Cyberattacks have doubled between 2020 and 2022 in the power sector, with 48 successful attacks hitting Europe’s energy infrastructure in 2022 alone. This is why cybersecurity has become a key component of ensuring overall energy security.
What is cybersecurity?
Cybersecurity is the protection of organisations, individuals and networks from digital attacks. These attacks through digital infrastructure and networks, when successful, can access, change or destroy sensitive information, extort money or interrupt normal business operations. Cybersecurity requires measures across an organisation. It’s about making sure all staff has a safety-first mindset, designing and maintaining both IT and operational systems, and making sure there is a clear action plan in the event of an incident.
Cyberattacks have doubled between 2020 and 2022 in the power sector, with 48 successful attacks hitting Europe’s energy infrastructure in 2022 alone. This is why cybersecurity has become a key component of ensuring overall energy security.
What is energy security?
Energy security is the capability to establish a reliable, sustainable and resilient power system that meets the energy demands of people and businesses to run their daily activities.
The International Energy Agency (IEA) defines it as having both long-term and short-term aspects. Long-term energy security involves investments in security of supply and its connection to economic developments and environmental needs, while short-term energy security addresses the system’s ability to respond to shifting supply and demand (i.e. flexibility).
How is cybersecurity becoming a cornerstone of Europe’s energy security?
The power sector, and utilities more broadly, are undergoing a digital transformation. Traditional power grids, once mostly connected to centralised generation and based on manual operations, are evolving into smarter grids that leverage automation, artificial intelligence (AI) and real-time data analytics. This shift enhances efficiency, flexibility and resilience, making modern power systems better equipped to integrate variable renewable energy sources and respond to changes in demand and production.
One of the key drivers of digitalisation is the growing adoption of decentralised energy sources. Other than relying on large, centralised power plants (think large gas power plants), today’s electricity system increasingly incorporates distributed generation, including rooftop solar panels, wind farms and battery storage. Therefore, transmission and distribution system operators require advanced digital technologies and platforms to coordinate power flows, connect these decentralised assets, and ensure overall grid stability.
Additionally, the increasing deployment of smart meters and connected devices allows consumers to actively participate in the market. Smart meters provide real-time insights into consumption, enabling automated demand response and dynamic pricing mechanisms. For the power suppliers and retailers, AI-driven forecasting systems further optimise the balance by predicting demand patterns and adjusting supply accordingly, thus preventing overloads.
Why digitalisation brings risks
Although digitalisation has numerous advantages, it also introduces new challenges. As more systems become interconnected and reliant on digital technologies, the number of potential access points for hostile actors increases, also known as attack surface.
Modern power systems rely on complex networks of smart meters, sensors and automated control systems, all of which can be exploited if not adequately protected. Cybercriminals can target weak points in these networks to disrupt operations, steal data or manipulate energy flows. The rise of decentralised assets, such as electric vehicles, heat pumps and solar PVs connecting to the grid at low voltage levels, also adds complexity creating potential security gaps.
Another key challenge is the dependency on real-time data and automation. While it optimises grid efficiency, it can also introduce risks if compromised. A cyberattack that manipulates data or disrupts automated controls could lead to widespread blackouts, equipment failures or financial losses.
Additionally, supply chain vulnerabilities pose a growing threat. Energy infrastructure increasingly relies on external software providers, cloud services and imported hardware components. Should these third-party systems become compromised, attackers can gain access to critical grid operations.
Types of cyber threats
Cybercriminals and state-sponsored actors increasingly exploit vulnerabilities in critical infrastructure such as utilities, aiming to disrupt operations, steal sensitive data or gain geopolitical leverage. These attacks take various forms, and here are just a few types:
1. Malware
Malware is designed to infiltrate and damage digital networks. One of the most common types of malwares is ransomware, which encrypts system data and demands a ransom for its release. In the energy sector, ransomware can cripple operations by locking out operators from critical control systems. For example, in 2023, cyberattackers used ransomware to infiltrate 22 European energy companies.
