The energy transition is also a digital transition. Electricity networks increasingly rely on smart meters, sensors, automated controls, distributed energy resources, artificial intelligence and platforms capable of exchanging large volumes of data in real time. These technologies help integrate renewables, manage increasingly complex electricity flows and give consumers a more active role in the power system. But they also change the nature of energy security. As electricity networks become more connected, cybersecurity in the energy transition is becoming an infrastructure issue rather than simply an IT concern. The question is no longer only how digital technologies can make power systems cleaner, more flexible and efficient, but whether the systems built around them can remain secure and operational when something goes wrong.
A recent collection of case studies by the United Nations Economic Commission for Europe (UNECE), Compendium of Case Studies on Digitalization in Energy in the UNECE Region, looks at this transformation from several angles, from AI-assisted electricity balancing and smart meters to distributed energy resources and cyber resilience. One conclusion runs through otherwise very different cases: as energy infrastructure becomes more connected, its dependence on digital systems grows. So does the number of points at which something can go wrong.
This is why cybersecurity is moving from the margins of the energy transition into discussions about how future power systems should actually be designed.
More connected means more exposed
The benefits of digitalisation are relatively easy to see. Better forecasting and digital system management can help operators manage increasingly complex power systems and variable solar and wind generation. Smart meters can support dynamic tariffs and demand response. Distributed batteries, rooftop solar, electric vehicles and other flexible resources can be coordinated instead of operating as isolated assets.
The UNECE collection gives a good indication of where this is heading. In Australia, distributed energy resources are expected to account for around 40% of total installed power capacity by 2050. The Australian Energy Market Operator (AEMO), working with the Energy Web Foundation, has therefore tested a decentralised data exchange through Project EDGE, designed to allow consumers, system operators, networks and flexibility providers to coordinate distributed resources more effectively.
The same decentralisation that can make a power system more flexible, however, also multiplies the number of digital assets that need to be secured. A traditional power system concentrated much of its control infrastructure in a relatively limited number of facilities. The emerging system may eventually contain millions of communicating devices. Smart meters, battery systems, EV chargers, solar inverters and household energy management systems all generate data or receive instructions. Connections between information technology (IT) and operational technology (OT), the systems that actually control physical equipment, become particularly important.

The problem is no longer theoretical. Dragos, a cybersecurity company specialising in industrial control systems, reported in its 2026 OT Cybersecurity Year in Review that 81% of its assessments found poor IT/OT network segmentation. Adequate OT network monitoring was present in only 46% of assessments. In its incident-response cases, compromised VPN or jump-host credentials were involved in 73% of cases in the company’s historical dataset.
These figures matter because an attack does not necessarily have to begin with highly specialised malware designed for a power station. Ordinary remote-access credentials or an inadequately separated corporate network can provide a route towards systems with physical functions. In other words, some of the vulnerabilities of an increasingly sophisticated power system can begin with surprisingly ordinary digital weaknesses.
Distributed energy brings new cybersecurity risks
The growth of batteries and other distributed resources adds another dimension. In its 2026 review, Dragos describes vulnerabilities discovered in battery energy storage systems, including authentication bypass and command-injection weaknesses. Its researchers identified more than 100 affected devices exposed to the internet, among them inverters rated at around 1 MW and designed to feed electricity into utility grids.
The number itself is less important than what it illustrates. A battery is no longer simply an electrical asset. An inverter is not simply power equipment. Once these devices are remotely controlled and integrated into grid operations, their software, credentials and communications become part of energy security.
That is particularly relevant as power systems become more decentralised. A cyber incident affecting one household battery is unlikely to threaten a grid. The calculation changes if large numbers of similar devices use common software, cloud services or remote management platforms. A vulnerability that looks small at the level of an individual device can become much more significant when the same technology is deployed at scale.

The UNECE collection makes a related point in its discussion of smart grids. AI and machine-learning applications can require large quantities of potentially sensitive information, including detailed energy-consumption patterns. The report consequently identifies data leakage, misuse of information, biased algorithms and limited accountability among the risks accompanying the expansion of smart-grid technologies.
Cybersecurity therefore has to cover more than the traditional perimeter of a utility company. It increasingly extends through equipment manufacturers, software suppliers, communications platforms and devices installed behind the meter. This makes energy cybersecurity partly a supply-chain issue as well as an operational one.
When patching is not simple
There is another reason why energy cybersecurity differs from conventional IT security: updating industrial equipment is not always straightforward. A laptop can normally be restarted to install a security update. Taking an operational energy asset offline may require advance planning, create costs or interfere with an essential service. Some industrial equipment also remains in operation for decades, much longer than the software lifecycle of ordinary consumer technology.
