PLC Security Flashpoint: Lithuania Pulls Plug on Insecure Solar Assets

PLC Security Flashpoint: Lithuania Pulls Plug on Insecure Solar Assets

PLC Security Flashpoint: Lithuania Pulls Plug on Insecure Solar Assets

Europe's accelerating green energy transition is connecting tens of thousands of programmable logic controllers (PLCs) and industrial control systems to national power grids , and with them, an expanding attack surface that most operators have not adequately secured. Lithuania has just become the first EU member state to draw a hard line: grid operators can now disconnect solar plants over 100kW t

3 min readContent reviewed

Detail

, elevating it from an operational concern to a matter of national energy sovereignty.

The legislation, effective for new projects since May 1, 2025, targets the remote-access capabilities embedded in modern inverters , devices that sit at the intersection of power electronics and networked industrial control. With 79 MPs voting in favour of the amendment to Lithuania's Law on Electricity, the message is unambiguous: the era of connecting critical energy assets to the grid without verified cybersecurity controls is over.

For much of the industrial automation community, the term “PLC” conjures images of ruggedized controllers on factory floors. But in renewable energy deployments, the inverter functions as a de facto PLC , executing real-time control logic, communicating over industrial protocols, and increasingly, maintaining persistent cloud connections to vendor servers located in jurisdictions beyond European regulatory reach.

These devices manage grid synchronization, power quality, and fault response. If compromised, an attacker could theoretically command thousands of distributed assets simultaneously , a scenario that moves well beyond data theft into the realm of physical infrastructure sabotage. The 2024 Deye inverter incident, where units across North America were remotely disabled via firmware-level lockout commands, demonstrated that this is not hypothetical.

The convergence of IT, OT, and IoT in renewable energy has created a threat landscape where a vulnerability in a cloud-connected inverter is indistinguishable from a vulnerability in a grid substation PLC. According to Forescout's 2025 OT/ICS vulnerability report, the ICS cybersecurity risk level hit a record high , 508 advisories covering 2,155 vulnerabilities. Energy infrastructure, once air-gapped by design, now presents one of the fastest-growing attack surfaces globally. The Energy & Utilities sector is experiencing 25% year-over-year IoT expansion, outpacing most other critical infrastructure verticals.

Lithuania's amendment to the Law on Electricity requires operators of power plants exceeding 100kW to implement “additional safeguards” for information management systems and connected inverters. Crucially, the legislation designates “hostile countries” , as defined by the country's National Security Strategy , and imposes restrictions on remote access originating from equipment manufactured in those jurisdictions.

The European Solar Manufacturing Council (ESMC) has publicly endorsed the Lithuanian approach, calling for wider EU adoption of similar policies. This signals a broader regulatory trajectory: cybersecurity compliance is shifting from voluntary best practice to statutory requirement , with teeth.

Sourcing help

Send the BOM for one quote covering active stock, EOL stock and cross-references.

Need a quote for this part?

Send us the part number or article link — we will confirm price, availability and lead time.

WhatsApp us

Related Articles

Retour au blog