2. Phishing
Phishing attacks trick employees into providing login credentials or downloading malicious software. Cybercriminals often impersonate trusted organisations, sending deceptive emails or messages that appear legitimate. Once access is gained, attackers can move through the network undetected, potentially taking control of critical operations.
3. Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) Attacks
In a DoS or DDoS attack, hackers overwhelm a system with excessive traffic, causing it to slow down or crash. For the power sector, these attacks can disrupt real-time monitoring systems, delay automated responses and hinder communication between grid operators. A prolonged DoS attack on a smart grid can even lead to cascading failures that impact entire regions.
4. Supply chain attacks
As the energy sector increasingly relies on third-party vendors for software, cloud services and even hardware, supply chain attacks have become a major concern. Cybercriminals can compromise a software update or embedded hardware component, gaining access to critical infrastructure. These are difficult to detect and can spread across multiple energy companies using the same vendor.
5. Hybrid threats
Hybrid threats combine cyberattacks with physical sabotage to maximise damage. During the invasion of Ukraine, Russian-backed hackers launched cyberattacks on the electricity grid while simultaneously targeting infrastructure with missile strikes. This type of attack underscores the importance of securing assets both digitally and physically, such as with anti-missile and/or anti-drone assets.
Why is the energy sector a target?
The power sector is one of the most frequently targeted industries due to its role as the backbone of modern economies. Electricity powers everything from homes and businesses to hospitals and national defence systems, making disruptions a severe risk.
Indeed, electricity grids, power plants and distribution networks are considered critical infrastructure, because a disruption can cause widespread economic and social consequences. A successful cyberattack on the electricity sector could lead to blackouts, financial losses and even threaten national security.
Cyberattacks on energy infrastructure have increasingly been used as weapons of hybrid warfare. One of the most well-documented examples is the series of cyberattacks against Ukraine’s power grid perpetrated by Russia in the lead-up to the 2022 invasion and throughout the war
Europe’s electricity grid is one of the most interconnected in the world, allowing for cross-border electricity trading and grid balancing. However, this interconnectedness also increases the risk of cyberattacks spreading rapidly across multiple Member States, as a breach in one country’s system could potentially affect neighbouring nations.
Europe’s growing cybersecurity woes
Cyberattacks on Europe’s energy sector have surged in recent years, posing a growing threat to the stability and security of our electricity systems.
One of the biggest concerns is the global rise of state-sponsored cyberattacks, particularly from Russian-backed hacker groups. In 2023, 61% of all recorded cyberattacks worldwide originated from Russia, many of which targeted European critical infrastructure, with attacks ranging from ransomware incidents to attempts at grid disruption.
To combat these risks, the EU has been strengthening its cybersecurity policies, but challenges remain in ensuring harmonised enforcement and coordination among Member States.
The growing role of AI
Artificial intelligence is a double-edged sword when it comes to cybersecurity. On the one hand, AI-driven tools can detect threats faster and improve real-time response capabilities. On the other, cybercriminals are leveraging AI to automate attacks, bypass security measures and create highly convincing phishing scams. As AI-powered hacking tools become more advanced, traditional defence mechanisms will need to adjust their protection.
As new technologies such as 5G, cloud computing, and IoT-connected devices become more integrated into the power system, and as IT and operational (OT) systems move closer, securing them against cyber threats will be a major challenge. A strong security strategy must therefore aim to balance technological innovation with robust security measures to ensure long-term resilience.
What has been the EU’s regulatory response so far?
Recognising these growing threats, the European Union has taken significant steps to strengthen its defences. Over the past decade, the EU has introduced several legislative and regulatory frameworks to enhance security across critical infrastructure such as electricity networks.
The NIS 2 Directive
One of the most important recent developments is the Network and Information Security Directive 2 (NIS 2 Directive), which builds on its predecessor to create a more robust and harmonised approach to cybersecurity across the EU. NIS 2 expands the scope of cybersecurity requirements to electricity, oil and gas networks. Some of its mandates include:
• Stronger risk management measures for energy operators.
• Improved incident reporting to national authorities.
• Greater coordination between EU Member States when responding to cyber threats.
