Centrii models 92% BESS attack probability in five-year UK window
Centrii, a cyber and operational risk firm serving energy infrastructure owners, has published GRIDLOCK, a Monte Carlo risk assessment modelling the probability and cost of a coordinated cyberattack on UK battery energy storage systems (BESS) before 2031. The headline finding is stark: under industry-average security practices, the report puts the probability of a major attack on battery storage infrastructure at 92% within five years, with financial damage estimated at between £2bn and £10bn.
The report, which ran 10,000 simulations across three security postures, argues that the attack mechanism does not require physical damage. Instead, a bad actor could desynchronise the balancing layer, forcing batteries to charge or discharge simultaneously or delaying their response to grid-frequency signals, triggering a cascading blackout within two minutes. The company says compromising roughly 29% of UK national capacity, around 400 units, could be sufficient to cause a nationwide outage affecting the entire population.
The risk calculus
The modelling suggests that security investment materially changes the picture. Under a voluntary-improvement scenario, with gradual and uneven adoption of better practices, the attack probability falls to 78%. Under mandatory adoption of IEC 62443 certification, an international industrial cybersecurity standard, combined with regular attack-readiness drills, it falls further to 61%. Crucially, each step also pushes the earliest likely attack window back: from 2027-28 under baseline conditions to 2029-31 under the most rigorous posture.
Centrii estimates that bringing the UK BESS fleet to IEC 62443 Security Level 2 would cost between £400m and £1bn across the national fleet, implying a return on proactive security investment of roughly five to 25 times in avoided damage. The company runs equivalent modelling for the ERCOT grid in Texas, where compromising 5.4% of the battery fleet, around 1,500 units, is assessed as sufficient to destabilise the grid, with modelled economic damage of between $12bn and $65bn.
Rafael Narezzi, co-founder and chief executive of Centrii, framed the board-level case directly: "Security spending in operational technology is rarely treated as return-generating, because its value shows up in an event that does not happen. This modelling makes that value visible and measurable."
Market and policy context
The report arrives as UK battery storage capacity is expanding rapidly. RenewableUK figures cited by Centrii indicate the UK government has estimated between 23 GW and 27 GW of BESS will be required by 2030, up from approximately 4.5 GW in 2024. That growth trajectory makes the attack surface considerably larger and the systemic consequences of a successful exploit considerably more severe.
Modern battery fleets are typically managed remotely through cloud-based platforms, a configuration that improves operational efficiency but broadens cyber exposure across cloud, remote-access and supply-chain attack paths. The release draws on two recent European events as illustrative context: a reported December 2025 attempt by state-sponsored actors to destabilise Polish grid infrastructure by rapidly cycling wind turbine output, and the April 2025 Iberian grid collapse, which authorities attributed to technical rather than adversarial causes, that left parts of Spain and Portugal without power for up to ten hours.
The policy backdrop is shifting. The EU's NIS2 Directive extends mandatory cybersecurity obligations to energy operators, and the UK's own Network and Information Systems regulations are under active review. Centrii, which recently rebranded from Cyber Energia, sells a software-as-a-service platform providing real-time visibility into operational technology environments and supports clients navigating NERC CIP compliance in North America. The company is headquartered in Houston and London.
GRIDLOCK is described as a public-facing summary of a peer-reviewed methodology. The underlying attack mechanism is said to be validated in a paper published in Energy Informatics in March 2025. All figures in the report are modelled projections, not observed incidents.