All news

Cyber Security Risks Facing UK Solar Farms

19 July 2026 Peter Flynn
Cyber Security Risks Facing UK Solar Farms

Solar farms may look like passive rows of photovoltaic panels, but modern sites are increasingly digital power stations.

Behind the panels sit internet-connected inverters, weather sensors, data loggers, CCTV systems, industrial controllers, remote monitoring platforms and grid-connection equipment. Operators, equipment manufacturers and maintenance contractors may all require remote access.

This connectivity makes solar farms more efficient and easier to manage. It also creates cyber security risks that did not exist when electricity generation equipment operated in isolation.

The most credible threat is not that an attacker somehow “hacks” an individual solar panel. The greater danger is that someone compromises the technology used to monitor, control and coordinate hundreds or thousands of inverters.

A single incident might only interrupt one site. However, a vulnerability affecting the same manufacturer, cloud platform or maintenance provider across numerous solar farms could create a much wider problem.

The wider operational risks, including attacks against control systems, communications and battery storage, are examined in Are Solar Farms Vulnerable to Cyber Attacks?

A solar farm in the British countryside

Solar generation increasingly depends on digital monitoring, communications and control systems. Image: Geograph/Wikimedia Commons.

Why Solar Farms Have Become Cyber-Physical Systems

A solar panel produces direct-current electricity when exposed to sunlight. On its own, it has little cyber risk because it contains no internet account, cloud application or remote-access service.

The wider solar installation is very different.

A utility-scale solar farm may contain:

  • Hundreds or thousands of photovoltaic panels
  • Multiple string or central inverters
  • A supervisory control and data acquisition system
  • A power plant controller
  • Weather and irradiance sensors
  • Network switches, routers and firewalls
  • CCTV and physical access-control systems
  • Grid-protection and substation equipment
  • Cloud-based monitoring portals
  • Remote maintenance connections
  • Software supplied by several different companies
  • Battery storage and an energy management system

This combination turns a field of panels into a connected operational technology environment.

Operational technology, usually shortened to OT, refers to the hardware and software that monitors or controls physical processes. At a solar farm, those physical processes include converting electricity, regulating voltage, responding to grid instructions and safely disconnecting equipment when necessary.

A cyber incident can therefore produce more than an IT inconvenience. It could affect electricity generation, safety systems, maintenance decisions and the accuracy of information supplied to the control room.

As explained in Are Solar Farms Vulnerable to Cyber Attacks?, the risk comes primarily from the connected technology surrounding the panels rather than from the photovoltaic modules themselves.

Remote Monitoring Platforms

Why solar farms need remote monitoring

Solar farms are often located in rural areas and may operate without permanent staff on site. Remote monitoring allows an operator to supervise several installations from a central control room.

A monitoring platform can show:

  • Current and historical power output
  • Individual inverter performance
  • Equipment temperatures
  • Grid voltage and frequency
  • Weather conditions
  • Alarm and fault information
  • Communications failures
  • Planned and unplanned downtime

These platforms help operators detect failed equipment, compare actual production with forecasts and decide when an engineer needs to visit the site.

Some platforms are limited to reading information. Others allow authorised users to change settings, restart equipment, acknowledge alarms or issue operational commands.

The risk increases considerably when monitoring and control are combined within the same account.

  • APP Remote Control: Effortlessly manage your home appliances anytime, anywhere through the Smart Life APP. No more worry…
  • Voice Control: Our smart plugs are compatible with Alexa and Google Assistant, enabling you to control your home electri…
  • Energy Consumption Monitoring: This feature enables you to closely track your devices’ energy consumption. You can acces…

Compromised cloud accounts

An attacker does not always need to exploit an obscure weakness in industrial equipment. Stealing an administrator’s username and password may be enough.

