Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Europe
  3. Europe leads the world in exposed solar power equipment, raising alarms on infrastructure security, report finds

Europe leads the world in exposed solar power equipment, raising alarms on infrastructure security, report finds

Scheduled Pinned Locked Moved Europe
europe
7 Posts 6 Posters 28 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • H This user is from outside of this forum
    H This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #1

    Archived

    Security firm Forescout identified almost 35,000 solar power devices from 42 vendors with exposed management interfaces. These devices include inverters, data loggers, monitors, gateways and other communication equipment.

    Key Findings

    • Despite being a rapidly growing renewable energy source, there are security issues with remote inverter management, via cloud applications or direct access to management interfaces within inverters.
    • Internet-exposed solar power devices are much more popular in Europe and Asia than in other regions. Europe accounts for 76% of exposed devices, followed by 17% in Asia and the remaining 8% in the rest of the world. Germany and Greece each account for 20% of the total devices worldwide, followed by Japan and Portugal with 9% each then Italy with 6%.
    • Four of the top 10 vendors with exposed devices are headquartered in Germany, two in China and one each in Austria, Japan, US and Italy. This distribution also does not match the top 10 vendors worldwide by market share, since 9 of those are Chinese.

    Mitigation Recommendations

    • Do not expose inverter management interfaces to the internet.
    • Patch devices as soon as possible and consider retiring those that for some reason cannot be patched.
    • If a device needs to be managed remotely, consider placing it behind a VPN and following CISA’s guidelines for remote access.
    • Follow the NIST guidelines for the cybersecurity of smart inverters in residential and commercial installations.
    W M G 3 Replies Last reply
    27
    • H [email protected]

      Archived

      Security firm Forescout identified almost 35,000 solar power devices from 42 vendors with exposed management interfaces. These devices include inverters, data loggers, monitors, gateways and other communication equipment.

      Key Findings

      • Despite being a rapidly growing renewable energy source, there are security issues with remote inverter management, via cloud applications or direct access to management interfaces within inverters.
      • Internet-exposed solar power devices are much more popular in Europe and Asia than in other regions. Europe accounts for 76% of exposed devices, followed by 17% in Asia and the remaining 8% in the rest of the world. Germany and Greece each account for 20% of the total devices worldwide, followed by Japan and Portugal with 9% each then Italy with 6%.
      • Four of the top 10 vendors with exposed devices are headquartered in Germany, two in China and one each in Austria, Japan, US and Italy. This distribution also does not match the top 10 vendors worldwide by market share, since 9 of those are Chinese.

      Mitigation Recommendations

      • Do not expose inverter management interfaces to the internet.
      • Patch devices as soon as possible and consider retiring those that for some reason cannot be patched.
      • If a device needs to be managed remotely, consider placing it behind a VPN and following CISA’s guidelines for remote access.
      • Follow the NIST guidelines for the cybersecurity of smart inverters in residential and commercial installations.
      W This user is from outside of this forum
      W This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #2

      Patch devices as soon as possible and consider retiring those that for some reason cannot be patched.

      Require all device firmware to be open source, and require all other software to be open sourced the moment it stops receiving sufficient support.

      H V 2 Replies Last reply
      11
      • H [email protected]

        Archived

        Security firm Forescout identified almost 35,000 solar power devices from 42 vendors with exposed management interfaces. These devices include inverters, data loggers, monitors, gateways and other communication equipment.

        Key Findings

        • Despite being a rapidly growing renewable energy source, there are security issues with remote inverter management, via cloud applications or direct access to management interfaces within inverters.
        • Internet-exposed solar power devices are much more popular in Europe and Asia than in other regions. Europe accounts for 76% of exposed devices, followed by 17% in Asia and the remaining 8% in the rest of the world. Germany and Greece each account for 20% of the total devices worldwide, followed by Japan and Portugal with 9% each then Italy with 6%.
        • Four of the top 10 vendors with exposed devices are headquartered in Germany, two in China and one each in Austria, Japan, US and Italy. This distribution also does not match the top 10 vendors worldwide by market share, since 9 of those are Chinese.

        Mitigation Recommendations

        • Do not expose inverter management interfaces to the internet.
        • Patch devices as soon as possible and consider retiring those that for some reason cannot be patched.
        • If a device needs to be managed remotely, consider placing it behind a VPN and following CISA’s guidelines for remote access.
        • Follow the NIST guidelines for the cybersecurity of smart inverters in residential and commercial installations.
        M This user is from outside of this forum
        M This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #3

        Thank god we do not buy or oil and gas from some dicatorship.....

        1 Reply Last reply
        2
        • W [email protected]

          Patch devices as soon as possible and consider retiring those that for some reason cannot be patched.

          Require all device firmware to be open source, and require all other software to be open sourced the moment it stops receiving sufficient support.

          H This user is from outside of this forum
          H This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #4

          Yes, and produce more of this stuff in Europe. And do not expose inverter management interfaces to the internet.

          1 Reply Last reply
          3
          • W [email protected]

            Patch devices as soon as possible and consider retiring those that for some reason cannot be patched.

            Require all device firmware to be open source, and require all other software to be open sourced the moment it stops receiving sufficient support.

            V This user is from outside of this forum
            V This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #5

            ...and require electricians to not think of themselves as IT experts that should have any say in configuring anything beyond maybe actual modbus on two wires.

            1 Reply Last reply
            2
            • H [email protected]

              Archived

              Security firm Forescout identified almost 35,000 solar power devices from 42 vendors with exposed management interfaces. These devices include inverters, data loggers, monitors, gateways and other communication equipment.

              Key Findings

              • Despite being a rapidly growing renewable energy source, there are security issues with remote inverter management, via cloud applications or direct access to management interfaces within inverters.
              • Internet-exposed solar power devices are much more popular in Europe and Asia than in other regions. Europe accounts for 76% of exposed devices, followed by 17% in Asia and the remaining 8% in the rest of the world. Germany and Greece each account for 20% of the total devices worldwide, followed by Japan and Portugal with 9% each then Italy with 6%.
              • Four of the top 10 vendors with exposed devices are headquartered in Germany, two in China and one each in Austria, Japan, US and Italy. This distribution also does not match the top 10 vendors worldwide by market share, since 9 of those are Chinese.

              Mitigation Recommendations

              • Do not expose inverter management interfaces to the internet.
              • Patch devices as soon as possible and consider retiring those that for some reason cannot be patched.
              • If a device needs to be managed remotely, consider placing it behind a VPN and following CISA’s guidelines for remote access.
              • Follow the NIST guidelines for the cybersecurity of smart inverters in residential and commercial installations.
              G This user is from outside of this forum
              G This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #6

              There is no Europe. Just Asia. If a chain of moutain could separate continent then Germany and Italy aren't on the same one

              D 1 Reply Last reply
              0
              • G [email protected]

                There is no Europe. Just Asia. If a chain of moutain could separate continent then Germany and Italy aren't on the same one

                D This user is from outside of this forum
                D This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #7

                You mean the continent Eurasia?

                1 Reply Last reply
                0
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups