Cybersecurity Forum: Europe’s energy sector must close gap between cyber regulation and real-world readiness
Polish cyberattack, Ukraine’s use of AI under attack and live hacking demonstration put real-world grid resilience at centre of 9th Cybersecurity Forum
Brussels, 8 October 2026: Europe’s energy sector needs to close the gap between rapidly evolving cyber threats and its ability to respond in practice, as geopolitical attacks, artificial intelligence (AI) and the rapid growth of connected energy technologies create risks that regulation alone cannot address, argue experts gathering at the 9th Cybersecurity Forum in Brussels today.
Recent attacks on Poland’s energy sector, Ukraine’s experience of operating a grid under sustained attack and a live demonstration of risks affecting connected energy devices are being used to examine what greater grid cyber resilience requires in practice.
The Forum, jointly organised by E.DSO, EE-ISAC, ENCS, and ENISA, comes just weeks after ENISA’s Threat Landscape 2026 analysed 8,257 cyber incidents affecting EU Member States and EU-based organisations during 2025. It found geopolitical developments continued to shape malicious cyber activity, while attackers increasingly incorporated AI into their operations and OT-related intrusion claims increased. OT, or operational technology, refers to the systems used to control and monitor physical equipment and industrial processes.
Recent attacks on European energy infrastructure provide a real-world test of what cyber resilience now requires. The Forum is hearing first-hand lessons from the coordinated cyberattacks on Poland’s energy sector in December 2025, which targeted numerous wind and solar farms and a combined heat and power plant supplying heat to nearly half a million customers. While electricity generation was not disrupted, communications between affected facilities and distribution system operators were lost, with attackers gaining a level of access that could have enabled disruption.
NPC Ukrenergo, Ukraine’s national electricity transmission system operator, is sharing how it is strengthening cyber resilience while operating a grid under sustained attack. This includes using AI to help cybersecurity teams react faster, identify gaps, support staff and assist with reporting, while keeping critical decisions with people. Its experience also highlights a growing challenge for the sector: maintaining specialist cybersecurity expertise when skilled teams cannot easily be rebuilt through recruitment.
The expansion of connected energy technologies is creating a different challenge. ENCS researchers are demonstrating how an attacker who has already compromised an everyday smart-home device, such as a router or camera, could potentially use it as a route to communicate with a residential solar inverter or home battery on the same network.
Some of these energy devices use control protocols that do not themselves authenticate who or what is issuing a command. An attacker may therefore not need to hack the inverter or battery itself to potentially influence whether it produces, consumes or stores electricity. While compromising one household is unlikely to affect the grid, manipulating
thousands of devices simultaneously could create sudden changes in electricity generation or demand and potentially contribute to wider grid disturbances.
Harm van den Brink, Security Researcher at ENCS, said: “More high-power IoT devices are being deployed every day, and vulnerabilities in some of these devices have already been exploited and could be exploited again to disrupt the electricity grid. In the short term, we need independent security testing, prioritised according to the amount of power potentially affected, combined with vulnerability management by manufacturers.”
Together, the sessions underline the Forum’s focus on turning cybersecurity requirements into practical resilience. Rapid implementation of measures including NIS2 and the Network Code on Cybersecurity remains important, but regulation cannot anticipate every emerging risk as technologies and threats continue to develop.
Dimitra Liveri, Head of the Resilience of Critical Sectors Unit at ENISA, summed up the challenge: “We must move from protecting individual systems to optimising the whole ecosystem for cybersecurity resilience.”
The Forum is examining how independent security testing, vulnerability management, information sharing and closer cooperation across the energy and cybersecurity sectors can help address that gap, while ensuring limited specialist resources remain focused on risks with the greatest potential impact.