taiyangnews 04月29日 22:18
EU Solar PV Industry Calls For Cybersecurity Measures
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

欧盟光伏产业协会SolarPower Europe发布报告,呼吁政策制定者和监管机构针对太阳能光伏系统制定并强制执行行业特定的网络安全控制措施,包括限制欧盟境外通过逆变器对太阳能光伏系统进行远程访问和控制。报告强调,现有网络安全框架未能充分解决分布式能源带来的独特挑战,建议欧盟采取“量身定制的方法”应对这些挑战。网络攻击对仅仅3吉瓦的能源发电就可能严重影响欧洲电网,因此解决电网相关设备中的网络安全漏洞至关重要。

💡欧盟光伏产业呼吁针对太阳能光伏系统制定行业特定的网络安全控制措施,特别是限制欧盟境外通过逆变器进行远程访问和控制,以应对日益增长的网络安全风险。

🛡️现有网络安全框架(如NIS2和NCCS)主要针对大型集中式发电厂,未能充分覆盖屋顶太阳能等分布式能源,这些系统更像物联网设备,传统工业网络安全措施难以有效应用。

🚨报告指出,网络攻击对仅仅3吉瓦的能源发电就可能严重影响欧洲电网,多个制造商控制的装机容量远超此数,在评估的14个风险领域中,多个领域被评为高风险或关键风险,凸显了采取行动的紧迫性。

🌐网络安全漏洞可能由犯罪分子或国家行为者引发,西班牙和葡萄牙在2025年经历的大规模停电事故,尽管原因尚未最终确定,但也突显了网络安全的重要性。

As digitalization takes over the solar power systems, the European Union (EU) solar PV industry demands that policymakers and regulators develop and mandate industry-specific cybersecurity controls. This includes limiting remote access and control of the bloc’s solar PV systems from outside the EU via the inverter.  

These are some of the recommendations made by a DNV-written and SolarPower Europe (SPE) commissioned report titled Solutions for PV Cyber Risks to Grid Stability. The association previously published a position paper in July 2024, demanding a cybersecurity standard for the secure operation of solar components like inverters and distributed energy resources (see SolarPower Europe Calls For Focus On Cybersecurity).  

The release of this report coincides with the major power outage experienced in Spain and Portugal on April 28, 2025. While the jury is still out on what caused this massive blackout, possibly a ‘rare atmospheric phenomenon’, these episodes can also be caused by criminals and nation-state attackers. Hence, these reinforce the fact that cybersecurity needs to be dealt with immediately. 

According to the report writers, there are broad regulatory frameworks such as the Network and Information Security Directive (NIS2) and the Network Code on Cyber Security (NCCS) among others that cover traditional energy infrastructure. This includes large, centralized power plants. However, these do not necessarily address the distributed energy sources (DER) — such as rooftop solar — that are important, as these reduce dependence on the grid and on single high-impact targets.   

Though the bloc has a Cyber Resilience Act (CRA) that applies to all products with digital elements sold within the EU and also applies to installers, the writers believe this is limited in addressing the full end-to-end infrastructure.  

Many rooftop PV systems and DERs are managed by homeowners or small businesses, making them too small to be classified as critical infrastructure usually required to be managed by utilities. These systems largely resemble Internet of Things (IoT) devices rather than centralized energy infrastructure. Therefore, as the writers point out, traditional industrial cybersecurity measures often don't apply.  

They recommend that the EU bring in ‘tailored approaches’ to address the unique cybersecurity challenges posed by these systems in the EU. 

A cyberattack on merely 3 GW of energy generation could seriously affect Europe’s power grid, according to the report. More than a dozen manufacturers control far more than this installed capacity currently. Out of the 14 risk areas evaluated in the report, 5 areas are categorized as medium risk, 6 areas are high risk, and 3 areas are critical risk. 

Such factors make it imperative that policymakers take action to address cybersecurity gaps in grid-relevant devices, it adds. 

“Like any technological revolution, digitalisation presents incredible opportunity, for example, energy system cost savings of €160 billion per year. It also comes with new challenges, like cybersecurity,” said SPE CEO Walburga Hemetsberger. “We didn’t need anti-virus protection for a typewriter – but we do need it for our laptops. As a responsible, forward-looking sector, we have mapped the cybersecurity challenge, and we’re rising to meet it with clear, comprehensive solutions.” 

The complete report is available for free download on SPE’s website.  

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

光伏 网络安全 欧盟 分布式能源 SolarPower Europe
相关文章