Modat counts 8,547 wind and solar systems reachable online: 93% solar, a floor, and the UK outside its scope
Modat counted 8,547 wind and solar systems that should not be reachable from the internet, 7,942 of them solar, in 35 countries across the EU, EFTA and candidate states. The UK is outside that scope, the count is a floor, and no public page says how many sit behind a login.
By Parminder Kumar Sharma · · 23 min read

8,547 systems that should not be reachable, 93 per cent of them solar, and the fact the count does not give
Modat, a Hague-based internet-intelligence company, counted 8,547 internet-facing systems at wind farms and solar parks that should not be reachable from the internet, in 35 countries. Its own pages give the split: 7,942 solar systems in 34 countries and 605 wind systems in 23. The two add to 8,547, and solar is 93 per cent of the total (92.9 per cent, derived). Spain's 2,766 is 35 per cent of the solar figure (34.8 per cent, derived), and Spain, Greece, Italy and Germany together hold 76 per cent of it (76.2 per cent, derived, from 2,766, 1,860, 753 and 672). On the wind side, Germany's 212 and Italy's 192 are 67 per cent (66.8 per cent, derived). Every percentage in the coverage reproduces from the counts. Modat's pages give Spain's count and the percentages; the counts for Greece, Italy and Germany come from Reuters, Help Net Security and pv magazine.
The count is a floor. Modat's press release says the researchers counted a system only "once they could confidently link it to a specific solar park or wind farm", and that many more systems share the same characteristics but have not been attributed yet. It also says the research counts systems, not turbines or panels, and that some of the systems control several turbines or a whole farm. A floor in systems says nothing about capacity: no public page gives the megawatts behind any exposed system.
The fact a reader needs is whether any control sits between the internet and a Stop button, and the public pages do not give a count for it. What they give is one example, a turbine's web interface showing live production data with Start, Stop and Reset controls, and, through Reuters, two statements: that most of the systems found were administration pages with login screens, and that Modat's chief executive told Reuters the researchers believed full control would have been possible at around 181 sites. That is 181 sites against 8,547 systems, which are different units, so no share is stated here (it would be 2.1 per cent if the units were alike, and they are not). The Hague's newsroom page on the report says the report does not state that the researchers actually switched farms off.
The United Kingdom is not in the 8,547. Modat says it mapped operating wind farms and solar parks in 40 countries in the EU, EFTA and EU candidate states, and found systems in 35 of them. That is 27 member states, four EFTA states and nine candidates on the Council's current list, and 27 + 4 + 9 is 40 (derived). The UK is in none of the three groups, so no UK count is stated and, on that scope, none was sought. That last step is inference from the scope: this briefing could not read the report's country table. The full PDF sits behind a form that asks for personal details, which this briefing did not fill in, so what follows rests on Modat's public pages, its press release, a newsroom page from The Hague and news coverage, and each figure says which.
What the count is, how it was made, and what it does not establish
The method is machine-learning clustering on scan data. Modat's pages say it used its Magnify platform to group similar systems found in internet-wide scan data, which surfaced device types for which no detection rules had been written, and that it first mapped every operating wind farm and solar park in scope. A reachability finding of this kind is useful and it is limited: it shows what answers, not what an answer allows.
What the public pages state about the research, and what they leave out. Read on 11 October 2026 from Modat's research post and press release, Reuters, Help Net Security, pv magazine and The Hague's newsroom; the full report was not read.
