A new Cyberwatch Finland’s White Paper about the cybersecurity of energy sector is published.
Cumulative worldwide installed solar photovoltaic capacity passed 2,260 GW by the end of 2024, with a further estimated 510 GW added in 2025. Control of the electricity system is shifting from a small number of large, regulated facilities to millions of consumer-owned, software-controlled devices, such as inverters, home batteries, electric-vehicle chargers and smart meters.
Adversaries have noticed. Between 2010 and 2024, energy was the second most targeted sector in cyber operations, after telecommunications. 2025 most likely saw the first demonstrated cyber-to-physical effects on European energy infrastructure. Attackers remotely seized the operational controls of a Norwegian hydropower dam, and a coordinated operation against more than 30 distributed energy sites in Poland was thwarted.
The central idea of the White Paper is to treat the cybersecurity of distributed energy resources (DER) as a governance question rather than a purely technical one. International standards such as IEC 62443, NIST CSF 2.0 and ISO/IEC 27001 already describe what secure energy infrastructure looks like. What they leave open is who sets the requirements, who enforces them and who is accountable, now that the population of actors is more diverse than ever. The problem is not one of scale but of kind.
The publication covers topics such as:
🔹 the transformation of the energy sector, as distributed energy resources move from marginal to structural
🔹 the cyber-physical threat landscape and real-world incidents, from the Norwegian dam and the Polish operation to Volt Typhoon and Eskom’s vending system
🔹 a four-pillar compliance framework: scope, baseline obligations, verification and accountability
🔹 role-specific obligations for manufacturers, installers, aggregators, distribution system operators and asset owners
🔹 a regional comparison: the EU, the UK, the US, Asia-Pacific, Africa, and Latin America and the Caribbean
🔹 four strategic tasks and a phased implementation model for policymakers, operators and financiers
A key finding is that aggregators are the most consistent governance gap across every region examined. No jurisdiction has made aggregator and virtual power plant compliance a condition of market access, even though the aggregator is the pivotal node between the individual device and the grid operator. The accountability mechanisms that do work all share one design principle: market access is conditioned on compliance, rather than penalties being applied after an incident. Examples include Chile’s fining powers, Australia’s licence conditions and the EU’s NIS2 supervisory sanctions.
The publication is intended as food for thought for public policy planners, regulators, energy sector executives and experts, investors and financiers, and anyone interested in the topic. It does not offer a ready-made blueprint. Instead, it provides an analytical structure for identifying which elements of a compliance regime are present, which are missing, and which governance decisions are needed to close the gap.
We hope this publication stimulates discussion and strengthens the cyber resilience of the energy system at its expanding edge.
We wish you an enjoyable and thought-provoking read!