Centrii models UK BESS cyber risk at 92%

Centrii models UK BESS cyber risk at 92%

Centrii models severe cyber risk across Britain’s battery storage fleet. Its GRIDLOCK assessment produces a 92% baseline five-year attack probability, although all probability and financial figures are modelled rather than observed.


IN Brief:

  • GRIDLOCK uses 10,000 Monte Carlo simulations for each of three assumed BESS security postures, producing five-year probabilities ranging from 92% to 61%.
  • Its UK scenario estimates £2bn–£10bn of financial damage from a major coordinated attack, but these figures are model outputs rather than observed loss data.
  • The underlying engineering concern is coordinated manipulation of remotely controlled batteries, potentially turning balancing assets into a simultaneous source of grid imbalance.

Centrii has published cyber-risk modelling that produces a 92% five-year probability of a major coordinated attack on battery energy storage infrastructure under its baseline assumptions, with a modelled financial impact of £2bn to £10bn for the UK scenario.

The figures come from GRIDLOCK, a Monte Carlo risk assessment covering three assumed industry security postures. Centrii says 10,000 simulations were run for each posture, with variables drawn from ranges covering factors including battery deployment, attacker capability, cloud access, remote connectivity, and supply-chain compromise.

The percentages are model outputs rather than observed attack frequencies. That distinction is essential when interpreting a result as precise as 92%, because the probability depends on assumptions about future attackers, system architecture, security controls, fleet growth, and the proportion of assets that could be compromised.

Under the baseline case, which Centrii describes as industry-average security practice, the model produces a 92% probability of a major attack before 2031. That falls to 78% under gradual and uneven voluntary improvement and to 61% under the most rigorous security posture.

The strongest scenario assumes mandatory IEC 62443 certification and regular attack-readiness exercises. Centrii also says the modelled earliest likely attack window shifts from 2027–28 under baseline assumptions towards 2029–31 under the more stringent posture.

Those results are more useful as comparisons between security assumptions than as a conventional forecast that a specific event will occur. Cyberattack probability cannot be measured like transformer failure rate because attacker capability and intent change, while the digital architecture and security maturity of the storage fleet are themselves moving targets.

The underlying power-system concern is less controversial. Utility-scale batteries increasingly operate through remote supervisory systems and cloud-connected optimisation platforms, allowing fleets to respond rapidly to electricity prices, balancing instructions, frequency changes, and other grid signals.

That controllability creates a cyber-physical consequence if enough assets can be manipulated simultaneously. Rafael Narezzi, Co-Founder and CEO of Centrii, said: “A coordinated attack does not need to stop generation to cause a blackout. It only needs to desynchronise the balancing layer, forcing batteries to charge or discharge together, or delaying how they respond to grid signals.”

A battery that changes operating direction can create a particularly sharp system disturbance. If a fleet stops discharging and begins charging almost simultaneously, the grid loses the previous export at the same time as acquiring a new electrical load.

The resulting power swing can therefore be larger than the charging demand viewed in isolation. Whether that disturbance remains manageable depends on its magnitude and speed, system inertia, fast frequency response, available reserves, network conditions, protection settings, and the behaviour of other generation and demand.

GRIDLOCK’s UK scenario assumes that compromising around 29% of national battery capacity, described by Centrii as approximately 400 units, could be sufficient to trigger a nationwide outage affecting roughly 67 million people. The company places the modelled financial damage from a major incident between £2bn and £10bn.

Those numbers should not be interpreted as evidence that compromising exactly 400 real installations would cause a national blackout. Britain’s battery fleet contains projects with different power ratings, energy durations, grid connections, control systems, owners, software, aggregators, and security architectures, while the state of the electricity system changes continuously.

The same qualification applies to Centrii’s investment comparison. The company estimates that bringing the UK fleet to IEC 62443 Security Level 2 would cost £400m to £1bn and compares that with the £2bn–£10bn modelled loss range, producing an avoided-loss ratio of roughly five to 25 times.

That is a scenario-based comparison rather than a guaranteed investment return. Security expenditure cannot guarantee that an attack will be prevented, and the modelled loss does not become cash simply because a control is installed.

The scale of deployment does make the issue more consequential. Britain expects to rely on substantially more battery capacity as renewable generation increases, adding fast-response flexibility but also increasing the amount of grid-connected power electronics potentially reachable through digital control paths.

Cybersecurity risk therefore extends beyond individual compounds. Common cloud platforms, remote-maintenance systems, equipment suppliers, software libraries, communications services, and fleet optimisers can create correlated exposure where a weakness affects many geographically separate assets.

Independent academic research supports the plausibility of that attack mechanism without validating Centrii’s probability figures. A 2025 peer-reviewed Energy Informatics study examined cloud-controlled BESS used for frequency balancing and found that cyberattacks against communications and control functions could materially threaten grid frequency and stability.

The study does not establish a 92% probability of a major UK attack, a £10bn loss, or the exact fleet-compromise threshold used by GRIDLOCK. Those figures belong to Centrii’s modelling and should remain attributed accordingly.

For operators, the practical response is less abstract than the headline percentage. Segmentation between operational and corporate networks, tightly controlled remote access, software-update assurance, supply-chain security, monitoring for abnormal fleet behaviour, incident-response exercises, and the ability to retain safe local control all reduce dependence on the assumption that a central digital layer will remain trustworthy.

Battery storage is valuable precisely because it can change power quickly. As the fleet takes a larger role in frequency response, balancing, constraint management, and energy shifting, the security of the systems issuing those commands increasingly becomes part of power-system engineering rather than a separate IT concern.

GRIDLOCK’s 92% figure will reasonably attract scrutiny because it converts numerous assumptions into a single striking number. The more durable issue is the one behind it: when hundreds of fast, remotely controllable electrical assets help balance the grid, correlated compromise has to be considered alongside conventional failures when operators assess system resilience.


  • Centrii models UK BESS cyber risk at 92%

    Centrii models UK BESS cyber risk at 92%

    Centrii models severe cyber risk across Britain’s battery storage fleet. Its GRIDLOCK assessment produces a 92% baseline five-year attack probability, although all probability and financial figures are modelled rather than observed.


  • Ofgem advances code-manager licence reforms

    Ofgem advances code-manager licence reforms

    Ofgem proposes new licence conditions for Britain’s energy code managers. Initial changes cover BSC and REC budgets, cost recovery, delivery plans, performance, and transferred governance responsibilities.