Part 2 of the “From Electrons to EBIT” series: security.
Building on Part 1 of this article, which covered the monetization of flexible energy assets, Part 2 analyzes the critical role of digital security in protecting a fragmented grid edge, before Part 3 evaluates the strategic path toward commercializing AI.
Security of the digital energy infrastructure
The increasing connectivity of energy systems has inherently led to greater vulnerability. The International Energy Agency (IEA), in its 2023 commentary, noted a surge in electricity-sector cyberattacks since 2018, urging governments and utilities to strengthen resilience measures as connectivity accelerates.
Diverse systems and devices across utilities often use incompatible security frameworks, making it difficult to implement cohesive, scalable security solutions. This fragmentation complicates threat detection and response and significantly increases overall vulnerability across the energy system. Operational technology (OT) environments in particular often lack the robust resilience and risk management features that are standard in information technology (IT).[14]
Digital security and resilience are not just operational necessities — they are now profitable business domains, from managed security services to secure-by-design digital products. Significant spending is now flowing into core areas:
- visibility and detection technologies
- zero-trust segmentation
- identity management for machines, users and data
- managed detection and response tuned for industrial protocols
A high-growth market with regulatory support
This activity is fueling a robust, double-digit growth market with regulatory tailwinds (NERC CIP, EU NIS2, IEC 62443). The expansion is creating a large opportunity around compliance, architecture modernization, and incident response. The global OT security market (all sectors) is projected at about USD 23.47 billion in 2025, reaching roughly USD 50.29 billion by 2030.[15] Energy and power are among the fastest-adopting verticals. Utilities are prioritizing solutions for:
- asset visibility in substations and control centers
- detection of protocol-level threats (IEC 61850, DNP3, Modbus)
- secure remote access and identity-centric controls for vendors and field crews
The grid security market highlights this growth: valued at USD 7.5 billion in 2024, it is projected to grow from USD 8.3 billion in 2025 to USD 22.7 billion by 2034 (an 11.7% CAGR).[16]
Emerging opportunity: grid-edge security
As electrification accelerates, the grid edge has become one of the most critical — and least protected — domains in the energy system. Unlike traditional utility environments, which are centralized, physically secured, and governed by well-established operational processes, the grid edge — driven by the proliferation of distributed energy resources (DERs), solar, battery storage, and EV charging networks — is heterogeneous, distributed, and highly dynamic.[17]
It includes millions of assets — often owned or operated by third parties — that sit outside the utility’s physical and logical perimeter, communicating over public or semi-secure networks. This introduces a radically expanded attack surface that legacy OT security architectures were never designed to cover.[18]
What counts as the grid edge?
- Distributed energy resources (DER): PV, batteries, microgrids
- EV charging infrastructure, including bidirectional V2G systems
- Smart inverters with advanced grid-support functions (IEEE 1547-2018)
- Virtual power plant (VPP) aggregated fleets of behind-the-meter resources
- Consumer and commercial IoT energy devices (thermostats, BEMS platforms)
- Field gateways, edge controllers, and DER orchestration platforms
Collectively, these represent tens of millions of endpoints globally, each capable of influencing real-time grid stability. Yet most operate with inconsistent security maturity, weak identity controls, and limited monitoring.
Why grid-edge security matters now
Three structural shifts are turning the grid edge into a priority risk domain.
1. Bidirectional power flows create new systemic risks. Historically, distribution networks were not engineered for high DER penetration. When millions of devices can inject or withdraw power based on software commands, malicious control of even a small percentage could:
- destabilize local feeders,
- cause voltage/frequency oscillations,
- overwhelm protection settings, or
- create coordinated load manipulation events.
This moves cyber risk from data loss to physical grid disruption.
2. Identity and trust models break down outside utility boundaries. Most grid-edge devices were manufactured without NERC-grade identity or attestation capabilities. Many rely on:
- shared credentials,
- insecure remote management channels,
- firmware without signature enforcement, or
- cloud-to-device models that utilities cannot audit.
As VPPs scale, utilities need cryptographic identity for devices, users, agents, and data streams — not just network perimeter controls.[19]
3. Regulatory pressure is expanding to the distribution domain. Regulators are now signaling higher expectations for distribution-connected assets: EU NIS2 obligations for essential energy entities, IEC 62443 profiles for distributed asset manufacturers, and national requirements for EV charging cybersecurity (e.g. UK, California). Utilities will increasingly need verifiable controls for DER fleets and aggregator operations.
Gaps in today’s approaches
Even sophisticated utilities struggle, because traditional OT security tools assume centralized systems, deterministic protocols, and physically managed assets. Grid-edge environments break these assumptions:
- Low-cost devices with limited compute often cannot run conventional endpoint agents.
- Protocol diversity (SunSpec, IEEE 2030.5, OCPP, proprietary vendor APIs) hinders unified threat detection.
- Aggregator ecosystems introduce third-party control paths that utilities cannot directly secure.
- Event volumes scale exponentially, demanding cloud-native analytics rather than substation-based systems.
