Trending Topics

Rafael Narezzi, CEO and Co-Founder of Centrii: “We need to grow the sector to meet energy demand, but that growth has to come with responsibility”
Battery storage is becoming an increasingly important part of the UK’s energy infrastructure, but the speed at which new assets are being connected is also creating a growing cybersecurity challenge. For Rafael Narezzi, CEO and Co-Founder of Centrii, the issue is not simply whether an individual battery site can be compromised. It is what happens when thousands of increasingly interconnected assets become part of the same system.
Narezzi has spent more than two decades working across technology, business and operational environments, including senior technology roles at CFP Energy and NextEnergy Capital / Wise Energy. At Centrii, he has focused that experience on the intersection of operational technology, cybersecurity and renewable energy. The company’s GRIDLOCK modelling estimates a 92% probability of a major attack on UK battery storage infrastructure within five years under current conditions, with a potential cost of up to £10 billion.
In this interview, Narezzi explains the assumptions behind that modelling and why the figure should be understood as a probability under current conditions rather than a prediction that an attack is inevitable. He also discusses how coordinated manipulation of battery output could affect grid stability, why cybersecurity needs to become part of the accountability model for new energy assets, and what he means by “cyber bankability” as boards and investors consider the financial consequences of an extended outage.
Your modelling suggests there is a 92% probability of a major attack on UK battery storage infrastructure within the next five years under current security practices. What are the biggest assumptions behind that figure, and what should readers understand about what a probability model can and cannot predict?
The prediction uses growth data from a public source, the Renewable Energy Planning Database: quarterly extract – GOV.UK. This data shows how many sites are operational, under construction, or in planning.
The key assumption is that the current trajectory of growth continues while security maturity and the regulatory environment remain broadly where they are today. In other words, we are not assuming that the sector suddenly becomes significantly more secure as it expands. That is an important caveat: the 92% figure is a modelled probability under current conditions, rather than a statement that an attack is inevitable.
There are several factors behind the model. First, the number of battery storage assets is increasing rapidly, creating a much larger and more distributed attack surface. Every new connection represents another potential entry point into an increasingly interconnected energy system. Second, security maturity across the sector is currently inconsistent and, in many cases, not keeping pace with the speed at which infrastructure is being deployed. Third, regulation and security requirements have not necessarily evolved at the same pace as the technology and the scale of deployment.
The decentralised nature of battery storage is particularly important. The risk is not simply that one individual site could be compromised; it is that a growing number of connected assets creates the potential for attacks to have consequences beyond a single installation. As the number of connections increases, so does the potential for correlated or systemic disruption. That is a central assumption underpinning GRIDLOCK.
You argue that an attacker would not necessarily need to damage batteries or take generation offline to cause serious disruption. Can you explain, in simple terms, how manipulating the balancing behaviour of thousands of batteries could destabilise the grid?
Take the New York blackout, where a surge in demand overwhelmed the grid and caused it to shut down, or the recent incident in Spain, where a sudden, uncontrolled loss of generation threw the grid’s balance out and brought it down. The same principle applies if you pump more power into the grid than it needs.
The UK grid has a ceiling, a kind of shock absorber, of around 1.8GW. If an attacker combines enough batteries, whether that’s many small ones or a few large ones, to exceed that ceiling and starts alternating their output, the resulting swings trigger the grid’s safety protections. As a precaution, those protections will shut down parts of the grid.
The report suggests that stronger security measures could effectively “buy time”, pushing the earliest likely attack window further into the future. Is buying time enough, or does the industry ultimately need to rethink how battery storage is architected and operated?
“Buying time” is important, but it cannot be the end goal. Stronger security controls can reduce the likelihood of an attack and give operators more time to detect, contain and respond to an incident, but ultimately the industry needs to think more fundamentally about how battery storage is designed, connected and operated.
