Exclusive Articles

Why cybersecurity is becoming an asset owner responsibility


Published in: Solar, Digital Blog


Why cybersecurity is becoming an asset owner responsibility image

As renewable generation becomes critical infrastructure, cybersecurity is moving from a technical concern to a business and regulatory priority. For solar asset owners in Europe, NIS2 is increasing accountability while connected devices, remote access and ageing equipment create new points of vulnerability.

Uri Sadot, Managing Director of SolarDefend and Chair of the Digitalisation Workstream at SolarPower Europe, argues that owners need greater visibility of what is connected to their plants, who can access those systems and how securely they are configured.

What NIS2 changes

NIS2 significantly expands the number of European organisations subject to cybersecurity requirements. More than 160,000 companies could now fall within its scope.

For renewable asset owners, potential consequences include executive liability and fines of up to 2 per cent of the parent company’s annual turnover.

Requirements vary between countries, but Sadot identifies continuous visibility as a central issue. In practice, this means understanding the devices operating within a plant and assessing whether they meet recognised standards such as IEC 62443.

Responsibility ultimately sits with the organisation that has the authority to implement risk mitigation measures and oversee the asset. Outsourced operational arrangements do not necessarily remove that responsibility.

Where vulnerabilities develop

Renewable portfolios can contain thousands of connected devices, including inverters, turbine controllers and communications gateways. Many portfolios have also grown through acquisitions, leaving owners with legacy equipment and incomplete asset inventories.

Common weaknesses include:

  • Unmanaged or unpatched devices
  • Incomplete equipment inventories
  • Unsupervised third-party remote access
  • Weak access controls
  • Limited visibility of network activity

Original equipment manufacturers (OEMs), monitoring providers and control system vendors often require remote access, creating additional routes into operational systems.

Sadot points to the coordinated cyberattack in Poland in December 2025, which affected 30 sites including wind and solar plants. Attackers disrupted communications, reducing operators’ visibility and control and requiring manual intervention.

Building a structured response

For asset owners, Sadot recommends moving from general awareness towards defined cybersecurity responsibilities and budgets.

The first priorities are securing remote access, strengthening communications between central systems and individual plants and maintaining an accurate inventory of connected equipment.

Further measures can include:

  • Real-time monitoring
  • External penetration testing
  • Intrusion detection systems
  • Cyber threat intelligence
  • Regular reviews of access permissions

Specialist providers may be required where asset owners do not have the internal resources to maintain these capabilities.

Cybersecurity solutions designed for large centralised power stations do not always suit renewable portfolios comprising numerous distributed sites. Cost and technical flexibility can therefore become barriers when the same approach must be applied across many smaller plants.

Compliance is already moving forward

Implementation differs across Europe. Italy expects compliance by 31st October 2026, while Belgium has opened its first NIS2 audit window. Germany’s cybersecurity authority, BSI, is also influencing how standards are applied.

Spain had yet to formally transpose NIS2 into national law at the time of publication, illustrating the variation between markets.

Despite these differences, Sadot’s central message is that asset owner responsibility is becoming firmly established.

Cybersecurity investment may also bring operational benefits. Better digital visibility and standardisation can help identify failing equipment earlier, reduce unnecessary site visits and improve portfolio uptime.

For renewable asset owners, the question is therefore no longer simply whether cyber protection is necessary. It is how quickly organisations can understand their exposure, establish responsibility and put appropriate controls in place as regulatory scrutiny increases.

Read the complete feature from SolarDefend on renewable asset cybersecurity, NIS2 compliance and portfolio risk in PES Solar: https://pes.eu.com/exclusive-articles/what-renewable-asset-owners-need-to-know-about-cybersecurity-and-nis2-compliance