Credentials can be obtained through:

  • Phishing emails
  • Password reuse
  • Infostealer malware
  • Compromised contractor computers
  • Exposed configuration files
  • Insecure password sharing
  • Social engineering
  • Credentials leaked in an unrelated breach

If multi-factor authentication is absent, a stolen password could provide direct access to a solar monitoring portal.

The consequences depend on the permissions attached to the account. An attacker might view commercially sensitive generation information, alter alarm settings, create new users or interfere with equipment controls.

A particularly serious weakness arises when one administrator account covers multiple sites. Compromising that account could give an attacker access to an operator’s entire solar portfolio.

False information can be as damaging as lost control

An attacker does not necessarily need to shut down equipment to cause harm. Manipulating the information seen by operators could be enough.

For example, false data might:

  • Make healthy equipment appear faulty
  • Hide a genuine inverter failure
  • Misrepresent the site’s electricity output
  • Suppress temperature or safety alarms
  • Cause unnecessary engineer visits
  • Distort generation forecasts
  • Interfere with maintenance planning

Operators must therefore protect both the availability and the integrity of monitoring data. A screen that remains online but shows false information can be more dangerous than one that is clearly unavailable.

Inverter Vulnerabilities

Why the inverter matters

The inverter is one of the most important intelligent components in a photovoltaic installation. It converts the direct-current electricity generated by the panels into alternating-current electricity suitable for use by the grid.

Modern smart inverters can also support:

  • Voltage regulation
  • Frequency response
  • Reactive power control
  • Power export limits
  • Remote firmware updates
  • Fault monitoring
  • Automated disconnection
  • Communication with plant controllers

The US National Institute of Standards and Technology describes the smart inverter as orchestrating the behaviour of a solar energy system and its interaction with the electricity grid.

That capability makes the inverter operationally valuable, but it also makes unauthorised access more consequential.

The SUN:DOWN research

In 2025, Forescout published its SUN:DOWN research into internet-connected solar technology. Researchers reported 46 previously undisclosed vulnerabilities affecting equipment from Sungrow, Growatt and SMA.

The reported weaknesses affected inverter management interfaces and associated cloud services. Depending on the product and vulnerability, researchers identified possibilities including unauthorised access, information disclosure, command execution and interference with device communications.

Forescout also reported identifying more than 35,000 internet-exposed solar devices worldwide during its research.

This does not mean all those devices were located in Britain, nor that every device could immediately be used to disrupt a power network. It demonstrates something more fundamental: solar equipment is sometimes deployed with management services unnecessarily exposed to the public internet.

The research also illustrates the concentration risk created when many installations use the same equipment and cloud infrastructure. One weakness can potentially be reproduced across a large installed base.

  • MULTI-LAYERED SECURITY HARDWARE: Reputation filtering (IP/DNS/URL) and SecuReporter visibility included in Entry Defense…
  • OFFLINE-CAPABLE SETUP AND UPDATES: Configure via Nebula portal wizard; update firmware offline via FTP on the local netw…
  • COMPACT FANLESS DESIGN: with SPI 2,000 Mbps firewall throughput, 1,000 Mbps IPS, 500 Mbps VPN, the firewall supports up …
£312.00

Firmware is part of the security boundary

An inverter is not simply an electrical box. It contains software that must be maintained throughout the equipment’s working life.

Operators need to know:

  • Who develops and signs the firmware
  • How updates are delivered
  • Whether the device verifies an update before installing it
  • How quickly the manufacturer fixes reported vulnerabilities
  • Whether older models still receive security support
  • Whether a compromised update can be rolled back
  • What happens if the manufacturer stops trading

Solar assets can remain operational for decades, while the commercial support life of their digital components may be considerably shorter.

A solar farm built today could therefore inherit a future security problem if its inverters, gateways or monitoring systems stop receiving updates long before the panels reach the end of their useful lives.

Technicians working beneath photovoltaic panels

Maintenance work increasingly involves both electrical equipment and the software used to configure it. Image: Department of Energy and Climate Change/Wikimedia Commons.

