Battery cyber-risk model puts billions in focus

Battery cyber-risk model puts billions in focus

Battery storage cyber-risk modelling puts multibillion-pound UK exposure in focus. Centrii’s GRIDLOCK analysis estimates sharply different attack risks under alternative security postures, although its headline probabilities and financial losses are simulated scenarios rather than forecasts.


A cyber-risk model from Centrii suggests coordinated attacks on battery energy storage could create multibillion-pound exposure for the UK’s electricity system, although its headline probability and loss figures are simulated scenarios rather than observed outcomes or forecasts.

The energy cybersecurity company has published GRIDLOCK, an assessment of cyber-physical exposure across battery energy storage systems, or BESS. The analysis uses 10,000 Monte Carlo simulations under three security postures to model attack probability, timing, and financial impact through 2031.

Under the model’s baseline assumptions, described as representing industry-average security practices, Centrii calculates a 92% probability of a major coordinated attack within five years. That falls to 78% under a scenario involving gradual voluntary security improvements and to 61% where the modelling assumes mandatory IEC 62443 certification and regular attack-readiness exercises.

The model also shifts the earliest likely attack window from 2027–28 in the baseline scenario to 2029–31 under its most stringent security assumptions.

Those percentages are outputs from a model built around assumptions for attacker capability, battery deployment, compromise rates, remote access, cloud systems, and supply chain attack paths. They are not measured historical attack probabilities and do not establish that a major incident will occur.

The potential financial consequences are also modelled. Centrii estimates that compromising around 29% of UK battery capacity — approximately 400 units in its scenario — could destabilise the national system sufficiently to produce a widespread outage, with economic damage estimated between £2bn and £10bn.

The company contrasts that potential exposure with an estimated £400m to £1bn cost for bringing the UK battery fleet to IEC 62443 Security Level 2. On those assumptions, it calculates a five-to-25-times relationship between preventative security expenditure and the avoided cost represented by a single major incident.

Rafael Narezzi, co-founder and CEO of Centrii, said: “Every board I speak to already accepts that cyber risk exists. What they haven’t had is a definitive assessment that helps them to reach the right figure.”

GRIDLOCK models an attack aimed at disrupting how battery assets respond to grid-balancing instructions rather than physically destroying generation equipment. Coordinated changes to charging, discharging, or response timing could, under the modelled mechanism, create instability between electricity supply and demand.

Battery storage is becoming increasingly important as deployment expands. Storage assets absorb excess electricity when generation is high and release it when required, supporting a grid that is incorporating more variable renewable generation.

Remote control and cloud-based management make large fleets easier to operate efficiently, but they also expand the digital systems connected to operational technology. The commercial challenge is to capture the flexibility benefits of connected assets without allowing common software, communications, remote-access, or supply chain dependencies to create concentrated vulnerabilities.

Centrii cites UK Government estimates that between 23GW and 27GW of battery capacity will be required by 2030, compared with approximately 4.5GW in 2024. If deployment reaches that scale, cybersecurity requirements will increasingly influence capital expenditure, vendor selection, insurance, financing, and operational-resilience planning.

The technical attack mechanism examined by GRIDLOCK has a separate research basis. Academic work published in Energy Informatics in 2025 examined cyber threats to battery energy storage systems and provides support for the proposition that coordinated manipulation of storage can affect grid stability.

That research does not independently validate Centrii’s later 92% probability, the 29% compromise threshold, or the £2bn to £10bn UK financial-loss range. Those figures belong to the GRIDLOCK modelling and depend on its assumptions.

For infrastructure owners, the decision is therefore how much to invest against low-frequency but potentially severe events when their probability cannot be observed directly.

Operational-technology security can be difficult to assess through conventional return-on-investment measures because successful preventative spending is intended to stop an event from occurring. Scenario models can help translate technical risk into financial exposure, but boards and investors need visibility over the assumptions driving the result.

The investment question also extends beyond software. Security standards for storage fleets can affect procurement specifications, remote-access design, supplier contracts, monitoring, incident-response exercises, maintenance practices, and how assets are integrated across portfolios.

As battery fleets grow, common technology suppliers and remote-management platforms may create efficiencies at scale while concentrating dependencies. That gives operators a reason to evaluate portfolio-level exposure rather than treating each individual battery site as an isolated cyber risk.

GRIDLOCK is therefore most useful as a stress-testing exercise rather than a prediction. Its findings put a financial value around different security assumptions and invite operators, investors, lenders, and boards to test whether current spending reflects the potential cost of disruption.

With storage becoming more central to grid balancing, cybersecurity is likely to become a larger component of asset economics and operational resilience. The critical question is not whether the 92% model output proves an attack will happen, but whether businesses understand how their own security posture changes the consequences if one is attempted.



  • AJ Bell reshapes board through succession plan

    AJ Bell reshapes board through succession plan

    AJ Bell is reshaping its board through planned succession changes. Craig Gentle and Steve Langan are joining as three existing non-executive directors prepare to leave the investment platform.


  • ENRC dispute with SFO and Dechert settles

    ENRC dispute with SFO and Dechert settles

    ENRC has settled litigation linked to Britain’s abandoned corruption investigation. The confidential agreement with the Serious Fraud Office and Dechert closes a long-running dispute over conduct surrounding the former criminal probe.


  • Battery cyber-risk model puts billions in focus

    Battery cyber-risk model puts billions in focus

    Battery storage cyber-risk modelling puts multibillion-pound UK exposure in focus. Centrii’s GRIDLOCK analysis estimates sharply different attack risks under alternative security postures, although its headline probabilities and financial losses are simulated scenarios rather than forecasts.