A recent report by Modat and the Dutch government's cybersecurity center, NCSC-NL, has revealed that 8,547 industrial control systems at wind and solar energy facilities across 35 countries in and around the European Union are directly accessible from the internet. These systems, which should be isolated from public networks, range from basic login portals to turbine control interfaces featuring "Stop" buttons.
The researchers identified these exposed systems using machine-learning clustering, which automatically groups similar devices and can uncover previously unrecognized system types. While the physical decentralization of renewable energy assets offers some protection against kinetic attacks, the report highlights a significant cybersecurity vulnerability, noting that "in cyberspace, there is no there there."
The exposed systems include web dashboards displaying live operational data such as power output, wind speed, and rotor information. Some control panels offer "Start," "Stop," and "Reset" functionalities. The report specifically mentions one wind turbine whose web server exposes a Siemens ET 200SP PLC, an industrial controller. Furthermore, some interfaces include map pages that reveal the precise geographical location of turbines, complete with aerial imagery of surrounding infrastructure.
While individual exposed systems can control a single turbine, others operate at a higher level, managing multiple turbines or entire energy farms, meaning a single compromised system could impact substantial generating capacity. The report also noted instances where login pages for wind parks explicitly named the sites and indicated that "root" is the default username in newer releases.
Of the 8,547 identified systems, 7,942 are associated with solar parks across 34 countries. Spain accounts for the largest share with 2,766 systems, representing 35% of the solar total. Greece (1,860), Italy (753), and Germany (672) collectively hold 76% of the exposed solar systems. For wind farms, 605 systems were found across 23 countries, with Germany (212) and Italy (192) making up 67% of this category. Despite the lower number, the exposed wind systems are significant, as some control multiple turbines at farms ranging from 10 megawatts to over 4,500 megawatts.
The report emphasizes that the actual number of exposed systems is likely higher, as systems were only included if they could be definitively linked to a specific solar or wind site.
The findings raise concerns about the security of remote access to critical infrastructure. While some countries, like Lithuania, restrict remote control by vendors from nations deemed national security threats, cybersecurity experts suggest that such measures address only one aspect of the problem. Most of the identified exposures are independent of the vendor's origin.
Experts recommend that organizations operating these facilities obtain a comprehensive list of all remote connections, including who connects, from where, to which assets, and their access permissions (read-only or operational control). They also advise requiring individual vendor accounts with strong authentication, limiting access to specific assets and actions, and separating permissions for sending commands from those for monitoring. Operators should maintain independent records of all commands and configuration changes, verify data and commands without relying solely on vendor systems, and ensure timely incident notification in compliance with directives like the EU's NIS2.
The immediate recommendation for operators is to remove administrative interfaces from the internet, plan and monitor systems with the assumption of an ongoing attack, and maintain the capability for manual site operation. The NIS2 directive holds management bodies of essential and important entities accountable for cybersecurity measures, whether systems are managed internally or outsourced.