This fragmentation mirrors the historical challenges of IT/OT integration — but multiplied by orders of magnitude in device count.
Where value is emerging: the grid-edge security stack
The most investable and impactful opportunities fall into four domains:
Zero-trust identity for devices, data, and agents. Every asset — DER inverter, charger, VPP controller, field gateway — requires a unique cryptographic identity, verifiable provenance, secure and revocable authorization policies, and integrity for telemetry and commands. This is essential for any future high-DER grid.
Secure onboarding and lifecycle governance. Utilities increasingly need the ability to onboard third-party devices at scale, validate firmware integrity, enforce secure update policies, and decommission or isolate compromised assets. This resembles mobile device management at industrial scale.
Distributed detection and behavioral monitoring. Grid-edge devices generate rich operational signatures — voltage reactions, charging curves, inverter behavior under frequency events — that can be used for anomaly detection. Emerging solutions aim to detect spoofed telemetry, unauthorized command injections, coordinated load manipulation and firmware tampering.
Secure control channels for VPPs and DERMS platforms. If VPPs become dispatchable grid assets, control signals must be authenticated, tamper-proof, non-repudiable and resilient to cloud or network outages. This is a prerequisite for using DER as capacity, flexibility, or reliability resources.
Market trajectory
Grid-edge security is quickly becoming a major subsegment of OT security, pulled by multiple forces:
- explosive DER adoption (30–40% CAGR in many markets),
- rapid EV charging infrastructure growth,
- increasing participation of behind-the-meter resources in wholesale markets,
- government incentives driving mass deployment of smart devices.
Most analysts expect grid-edge security spend to outpace traditional OT security growth, driven by the sheer volume of assets and the essential role of identity at scale.
Strategic implication
Utilities, OEMs, aggregators, and software providers will need a unified trust and identity layer that spans utility OT, cloud platforms, and field devices. This is a fundamental enabler of:
- secure DER integration
- reliable VPP operations
- trustworthy aggregation markets
- cyber-resilient distribution grids
It is also a space where incumbents have a limited foothold — making it a high-value opportunity for innovators offering distributed identity, attestation, and secure data-exchange architectures.
Key takeaway: In a high-DER grid, cyber risk has evolved from simple data loss to physical grid disruption — making a unified security layer the only path toward a resilient and dispatchable energy future.
Conclusion
Ultimately, securing the grid edge is the “license to operate” in a decentralized world. By establishing a foundation of cryptographic trust and identity, utilities and innovators move beyond simple risk management into a realm where secure connectivity becomes the backbone of a high-value, automated energy economy.
Having secured the infrastructure, Part 3 pivots to the monetization of AI in energy. AI monetization currently thrives as an embedded enabler that boosts margins in trading, flexibility, and security, rather than as a standalone software product. While regulatory hurdles and integration risks slow direct sales to utilities, the fastest ROI is found in bundling AI with revenue-generating assets like VPPs or C&I optimization. As trust architectures mature, the industry will shift from using AI as a decision-support tool to deploying autonomous agents that trade and manage energy.
Continue with Part 3Artificial Intelligence: commercializing AI in energy →References
[14] National Institute of Standards and Technology, NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security, 2023. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r3.pdf
Egide, N., & Li, F. (2023). HAP-SG: Heterogeneous authentication protocol for smart grid. Peer-to-Peer Networking and Applications, 16, 1365–1379. https://link.springer.com/article/10.1007/s12083-023-01485-x
[15] MarketsandMarkets, Operational Technology (OT) Security Market, 2025. https://www.marketsandmarkets.com/Market-Reports/operational-technology-ot-security-market-18524133.html
[16] Global Market Insights, Smart Grid Cybersecurity Market Size, October 2025. https://www.gminsights.com/industry-analysis/smart-grid-cybersecurity-market
[17] Feldman, M., Rice, A., Venkatesh, B., & Bartock, M. (2021). Distributed energy resource security: Potential guidelines and research topics (NIST Technical Note 2182). https://doi.org/10.6028/NIST.TN.2182
Gao, Y., Ali, S., & Sun, K. (2024). A risk assessment framework for cyber-physical security in distribution grids with grid-edge distributed energy resources. Energies, 17(6), 1375. https://doi.org/10.3390/en17061375
[18] Juanwei Chen, Jun Yan, Anthony Kemmeugne, Marthe Kassouf, Mourad Debbabi, Cybersecurity of distributed energy resource systems in the smart grid: A survey, Applied Energy, Vol. 383, 2025. https://doi.org/10.1016/j.apenergy.2025.125364
[19] Alajlan, R., Rahman, M. M., Alnaeem, M., & Almaiah, M. (2024). A Literature Review on Cybersecurity Risks and Challenges Assessments in Virtual Power Plants: Current Landscape and Future Research Directions. IEEE Access. https://www.researchgate.net/publication/386891400_A_Literature_Review_on_Cybersecurity_Risks_and_Challenges_Assessments_in_Virtual_Power_Plants_Current_Landscape_and_Future_Research_Directions