The Cyber Resilience Act
In addition to NIS 2, the EU has introduced the Cyber Resilience Act (CRA) to further enhance security in digital infrastructure. This Act sets new cybersecurity standards for hardware and software products, ensuring that all digital components used in energy systems meet strict security requirements. It applies to smart meter gateways (SMGW).
The Network Code on Cybersecurity
To address cybersecurity risks specific to the energy sector, the EU has also developed the Network Code on Cybersecurity. This introduces cybersecurity rules tailored to electricity networks, focusing on:
• Grid protection measures to prevent unauthorised access.
• Incident response protocols to detect and contain cyber threats.
• Stronger security requirements for third-party vendors supplying IT and operational technology to energy companies.
Challenges in implementation
Challenges persist when it comes to ensuring harmonised enforcement across EU Member States. Differences in national capabilities, regulatory frameworks and investment levels have all played a part in creating gaps. Additionally, coordination between regulators, security agencies and private sector operators should improve. As cyber threats to the power sector keep rising, the EU’s regulatory framework must remain dynamic and adaptive.
How to improve cyber resilience in Europe’s electricity sector?
Beyond regulatory measures, the power sector must adopt proactive security strategies, increase investments in cybersecurity and foster collaboration between public and private entities.
I. Enhancing investments
One of the most pressing challenges is the need for increased financial investment in cybersecurity. Although the power sector invests more in cybersecurity than many other industries, European utilities still need to increase their investments in cyber to adjust to increased threats.
Potential areas for investment include:
• Upgrading legacy systems – those outdated computing software or hardware that are still in use but that were not designed with cybersecurity in mind.
• Deploying advanced threat detection technologies, such as AI and machine learning, to identify and mitigate risks in real-time.
• Strengthening network defences, including firewalls, encryption and multi-factor authentication to reduce unauthorised access.

II. Developing a skilled workforce
The EU also faces a sizeable cybersecurity workforce shortage, with an estimated 260,000 to 500,000 unfilled positions across all sectors. The power sector especially has struggled to attract and retain skilled cybersecurity professionals.
To address this gap, the EU ought to:
• Expand training programs focused on cybersecurity in the power sector.
• Encourage public-private partnerships to develop specialised skill sets for utility operators and IT professionals.
• Support knowledge-sharing initiatives between cybersecurity experts and power companies to enhance industry-wide expertise.
III. Improving collaboration and information sharing
Cyber threats evolve rapidly, making real-time information sharing between industry players, regulators and agencies crucial for resilience. Key initiatives to continue supporting ought to include:
• The role of ENISA, CERT-EU, and the European Cybersecurity Competence Centre (ECCC) in facilitating intelligence sharing and rapid response coordination.
• Public-private partnerships to improve threat monitoring and joint cybersecurity drills.
• Cross-border cooperation among EU Member States to ensure a unified response to any attempts to disrupt shared electricity infrastructure.
Power companies must also embed cybersecurity into every stage of system development, ensuring that security is not an afterthought. This means integrating security measures into smart grid and digital infrastructure designs from the outset, but also applying strict cybersecurity standards to third-party vendors and supply chain partners to prevent vulnerabilities.
By adopting these strategies, the EU power sector can enhance its resilience, ensuring that the risk of threats compromising Europe’s electricity supply remains low and manageable.
Moving forward
Cybersecurity will be key for a successful green transition. As Europe moves towards a decarbonised future, the role of electricity will only expand, making power systems even more attractive targets.
Eurelectric plays a key role in advocating for stronger cybersecurity policies across the European energy sector. By working closely with policymakers and industry leaders, we help shape regulatory frameworks, promote best practices and drive investment in cyber resilience. Our organisation also facilitates knowledge sharing and collaboration, ensuring that Europe’s power sector remains protected against emerging cyber threats.
As cyber risks continue to evolve, Europe must remain vigilant. Only by integrating cybersecurity into every aspect of the green transition can the EU ensure a secure, sustainable and resilient electric future.
Disclaimer: This article is for informative purposes only and may not entirely reflect Eurelectric official positions. For formal positions, please consult our position papers here.