What is solar inverter cybersecurity?
Solar inverter cybersecurity is the protection of the grid-connected power electronics in photovoltaic systems, including their firmware, communication modules and cloud portals, against abuse that would let an attacker switch off, manipulate or pivot through solar generation. An inverter converts the direct current from solar panels into alternating current and decides how much power flows into the grid. Because most inverters talk to a vendor portal over Wi-Fi or a plug-in dongle, a house with solar panels is effectively a small piece of OT connected to the internet. Multiply that by millions of installations and it becomes a question of grid stability and critical infrastructure.
🧠 Why is a solar inverter operational technology?
An inverter is not an ordinary consumer IoT gadget like a smart bulb. It is a controller that regulates physical energy flows within milliseconds and has to comply with the grid code: it tracks voltage and frequency, disconnects during faults and can curtail its output. At the same time it is tied to the manufacturer’s cloud platform, which can change settings and push firmware updates remotely.
| Characteristic | Classic OT (PLC, RTU) | Solar inverter |
|---|---|---|
| Physical impact | Controls a process | Controls power fed into the electricity grid |
| Location | Behind fences, in a control room | In the loft or meter cupboard of a private home |
| Management | Dedicated OT team | Often nobody; the installer or vendor via the cloud |
| Connectivity | Segmented network | Home Wi-Fi, 4G dongle or direct internet |
| Volumes | Tens to thousands per company | Millions per country, often from a handful of brands |
That last row is the crux: a single flaw in a vendor’s cloud platform can reach hundreds of thousands of devices at once. It is supply chain risk in its purest form.
📊 How many solar inverters are there in the Netherlands?
According to Statistics Netherlands (CBS), the country had almost 3.3 million solar PV installations at the end of 2024, with 28.6 gigawatt-peak of panels and 25.6 gigawatts of inverter capacity. Homes accounted for roughly 40 per cent of panel capacity; businesses and solar parks for the rest. On a sunny spring afternoon, solar PV therefore covers a large share of Dutch electricity demand.
For comparison, the Continental European grid is designed to absorb the sudden loss of 3,000 megawatts, the so-called reference incident, at a nominal frequency of 50 Hz. Anyone able to control even a fraction of Europe’s inverters at the same moment could, in theory, exceed that margin. The market is also concentrated: a large share of the inverters installed in Europe comes from Chinese manufacturers such as Huawei, Sungrow and Growatt. In 2026, MEP Bart Groothuis put the Chinese share of imported inverters at around 80 per cent; precise national figures are not published.
🔍 Which vulnerabilities and incidents are known?
- Horus scenario (2017) — Dutch researcher Willem Westerhof found 17 vulnerabilities in SMA inverters, 14 of which received CVE identifiers. He showed how an attacker could switch off or oscillate large numbers of inverters to unbalance the grid.
- RDI investigation (May 2023) — the Dutch Authority for Digital Infrastructure tested nine inverters from eight manufacturers; none met the cybersecurity standard used, ETSI EN 303 645. Some inverters broadcast a permanent Wi-Fi hotspot protected by a default password that could be found in manuals online.
- DIVD disclosures (2024–2025) — the Dutch Institute for Vulnerability Disclosure coordinated zero-days in the Enphase IQ Gateway and flaws in consumer inverters discovered by ENCS.
- SUN:DOWN (March 2025) — Forescout published 46 new vulnerabilities in Sungrow, SMA and Growatt products, including takeover via the cloud platform and hard-coded credentials.
- Internet exposure (May 2025) — Forescout counted almost 35,000 solar devices with an exposed management interface, 76 per cent of them in Europe; see also Internet-Exposed OT.
- Undocumented radios (May 2025) — Reuters reported that US investigators had found undocumented communication components, including cellular radios, in Chinese inverters and batteries. No manufacturers were named. Such a hidden communication channel bypasses the owner’s firewall entirely.
⚡ What attack scenarios threaten the power grid?
The most dangerous scenario is not one hacked rooftop but coordinated abuse at scale. An attacker who compromises a cloud platform or a shared password can switch off thousands of inverters simultaneously, make their output swing, or alter the frequency and voltage protection settings. The resulting frequency deviations must be absorbed by grid operators using reserve capacity, and a large enough swing can trigger cascading disconnections. Hijacked inverters can also serve as a foothold into the home or corporate network, or be recruited into a botnet. State-sponsored groups such as Sandworm have already attacked power grids with Industroyer, while Volt Typhoon focused on pre-positioning inside US infrastructure.
