Exclusive Articles

The trusted megawatt: cyber resilience you can evidence


Published in: Wind, Ask the Experts, Exclusive Articles


The trusted megawatt: cyber resilience you can evidence image

Hybrie De Jager, Compliance Specialist at Centrii, examines how NIS2 is reshaping cyber resilience in the wind sector, from supplier risk and governance to operational recovery, and why operators need to be able to evidence a ‘trusted megawatt’.

PES: Hybrie, thank you for joining us. Cybersecurity has been a priority for the wind industry for some time, but the conversation is moving beyond technical protection. How is the arrival of NIS2 changing the way organisations think about cyber resilience?

Hybrie De Jager: A cyber incident does not follow the organisational structure around a wind farm. It can spread across turbine systems, remote connections and supplier relationships, while authority remains split between owners, asset managers, O&M providers and technology partners. NIS2 changes less about the number of controls required and more about how closely management oversight is linked to decisions made under pressure.

The real test comes in the first hour of disruption. Who sees enough of the picture to act, and who can disconnect a supplier or suspend generation? The measure that matters is decision latency: the time between the first warning and a coordinated, authorised response.

 Download full article