| Question | Stated, and by whom | Not stated |
|---|---|---|
| What was counted | Systems that should not be reachable from the internet, including admin interfaces and control panels (Modat). Systems, not turbines or panels (Modat). | How many systems per site, how many sites, and the split between login pages, control pages and dashboards. Reuters says most were admin pages with login screens. |
| Which countries | Operating parks in 40 countries in the EU, EFTA and EU candidate states; systems found in 35 (Modat). pv magazine says rooftop installations were excluded. | Which five countries had no findings. A Dutch trade magazine says large solar roofs were in scope, which conflicts with pv magazine; the report was not read to settle it. |
| Can anyone log in | Help Net says a turbine control page offers a Stop button "to anyone with a browser". Modat's wording is a web interface "showing" production data with Start, Stop and Reset controls. Modat's chief executive told Reuters full control would have been possible at around 181 sites. | How many systems accept commands with no login, how 181 was reached, and whether anyone logged in or sent a command. The Hague's newsroom says the report does not state that farms were switched off. |
| Who did the work | Modat's post calls it Modat research, written together with a co-author, presented at The ONE Conference on 6 October. Help Net, pv magazine and Windtech name NCSC-NL as a partner. | Any NCSC-NL statement. Its news page, newest item 7 October, and its site search for the company's name and for windparken returned nothing. Modat's current press release says "Research by" Modat alone and mentions NCSC only in a reference to a September joint statement by Dutch services. Its old address, which contains ncsc-nl, redirects to it. |
| When it was scanned | Presented on 6 October; five days before this briefing (derived). | Any observation date or period. An independent analysis (l0g.fr) says the public pages give no single date for every system. |
| How big the sites are | Help Net: wind farms in scope run from 10 megawatts to more than 4,500. | Capacity of any exposed system. A Dutch trade magazine says some farms exceed 4,000 megawatts, so the two upper figures differ. |
| What was done about it | Aggregated country figures only; affected parties informed through national CERTs; operators can email Modat to ask whether systems linked to them are in the findings (7 October). | How many parties were told, how many have closed an interface since, and whether any vendor or installer was named to its customers. |
Read together, the table separates three claims that headlines merge: that an interface answers a browser, that it accepts a command, and that a command would change power output. The public pages support the first at 8,547 systems, give an example of the second, and give a conditional number for the third (181 sites, as a belief, told to a news agency). None of them says any system was attacked, accessed by anyone other than the researchers, or switched off.
The arithmetic, and where the count is concentrated
Every percentage Modat published reproduces from the published counts, which is the first thing worth checking in a vendor's number. The next is how unevenly the count is spread. Spain alone is 32.4 per cent of the whole 8,547 (derived). Nine named solar countries hold 7,486 of the 7,942 solar systems, 94.3 per cent (derived), which leaves 456 across the other 25 solar countries, about 18 each. The average of 244 per country across 35 (derived) describes no country.
Published figures against this briefing's checks. Checks are derived from the counts in the Modat press release and the news coverage cited in the sources.
| Figure | As published | Check (derived) |
|---|---|---|
| Total | 8,547 systems | 7,942 + 605 = 8,547. Matches. |
| The three percentages | 35 per cent (Spain, solar), 76 per cent (top four, solar), 67 per cent (Germany and Italy, wind) | 2,766 of 7,942 = 34.8; 6,051 of 7,942 = 76.2; 404 of 605 = 66.8. All three reproduce. |
| Countries in both lists | 34 solar, 23 wind, 35 in all | 34 + 23 = 57 listings across 35 countries, so 22 countries have both, 12 are solar only and 1 is wind only. Assumes every country has at least one. |
| Netherlands | 132 solar, 9 wind | 141 together. A Dutch outlet gives 141. Matches. |
| Scope | 40 countries mapped, 35 with findings | 27 + 4 + 9 = 40, so five mapped countries had no finding. The UK is not among the 40. |
| Age of the data | Presented 6 October | 5 days to 11 October. No scan date is stated, so the age of the data itself is unknown. |
Two friendly names: "exposed" and "decentralised"
"Exposed to the internet" is a reachability fact, not a compromise and not, by itself, a vulnerability. Reuters says most of the counted systems are administration pages with login screens, and a login page is a control only if the account behind it is unique, strong and changed from its default. Modat reports that one login page showed a default account name, which this briefing does not reprint, and that login pages named the parks they protect. The reason reachability still matters is practical. The NCSC's guidance on operational technology says discovery tools index internet-connected assets, and that systems visible to them are "highly likely to be found and targeted by malicious actors". Modat says the same of its own method: what it can map in hours, an attacker can map in hours.
"Decentralised is resilient" is true of generation and not of control. The authors put the physical half plainly, that wind and sun are the hardest target there is, and Help Net quotes them on the other half: "in cyberspace, there is no there there". Modat's post adds that every reachable site is "just as close to an attacker as the next one". Poland is the record to hold that against. On 29 December 2025 coordinated attacks hit more than 30 wind and photovoltaic farms, and CERT Polska says the farms lost the ability to communicate with the distribution operator's systems and remote control was prevented, while electricity production carried on (initial report, 30 January 2026). Spread-out generation kept generating. What it did not keep was the ability to be told what to do, at more than 30 sites on one day. The follow-up report of 8 August 2026 adds a second, smaller combined heat and power plant and a route in through a private cellular network.