Default Passwords and Exposed Internet Interfaces

The simplest weaknesses are often the most useful to attackers

Sophisticated energy infrastructure can still be compromised through basic security failures.

Equipment may arrive with factory credentials such as “admin” combined with a published or easily guessed password. Installers sometimes leave these credentials unchanged because commissioning must be completed quickly or because nobody has been assigned responsibility for ongoing cyber security.

Shared passwords are particularly dangerous. If the same credential is used across every inverter or gateway at a site, one disclosed password can unlock the entire installation.

If the manufacturer uses the same default credential across its product range, the potential exposure becomes much larger.

CISA has warned for years that attackers can identify internet-connected systems using shared default passwords and gain access without developing a sophisticated exploit.

How equipment becomes exposed

A solar device can become publicly reachable through:

  • Router port forwarding
  • An incorrectly configured firewall
  • A public IP address assigned during commissioning
  • An internet-connected cellular modem
  • An exposed web administration page
  • Remote Desktop or Virtual Network Computing services
  • An unprotected application programming interface
  • A virtual private network with weak authentication
  • A temporary engineer connection that was never removed

This is not always deliberate. An engineer may create temporary remote access to solve a commissioning problem, expecting it to be removed later. Years afterwards, the connection may still be active.

Internet search services continuously catalogue exposed systems. Attackers can use these services to find devices by manufacturer, software version, open port or page title.

The operator should assume that any service exposed to the public internet will eventually be discovered.

Why changing the password is not enough

Replacing a factory password is essential, but it does not make an exposed industrial device safe.

The interface may still contain an unpatched vulnerability. It may not support multi-factor authentication, modern encryption or effective account lockout. It may also disclose product and firmware information that helps an attacker select a suitable exploit.

Where possible, inverter and plant-control interfaces should not be directly accessible from the public internet. Access should pass through a controlled and monitored route using strong authentication, restricted permissions and approved devices.

Third-Party Maintenance Access

The trusted contractor problem

Solar farm operators depend on external specialists.

An inverter manufacturer may diagnose faults remotely. An engineering company may maintain the substation. Another supplier may operate the monitoring platform, while an asset manager reviews performance across numerous sites.

Each relationship can introduce a route into the operational environment.

The risk is not limited to malicious contractors. A perfectly legitimate supplier can be compromised without realising it. An attacker who steals a maintenance engineer’s credentials may appear to be an authorised user.

This is a classic supply-chain attack: the attacker reaches the intended target through a trusted organisation with weaker security.

These dependencies are not unique to solar generation, as Can Wind Farms Be Hacked? shows how remote monitoring and third-party software create similar risks across Britain’s wind sector.

Persistent access creates persistent risk

Maintenance access is sometimes configured to remain available continuously, even when no work is taking place.

This is convenient, but it can leave:

  • Dormant accounts
  • Unmonitored VPN connections
  • Shared engineer credentials
  • Old remote-support tools
  • Access belonging to former suppliers
  • Administrator rights that are no longer required

A stronger arrangement grants access only for a defined job and time period. The operator approves the connection, monitors the session and removes access when the work is complete.

Privileged maintenance sessions should also be recorded where proportionate and lawful. This provides an audit trail and helps investigators understand what happened if equipment settings change unexpectedly.

One supplier may connect many operators

A specialist solar maintenance business may support dozens of farms. Its remote-management system can therefore become a concentration point.

If that supplier is compromised, the attacker could potentially use its trusted connections to reach several operators.

Before awarding a contract, a solar farm owner should establish:

  • How the supplier protects privileged accounts
  • Whether multi-factor authentication is mandatory
  • How access is approved and withdrawn
  • Whether engineers use managed devices
  • How security updates are applied
  • How incidents are reported
  • Whether subcontractors receive equivalent scrutiny
  • How quickly access can be disabled in an emergency

Cyber security obligations should appear in the contract rather than being left to an informal understanding.

