A cyber risk model published by energy risk specialist Centrii estimates a 92% probability of a major coordinated attack on UK battery energy storage systems within the next five years under what it describes as industry-average security practices.
The company’s GRIDLOCK assessment uses 10,000 Monte Carlo simulations across three security postures to model attack probability and financial exposure through 2031. Under its baseline scenario, the five-year probability is 92%. That falls to 78% where security improvements are adopted gradually and unevenly, and to 61% under the most stringent scenario, based on mandatory IEC 62443 certification and regular attack-readiness exercises.
The modelling also shifts the earliest likely attack window from 2027–28 under the baseline posture to 2029–31 under the most rigorous security assumptions.
For the UK, Centrii estimates that compromising around 29% of national battery capacity — approximately 400 units in its model — could be sufficient to cause a nationwide outage. The company puts the financial impact of a major incident at between £2bn and £10bn.
It estimates that raising UK battery storage infrastructure to IEC 62443 Security Level 2 would cost between £400m and £1bn across the national fleet. The figures are modelled rather than observed, but they place the cost of preventive security alongside the potential financial consequences of a coordinated attack.
Rafael Narezzi, co-founder and CEO of Centrii, said the concern is not necessarily physical damage to battery assets, but coordinated manipulation of their grid-balancing role.
“A coordinated attack does not need to stop generation to cause a blackout. It only needs to desynchronise the balancing layer, forcing batteries to charge or discharge together, or delaying how they respond to grid signals,” he said.
That mechanism has been examined independently. Research published in Energy Informatics in March 2025 modelled attacks against cloud-controlled battery energy storage used for load balancing and found that compromised control and communications could threaten grid stability.
The exposure is becoming more significant as storage deployment accelerates. The UK’s Clean Power 2030 plans require an estimated 23GW to 27GW of battery storage by 2030, compared with about 4.5GW in 2024, according to figures cited by RenewableUK.
Recent European incidents have also underlined the sensitivity of increasingly complex electricity systems. ENTSO-E’s final investigation into the April 2025 blackout in Spain and Portugal found that interacting factors including oscillations, voltage and reactive-power control gaps, rapid output reductions, and cascading generator disconnections led to the failure; it was not attributed to a cyberattack.
Poland, meanwhile, experienced coordinated destructive cyberattacks against more than 30 wind and solar installations and other energy infrastructure in December 2025. CERT Polska said the attacks disrupted communications between renewable sites and distribution operators, although they did not interrupt electricity production.
Centrii’s analysis does not predict that a specific attack will occur, and its percentages depend on the assumptions built into the model. It does, however, put a financial measure against an expanding operational-technology risk: as battery fleets take on more responsibility for balancing the electricity system, the resilience of the platforms controlling them becomes part of grid resilience itself.