Dragos found that 25% of the vulnerability advisories it analysed had no available patch or mitigation, while in 52% of cases its researchers had to develop alternative mitigation measures. Four percent of the vulnerabilities examined were already being actively exploited.
This is where the distinction between cybersecurity and cyber resilience becomes useful. Preventing intrusion remains important, but a critical infrastructure operator also needs to know what happens when prevention fails. Can an abnormal event be detected quickly? Can the affected part of the network be isolated? Can operators maintain essential functions? And how rapidly can normal operation be restored?
Here, the UNECE report draws on the familiar NIST logic of identifying risks, protecting systems, detecting incidents, responding and recovering. The emphasis on recovery is significant. For infrastructure that cannot simply stop operating, resilience may be as important as protection.
There is still a gap between that principle and operational practice. According to Dragos, 82% of organisations assessed lacked clear criteria for deciding when unexplained operational behaviour should trigger a cybersecurity investigation. In 30% of its incident-response cases, the incident initially appeared as an unexplained operational problem rather than an obvious cyberattack.
That ambiguity is particularly uncomfortable in energy infrastructure. A malfunctioning piece of equipment, a software error and hostile activity can initially look remarkably similar.
Europe is treating cyber risk as an energy issue
Regulation is beginning to reflect this changing risk profile. The EU’s first Network Code on Cybersecurity for the electricity sector entered into force in June 2024. It introduces sector-specific requirements for cross-border electricity flows, including common minimum requirements, cybersecurity risk assessments, monitoring, reporting and crisis management.
The Commission’s explanation for having energy-specific rules is revealing. Electricity systems require rapid responses, cyber incidents can produce cascading effects, and new digital technologies have to operate alongside legacy equipment. Cybersecurity in energy therefore cannot be addressed entirely through general rules applying to conventional IT systems.
The regulatory framework is still developing. In July 2026, the European Commission published a new overview of current and emerging EU legislation dealing specifically with cybersecurity and the energy sector.
This sits within a much broader threat environment. ENISA’s Threat Landscape 2025 analysed 4,875 cybersecurity incidents affecting the EU between July 2024 and June 2025. More than half, 53.7%, concerned entities classified as essential under the NIS2 framework. ENISA also stresses the possibility of ripple effects because critical systems and services are increasingly interconnected.
These figures should not be read as 4,875 attacks on the energy sector. They describe the wider European threat landscape. But that wider environment matters precisely because electricity, transport, communications, digital infrastructure and other essential systems increasingly depend on one another. This interdependence is one reason cybersecurity in the energy transition cannot be treated in isolation. The consequences of a digital failure may not remain within the system where the problem first appears.
Cyber resilience by design for the energy transition
None of this weakens the case for digitalising the energy system. Managing a grid with growing shares of variable renewable generation and millions of distributed assets without better data, automation and forecasting would be increasingly difficult. The Australian case described by UNECE shows why information exchange and digital coordination are becoming necessary components of distributed energy systems.
The more relevant question is whether cybersecurity develops at the same speed. For years, the energy transition has largely been discussed through generating capacity, grids, storage and investment. Digital infrastructure adds another layer. A smart meter rollout, a battery project or an AI-based grid management platform is not only an energy technology investment. It also creates software dependencies, data flows and access points that have to remain secure over the lifetime of the asset.
This has consequences beyond system operation. Cyber resilience can affect procurement requirements, technology choices, maintenance costs and due diligence around energy infrastructure. As assets become more dependent on software and remote management, the security of those systems increasingly becomes part of the long-term risk attached to the investment itself.
That makes cyber resilience less of an IT issue than it first appears. It belongs in decisions about procurement, equipment standards, grid architecture, investment and regulation. Security requirements introduced after systems have already been connected are inevitably harder, and often more expensive, to implement.
These questions will also be part of the discussion at Energy and Investment Days, taking place in Novi Sad, Serbia, on 14–15 October 2026. Bringing together energy companies, investors, public authorities, technology providers and other stakeholders from across Southeast Europe, the event will address energy security, grid modernisation and digital energy, including the challenges emerging as energy infrastructure becomes more connected and technology-dependent.
The energy system of the future will almost certainly be more digital, distributed and automated than today’s. Those characteristics can make it more efficient and flexible. Whether they also make it more resilient will depend on whether cybersecurity is treated as part of the energy transition itself, rather than as a problem to be solved after the infrastructure has been built.


