UK battery attack risk hits 92% as grid, insurers brace
The gist
A staggering 92% chance of coordinated cyberattacks on UK and global battery storage threatens blackouts and multi-billion-pound losses as new security rules become mandatory.
What to know
- Centrrii’s 10,000-simulation model predicts a 92% likelihood of major BESS cyberattacks by 2031, with UK losses between £2 billion and £10 billion.
- Cloud-controlled battery fleets could be manipulated in sync, triggering grid instability and cascading blackouts, according to GRIDLOCK analysis.
- As more batteries and solar share grid connections, insurers face skyrocketing aggregation risk—where one attack or failure could spark billions in correlated claims.
Compliance Bar Raised Overnight
Tougher security mandates and lower registration thresholds are forcing operators to treat battery system cyber threats as urgent, not hypothetical.
The late-September 2026 modeling result putting the five-year probability of coordinated cyberattacks on battery storage systems at 92% landed in a sector that was already moving from voluntary hygiene to hard compliance, sharply raising the significance of the forecast. As the August NERC CIP explainer made clear, the baseline is now “mandatory and enforceable,” requiring operators to “declare which systems are critical” based on whether compromise could affect operations within “15 minutes,” alongside security policies, personnel screening and training, access controls, electronic and physical perimeters, logging, monitoring, incident response, backups, configuration discipline, information protection, and supply-chain security.
What made the September probability estimate especially consequential was that baseline expectations were simultaneously tightening in scope and visibility, suggesting the threat was no longer theoretical or confined to a narrow set of large assets. The same NERC CIP explainer said facilities must register if they exceed “75 MVA aggregate behind a single point of interconnection,” noted some had stayed at “74.5” to avoid scope, and added that “we’re taking that threshold down” to 20 MVA, while newer rules require encrypted “control center to control center” communications and monitoring traffic between critical systems so operators can see what those systems are saying to each other.
Remote Control: BESS as Attack Vector
Software-driven batteries with weak defenses can be hijacked at scale, turning grid assets into synchronized weapons for mass disruption.
The urgency is no longer theoretical: ESS News reported that Centrrii ran “10,000 Monte Carlo simulations” and calculated “a 92% probability of a major coordinated cyberattack on battery energy storage system (BESS) infrastructure by 2031 under current operational baseline standards.” That matters because BESS are software-controlled, grid-interactive assets whose automated dispatch can be manipulated through remote access, weak VPN controls, outdated firewalls, irregular patching and poor segmentation, creating a realistic path for synchronized interference with charging, discharging and frequency response rather than a conventional data breach.
The scale of potential damage is what turns cyber risk into a grid and insurance problem: ESS News said that in Texas’s “effectively islanded grid,” “manipulating… just 5.4% of connected BESS assets, roughly 1,500 units on the ERCOT system, could disrupt power for up to 30 million people and trigger billions in economic fallout,” while “in the UK… 29% of its storage fleet (or around 400 assets) could trigger a national blackout.” SecurityBrief UK added that battery storage is being deployed faster than many operators can secure it, global capacity is expected to grow more than six-fold by 2030, and a UK attack could cost £2 billion to £10 billion.
Chain-Reaction Blackouts Unleashed
Coordinated hacks can trigger automatic grid disconnects faster than human intervention, escalating isolated attacks into nationwide outages.
The blackout mechanism is not a matter of isolated battery failures but of synchronized behavior across fleets that are centrally reachable. Industrial Cyber says the GRIDLOCK analysis focuses on “cloud-controlled BESS attack surfaces” and “cascading grid disruption,” framing the danger as an attacker forcing many systems to charge or discharge at once, abruptly shifting power flows, pushing grid frequency outside tolerances, and triggering automated protections designed to disconnect unstable assets before equipment is damaged.
That sequence matters because once protective trips begin, the disturbance can spread faster than operators can manually rebalance supply and demand. Using “a 10,000-iteration Monte Carlo risk assessment,” Industrial Cyber reports that GRIDLOCK “quantifies potential impacts on the Texas and Great Britain grids” and “models attack probability through 2031 across different security postures,” treating coordinated BESS manipulation as a system event capable of propagating through real networks into wider outages rather than remaining confined to the initially compromised sites.
Single Point, Massive Exposure
The shift to co-located battery and solar sites is concentrating billions in insurance risk behind shared grid connections, amplifying the impact of any single failure.
Aggregation risk starts with how battery projects are now being built: alongside solar on the same sites and behind the same grid connection. As pv magazine Global reported, developers increasingly see that “if you already have the grid connection, you have the solar park behind it, then you want to invest in a battery,” and while “Currently only 2% of solar capacity is co located with storage, but that's now increasing,” that trend means more insured assets will depend on the same export route, transformer chain, and connection point.
For insurers, that design logic turns operational efficiency into portfolio concentration. Olly Litterick of TMGX, the Tokio Marine group launched in 2025, said shared grid connections at co-located solar-plus-storage sites are concentrating insured revenue into “a growing risk for BESS insurers,” with projects carrying “hundreds of millions of dollars or even billions of dollars of exposure in a single location where multiple insureds share grid connection points”; if a shared export point or transformer fails, one incident can hit several policies at once, producing correlated business-interruption and property claims rather than an isolated loss.