The DESNZ and Ofgem consultation of March 2026 cites the Polish attack and says it "was not deemed to be a sophisticated attack" and that most of the weaknesses used could have been prevented by cyber hygiene. That is the UK government's reading of a foreign incident. It is not a finding about the 8,547, and nothing read says any of them was involved in it.
Whose count, and whose interest
Modat sells internet-exposure intelligence, and its pages say so: the research post ends with offers to operators, vendors and national CERTs, a follow-up of 7 October invites operators to email and ask whether they are in the findings, and the site's calls to action are a demo and a trial of its platform. A large count is in its interest, and the data behind it is Modat's. That is not a reason to doubt the arithmetic, which checks. It is a reason to attribute the numbers to Modat and to want the method.
NCSC-NL is a public body. Whether the study is NCSC-NL's work is less settled than the coverage suggests: Help Net, pv magazine and Windtech say it is, pv magazine describes the co-author as NCSC-NL's, and Modat's current release does not name it as a partner. As of the reading, NCSC-NL's own news page had no item on it. In the UK sources, NCSC-NL does appear as one of the partner agencies on the NCSC's secure connectivity principles for OT, which is presumably what the study's recommendation to follow the principles published for operational technology refers to (inference).
Help Net's article quotes the chief executive of an industrial-security vendor, and pv magazine quotes the same person, naming the company as Austrian, Tributech. The advice reads as a sound control list (who connects, from where, to which assets, read or write, with individual accounts and a separate right to command), and pv magazine describes the company as an industrial cybersecurity company, so the commercial interest in it is plain. That is stated here once and applies to every vendor quoted. Nothing in the public pages says whether the exposure is the operators' fault, the installers' or the vendors', and no one has the evidence to say.
Two other vendors have recently offered to look for exposure at critical infrastructure. Wiz, owned by Google, launched a free AI scan on 24 September, and this site's briefing on it found that the terms accept no liability for disruption. Anthropic launched a Critical Infrastructure Defense Program on 8 October, and the briefing on that launch found eleven founding partners and no published result, count or named operator. Neither briefing establishes that either programme covers wind or solar sites. Both are what an operator might be offered; Modat's count is what an outside scan returns without being asked.
The UK: outside the count, and the regulation's bar for generators is high
The count says nothing about British sites. Nothing in the public pages suggests the exposure is a feature of the EU, though: it concerns classes of equipment and habits of remote access, which do not stop at the Channel (inference). The NCSC's advisory of 27 August 2026 says it has seen increased targeting of operational technology across multiple sectors globally, including in the UK, with some limited real-world disruption, and that organisations should not assume their OT is inaccessible from the internet without verifying it. The DESNZ and Ofgem consultation expects the UK's wind and solar capacity to almost triple by 2030. Whether any Northern Ireland site was mapped is not stated.
Who the law reaches is a narrower question than who is exposed. The tables below set out what the primary texts say, read on 11 October.
The Network and Information Systems Regulations 2018 as they apply to electricity, from legislation.gov.uk (Schedules 1 and 2, regulations 8, 10, 11 and 18, up to date to 11 October 2026) and the DESNZ and Ofgem consultation of 27 March 2026.