A major part of that is accountability. We need to make asset owners and operators more accountable for the cyber resilience of the infrastructure they are putting onto the grid. At the moment, there can be a disconnect between the rapid deployment of new assets and the responsibility for managing the cyber risk those assets introduce into a much wider, interconnected energy system.
The battery storage industry already has very robust health and safety standards because we recognise that failures can have serious consequences for people, assets and the wider environment. Cybersecurity needs to be viewed through a similar lens. If a compromised battery storage asset, or a coordinated attack across multiple assets, has the potential to contribute to a significant grid disruption or blackout, should cybersecurity really be treated as a fundamentally different category of risk?
That doesn’t mean every cyber incident will lead to a blackout, but it does mean we need to consider the potential consequences in the same way we consider other forms of critical infrastructure risk.
Your findings put the cost of bringing the UK’s battery fleet up to IEC 62443 Security Level 2 at £400 million to £1 billion, compared with potential attack costs of up to £10 billion. If the business case appears so compelling, why hasn’t security investment kept pace?
We’re currently only using a basic standard configuration, covering the fundamentals. We’re not suggesting that’s the solution, but the minimum requirements today need to be raised, and regulators need to move towards properly understanding the risk.
Battery storage is expanding rapidly as grids become more dependent on renewable energy. Do you think cybersecurity and operational resilience are being treated as an afterthought in that expansion, and where are the biggest gaps today?
We need to grow the sector to meet energy demand, but that growth has to come with responsibility. Today, sites are being connected without that responsibility in place, and that’s the gap we’re highlighting. Anything that connects to the grid is a point of risk, regardless of whether it’s small, medium or large.
Smart Secure Electricity Systems (SSES) is coming soon, which will start to shape the model going forward. In practice, this means that to energise a site, operators will need to hold the relevant licence.
You say that cyber risk is already understood at board level, but that organisations struggle to put a meaningful financial figure on it. How can modelling like GRIDLOCK change the conversation between cybersecurity teams, operational leaders and the board, and what decisions do you hope it will lead to?
The aim of GRIDLOCK is to move cyber risk out of the purely technical conversation and translate it into something that operational leaders, finance teams and boards can make decisions around: financial and operational exposure.
Alongside traditional cyber risk KPIs, we break the risk down by asset type – wind, battery, solar and so on – because each has different risk characteristics, production profiles and financial consequences. Understanding those differences allows organisations to move beyond a single, headline cyber-risk score and identify where their most material exposures actually sit.
We also need to look at the commercial reality around each asset. That includes electricity price exposure, power purchase agreements (PPAs), contractual obligations and the financing structure behind the project. A site doesn’t operate in isolation: it has revenues that need to be generated, contracts that need to be honoured and, often, significant debt that still needs to be serviced even when the asset isn’t operating.
This is where what we call “cyber bankability” becomes important. If a site is unable to deliver the output it was expected to deliver because of a cyber incident, what happens to the project’s ability to meet its financial obligations? If a battery storage site is offline for a month, for example, the loan repayments don’t stop simply because the asset isn’t generating revenue. The question for an owner, lender or investor becomes: how resilient is the financial model to a cyber-driven loss of availability?
That changes the conversation at board level. Instead of asking simply, “Are we secure enough?”, the board can ask: “What is our potential financial exposure if this asset is unavailable for a week, a month or longer? What would a major cyber incident mean for our revenues, contractual commitments, debt servicing and ultimately the viability of the project?”
That’s the kind of decision-making we want GRIDLOCK to enable. It can help boards and asset owners understand where investment in cyber resilience is proportionate to the potential financial and operational loss, and help them prioritise the assets where additional protection could have the greatest impact.
More great interviews
- Nita Patel, CMO of Lickly: “Marketing doesn’t have an information problem. It has a decision problem.”
- Rob Harrison, SVP Product Management at Sophos: “The use of AI voice deepfakes is by far the most concerning case”
- Crystel Robbins Rynne, CEO at HRLocker: “Not everything needs AI. Sometimes the right answer is to leave the process alone.”
