pexels








