Key Takeaways

  • Centrii says nation-state access to operational technology and ransomware are raising utilities’ operational and financial exposure.
  • Concentrated mineral, solar, and wind-component supply chains create another potential point of disruption.
  • Utilities can reduce risk through stronger asset visibility, network segmentation, supplier oversight, and tested recovery plans.

Centrii is warning energy-sector leaders to treat cybersecurity and renewable supply-chain concentration as parts of the same resilience problem. One threat can disrupt the systems controlling electricity. The other can delay access to the equipment and materials needed to restore, maintain, or expand them.

That convergence matters because electric infrastructure is becoming more digital as utilities add distributed energy resources, automated substations, smart meters, remote maintenance, and software-connected generation. Those technologies can improve grid management. They also create more connections between traditional IT environments and operational technology, or OT, where an incident can have physical consequences.

The scale of hostile activity is already substantial. U.S. energy and utilities organizations faced more than 1,160 cyberattack attempts per week per organization in 2024, a 70% year-over-year increase, according to Check Point Research data cited in CSIS’s 2026 analysis (source). China, Russia, and Iran together accounted for roughly two-thirds of 62 attributed recent cyberattacks against the energy sector in that analysis.

Not every intrusion is intended to cause immediate disruption. Campaigns such as Volt Typhoon have drawn attention because they involve pre-positioning inside critical-infrastructure networks, potentially giving an adversary options during a future geopolitical crisis. That changes the defensive calculation. A utility may be dealing with quiet, persistent access rather than a conspicuous attack that triggers alarms right away.

Criminal ransomware presents a different but overlapping problem. It can interrupt business operations, delay field work, compromise billing or customer systems, and create measurable financial exposure. If attackers move from enterprise IT into poorly segmented operational environments, the stakes rise sharply. Recent energy-sector risk assessments from Quorum Cyber and Shieldworkz reflect the growing focus on OT, industrial control systems, and SCADA environments.

Cyber resilience alone does not solve the broader physical supply chain exposures Centrii identifies.

The IEA reports that a single country is the dominant refiner for 19 of 20 strategic energy minerals, with an average share of about 70%. By November 2025, more than half of those minerals had faced export controls. Solar-PV supply-chain concentration is projected to remain above 90% in key production segments through 2030, while China supplies about 90% of the rare-earth magnet production used in wind turbines.

That concentration can amplify the impact of trade restrictions, political disputes, transportation interruptions, or manufacturing bottlenecks. What happens if a cyber incident damages equipment just as replacement components become difficult to source? Recovery planning based only on data backups may look increasingly incomplete.

The operational consequences are not theoretical. The IEA says recent annual disruptions to critical energy infrastructure affected supplies serving more than 200 million households globally. Transmission and distribution grids appeared in about 85% of the incidents (source). Cyberattacks were not the sole cause, but the figures illustrate how much economic and social activity depends on infrastructure with little tolerance for prolonged downtime.

For utility executives, the response starts with visibility. Operators need an accurate inventory of OT assets, firmware, communications paths, remote-access accounts, and vendor dependencies. Tools from OT-security vendors such as Dragos and Nozomi Networks can support monitoring and anomaly detection, although technology works better when paired with clear incident authority and practiced operating procedures.

Segmentation can also limit movement between corporate systems and control networks. Multifactor authentication for remote access, tightly managed vendor sessions, offline recovery materials, and exercises involving both cyber and field teams can further reduce exposure. NIST Cybersecurity Framework 2.0 offers a governance structure, while NERC Critical Infrastructure Protection standards provide requirements for applicable bulk electric system assets.

Supply-chain planning deserves similar discipline. Utilities can map single-source dependencies, assess lead times for critical components, qualify alternative suppliers where practical, and incorporate geopolitical scenarios into procurement decisions. Holding every component in reserve would be expensive and unrealistic. Prioritizing items with long replacement times or few available suppliers is more workable.

Centrii’s warning ultimately pushes energy security beyond the security operations center. Cyber teams, engineers, procurement leaders, finance executives, and boards increasingly share the same risk picture. The organizations that connect those functions can be better positioned to detect hidden access, contain ransomware, source replacement equipment, and keep essential services operating when multiple pressures arrive at once.