| Question | What the text says | What it does not reach |
|---|---|---|
| Competent authority | Electricity, England, Wales and Scotland: the Secretary of State for Energy Security and Net Zero and the Gas and Electricity Markets Authority, acting jointly. Northern Ireland: the Department of Finance. | Ofgem and DESNZ regulate energy in Great Britain; the Regulations apply UK-wide. |
| Who is an operator of essential services | Great Britain, electricity supply: more than 250,000 final customers, or supply plus generation that, cumulated across affiliates, is 2 gigawatts or more in input to a transmission system. Northern Ireland: a generation licence holder of 350 megawatts or more. Nuclear generators and generators not connected to a transmission system are excluded from the 2 gigawatt test. | On this briefing's reading of the text, a wind or solar owner that does not also supply, or whose farms connect below transmission, does not meet the test. At the 10 megawatt end of Help Net's range it takes 200 farms to reach 2 gigawatts (derived). |
| Discretion | Regulation 8(3) lets the authority designate a person below the threshold if an incident would likely have significant disruptive effects on the service. | Nothing read says it has been used for a wind or solar owner. |
| Duties and penalties | Regulation 10: appropriate and proportionate technical and organisational measures. Regulation 11: notify a significant incident within 72 hours of becoming aware. Regulation 18: penalties up to £17,000,000 for a material contravention that has or could have created a significant risk to the service. | An interface that answers a browser is not itself a regulation 11 incident (inference from the wording, which turns on significant impact on continuity). |
| Reform under way | Consultation 27 March to 22 May 2026 proposed baseline cyber requirements for all Ofgem licensees and a review of the NIS thresholds. The response, last updated 5 August 2026, takes both forward; 19 respondents said the generation threshold should change. | A date. Ofgem and DESNZ say they will consult within 2027, DESNZ subject to the Bill's Royal Assent, expected in early 2027. |
The consultation says the quiet part itself: the shift to a more distributed system "means supply resilience will depend on an increasing number of smaller organisations that are unregulated for cyber resilience". The commitments the government's response repeats are to shape baseline proposals for every Ofgem licensee by the end of 2027 and to have a baseline across the whole system by the end of 2030. That is a licence reform for licensees. Generators that hold no Ofgem licence, and the installers and aggregators who run them, are outside it unless the review reaches them, and the consultation says unlicensed sectors may be considered. Which generators are licensed was not read.
The Cyber Security and Resilience (Network and Information Systems) Bill was introduced on 12 November 2025. Parliament's tracker, read at about 09:47 BST on 11 October 2026 and again at 10:07 BST, shows that Lords committee stage began on 1 September, that the current version is as amended in Grand Committee (7 September), and that report stage is listed for 26 October, 15 days away and provisional. It is not law. This site's briefing on regulator clocks covers the difference between the 72 hours that runs to a regulator and the clock the public sees.
The NCSC's guidance that bears on exposure and remote access, as read on 11 October 2026 on ncsc.gov.uk. Quotations are short and exact.
| Source | What it says | Limit |
|---|---|---|
| CAF version 4.0, B2.a identity and access | The "Achieved" column expects multi-factor authentication "for all user access, including remote access" to the systems that support the essential function. The "Not achieved" column includes "Unauthorised individuals or devices can access your network". | The CAF is built for operators of essential services. The NCSC says others may find it useful; it is not a duty for them. |
| CAF, B4.a secure by design and B4.d vulnerability management | "Not achieved" includes "Remote or third-party accesses circumvent some network controls", and "You do not understand the exposure of your essential function(s) to publicly-known vulnerabilities". | Describes the outcome, not a product. |
| CAF, A3.a asset management and A4 supply chain | Achieved means all assets relevant to the function are inventoried and kept up to date, and that "All network connections and data sharing with third parties are managed effectively and proportionately". | An inventory of the operator's own estate does not list what an installer left reachable. |
| NCSC advisory, 27 August 2026 | Eight actions, including: build a definitive view of OT assets and ensure PLCs and HMIs are not directly exposed to the public internet; change default credentials and use MFA; log and monitor all connectivity; and register for the free Early Warning service. | Advice to all organisations that use OT. Not a legal duty. |
| Secure connectivity principles for OT, 14 January 2026 | Produced by the NCSC with partner agencies including NCSC-NL. Principle 2 says to limit exposure, make connections outbound from inside OT, and use brokered connections for remote vendor support, so the OT system is "never directly exposed to the internet". | Design principles for large organisations, not a checklist for a small site. |
| Early Warning | Free, for any UK organisation; sign-up needs the organisation's public IP addresses and domain names; includes "Vulnerability and Open Port Alerts"; "does not conduct any active scanning" itself. | It can only watch addresses the owner registers. A router an installer set up may not be on the owner's list (inference). |
The supply chain is the second front. The NCSC's principle is that vendor support should arrive through a broker the operator controls, switched on when needed, rather than through a port left open. Help Net's quoted vendor says many operators cannot list their remote connections today, and nothing read contradicts that. Under the CAF, an operator that outsources is still accountable for the function, and a third party's access that goes around the network controls is a "Not achieved" statement. For a small owner there is no framework to assess against. There is the installer's contract.
