IN Brief:
- North Sea countries are pursuing a combined offshore wind ambition of 300GW by 2050.
- EIES says turbines, substations, subsea cables, controls, remote access, and supply chains must be treated as one cyber-physical security system.
- The report calls for stronger recovery capacity, secure information sharing, resilient procurement, spares, and regular cross-border exercises.
The European Initiative for Energy Security has called for cyber, physical, and supply chain security to be designed into offshore wind development as North Sea countries pursue a combined ambition of 300GW by 2050.
Its latest analysis uses Germany as a test case for protecting a power system in which offshore wind, subsea cables, substations, digital controls, and cross-border infrastructure are becoming more interconnected. The report argues that the expansion programme is increasing the number and importance of assets that have to remain available during cyber incidents, physical damage, or wider security disruption.
Offshore wind is unusually exposed because much of the equipment sits far from shore and outside normal controlled sites. EIES says approximately 95% of Germany’s existing offshore wind capacity is located beyond territorial waters, complicating surveillance, access, repair, and emergency response.
The generation fleet is also expanding quickly. EIES puts European offshore wind additions at 2.1GW in the first half of 2026, three times the level recorded in the equivalent period of 2025, while Germany plans to increase offshore capacity from around 10.8GW in July 2026 to at least 30GW by 2030.
A modern offshore project combines turbine controllers, converter and transformer systems, offshore substations, export cables, communications, remote access, monitoring platforms, and onshore grid interfaces. A failure or compromise at one part of that chain can affect both information systems and electrical operation.
Protection consequently extends beyond conventional IT controls. Operators have to consider network segmentation, authenticated remote access, software maintenance, communications redundancy, protection and control integrity, physical access, cable routes, spare equipment, vessel availability, and the procedures needed to restore service after a fault or deliberate attack.
ENTSO-E has already set wider priorities for transmission infrastructure security, covering physical protection, cybersecurity, offshore recovery, crisis responsibilities, cross-border resources, information controls, and dedicated security investment. EIES applies a similar resilience argument specifically to offshore wind.
The organisation wants security requirements embedded in planning, procurement, and investment decisions before assets are built. Its recommendations include stronger European manufacturing capacity for critical components, use of legal tools to exclude high-risk suppliers where appropriate, better access to spares and specialist repair capability, and more secure information sharing between operators and public authorities.
EIES also calls for regular national, EU, and NATO exercises to test crisis response and recovery. Restoration of an offshore asset can involve the wind-farm operator, transmission operator, equipment suppliers, cable owners, maritime authorities, security agencies, ports, and specialist vessel contractors, with each organisation holding only part of the response capability.
Subsea repair capacity is a particular constraint. Cable faults are technically demanding even in routine conditions, and the available pool of suitable vessels, joints, spare cable, trained personnel, and weather windows is finite. An incident affecting several assets at once would expose how much of that capability can be mobilised simultaneously.
Cyber recovery has a different shape but similar dependencies. Restoring a control system safely may require known-good software, trusted configuration data, clean engineering workstations, secure communications, vendor support, and evidence that protection and control settings have not been altered before equipment is re-energised.
The regulatory base is becoming more explicit. EIES points to the revised NIS2 Directive and Critical Entities Resilience Directive, their implementation in German law, and the 2026 Hamburg Declaration’s commitments on coordination, situational awareness, harmonisation, incident response, and preparedness among North Sea governments.
European institutions are also funding undersea resilience measures. The European Commission announced €5.8 million for initial regional cable hubs in the Baltic and Mediterranean Seas and a €40 million call intended to expand submarine-cable repair capacity, while NATO has established a Maritime Centre for the Security of Critical Undersea Infrastructure.
The incident base is rising at the same time. EIES says German critical-infrastructure operators reported 724 incidents in 2025, up from 452 in 2021, with energy infrastructure accounting for 153 of the 2025 total. It also cites at least 11 damaged Baltic Sea cables since October 2023 as evidence of the physical exposure of maritime infrastructure.
Security requirements will increasingly affect procurement, capital cost, operating expenditure, and project schedules. Redundant communications, hardened equipment, secure remote-access architectures, additional spares, surveillance, training, and recovery exercises all consume money and engineering time, but they also determine how quickly an asset can return to service after disruption.
The North Sea’s 300GW ambition will therefore be judged on more than installed turbine capacity. Cables, substations, controls, communications, suppliers, and recovery resources have to be treated as one connected piece of critical infrastructure if the generation fleet is expected to carry a larger share of European electricity supply.
For Germany, where roughly 95% of existing offshore wind capacity already sits beyond territorial waters, that requirement is immediate rather than theoretical. The build-out to at least 30GW by 2030 leaves little room to bolt resilience onto finished projects after the electrical and digital architecture has already been fixed.