Overseas Manufacturers and Remote Control

Country of origin is only one part of the risk

Much of the global solar manufacturing supply chain is concentrated outside the UK. British projects consequently use panels, inverters, communications equipment and software developed by international companies.

This creates legitimate questions about:

  • Where cloud data is stored
  • Which jurisdiction governs the service
  • Who can issue remote commands
  • Where firmware is developed
  • Whether updates can be independently verified
  • Which subcontractors can access the platform
  • How the operator would function if the cloud service became unavailable
  • Whether remote access can be disabled without losing essential functionality

However, country of origin should not be used as a substitute for technical assessment.

An insecure product does not become safe merely because it was manufactured in Britain or Europe. Equally, allegations about deliberate “back doors” should not be presented as established fact without verifiable technical evidence.

The appropriate approach is evidence-led supplier assurance.

The more important question: who retains control?

A British solar operator should understand whether a manufacturer can remotely:

  • Change inverter settings
  • Install firmware
  • Disable equipment
  • Create or recover administrator accounts
  • Access generation data
  • Redirect communications
  • Alter cloud integrations

Remote manufacturer support can be useful, particularly when a site is experiencing a fault. But the capability should be transparent, contractually controlled and technically restricted.

The owner should not discover during an incident that a distant supplier retains undocumented control over equipment connected to Britain’s electricity system.

  • Installs in circuit panel of most small businesses with clamp-on sensors. Supports single phase, single-split phase, and…
£109.99

What happens if the international connection fails?

A resilient solar farm should continue operating safely if its external cloud platform or overseas support connection becomes unavailable.

Questions to test include:

  • Can local operators still see essential information?
  • Can the plant run safely without continuous cloud access?
  • Are local copies of configurations available?
  • Can replacement equipment be commissioned independently?
  • Is there a documented manual operating procedure?
  • Can remote manufacturer access be blocked during an incident?
  • Are critical spare parts available from more than one source?

This is as much a resilience issue as a cyber security issue.

Solar Farms With Battery Storage

Increasing numbers of solar developments include battery energy storage systems. Batteries allow electricity generated during sunny periods to be stored and exported when demand or prices are higher.

Co-location also creates a more complicated digital environment.

The site may contain:

  • A battery management system
  • An energy management system
  • Power conversion equipment
  • Fire and temperature monitoring
  • Grid-balancing interfaces
  • Optimisation software
  • Connections to energy markets or aggregators

A compromised solar monitoring account might not automatically provide control of the battery. Nevertheless, weak network separation could allow an attacker to move between systems.

Are Battery Storage Sites Vulnerable to Cyber Threats? examines this additional layer of risk in greater detail.

Operators should treat the solar farm, battery system and grid connection as one connected environment while still maintaining security boundaries between their individual components.

What Could a Successful Attack Actually Achieve?

The consequences depend on the equipment compromised, the attacker’s privileges and the site’s engineering protections.

A realistic incident might cause:

  • Loss of remote visibility
  • Incorrect generation data
  • Repeated inverter shutdowns
  • Changes to export limits
  • Suppressed alarms
  • Equipment operating outside preferred settings
  • Disruption to maintenance
  • Loss of commercially sensitive data
  • Temporary reduction in electricity output
  • Disconnection of part or all of a site

Physical protection systems should prevent unsafe commands from immediately damaging equipment or destabilising the network. Solar farms also represent only one part of Britain’s diverse electricity system.

It would therefore be misleading to suggest that compromising one ordinary solar farm would switch off the country.

The systemic concern comes from scale and coordination. If the same platform controls many sites, or if identical equipment shares the same exploitable weakness, an attacker might attempt to disconnect or manipulate a large amount of generation at once.

The impact would also depend on the time of day, weather, electricity demand, network conditions and the availability of alternative generation.

Solar farms form part of the wider threat landscape examined in What Are the Emerging Cyber Threats Facing UK Energy Infrastructure?, where attackers increasingly target operational technology, suppliers and remotely managed energy assets.

