IN Brief:
- Modat and NCSC-NL identified 8,547 publicly reachable systems associated with wind and solar sites across 35 European countries.
- The exposed equipment includes administration interfaces and control panels that should not be reachable directly from the public internet.
- Remote maintenance and access by multiple suppliers increase the number of connections that renewable operators need to control.
Modat and the Netherlands’ National Cyber Security Centre have identified 8,547 systems associated with operating wind farms and solar parks across 35 European countries that can be reached from the public internet, including administrative interfaces and control panels.
The researchers mapped operating renewable sites across 40 countries in the EU, EFTA, and EU candidate states before comparing those locations with internet scan data. Confirmed exposure was found in 35 countries. Names, operators, locations, and IP addresses have not been published, while affected parties are being contacted through national computer emergency response teams.
The figure does not mean that 8,547 turbines, inverters, or generating plants can all be controlled remotely by an unauthenticated attacker. The exposed systems cover a wider set of equipment, including administration and management interfaces. Public reachability nevertheless increases the attack surface because automated scans can discover the same interface without first gaining access to a private network.
Renewable generation creates a difficult access problem because the physical assets are widely distributed. Wind and solar sites can be remote and unmanned for long periods, while operators, maintenance contractors, equipment manufacturers, energy traders, and network parties may all require access to operational information or plant systems. Remote connectivity is therefore a normal operating requirement rather than an exceptional arrangement.
Secure remote operation depends on how that access is provided. A management function can sit behind a private network, controlled gateway, or other authenticated route without exposing the underlying device directly to anyone scanning the internet. When an administration panel or control interface is publicly reachable, automated discovery tools can identify it at much the same scale as legitimate asset discovery work.
Modat used machine learning clustering within its Magnify platform to group similar systems and identify device types for which fixed detection rules had not previously been written. That approach matters because an asset inventory cannot depend entirely on a known catalogue of vendor signatures. Equipment changes, service providers introduce new remote tools, and integrators can expose similar functions through different interfaces.
Removing unnecessary public exposure reduces one route into an operational environment, but it does not establish that every command, software update, configuration change, or telemetry stream can be trusted. Renewable sites exchange information between field equipment, plant controllers, supervisory systems, service platforms, and external organisations. Compromise further upstream can therefore affect operation even where the final control device is not itself publicly reachable.
Authentication, access control, network segmentation, logging, and integrity checks have to cover those remaining paths. Operators need to know which systems can be reached remotely, who can use each route, what privileges are available, and whether the access still has an operational purpose. Connections created for commissioning or vendor support can persist for years unless they are recorded and reviewed as part of the asset inventory.
Data leaving the plant carries a related risk. Monitoring information supports maintenance, performance analysis, trading, and grid operation, but the receiving system needs confidence that measurements have not been altered. False data can drive poor operating decisions without an attacker ever issuing a direct command to a turbine or inverter, particularly where automated processes rely on remote measurements.
Recent work on offshore wind security has already highlighted the interaction between cyber, physical, and supply chain resilience as generation becomes more distributed. The Modat and NCSC-NL findings extend that problem across a much wider operating fleet of solar and wind assets, where the number of organisations with legitimate access can increase the number of interfaces that need to be governed.
A single renewable project can contain equipment from several manufacturers together with separate monitoring, communications, weather, security, and grid interface systems. Responsibility may also be divided between the asset owner, operator, maintenance company, turbine or inverter supplier, communications provider, and other specialists. An inventory limited to equipment physically owned by the generator can therefore miss services or supplier connections that still reach the operating environment.
Public exposure can be addressed by removing unnecessary services from the internet and placing required remote functions behind controlled access. The longer task is maintaining that discipline as equipment is replaced, software changes, new contractors arrive, and operational responsibilities shift. A system secured at commissioning can become exposed later if a temporary maintenance route becomes permanent or a new management product is deployed without the same controls.
The research was presented at The ONE Conference in The Hague on 6 October. Modat and NCSC-NL have published only aggregated findings by country while national response organisations work to identify and notify affected operators. The immediate engineering task is to establish why each exposed interface is reachable, whether that access is necessary, and what control exists over the commands and data crossing the boundary.



