Technology
Article 6 of 13 · Technology and AICybersecurity in energy systems: a guide for businesses
Direct answer
Cyber security in energy systems means protecting energy installations and their digital control systems against attacks and misuse. This includes inverters, batteries, charging stations, building management systems and energy management systems that can be reached via the internet. Because these systems control physical processes, a digital break-in can lead to outages, damage or manipulation of your energy supply.
- Clear definition
- Data-driven assessment
- Risks and opportunities visible
- Practical next steps

Cybersecurity in energy systems: scattered information versus Energy Intelligence
A building management system that controls the climate installation, an inverter that the installer reads remotely, a charging plaza with an online management portal: an average business premises contains dozens of digitally connected energy components. That is convenient for management and maintenance, but every connection point is also a possible entrance for malicious actors. For facility managers and business owners, digital security has therefore become part of the energy supply itself. New legislation also sets increasingly clear requirements.
- Energy installations are increasingly connected to the internet for monitoring and control, which also makes them reachable for attackers.
- The Dutch Cyber Security Act (Cyberbeveiligingswet), the national implementation of the European NIS2 directive, applies from 15 August 2026 and obliges organisations in sectors including energy to manage risks and report incidents.
- Basic measures such as network segmentation, timely updates, strong access management and clear supplier agreements considerably reduce the risk.
Insight
Traditional approach
Information is scattered across portals, documents, invoices or separate spreadsheets.
Modern approach
Data, context and interpretation are brought together into a clear decision picture.
Decision-making
Traditional approach
Choices are made based on averages, assumptions or occasional analyses.
Modern approach
Scenarios, KPIs and current measurement data make the trade-off more concrete and repeatable.
Follow-up
Traditional approach
Actions often stay non-committal or disappear into separate reports.
Modern approach
Follow-up actions, monitoring and reporting are linked to the same energy data.
Why are energy systems a target?
Energy is critical infrastructure: when the power fails, a business or even a region comes to a standstill. That makes the sector attractive to criminals and state actors, as the European cyber security agency ENISA also observes. In addition, many control systems, known as operational technology or OT, were designed for reliability rather than security. Older communication protocols often do not verify who is sending a command. Installations also run on outdated software for years, because updates can mean downtime. Now that these systems are increasingly linked to office networks and the internet, an attacker can eventually reach the installation itself through an ordinary phishing email.
- Energy outages have a direct physical and financial impact, which makes extortion attractive
- Outdated OT protocols often lack authentication and encryption
- Links between office IT and installations enlarge the attack surface
- Suppliers and installers often have permanent remote access for maintenance
- Unpatched systems remain vulnerable to known attack methods for years
Which rules apply from 2026?
The European NIS2 directive obliges member states to set cyber security requirements for essential and important sectors, including energy. The Netherlands implements this through the Cyber Security Act (Cyberbeveiligingswet). The act was adopted by both chambers of parliament in 2026 and applies from 15 August 2026. Organisations covered by the act must register in the national entity register, carry out a risk analysis and take appropriate security measures. They must report significant incidents to the Computer Security Incident Response Team and the supervisory authority, in any case within 24 hours of discovery. The board is ultimately responsible and must demonstrably understand cyber risks. Even organisations outside the act will notice the effects: large customers pass the requirements on to their suppliers.
- Registration duty in the entity register via the Dutch NCSC
- Duty of care: risk analysis and appropriate measures for network and information systems
- Reporting duty: significant incidents must be reported in any case within 24 hours
- Board members are ultimately responsible and follow appropriate training
- For securing industrial automation, the IEC 62443 standard also exists
What can you do yourself?
Start with insight: map which energy and building systems are digitally connected and who has access to them. Then separate networks, so that an infection in the office does not spread to the installation. Limit remote access to what is genuinely needed and secure that access with strong authentication, such as two-step verification. Agree with installers and suppliers how they deliver updates and how their maintenance access is secured, and record this in the contract. Finally, monitor for unusual behaviour, so that you notice an intrusion early. The Digital Trust Center, now part of the Dutch NCSC, offers free tools for this, such as a security check for process automation.
- Take stock of all connected energy components and who has access to them
- Segment networks: separate office IT from installations and control systems
- Use strong authentication and limit remote access for suppliers
- Make contractual agreements about updates and maintenance access
- Monitor systems for unusual behaviour to detect intrusions early
Curious what this looks like with your own data?
In a no-obligation call, a specialist looks at your meters, sites and energy questions with you. Response within one business day.
Search the knowledge base
Find the answer to your question.
Search using your own words. Abbreviations and spelling variants are recognised, so EMS also finds the articles on energy management systems.
Topic