This article is sponsored by Sungrow. In this Voices interview, Solar Power World spoke with Michael Hudson, Director of Cybersecurity Strategy for Sungrow North America, about the growing importance of cybersecurity as solar and storage systems become more connected and take on a larger role in grid reliability. Hudson shared insights on secure-by-design, system-level risk, visibility, documentation and the role of standards and verification in helping the energy industry move forward securely.
Solar Power World: Why has cybersecurity become a bigger issue for solar and storage systems as they take on a larger role on the grid?
Michael Hudson: Solar and storage systems are no longer just passive generation assets. As distributed energy resources take a larger role on the grid, they are more connected and more involved in grid stability, dispatch, coordination and the everyday operational decisions that help keep the power on and people safe.
In the past, such systems were more segmented and generated less data. Today, the industry is moving from connectivity with little control to connectivity with accountability, where products and systems must manage data responsibly. At Sungrow North America, we believe customers should retain control over connectivity to their deployed systems, with access clearly defined, visible and governed throughout the product lifecycle.
Making these assets part of an operational control environment rather than just production assets changes the risk profile significantly. It’s not just whether a system functions properly, but whether operators and users can maintain control, trust and visibility into those systems under all conditions, including disruption.
What are some of the consequences of a cybersecurity attack on these systems if it goes unaddressed?
They could be significant, depending on the scale of the attack. Cybersecurity incidents can affect availability, operational visibility, equipment control and recovery. At sufficient scale, those effects can become reliability concerns, which is why cybersecurity has to be treated as part of operational resilience rather than solely as an IT issue.
Energy is generated and balanced in real time. When generation or control systems become unavailable or behave unexpectedly, operators still have to maintain that balance. A localized incident may result in an equipment outage, loss of visibility or operational disruption. A coordinated or sufficiently widespread event could have much broader consequences for grid reliability. The consequences ultimately extend beyond the equipment itself because nearly every critical service depends on reliable electricity and increasingly on the data systems electricity supports. Consider a hospital that loses power or access to critical systems: patient information, prescriptions, allergy histories and other information may become unavailable when it is needed most.
That is an extreme scenario, but cybersecurity requires us to consider both likelihood and consequence. The potential impact ranges from localized operational disruption to events affecting critical infrastructure, public safety, property and people’s lives. Our responsibility is to build resilience for that range of outcomes, including the scenarios we hope never occur.
Why does greater scrutiny of grid-connected equipment make sense today?
It comes down to scale. As distributed resources are aggregated and coordinated, issues don’t stay contained. If they are not caught early, they can spread across the grid. To ensure these systems will behave in the real world, we need to stress-test them. We need to know they are secure and flexible enough to operate as expected in the environments they are actually going to face. And that, if something does happen, operators can respond in a way they have prepared for.
Why does cyber risk need to be evaluated at the full-system level, not just at the component level?
Component security definitely matters, but many of the most consequential risks emerge at the system level, where everything connects; hardware, software, communications, remote access if any, and third parties that may interact with the system.
If you only look at components in isolation, you can miss how something actually turns into an operational problem. Something might look secure on paper, or when viewed by itself, but that may not hold true once you add other connections or components into the environment, and the systems are accessed and operated.
It comes down to provenance across the entire chain, and requires a “shift left” mentality — a term from software development that means moving tasks such as testing, security checks and quality assurance to earlier stages of the lifecycle.
When you develop a product, you need to look at the system architecture and build it with security in mind from the start. The same applies to software. Development teams should be looking for known vulnerabilities, testing third-party libraries and using a secure development pipeline across hardware, firmware, software and anything else that will be in the devices as they are deployed.
From there, you need to understand what is expected in the environment. That includes networking protocols, ports, communication layers and whatever might indicate that something is happening that should not be happening. To do that, you need documentation, device diagrams, system architectures and people who understand how those pieces fit together.
You also need monitoring appropriate to the technology. These systems can be very sensitive. Something that might be routine in a normal enterprise environment could potentially take down a technology deployment. It’s important to understand the context the device was made for before implementing controls.
What does ‘secure by design’ mean for modern solar and storage equipment?
