A wind turbine on a distant ridge still looks like old-fashioned physical infrastructure. So does a field of solar panels beside a highway. But increasingly, each is also part of a digital system that can be reached, monitored, and sometimes controlled from somewhere else. That shift matters. The green transition is not only adding generation capacity; it is also adding digital entry points to the infrastructure that produces and distributes energy.
Dutch researchers working with the Netherlands’ National Cyber Security Centre reported this week that 8,547 wind and solar systems across 35 European countries were improperly exposed to the internet. Reuters reported that around 181 sites appeared to offer interfaces capable of operational control, including actions such as turning turbines on or off.
The immediate lesson is obvious: exposed administrative interfaces should not be sitting openly on the internet. The larger lesson is less comfortable. We are building critical infrastructure faster than we are learning to count all the ways it can be reached.
I do not see this as an argument against renewable energy or connected infrastructure. Quite the opposite. Connectivity is one of the reasons modern energy systems can be monitored, maintained, and balanced efficiently. Remote access can reduce downtime and allow specialists to diagnose equipment without travelling to every site. Digital systems can make energy infrastructure more efficient and resilient.
The problem begins when convenience and authority travel through the same digital doorway without enough separation between them. The ability to monitor a turbine remotely is useful. The ability to issue a command to that turbine through the same pathway carries a very different level of risk.
Morocco’s renewable ambitions make this European finding especially relevant. Large projects attract attention, but the harder security challenge often sits at the edge: remote devices, vendor accounts, maintenance portals and smaller connected assets that do not look dramatic enough to be treated as critical.
That is precisely where cybersecurity can become an operational blind spot. A system does not have to look like a power plant to have consequences for one.
This is where I think the usual cybersecurity question is too narrow. We often ask whether a device is secure. Operators should also ask three simpler operational questions: Who can reach it? What authority does that access provide? What physical consequence can follow?
I think of this as a Reach–Authority–Consequence test. A public dashboard, a maintenance portal, and a command interface may all be connected to the same asset, but they should never be treated as if they carry the same risk. Knowing that a system is connected is only the starting point. Operators need to understand what that connection permits and what could happen if it were misused.
The distinction becomes important in distributed energy. A traditional power station concentrates equipment, people and security controls in a relatively bounded place. Renewable systems distribute assets across rooftops, farms, industrial sites and remote terrain. That is a strength for generation, but it also distributes the security problem. Energy decentralisation creates security decentralisation. Every new inverter, turbine controller, gateway, vendor account and remote-maintenance path can become part of the operational perimeter.
As Morocco prepares infrastructure for a decade of investment and major events, resilience will depend on whether operational technology is protected as part of the national infrastructure story, not added later as a specialist concern.
There is a useful connection here with what the UAE announced on 6 October. The UAE Cyber Security Council and SCC Middle East said they plan to establish a Centre of Excellence for Cyber Resilience and Trusted Technology where government, industry and specialists can test real use cases and examine how technologies can be adopted securely at scale. What interests me is not the existence of another technology centre. It is the emphasis on proving how technology behaves in the environment where it will actually be used. That is exactly the habit critical infrastructure needs.
A procurement checklist can tell an organisation that a product supports encryption, authentication or logging. It cannot by itself tell an operator what happens when a contractor account is compromised at 2 a.m., whether a remote command can bypass a local safeguard, or how quickly a control room can isolate a connection without taking down the service it is trying to protect. Those questions need exercises, test environments, and people from operations, engineering, and cybersecurity sitting at the same table.
The practical response does not have to begin with an expensive new platform. Asset owners can start by identifying every internet-reachable operational interface, removing public exposure that is not necessary, separating monitoring from command authority, tightening vendor access, and testing whether operators can revoke remote privileges quickly. Most importantly, they can map digital access to physical consequence. A credential that can only read performance data is not the same as a credential that can stop equipment. Security architecture should make that difference visible.
I would also resist the instinct to turn every discovery into a story about an inevitable cyber catastrophe. The researchers found exposure and potential control paths; that is serious enough without exaggeration. There is a difference between identifying a vulnerable interface and claiming that an attack has occurred or that a major disruption is inevitable.
Good security culture is built on precision. If we overstate every weakness, operators eventually stop listening. If we understate reachability, we discover too late that a digital convenience had become operational authority. The objective should be neither alarmism nor complacency, but a clear understanding of where digital access intersects with physical infrastructure.
Morocco and the UAE have both treated renewable energy as part of a wider development strategy. The next step is to make operational reachability a design question from the beginning.
The green transition will put more intelligence at the edge of the energy system. That is not something to fear. It is something to design for. The next generation of resilient infrastructure will not be defined by how few devices are connected, but by whether every connection has a reason, a boundary, and a consequence the operator understands.