The EU comparison, and Lithuania. NIS2 lists "producers" of electricity among its high-criticality entities and applies a size rule, medium-sized enterprises and above, rather than a 2 gigawatt test. Article 20 says management bodies approve the cybersecurity measures, oversee them and "can be held liable", and Article 23 sets an early warning within 24 hours and a notification within 72. A UK developer or fund that owns parks in Spain, Greece, Italy or Germany answers to those countries' regimes for those sites (inference; the national laws were not read). Lithuania's parliament passed on 12 November 2024 an amendment to its Law on Electricity, for installations above 100 kilowatts, so that entities from states its national security strategy names as threats cannot gain access that lets them remotely change power output or switch plant on or off (the Seimas's own release, read in Lithuanian). The vendor quoted by Help Net says such a rule addresses who connects and not what happens once they do. That describes the rule's design accurately, and the Modat count points at the other half.
The ICO angle is minimal. A turbine or inverter control interface is not personal data. The Information Commission, the name the amended Regulations now use, reaches this only if an exposed dashboard or installer portal also holds customer or staff records, and no public page about this study says that any does.
What to do, in the order worth doing
The order follows what can be done from a desk in a week first, and what needs a site visit or a contract change after. Everything below is defensive and aimed at an operator, an owner, an asset manager or an insurer of a wind or solar site, in the UK or elsewhere.
Take this with you
Actions, in order
- Inventory every internet-reachable interface of every site, including the ones a third party installed: inverter and controller web pages, data loggers, cellular routers, remote-access gateways and vendor portals. Ask the installer and the O and M contractor for their list, and do not rely on your own diagram.
- Check from outside. Use an external attack surface management service, or register the sites' public IP addresses and domains with the NCSC's free Early Warning service, which reports open ports and vulnerable services but does not scan for you. Treat anything found as at risk until the NCSC's questions are answered: was it built for direct internet access, how long has it been exposed, what else is open.
- Take admin interfaces, dashboards and controllers off the direct internet. Where remote access is needed, use a VPN or a brokered gateway with multi-factor authentication and individual accounts, with the connection started from inside the site and switched on only when needed.
- Change default credentials, remove shared and built-in accounts, and disable remote services nobody uses. A login page is only a control if what stands behind it is unique to the person using it.
- Record every vendor remote connection: who, from where, to which assets, and whether read only or able to change settings. Split the right to monitor from the right to command, and require individual vendor accounts.
- Require installers and vendors to hand over a list of exposed services at commissioning and again at every handover, and put it in the contract with a right to test it from outside.
- Log and monitor logins and commands, with an alert for a command from an unexpected source or route. Keep your own record of configuration changes rather than the vendor's.
- Have a manual-operation plan and tested backups of configurations, and rehearse them, so that losing remote control does not mean losing the site. Poland's farms kept generating with remote control prevented; the plan is what lets a site carry on when remote control is lost.
- Know your obligations. An operator of essential services notifies its competent authority of a significant incident within 72 hours (regulation 11). An exposure with no incident is not that report, so ask the regulator how it wants one raised, and treat any sign that someone used an exposed interface as an incident.
- If you own a small installation, ask the installer in writing what is reachable from the internet, who can control the inverter, from where, and with what login, and ask for the answer to be checked from outside. Do not accept 'it is behind the router' as an answer.
What could not be verified
The full report. The PDF answered a plain request with HTTP 403 and the message that it is released once a short form on its page has been filled in. This briefing did not submit it, because that means handing over personal details, and no other copy was found. Everything above that the report would settle is therefore open: its country table, the scan dates, the share behind a login, per-site counts, any product breakdown, and the disclosure counts.
Figures read second-hand. The solar counts for Greece, Italy and Germany, and Spain's 11 wind systems, are in Reuters, Help Net Security and pv magazine but not on Modat's pages. Hungary's 514 and Turkey's 454 are in pv magazine only. Belgium's 195 and France's 140 are in Solar and Storage Magazine only. The 181 sites are a statement by Modat's chief executive to Reuters, read in Insurance Journal's reproduction of the agency copy. The 10 and 4,500 megawatt range is Help Net's, and the "more than 4,000" is a Dutch magazine's.
NCSC-NL's role. No NCSC-NL announcement was found. Whether NCSC-NL is a publisher of the study, a partner, or the employer of one co-author is unresolved, and Modat's release page appears to have been edited since it went out, because copies dated 7 and 9 October name the agency in the first sentence and the current page does not. That is an observation about pages, not an allegation. The Internet Archive answered the request that would have shown the earlier text with a rate-limit error, so the earlier text was not seen.