🏛️ Which Dutch and EU rules apply to inverters?
| Rule | What it covers | Applies since |
|---|---|---|
| RfG network code (Regulation (EU) 2016/631) | Technical connection requirements; Dutch grid operators publish a list of compliant inverters | 27 April 2019 |
| RED delegated act (EU) 2022/30 with EN 18031 | Baseline security for wireless devices: no universal default passwords, secure updates | 1 August 2025 |
| Cybersecurity Act (NIS2) | Duty of care and incident reporting for energy companies and large producers; private installations are out of scope | 15 August 2026 |
| Network Code on Cybersecurity (NCCS, Regulation (EU) 2024/1366) | Cybersecurity for cross-border electricity flows | fully by around 2028 |
| Cyber Resilience Act | Secure by design, vulnerability handling and updates for all products with digital elements | 11 December 2027 |
Since 1 August 2025 the Dutch Authority for Digital Infrastructure (RDI) has checked whether wireless-enabled inverters meet the RED cybersecurity requirements, sampling devices for laboratory testing. In a parliamentary letter of November 2025 the government stressed that hidden functionality to switch devices on or off remotely is already prohibited, and announced that ministers should be able to exclude suppliers as a last resort. In September 2026 the Minister for Climate and Green Growth reported that NEN is developing Dutch technical agreements for inverters, home batteries, charge points, heat pumps and home energy management systems. At EU level, the Commission proposed a revision of the EU Cybersecurity Act (Regulation (EU) 2019/881) in January 2026, including a mechanism to designate high-risk suppliers. Separately, from 1 November 2026 EU-funded energy projects must exclude inverters from high-risk suppliers or progressively replace them. Lithuania moved first: a law adopted in November 2024 bars manufacturers from countries deemed a security threat, China among them, from remotely managing installations above 100 kW.
🔐 How do you secure a solar inverter in practice?
| Role | Key measures |
|---|---|
| Homeowner | Change the default password, put the inverter on a separate guest network or IoT network, install updates, disable features you do not use |
| Installer | Hand over unique passwords, document which cloud link is active, choose inverters with demonstrable EN 18031 or CRA conformity, never open ports to the internet |
| Solar park or commercial roof owner | Apply segmentation with a dedicated OT zone, restrict remote access to a managed VPN with MFA, monitor traffic to vendor clouds, make patch management a contractual obligation |
For larger installations a fixed approach works well:
- Inventory every inverter, data logger and dongle, including firmware versions and cloud connections.
- Establish who can switch remotely: the manufacturer, installer, energy supplier or aggregator.
- Prefer local control through your own power plant controller or SunSpec Modbus where possible, and make the cloud read-only or disable it.
- Segment and filter: allow outbound traffic only to known destinations, and no inbound connections.
- Monitor and rehearse: log configuration changes and decide what you will do if the vendor itself is compromised.
Designing according to Cyber-Informed Engineering adds one more question: which physical limits must the inverter never exceed, whatever the software tells it?
❓ Frequently asked questions
Can hackers switch off my solar panels?
Yes, if the inverter has a weak or default password, is reachable from the internet, or is managed through a vulnerable cloud platform. An attacker can then shut the inverter down or change its settings. A unique password, regular updates and a separate network greatly reduce that risk.
Are Chinese inverters less secure than European ones?
Vulnerabilities occur in inverters of every origin; European brands such as SMA have also had serious flaws. The additional risk with Chinese inverters lies mainly in the possibility that a manufacturer intervenes remotely under pressure from a foreign government. That is why the EU and member states focus on restricting remote access by high-risk suppliers.
Does my home installation fall under NIS2 or the Dutch Cybersecurity Act?
No, private solar PV installations are not covered by NIS2 or the Dutch Cybersecurity Act. That law targets energy companies, grid operators and large producers. Your inverter is, however, subject to product rules: the RED cybersecurity requirements and, from December 2027, the Cyber Resilience Act.
Should I disable my inverter’s cloud connection?
That depends on what you need. Without the cloud you may lose app monitoring and automatic updates, but you shrink the attack surface considerably. A middle ground is local monitoring via the inverter’s own network interface, combined with manual or controlled firmware updates.
What does the RDI do about inverter security?
The Dutch Authority for Digital Infrastructure (RDI) carries out market surveillance of radio equipment, including inverters with Wi-Fi or cellular connectivity. Since 1 August 2025 the RDI has checked whether such inverters meet the RED cybersecurity requirements. Non-compliant products can be withdrawn from the market.
What was the Horus scenario?
The Horus scenario is a 2017 study by Dutch security researcher Willem Westerhof into vulnerabilities in SMA solar inverters. He described how an attacker could unbalance the European power grid by manipulating inverters en masse. The research was the first to put solar inverter cybersecurity firmly on the public agenda.
📌 In summary
Solar inverters are grid-connected OT devices that are reachable by the million through vendor clouds, so a single vulnerability or a single malicious supplier can affect grid stability. Rules such as the RED, the Cyber Resilience Act and the Dutch Cybersecurity Act raise the bar, but owners and installers still have to get passwords, segmentation, updates and remote access in order themselves.