It goes back to that “shift left” approach: bringing security into the process from the very beginning, not waiting until the product is already built.
When a company develops modern solar or storage equipment, security teams should be involved throughout the product lifecycle, with independent third-party expertise incorporated where it provides meaningful validation and additional assurance. Once there is a concept for a product, the team should consult the security professionals early so they can review the architecture and identify potential issues.
They may say, “Here are some risks with this device, here are some mitigating controls, or this part of the design may need to change completely.” You want to catch those issues early, while the product is still being designed.
Testing is also a major part of secure-by-design. You don’t want to wait until the very end and discover a list of problems right before launch. At that point, remediation can affect the product timeline. It’s about testing throughout the process and building security into product conception, development, firmware, software and deployment.
Remote access is an important part of this conversation because a lot of products today allow it. That creates a new form of risk. At the same time, not having remote access can also create operational constraints, especially in updates and maintenance, so customers may want it and some add it themselves.
The general principle is that connectivity expands the attack surface and therefore must be deliberately governed. That’s why a secure-by-design architecture, segmentation and security controls are so important. You need to know who has access to your environment, and more importantly, to control their level of access.
That includes principles such as “least privilege” — a fundamental cybersecurity rule stating that a user, program or process must only have the minimum necessary access rights to perform its specific task, and absolutely nothing more.
Defining boundaries between systems and components is another major part of secure-by-design. Components are built for specific functions, which need to be clearly defined. Communication should only happen where it is expected and allowed.
Logging should record what is happening, what changed and where feasible, communications between devices. That can be difficult when a lot of devices and components are involved, but those boundaries are still important.
The goal is to prevent unnecessary communication and reduce the chance of lateral movement between systems or components. That can include microsegmentation inside the network and making sure access controls follow that same segmentation. Otherwise, one exposure can grow into a much larger problem.
Why do visibility and documentation matter so much in energy cybersecurity?
If you cannot see the assets, you cannot manage them.
Operators need to know what is in their environment, how it is connected and how it behaves over time. They also need to know what changed, when it changed and why it changed. Without that visibility, it becomes very difficult to tell the difference between normal activity and something more serious. That delay in understanding is where risk will start to grow.
Documentation also matters for basic operations: if you update something on a device and it breaks something else, you need to know what changed. That becomes very important for rollback and recovery. In these environments, timing matters. When devices go down, organizations or utilities can lose a significant amount of generation unless the problem can be quickly addressed.
What role should transparency and verification play when customers and regulators evaluate equipment?
In security, there is a common phrase: trust, but verify.
Our industry is shifting towards proof. When customers and regulators look at these systems, they want to understand not just how they are supposed to behave on paper, but whether they work as intended in real-world environments for the provider and everyone who will depend on it. Transparency around access, communications and system changes helps provide that understanding.
Independent verification can add credibility by providing an additional, independent assessment of how equipment performs under defined test conditions.
How can standards and certification frameworks help the industry move forward?
Standards and certification frameworks can be very helpful as a baseline. However, there are too many products out there doing many different things for one standard or certification to cover every product, every deployment, or every scenario.
So, compliance is not the same thing as security. It’s a misconception that if a product is compliant or if it has a certification, then it is automatically secure.
These frameworks should be the baseline, and a way to make sure companies have their foundational controls in place before they move forward. From there, organizations can build more mature security controls on top of that foundation. The goal should always be to keep building on that baseline with a security-first, secure-by-design mindset. And, continuing to mature our cybersecurity as organizations, deployments, and energy generation — and threats — continue to grow.
Sungrow, a global leader in renewable energy technology, has pioneered sustainable power solutions for over 28 years. In December 2025, Sungrow surpassed 1,000 GW (1 terawatt) of power electronic converters installed worldwide. Sungrow is recognized as the world’s most bankable PV inverter and energy storage company (BloombergNEF). Its innovations power clean energy projects across the globe, supported by a network of 520 service outlets guaranteeing excellent customer experience. At Sungrow, we’re committed to bridging to a sustainable future through cutting-edge technology and unparalleled service. For more information, please visit: www.sungrowpower.com.