Cybersecurity

Cybersecurity in energy assets: beyond regulatory compliance

The ransomware attack on a Colombian distributor — which left thousands unable to pay their bills — shows what's at stake: cybersecurity is no longer a regulatory cost — it's what determines which energy assets stay profitable and which become liabilities.

EnergySage

Ciberseguridad en activos energéticos

In our analysis “Resilient Energy: Designing Tomorrow’s Chilean Power System Today” we argued that resilience must be a central pillar of national energy strategy. Today, after reviewing recent developments and international cases, we go deeper into one specific but critical dimension: how cybersecurity has become a determining factor in investment decisions for generation and storage assets.

A recent analysis by Grid Strategies, discussed in the February 25, 2025 episode of Columbia Energy Exchange, shows that between 2024 and 2029 U.S. electricity demand will grow five times faster than projected in 2022, driven mainly by artificial intelligence and data centers. This explosive growth coincides with a worrying picture: cyberattacks on essential-service operators in Spain, across all sectors, rose 43% in 2024 according to El Periódico de la Energía, while Mexico logged 324 billion attempted cyberattacks over the same period.

Control centers: where an asset is actually monetized

Control centers are far more than an operational obligation: they’re the core from which an energy asset is genuinely monetized. Every MWh dispatched, every ancillary service billed, every revenue optimization through price arbitrage depends on the integrity of these systems.

The case of a Colombian distributor is telling. In 2024, the company suffered a ransomware attack that not only hit its internal systems but left customers unable to pay their bills for weeks. For an investor, this represents a double loss: disrupted operating cash flow and damaged customer relationships.

In Chile, where the NERC-CIP standard adopted by the grid operator (Coordinador Eléctrico Nacional, CEN) has set specific requirements since 2020, we’ve observed a critical gap: many investors view cybersecurity as a regulatory cost, not a value enabler. That view is expensive.

What’s more, it’s essential that investors verify that their technology and critical-service providers fully comply with CEN standards and current Chilean regulations. This verification shouldn’t be superficial: it should include technical audits, incident-response protocols, and business continuity plans that protect the investment.

The new risk equation

The Industrial Cybersecurity Center (CCI) analysis of Latin American hydroelectric plants identifies a scenario every generation investor should consider: dam flooding through cyber compromise. In this scenario, a remotely operated hydroelectric plant — like most modern assets — suffers an attack that compromises the dam’s control systems, with consequences ranging from operational losses to civil and environmental liability.

The Itaipú plant, which supplied 17% of the energy consumed in Brazil and 76% in Paraguay according to the CCI’s 2020 analysis, is currently undergoing a digitalization process that will take more than a decade. This project, per the CCI’s analysis, has “data as its main raw material (…), whose analysis improves the production process and achieves greater efficiency.” But every data point is also an attack vector.

For investors in BESS and LDES assets — segments where EnergySage has identified strategic opportunities — the risk is amplified. These assets depend heavily on control systems that operate in milliseconds and on optimization algorithms that capture price arbitrage. A cyber compromise can turn a profitable asset into an instant operating loss.

What international cases show

The recent x63 Unit report (from Cipher, Prosegur’s cybersecurity division) documents that during the first months of 2025, multiple ransomware campaigns were identified specifically targeting Spanish energy companies. Beyond the media coverage, these attacks reveal patterns every investor should understand:

First, IT/OT convergence is irreversible. The SCADA systems monitoring these assets are no longer isolated. Revenue optimization requires integration with forecasting systems, trading platforms, and advanced analytics.

Second, remote operation is now the baseline. In LDES technologies, the economic viability of many projects depends on operating multiple sites from centralized control centers. The SCADA market will grow from US$41.75 billion in 2024 to US$78.62 billion in 2032, according to Smart Grids Info.

Third, attackers understand the sector’s business model. PIPEDREAM and Triton malware are designed to compromise industrial control systems — such as those running energy infrastructure — not just steal data. These attacks aim to disrupt operations and generate direct economic losses.

Cybersecurity as portfolio strategy

In our conversations with international developers seeking entry into the Chilean market, we see a pattern: those who build in cybersecurity from the project-design stage get better financing and insurance terms. A solar project with robust cybersecurity can access cyber-insurance policies that cover not just system restoration, but also business interruption losses.

The strategic imperative for Chile

The NERC-CIP standard implemented by the CEN is just the floor, not the ceiling. Treating it as mere compliance leaves opportunities for competitive differentiation uncaptured. In a spot market like Chile’s, where every MWh counts, the ability to operate securely can be the difference between being a price-taker and a price-maker.

The data is stark: in Spain, according to the same x63 unit, the energy sector accounted in 2024 for 9% of cyberattacks on essential-service operators. Extrapolated to Chile, with its growing digitalization and remote operation, the country is building assets in an environment of rising threat.

For investors and developers who recognize this reality, EnergySage offers a strategic perspective that combines energy business analysis with specialized access to cybersecurity legal expertise. Through our established partnership with legal specialists in energy cybersecurity regulatory frameworks, we structure assessments that go beyond technical compliance toward genuinely protecting investment value.

Cybersecurity isn’t just another operating expense: it’s critical infrastructure that determines the long-term economic viability of any digitalized energy asset.

The energy transition isn’t just technological — it’s digital. And digital, by definition, is vulnerable. Investors who understand cybersecurity as a value enabler, not a regulatory cost, will build more resilient and profitable portfolios.

On the path toward a 24/7, emissions-free energy mix — “putting the sun in the night” — cybersecurity isn’t optional. It’s the invisible infrastructure that will determine which assets thrive and which become operating liabilities.

How to cite this analysis

EnergySage (2025). "Cybersecurity in energy assets: beyond regulatory compliance". Published Jun 2, 2025. https://energysage.cl/en/analisis/ciberseguridad-activos-energeticos-regulatorio/

Plain-text version (Markdown)

Let's talk

Our first conversation is about understanding where you stand. Direct and to the point.

Write to us at

[email protected]

Open in Gmail Open in Outlook