Real-World Attack Scenarios

Stolen monitoring account

A maintenance employee receives a convincing Microsoft 365 phishing email. The attacker captures the employee’s password and session token, bypassing the protection offered by a simple login prompt.

The stolen account provides access to a portal covering six solar farms. The attacker suppresses several alerts and changes plant settings. Operators initially believe falling output is caused by passing cloud.

The technical impact remains manageable, but several hours of generation are lost before the account is disabled.

Exposed inverter interface

During commissioning, an engineer exposes an inverter gateway so that the manufacturer can diagnose a communications fault.

The connection is never removed. Two years later, an attacker discovers the interface through an internet search engine and identifies its outdated firmware.

The attacker restarts the gateway repeatedly, disrupting monitoring and forcing the operator to send engineers to the site.

Compromised maintenance provider

A specialist contractor uses one remote-support platform for multiple renewable energy customers. Its administrator account is compromised because multi-factor authentication has not been enforced.

The attacker uses the contractor’s legitimate connection to access a solar operator’s network. Because the connection is trusted, the activity initially avoids some perimeter security controls.

This scenario demonstrates why supplier security and internal network segmentation must work together.

Malicious firmware update

An attacker compromises part of a manufacturer’s software distribution process. A modified update appears legitimate and is installed across numerous devices.

Properly implemented digital signing, verification and staged deployment should make this scenario harder. Without those protections, a software supply-chain incident could affect many geographically separate sites simultaneously.

The UK Regulatory Direction

The Government’s Energy Sector Cyber Security Strategy 2026–2030 recognises that Britain’s changing energy system brings new technology, new participants and new dependencies.

The strategy calls for a better understanding of the whole energy system, including critical suppliers, high-impact points of failure and areas where risk is concentrated. It also prioritises accelerated resilience, stronger response and recovery arrangements, and cyber requirements that keep pace with the changing energy landscape.

This is directly relevant to solar generation.

The Government’s 2026 consultation on whole-energy resilience noted that UK wind and solar capacity is expected to grow substantially towards 2030. It warned that new operators need to build security into infrastructure while it is being expanded, avoiding expensive “security debt” later.

Not every solar farm will be regulated in exactly the same way. Obligations can depend on factors such as size, function, grid role and whether the organisation falls within the Network and Information Systems Regulations.

Good security should not begin and end at the regulatory threshold. Smaller operators can still:

  • Provide an entry route to larger organisations
  • Use technology shared by major sites
  • Participate in aggregation platforms
  • Affect local electricity networks
  • Hold commercially sensitive operational data

Many of the network controls, monitoring arrangements and access restrictions described in What Cyber Security Protections Do Renewable Energy Projects Use? are directly applicable to utility-scale solar farms.

How UK Solar Farm Operators Can Reduce the Risk

Create an accurate asset inventory

Operators cannot secure equipment they do not know exists.

The inventory should record:

  • Device manufacturer and model
  • Serial number and physical location
  • Firmware and software version
  • Network address
  • Business owner
  • Maintenance supplier
  • Support status
  • Remote-access method
  • Criticality to site operation

Temporary communications equipment introduced during commissioning must also be identified and removed when no longer required.

Eliminate default credentials

Every factory password should be changed before a device is connected to an operational network.

Accounts should be unique, traceable and granted only the permissions required. Shared administrator passwords should be replaced with individual identities wherever the equipment supports them.

Where legacy devices cannot support acceptable access controls, operators should isolate them behind stronger security infrastructure.

Remove direct internet exposure

Management interfaces should not be publicly reachable unless there is an unavoidable and carefully assessed requirement.

Remote access should use:

  • A managed and monitored gateway
  • Multi-factor authentication
  • Encryption
  • Named user accounts
  • Time-limited permissions
  • Approved support devices
  • Source restrictions where practical
  • Session logging

Periodic external scanning can help confirm that forgotten interfaces have not become publicly visible.

