Beyond Compliance: Building resilient solar security

In recent years, energy companies have been under intense pressure to improve their cybersecurity posture as existing threats and government entities increasingly elevate expectations from energy producers of all sizes. 

Solar sites in particular face significant risk because many are operated remotely. These facilities often have no operators on site, maintained instead by personnel in remote operations control centers that may be hundreds or thousands of miles away. Remote configuration and intermittent oversight make these facilities perfect targets for cybersecurity bad actors (Figure 1).

unlock

 

Figure 1: Many solar sites face significant cybersecurity risk as they are operated remotely. 

Such cyberattacks on energy company targets continue to increase in frequency with each passing year, evidenced by a recent report demonstrating that data breaches have impacted 90 percent of the largest energy companies globally, including all top 10 companies in the United States[1]. One key response to these breaches has been the evolution of North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) reliability standards. 

While a strong cybersecurity posture should be any solar facility’s goal, NERC CIP standards have created deadlines that accelerate the need for compliance. Companies must bring their systems up to date by October 2030 at the latest, with some needing to comply as early as 2028. 

Bringing solar facilities in line with NERC CIP standards will take time, and the process can often be complex, costly, and time-consuming. To help navigate this challenge, many organizations are collaborating closely with an expert industry partner as a critical enabler of success.

Strong cybersecurity delivers value

Many energy companies are building or acquiring solar plants to fill out their energy portfolio as both an added source of revenue and increased production, and to meet increasing sustainability goals. Whether these organizations acquire existing assets, pursue greenfield projects, or both, the focus is return on investment (ROI). 

In many cases, cybersecurity is seen as a high expense with little acknowledgement of its ROI. But a strong cybersecurity posture can deliver significant ROI through incident avoidance; properly implemented cybersecurity solutions also reduce overhead costs. 

Solar sites can no longer rely on security by obscurity. Today, they are as critical to the energy infrastructure as traditional generation facilities, so it is typically a matter of when they will be targeted by cyber attackers, not if. The fallout from a cybersecurity incident can have a significant negative impact on revenue generation. In fact, the average data breach in the energy sector now costs companies over $5 million, significantly more than the cross-industry average[2]. A cybersecurity incident like a data breach can also become a public event very quickly, leading to a loss of reputation that can have costly consequences for competitive advantage.

Yet even without an incident, increasing regulation means organizations can be subject to penalties and fines for not proving their ability to meet standards like NERC CIP. As companies calculate the potential revenue lost from any of these incidents, the ROI of a strong cybersecurity investment rapidly increases.

Renewables introduce unique challenges

Solar plants have many components (inverters, trackers, balance of plant technologies) all of which must be accounted for in a cybersecurity plan. Typically, each solution provider architects its own segment of the overall network and system when installing components. Often, the solutions do not integrate seamlessly with the rest of the system, and they rarely integrate easily with the owner’s cybersecurity platforms and processes. A strong network security posture can help mitigate the risks stemming from this supply chain — a critical competency, as in 2023 alone, 264 reported breaches in the energy sector were linked to third-party issues[3] (Figure 2).

secure by design

 

Figure 2: A strong cybersecurity plan with segmented networking should be implemented at every layer of a solar plant across the entire system. 

In addition, a complex web of custom-engineered connections between components can dramatically limit visibility into the system. Unraveling that web is complicated, requiring a breadth of knowledge and experience spanning both information technology (IT) and operational technology (OT). For teams short on expert personnel with decades of industry expertise, navigating that OT/IT convergence can take many hours of trial and error. 

Implementing cybersecurity solutions by trial and error comes with its own set of challenges. Meeting NERC CIP standards is a very technical process and the stakes are high. Companies can easily waste a great deal of capital, or even potentially introduce new threat vectors, searching for a solution. Moreover, if they are unsuccessful, the results of a failed audit could mean financial penalties, plus additional costs to reimplement effective solutions.

Collaboration drives success

Working closely with an expert automation solutions partner can help reduce much of the complexity of implementing cybersecurity. When teams work closely with a solution provider with decades of expertise in both the energy industry and cybersecurity —independent of OEMs — they gain access to both deep knowledge and close partnerships across a wide variety of applicable technologies. This knowledge not only helps organizations more easily meet compliance goals, but also helps them establish best practices that go beyond the regional scope of standards organizations like NERC, delivering value around the globe and helping future-proof investments. 

As teams collaborate with their expert providers, everyone brings their shared expertise together to architect a system that is secure and protected as well as flexible and customized to the company’s individual needs. An expert partner will help organizations embrace a cybersecure-by-design approach, engineering and implementing solutions correctly the first time, while ensuring suppliers meet cyber requirements. They can also help deliver more cost-effective and long-term solutions, particularly in the case of retrofits, where complexity increases dramatically.

In addition, collaborating with an expert partner opens the door to ongoing support options. Cybersecurity technology is not a set-and-forget solution; it requires ongoing maintenance and updates to stay relevant because existing threats evolve and new threats emerge. An expert partner can help maintain a strong cybersecurity posture, empowering the organization to focus its efforts on energy production and management instead of security. 

Ready for today and tomorrow

NERC CIP standards help define a pathway to a more cybersecure posture for all energy companies — even ones with challenging architectures like solar facilities. The path to meeting NERC CIP standards is long and complex, so starting today is critical. Moreover, because minimum requirements tend to trickle down between the standards levels, it is a good idea not just to meet today’s standards, but to exceed them to prepare for potential future requirements — one more reason why collaborating with an expert automation solutions provider is a key strategy for cybersecurity success.

 

 

Nicholas Janouskovec Nicholas Janouskovec is the global cybersecurity product manager for Emerson’s Power and Water Solutions business. He is responsible for setting the direction of Emerson's global security solutions business including establishing product and service roadmaps and providing sales support. Nicholas received a Bachelor of Science from Appalachian State University (majoring in Political Science and minoring in Business Administration), a master’s from Appalachian State in Public Administration, and is a certified Global Industrial Cybersecurity Professional. 

Emerson | www.emerson.com

 


[1] https://www.ibm.com/think/insights/third-party-breaches-top-global-energy-companies

[3] https://www.ibm.com/think/insights/third-party-breaches-top-global-energy-companies

 


Author: Nicholas Janouskovec
Volume: 2026 March/April