The UK. That the UK was outside the 40-country scope is read from Modat's wording and the Council's list of 27 members and nine candidates, plus the four EFTA states. EFTA's own page returned a bot check and was not bypassed. The UK is not among those groups, and 27 + 4 + 9 equals 40, but a UK count was not seen anywhere and the possibility of a Northern Ireland site was not excluded by any source.
The question that exposes the gap
Modat counted what answers a browser, and could attribute only part of it. The count is a floor for Europe, the UK is not in it, and nothing public says how many of the 8,547 would obey a command. The same uncertainty sits inside every owner's own estate, one site at a time.
If someone typed the address of each of your sites into a browser tonight, what would answer, who would know, and who could show you from the outside rather than from the commissioning file?
Key facts
Sources
- PrimaryModat's research post, 6 October 2026: the 8,547 count across 35 countries in the EU, EFTA and EU candidate states, the clustering method, 'what is attributed so far and more remains', aggregated figures only, disclosure through national CERTs, and the offers to operators and CERTs. The vendor's own pageModataccessed 2026-10-11
- PrimaryModat's press release, 6 October 2026, current page: the solar, wind and Netherlands counts and percentages, the 40 countries mapped, the lower-bound wording and the recommendations. The earlier address containing ncsc-nl redirects hereModataccessed 2026-10-11
- PrimaryModat's follow-up, 7 October 2026: operators can email to ask whether systems linked to them are in the findings, with a private answer after confirmationModataccessed 2026-10-11
- PrimaryThe full report, To See the Wind and the Sun. NOT READ: a plain request answered HTTP 403 with the message that it is released once a short form has been filled in, and the form was not filled inModataccessed 2026-10-11
- PrimaryNCSC-NL news listing and site search, read 11 October 2026: the newest item is dated 7 October and nothing mentions the study, the company or wind parksNCSC-NLaccessed 2026-10-11
- PrimaryThe Network and Information Systems Regulations 2018, Schedule 2, up to date to 11 October 2026: the electricity thresholds, 2 gigawatts cumulative in Great Britain with supply, 350 megawatts in Northern Ireland, and the exclusionslegislation.gov.ukaccessed 2026-10-11
- PrimaryNIS Regulations 2018, Schedule 1: the designated competent authorities for electricitylegislation.gov.ukaccessed 2026-10-11
- PrimaryNIS Regulations 2018, regulation 8: deemed designation at the threshold, and designation below it by the competent authoritylegislation.gov.ukaccessed 2026-10-11
- PrimaryNIS Regulations 2018, regulation 10: the security duties of operators of essential serviceslegislation.gov.ukaccessed 2026-10-11
- PrimaryNIS Regulations 2018, regulation 11: incident notification within 72 hourslegislation.gov.ukaccessed 2026-10-11
- PrimaryNIS Regulations 2018, regulation 18: penalties of up to 1,000,000, 8,500,000 and 17,000,000 poundslegislation.gov.ukaccessed 2026-10-11
- PrimaryReshaping cyber regulation in downstream gas and electricity, consultation of 27 March 2026: Table 1 of NIS thresholds, the proposals, the Clean Power 2030 capacity statement and the account of the Polish attackDESNZ and Ofgemaccessed 2026-10-11
- PrimaryThe government response, page last updated 5 August 2026: 49 responses, both proposals taken forward, consultations within 2027, Royal Assent of the Bill expected early 2027 and the baseline commitment by the end of 2030DESNZ and Ofgemaccessed 2026-10-11
- PrimaryCyber Security and Resilience (Network and Information Systems) Bill, stages page read at about 09:47 BST on 11 October 2026: Lords committee from 1 September, report stage listed for 26 OctoberUK Parliamentaccessed 2026-10-11
- PrimaryNIS Guidance for Downstream Gas and Electricity Operators of Essential Services in Great Britain, version 3.0, 14 January 2026: Ofgem's guidance that operators must have regard to under regulations 10(4) and 11(12)Ofgemaccessed 2026-10-11
- PrimaryThe Cyber Assessment Framework collection, version 4.0: who the CAF is for and the Basic and Enhanced profilesNational Cyber Security Centreaccessed 2026-10-11
- PrimaryCAF principle B2, identity and access control: B2.a on MFA for all user access including remote accessNational Cyber Security Centreaccessed 2026-10-11