Separate business and operational networks

Email, office applications and general internet browsing should not share an unrestricted network with inverters, plant controllers and substation systems.

Segmentation limits the damage if an employee laptop or business account is compromised.

Critical systems should also be divided into appropriate security zones so that access to CCTV or a weather station does not automatically provide a route to plant controls.

Control suppliers throughout the contract

Supplier assurance should continue after procurement.

Operators should maintain:

  • A current register of third-party connections
  • Named supplier accounts
  • Formal access approval
  • Regular access reviews
  • Security notification clauses
  • Vulnerability disclosure requirements
  • Support and end-of-life commitments
  • An exit plan for replacing the supplier

Access belonging to former employees, installers and contractors should be removed promptly.

Monitor operational behaviour

Traditional IT security monitoring may identify suspicious logins and malware, but OT monitoring must also recognise abnormal plant behaviour.

Warning signs might include:

  • Unexpected configuration changes
  • Commands issued outside maintenance windows
  • Multiple inverters restarting simultaneously
  • Connections from unusual countries or addresses
  • New administrator accounts
  • Disabled alarms
  • Sudden loss of communications
  • Firmware changes that were not approved

Monitoring should be designed carefully so that it does not interfere with time-sensitive industrial communications.

Prepare for loss of the cloud platform

The operator needs a tested procedure for operating safely when the main monitoring service is unavailable.

This should include local access, essential contact information, copies of approved configurations, manual reporting processes and clear authority for isolating remote connections.

Backups are only useful if the organisation can restore them. Recovery exercises should therefore include plant configurations and operational technology, not just office files.

Demand secure products

Future procurement should ask manufacturers to demonstrate:

  • Secure-by-default configuration
  • No universal default password
  • Multi-factor authentication support
  • Signed and verified firmware
  • A published vulnerability disclosure process
  • A clear security update policy
  • Software component transparency
  • Configurable remote access
  • Security logging
  • A supported route for local operation

The cheapest compliant inverter may not represent the lowest lifetime risk if it cannot be patched, monitored or operated independently of an overseas cloud service.

The Real-World View

The cyber risk facing UK solar farms should be taken seriously, but it should also be described proportionately.

Most incidents are more likely to cause loss of visibility, reduced output, commercial disruption or temporary equipment shutdown than an immediate nationwide blackout.

The more significant national risk comes from concentration:

  • Many sites using the same inverter
  • Several operators depending on one cloud platform
  • One maintenance provider holding access to numerous farms
  • Identical default credentials
  • A common vulnerable firmware version
  • Remote control concentrated outside the UK

Solar generation is becoming a larger part of Britain’s electricity system. That makes secure design, supplier assurance and recoverability increasingly important.

The objective is not to disconnect solar farms from useful digital services. It is to ensure that connectivity does not silently transfer control of important energy infrastructure to poorly protected accounts, exposed devices or inadequately scrutinised suppliers.

Conclusion

The greatest cyber security risk facing a solar farm is rarely the panel in the field. It is the chain of digital services surrounding it.

Remote monitoring platforms can expose entire portfolios through one compromised account. Vulnerable inverters can provide access to operational functions. Default passwords and public interfaces make discovery easier. Maintenance contractors create trusted pathways into site networks. Overseas cloud and manufacturing dependencies raise questions about control, jurisdiction and long-term support.

None of these risks makes solar energy inherently unsafe. They show why modern renewable generation must be treated as critical digital infrastructure as well as electrical infrastructure.

Operators that know what is connected, restrict remote access, scrutinise suppliers, monitor plant behaviour and practise recovery will be far better prepared for both ordinary cybercrime and more capable attacks.

Organisations and smaller energy users can also use the UK Energy Cyber Risk Assessment Tool — Free Score to identify common weaknesses in connected solar, battery and energy equipment.

Reference Material and Research