Skip to navigation Skip to main content Skip to footer

Thousands of wind and solar systems exposed to cyber risk

08 October 2026

Research by Modat and the NCSC has revealed that 8,547 systems associated with wind and solar farms are vulnerable to cyberattacks, including 141 in the Netherlands.

Floris Dankaart-Chang, Associate Director, Portfolio Strategy at NCC Group, commented:

 

"Research by Modat and the NCSC has revealed that thousands of systems at wind and solar farms are vulnerable to cyberattacks. Of the 8,547 vulnerable systems, 141 are located in the Netherlands. 'Duizenden systemen wind- en zonneparken zijn kwetsbaar voor cyberaanvallen' - Tweakers
 
The research makes it clear that critical infrastructure is at risk of being hit by a cyberattack. An important caveat, however, is that most of the systems identified are login pages and therefore not yet directly accessible control panels. Nevertheless, this offers little reassurance. In the attack on more than 30 Polish wind and solar farms in December 2025, attackers gained entry precisely via these kinds of access points. Without MFA and additional security measures, such an access point remains a door with a very poor lock.
 
Operators of wind and solar farms are not always aware of the risks posed by this exposure. Particularly when installers, suppliers and maintenance contractors need easy access to carry out their work, vulnerable entry points can inadvertently arise. Anyone who focuses solely on their own network can easily overlook these access routes.
 
That is why it is important to also map out all external access to OT networks and critical infrastructure. Remove control interfaces from the public internet, ensure that management takes place exclusively via a secure and monitored access route with MFA, and, of course, replace all default passwords. Once these basics are in place, 24/7 monitoring is a logical next step. After all, what researchers can find, attackers can find too."


 
"Uit onderzoek van Modat en het NCSC blijkt dat duizenden systemen wind- en zonneparken zijn kwetsbaar voor cyberaanvallen. Van de 8547 kwetsbare systemen bevinden 141 zich in Nederland. 'Duizenden systemen wind- en zonneparken zijn kwetsbaar voor cyberaanvallen' - Tweakers
 
Het onderzoek maakt duidelijk dat kritieke infrastructuur risico loopt om getroffen te worden door een cyberaanval. Een belangrijke nuance is echter dat de meeste gevonden systemen inlogpagina’s zijn en dus nog geen direct toegankelijke bedieningspanelen. Toch biedt dat weinig geruststelling. Bij de aanval op ruim 30 Poolse wind- en zonneparken in december 2025 kwamen aanvallers juist via dit soort toegangspoorten binnen. Zonder MFA en aanvullende beveiligingsmaatregelen blijft zo’n toegangspoort een deur met een wel erg matig slot.
 
Exploitanten van wind- en zonneparken zijn zich niet altijd bewust van de risico’s van deze blootstelling. Zeker wanneer installateurs, leveranciers en onderhoudspartijen eenvoudig toegang moeten krijgen om hun werk te kunnen doen, kunnen onbedoeld kwetsbare ingangen ontstaan. Wie alleen naar het eigen netwerk kijkt, ziet deze toegangsroutes gemakkelijk over het hoofd.
 
Daarom is het belangrijk om ook alle externe toegang tot OT-netwerken en kritieke infrastructuur in kaart te brengen. Haal bedieningsinterfaces van het publieke internet, laat beheer uitsluitend verlopen via een beveiligde en gemonitorde toegangsroute met MFA en vervang uiteraard alle standaardwachtwoorden. Wanneer die basis op orde is, is 24/7 monitoring een logische volgende stap. Want wat onderzoekers kunnen vinden, kunnen aanvallers ook vinden." 

 

Floris Dankaart-Chang biography

Floris Dankaart-Chang is Associate Director, Portfolio Strategy at Fox-IT (an NCC Group subsidiary), owning and leading the global portfolio strategy, roadmap, and execution for NCC Group’s Managed Extended Detection & Response (MXDR) services.

 

Floris is based at Fox‑IT in the Netherlands, operating as part of the Fox‑IT senior leadership team to support enterprise clients with proposition, service, and technical expertise. He is responsible for aligning MXDR with adjacent cyber security services, driving market differentiation, product evolution, pricing models, and performance metrics across a highly competitive market.

 

In previous roles, Floris was responsible for NCC Group's Managed Extended Detection & Response service based on Splunk technology as well as the Managed Canary (Honeypot) and GMS OT services.

 

 

Contact

NCC Group Logo Icon for Author Bio

NCC Group Press Office

All media enquires relating to NCC Group plc.

press@nccgroup.com

+44 7721577574