Security flaws in solar systems threaten the grid (cross-border guide)

Solar photovoltaic systems on Swiss rooftops

The National Cybersecurity Testing Institute has detected over fifty vulnerabilities in eleven widely distributed photovoltaic products.

Context

In brief

  • Over 50 vulnerabilities detected in photovoltaic systems
  • Seven out of eleven products present serious flaws
  • Risk of cyber attacks and remote manipulation
  • Minimum security requirements requested by politics

Key facts

  • Testing agency: National Institute for Cybersecurity Testing
  • Tested products: 11 devices from 8 companies
  • Inverters analysed: 7
  • Energy management systems: 4
  • Critical vulnerabilities: 7
  • Serious vulnerabilities: 6

Serious flaws in Swiss photovoltaic systems risk compromising their stability. The National Institute for Cybersecurity Testing examined eleven widely used products belonging to eight companies, identifying over fifty vulnerabilities in total. Among the examined devices are seven inverters, i.e., the electronic devices that convert direct current into alternating current, and four energy management systems. The investigation highlighted that seven of these issues were classified as critical and six as serious, while five of the eleven products presented at least one serious security flaw.

Technical shortcomings identified

The technical analysis conducted by experts revealed alarming shortcomings. In practically all tested inverters, technicians managed to reduce the power fed into the grid to zero without any need for authentication. Additional vulnerabilities identified concerned preset passwords, unprotected maintenance accesses, and insufficient encryption that exposes components to unauthorized intrusions. Nevertheless, experts found no indications of intentionally inserted backdoors, understood as hidden methods to bypass normal authentication and security systems.

Operational details

The general safety level of the analyzed products is not fundamentally worse than that of other Internet-connected devices available on the consumer or industrial market. What distinguishes these devices, however, is their systemic relevance for the national and cantonal electricity grid. A large‑scale cyber attack could theoretically compromise the stability of power supply, creating immediate imbalances between distributed generation and the country’s total energy demand.

Risk scenario and market reaction

The concentration of thousands of plants linked to the same manufacturers’ cloud platforms represents a systemic vulnerability point. When a software update or remote connection is compromised, the domino effect can spread nationwide. Fortunately, in most of the cases examined, manufacturers have responded quickly after the vulnerabilities were reported by technicians, releasing corrective patches or modifying access protocols.

From the perspective of critical‑infrastructure protection, the situation highlights the need to rethink the cyber‑security perimeter—not only around large hydroelectric or nuclear plants, but also toward the myriad of small residential and commercial photovoltaic installations distributed across the territory. Those who manage a photovoltaic installation today depend on global components whose cybersecurity was traditionally not considered a parameter of stability for the Swiss electricity grid. The growing digitalization of the energy transition therefore imposes a radical shift in technological‑risk management on the part of installers, manufacturers, and grid operators.

Recommended tools

For an updated estimate, use the net salary calculator and the CHF-EUR exchange comparator.

Key points

Faced with the critical issues that emerged from cybersecurity tests, the institute recommends the immediate adoption of concrete preventive measures for all owners of photovoltaic systems and for operators in the sector. Practical indications include the strict use of individual access credentials, the strengthening of remote access and the physical or logical separation of photovoltaic systems from the rest of the company or home network. Manufacturers are also encouraged to integrate advanced security standards already in development and implement digital authentication for any software updates.

Regulatory requests and future prospects

Institutionally, the institute calls on policy and federal authorities to introduce mandatory minimum requirements for all devices placed on the Swiss market. Cybersecurity should become a formal and essential requirement for the connection of any photovoltaic system to the national electricity grid. To deepen the aspects related to the management of the house, the protection of buildings and the economic and structural implications related to the real estate and residential sector, you can consult the dedicated resources on the portal, such as home renovation and security.

For a precise net salary calculation, use our tax comparator: compare take-home pay between G and B permits with all 2026 deductions.

Source: swissinfo.ch

Frequently Asked Questions
What products have been tested by the National Cybersecurity Testing Institute?
The National Cybersecurity Testing Institute examined eleven widely distributed products belonging to eight companies. The devices examined include in particular seven inverters, which are the electronic devices in charge of transforming direct current into alternating current, and four energy management systems. Overall, over fifty vulnerabilities were identified in the devices analysed.
What are the main technical criticalities found in the devices?
The technical analysis showed that in almost all the inverters tested, the technicians were able to reduce the power fed into the grid to zero without any need for authentication. Additional vulnerabilities identified include the use of preset passwords, unprotected maintenance logins, and insufficient encryption that exposes components to unauthorized intrusion. Despite this, no intentionally entered backdoor indications were found.
What measures does the institute recommend for owners and operators?
The institute recommends the immediate adoption of concrete preventive measures, including the strict use of individual access credentials, the strengthening of remote access and the physical or logical separation of photovoltaic systems from the rest of the company or home network. Manufacturers are also encouraged to integrate advanced security standards already in development and implement digital authentication for any software updates.

Related articles