8,500+ European Wind, Solar Systems Exposed

The Dutch National Cyber Security Centre (NCSC-NL) and cybersecurity organization Modat discovered more than 8,500 exposed systems linked to European wind farms and solar parks.
Across 40 examined European countries, 35 had exposed systems. Solar installations in 34 countries accounted for 7,942 exposures, and wind farms in 23 countries accounted for 605.
Some exposed systems included sensitive operational panels. Researchers estimated 181 sites could have allowed full operational control.
Security Leaders Weigh In
Damon Small, Board of Directors, Xcape, Inc.:
Unauthenticated, Internet-exposed interfaces on critical infrastructure threaten regional grid resilience and create operational, legal, and reputational risk across renewable energy portfolios. The discovery of over 8,500 exposed European wind and solar management endpoints, including over 180 permitting full operational intervention, highlights fundamental identity and network perimeter failures. While remote access to operational technology (OT) systems is a clear operational requirement, it must be delivered securely through zero-trust access, network segmentation, and multi-factor authentication rather than exposing control panels directly to the public Internet. To prevent these foolish architectural decisions, organizations must conduct mandatory threat models and architecture reviews before production systems go live, while immediately pulling existing interfaces behind secure gateways and enforcing credential rotation.
Critical Takeaways:
- Publicly exposing OT control interfaces directly to the Internet turns standard management features into severe grid resilience vulnerabilities.
- Remote access is a valid operational requirement, but it must be mediated via zero-trust architecture, multi-factor authentication, and secure gateways.
- Formal architecture reviews and threat modeling must occur prior to live deployment to catch perimeter and identity flaws early.
Threat modeling before deployment costs a fraction of what an incident responder will charge to explain why “root” was still the password.
Steven Swift, Managing Director, Suzu Labs:
This isn’t an AI problem, even if the authors of the research claim that “AI made things a little faster.” We’ve seen decades of organizations putting resources directly onto the public internet with minimal to no protections in place, and then act surprised when its found and exploited.
There’s already a rich well developed industry of mapping the entire attack surface of literally every single public IP. This isn’t new, and it doesn’t depend on AI. If you put a resource on the internet, existing (non-ai) automation will find it, document it, and put it into a database for easy access by others.
For this research specifically, there’s a mix of single devices and management interfaces for groups of devices. That said, much of the wind and solar infrastructure is decentralized. So while 8,500 devices being directly exposed to the internet is a lot, if a threat actor wanted to cause harm, they would be limited to a subset of these at a time.
That’s still a problem. Power is part of critical infrastructure. People want their power to keep working, and not to have an outage because someone decided to hack in. If an attacker wanted to cause harm, rather than simply turning power generation off they could tamper with the working configuration. If the system can be misconfigured to intentionally overload for example, permanent damage could result.
This is an example where security best practices are completely basic, yet still not being followed. Literally just don’t have equipment directly exposed to the internet. Having remote access to systems is fine, but it needs to be secure. Putting equipment behind a secure VPN for example is only minimally more complex to setup, and orders of magnitude more secure.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!








