Four hundred battery units is the number a modelled grid attack would need

Technology and AI

Four hundred battery units is the number a modelled grid attack would need

By Staff Writer  |  3 September 2026

Long parallel rows of white battery containers on a graded desert site, with a solar array on the right hand side and low mountains on the horizon

A cyber security firm has put a figure on what it would take to black out Britain through its battery fleet. Compromise 29 per cent of the units, about 400 out of roughly 1,400, and the model produces a cascading failure in under two minutes. The trade body for the sector does not dispute the mechanism, and says the assumptions about coordination are doing a great deal of the work.

The assessment was published on 2 September by Centrii, a firm that sells operational technology risk services to energy operators, so its commercial interest in the answer should be read alongside it. The method is stated openly: a Monte Carlo simulation run 10,000 times for each of three security postures, drawing each variable from a range rather than fixing it, and accounting for compromise across cloud, remote access and supply chain routes.

The scenario it models is called Gridlock. Rather than attacking bandwidth, an attacker who holds several battery energy storage units manipulates physical power flows, pushing units to charge or discharge together and so destabilising grid frequency. The academic finding it builds on, published in 2025, is that a load altering attack using 15 per cent of a fleet's power could push frequency outside normal operating bounds. The figure of 11 to 21 compromised 2MW units is Centrii's extrapolation from that work, not the finding itself.

The United Kingdom numbers

The case study puts national battery capacity at 6.8 GW across about 1,400 individual units, with 79 per cent of it in England. On the model's arithmetic, compromising 400 of those units, 29 per cent of the fleet, triggers a national blackout affecting 67 million people, with economic damage put between 2 billion and 10 billion pounds. The report attributes heightened exposure to two structural features rather than to any operator: a single national grid with no internal isolation, and the concentration of deployment in England.

The probability figures are the ones that carry the argument. Under current sector practice the model puts the chance of at least one major attack affecting a million or more people by 2031 at 92.1 per cent. That falls to 61.4 per cent where operators are required to certify against IEC 62443, the industrial control system security standard, and to drill against the scenario every quarter.

Those figures are the output of the assumptions fed in, and the assumptions are stated: attacker capability gaining 15 per cent a year, installed storage growing 25 to 35 per cent a year, and entry through a cloud platform succeeding 35 to 70 per cent of the time over two to five weeks at intermediate skill. Nothing of this kind has happened, so the simulation describes its own inputs at least as much as it describes the grid.

A coordinated attack does not need to stop generation to cause a blackout. It only needs to desynchronise the balancing layer, forcing batteries to charge or discharge together, or delaying how they respond to grid signals. Neither action damages a battery.

Rafael Narezzi, co-founder of Centrii

What the sector and the government said back

The Energy Storage Association (UK) welcomed the attention to cyber resilience and then set about the modelling. Its answer is that the scenarios assume both a high level of attacker capability and successful coordination across a large proportion of a fleet it describes as highly diverse, and that work is already running through the Smart Secure Electricity Systems programme, alongside the Department for Energy Security and Net Zero, to put safeguards in place. A government spokesperson said the energy system is highly resilient and that legislation is going through parliament to introduce new powers against threats to national security.

Neither side argues about the mechanism. The disagreement is about how hard it is to hold 400 units of different makes at the same moment.

Why this belongs on a construction desk

Because the difference between the two headline probabilities is contractual rather than technical. Certification to a named standard and rehearsed drills are things an employer specifies, prices and enforces, and they are written into employer's requirements, operations and maintenance agreements and supply chain warranties before anyone installs a firewall. A cloud controlled asset also spreads the obligation: who holds remote access, who patches, on what notice period, and what happens to that arrangement when the operations contractor changes hands are all settled at contract stage, on schemes now being tendered.

The figure to carry away is not 400. It is that a supplier with something to sell and a trade body with something to defend agree on how the attack would work, and part company only over how easily it could be organised. That is a narrower argument than the headline suggests, and it is one worth having on paper now rather than in an incident room later.