Summary
- Centrii's GRIDLOCK model estimates a 92% five-year probability of a major UK BESS cyberattack under its baseline security assumptions.
- The analysis estimates a single severe UK event could cause £2bn to £10bn in losses, but the figures are model outputs rather than observed probabilities.
- Britain's planned expansion from around 5GW of battery storage today towards 23–27GW by 2030 increases the operational importance of remote battery-control security.
A new risk model estimates that a coordinated cyberattack against UK battery energy storage could cause losses of between £2 billion and £10 billion, as the electricity system becomes increasingly dependent on remotely managed storage for grid balancing.
London-based Centrii has published the figures in GRIDLOCK, an analysis based on 10,000 Monte Carlo simulations across three assumed security postures. Under its baseline scenario, representing what it describes as industry-average practices, the model produces a 92% probability of a major attack within five years.
That figure is a modelled risk estimate rather than an observed attack rate or independently established prediction. Centrii says the probability falls to 78% where voluntary security improvement is introduced gradually and unevenly, and to 61% under a more rigorous scenario built around IEC 62443 certification and attack-readiness exercises.
The company estimates that compromising around 29% of the UK battery fleet represented in the model — approximately 400 units — could produce a grid disturbance capable of escalating into a nationwide outage. It places the economic loss from one such event between £2 billion and £10 billion.
The underlying technical concern is not confined to Centrii’s modelling. Peer-reviewed research published in Energy Informatics last year examined cloud-controlled battery energy storage used for frequency balancing and found that cyberattacks affecting control communications and battery behaviour could threaten grid stability. That work demonstrated the feasibility of the attack class, but it did not independently validate Centrii’s probability, fleet-compromise, or financial-loss estimates.
Battery storage is becoming a larger part of Britain’s electricity system. The government’s Clean Power 2030 programme originally identified 23GW to 27GW of battery capacity as the range required by 2030, up from around 4.5GW in 2024. A more recent government roadmap says more than 5GW is now on the grid, with substantially more capacity holding Capacity Market agreements or planning approval.
That growth changes the consequences attached to the digital systems controlling battery fleets. Grid-scale batteries are designed to absorb or release power rapidly, providing flexibility when renewable generation and demand move out of balance. Many installations depend on networked management platforms, remote-access systems, cloud services, and third-party components to coordinate that behaviour.
Rafael Narezzi, co-founder and chief executive of Centrii, said the model focuses on coordinated manipulation rather than physical battery damage. “A coordinated attack does not need to stop generation to cause a blackout. It only needs to desynchronise the balancing layer, forcing batteries to charge or discharge together, or delaying how they respond to grid signals.”
Recent European electricity incidents show why disturbances in a tightly balanced system can propagate quickly, although they should not be conflated with the attack scenario in GRIDLOCK. The April 2025 blackout in Spain and Portugal was attributed by ENTSO-E to interacting technical and operational factors, including voltage-control weaknesses, output reductions, and cascading generation disconnections — not a cyberattack.
Poland has separately experienced destructive cyber activity against energy infrastructure. CERT Polska said coordinated attacks in December 2025 targeted more than 30 wind and photovoltaic installations and combined heat and power facilities. The renewable sites lost communications with distribution operators, but electricity generation continued and grid stability was not affected.
Those distinctions are important because GRIDLOCK is a forward-looking scenario model. Its value depends on the assumptions used for attacker capability, compromise rates, fleet architecture, security controls, and financial consequence. The output should therefore be treated as a quantified risk case rather than evidence that a nationwide battery attack is likely to occur at the stated rate.
Even with that qualification, Britain’s rapid storage build-out is creating more operational dependency on digitally controlled energy assets. As battery fleets become a larger balancing resource, cyber risk increasingly sits alongside connection policy, market design, and physical engineering in determining how resilient that capacity will be.