- PrimaryCAF principle B4, system security: B4.a secure by design and B4.d vulnerability management wordingNational Cyber Security Centreaccessed 2026-10-11
- PrimaryCAF principle A3, asset management: the inventory outcomeNational Cyber Security Centreaccessed 2026-10-11
- PrimaryCAF principle A4, supply chain: accountability where third parties are used and managed third-party connectionsNational Cyber Security Centreaccessed 2026-10-11
- PrimaryNCSC news item, 27 August 2026: increased targeting of OT including in the UK, the eight actions, and the call to register for Early WarningNational Cyber Security Centreaccessed 2026-10-11
- PrimarySecure connectivity principles for OT, principle 2, limit the exposure of your connectivity: brokered connections, outbound-only, external attack surface management; published 14 January 2026 with partner agencies including NCSC-NLNational Cyber Security Centreaccessed 2026-10-11
- PrimaryNCSC Early Warning: free for UK organisations, sign-up needs public IP addresses and domain names, Vulnerability and Open Port Alerts, and no active scanningNational Cyber Security Centreaccessed 2026-10-11
- PrimaryThe NIS2 Directive (EU) 2022/2555: Annex I electricity entities including producers, Article 20 management accountability, Article 23 24 and 72 hour reporting, and the size-cap recitalEUR-Lexaccessed 2026-10-11
- PrimaryNCSC-NL on the electricity network code on cybersecurity, in Dutch: aimed at large producers and system operators, with high thresholds. Read, and only mentioned for scopeNCSC-NLaccessed 2026-10-11
- PrimarySeimas press release, 12 November 2024, in Lithuanian: amendments to the Law on Electricity for generation and storage above 100 kilowatts, 79 votes for, in force 1 May 2025Seimas of the Republic of Lithuaniaaccessed 2026-10-11
- PrimaryEnergy Sector Incident Report, 30 January 2026: coordinated attacks of 29 December 2025 on more than 30 wind and photovoltaic farms, loss of communication and remote control, and production unaffectedCERT Polskaaccessed 2026-10-11
- PrimaryFollow-up report, 8 August 2026: a second combined heat and power plant and a private APN routeCERT Polskaaccessed 2026-10-11
- PrimaryEU enlargement page: nine candidate countries (Montenegro, Serbia, Albania, North Macedonia, Bosnia and Herzegovina, Turkiye, Ukraine, Moldova, Georgia) and 27 member states, used for the scope checkCouncil of the European Unionaccessed 2026-10-11
- Reported byReuters, 6 October 2026: most systems were admin pages with login screens; around 181 sites where full control was believed possible; the rankings partly reflect where systems could be linked to sites; the report's citation of CERT Polska's analysisReuters, via Insurance Journalaccessed 2026-10-11
- Reported byHelp Net Security, 9 October 2026: the article that named Modat and NCSC-NL, the 10 to more than 4,500 megawatt range, the Stop button wording, the Lithuanian rule and the vendor quotations. Used as a pointer, not a source of factHelp Net Securityaccessed 2026-10-11
- Reported bypv magazine, 7 October 2026: Greece, Italy, Germany, Hungary and Turkey solar counts, Spain's 11 wind systems, rooftops excluded, the co-author described as NCSC-NL's, and Italy's remote-control rulepv magazineaccessed 2026-10-11
- Reported bySolar and Storage Magazine, 8 October 2026, in Dutch: Belgium 195 solar and 11 wind, France 140, the 141 for the Netherlands, large solar roofs said to be in scope and farms above 4,000 megawattsSolar and Storage Magazine (Netherlands)accessed 2026-10-11
- Reported byThe Hague's newsroom item, 6 October 2026: exposed systems rather than confirmed attacks, and that the report does not state that farms were switched offThe Hague newsroomaccessed 2026-10-11
- Reported byWindtech International, 7 October 2026: a copy of the release that names NCSC-NL as a partnerWindtech Internationalaccessed 2026-10-11
- Reported byCyprus Shipping News, 9 October 2026: a copy of the release headed Modat and NCSC-NLCyprus Shipping Newsaccessed 2026-10-11
- Reported byEnergias Renovables, 8 October 2026, in Spanish: the study does not allow the reader to tell how many systems remain exposedEnergias Renovablesaccessed 2026-10-11
- Reported byl0g analysis, 10 October 2026: the full report was form-gated and not reviewed, and no single observation date is publicl0gaccessed 2026-10-11


