cybersecurity
Connected solar systems expose Switzerland’s power grid to cyber risks
Cybersecurity experts warn that internet-connected solar inverters could be exploited to disrupt parts of Switzerland’s electricity network. The article should explain how inverter vulnerabilities work and what operators, manufacturers and households can do to reduce systemic risk.

Solar’s rapid growth opens a new grid exposure
More than 338,000 photovoltaic systems are now connected to Switzerland’s electricity grid, turning rooftop solar into a major part of the country’s energy transition. The rapid buildout also creates a new point of exposure: the inverter, the device that converts electricity from solar panels into the alternating current used by the grid.
A warning from the National Test Institute for Cybersecurity, or NTC, places that equipment under fresh scrutiny. The institute’s unpublished study, obtained by Swiss public broadcaster SRF, says weaknesses in inverters could allow attackers to disrupt parts of the national power network.
Most modern inverters connect permanently to the internet through built-in communication modules. They exchange data with servers operated by manufacturers, enabling remote maintenance and system management. Andreas Leisibach, an NTC cybersecurity expert, told SRF that the same links could be used to switch devices off or manipulate them.
The risk matters because solar generation is distributed across homes, businesses, farms and public buildings. A failure affecting many systems at once would not resemble an outage at one power plant. It could involve thousands of installations sharing the same software, supplier or remote-control infrastructure.
The inverter puts remote control in the spotlight
The inverter acts as the control centre for each photovoltaic installation, making its security more important than its small size might suggest. It receives the direct current produced by solar panels, converts it into grid-compatible alternating current and can communicate with external systems.
That connectivity supports legitimate functions such as diagnostics, updates and remote servicing. It also creates a pathway through which a compromised account, vulnerable server or malicious command could affect equipment in the field. The NTC has examined Swiss solar inverters for the first time and identified remote control as a central concern.
Raphael Reischuk, the institute’s founder, said control over an inverter gives influence over the entire installation and, ultimately, over the electricity grid. A coordinated shutdown could remove a substantial amount of generation at a moment when the system is operating close to capacity.
The study does not say that such an attack is under way in Switzerland, and it does not establish that manufacturers intend to cause disruption. Reischuk said companies could be pressured by state actors or targeted by criminals seeking extortion. The exposure comes from the combination of remote access, common suppliers and a growing number of connected devices.
A concentrated market magnifies the risk
Around 100,000 Swiss solar installations use inverters from China, according to estimates from the Federal Office of Energy. Huawei and Sungrow together account for more than 60% of the Swiss inverter market, while more than half of newly installed inverters come from Huawei.
The figures point to concentration risk. If many devices share the same manufacturer, firmware or cloud platform, one vulnerability could affect a large number of systems. The concern does not depend on an individual homeowner making a poor security choice. It can arise from market structure, procurement decisions and the design of vendor-managed services.
The issue is visible at the Bern vocational school, where solar company Clevergie is installing a rooftop system with Huawei inverters. CEO Lukas Meister described the equipment as reliable and competitively priced. Those considerations help explain why a small group of suppliers has gained ground, but they do not resolve the question of how Switzerland should manage systemic exposure.
The Federal Office of Energy has only recently begun collecting more detailed data. Better information about brands, models, locations and remote-control capabilities would help authorities estimate how much generation could be affected by a common failure or coordinated attack.
An overseas shutdown exposes the practical stakes
A previous overseas incident shows that remote shutdown is more than a theoretical capability. Swissinfo reports that a Chinese manufacturer remotely disabled large numbers of inverters in the United States and other countries during a commercial dispute. Some users saw an error message stating, “Not allowed to use”.
The episode did not involve an attack on Switzerland’s grid, and the source does not identify it as a cyberattack. It does show that manufacturers can retain meaningful control over equipment after installation. For Swiss operators, that raises practical questions about account ownership, cloud dependence, software updates and the ability to operate systems locally if a vendor connection fails.
The potential impact would vary with timing. A simultaneous shutdown during high solar production could remove a large amount of electricity from the system. Manipulating output could also complicate balancing for grid operators. The NTC warning focuses on the possibility of disruption, not on a forecast that it will occur.
Switzerland’s decentralised energy model makes technical visibility essential. Authorities need to know which devices are installed, who can access them remotely and how quickly operators can isolate compromised systems. Without that information, estimating the effect of a common vulnerability remains difficult.
Swissolar pushes for rules before the fleet grows
Swissolar is calling for binding cybersecurity standards and a central registry of remotely controllable generation. The industry association wants clearer rules as solar becomes a larger component of the national electricity system.
A registry could help authorities measure concentration by manufacturer and identify how much capacity depends on external servers. Standards could set requirements for authentication, software updates, vulnerability reporting, local operating modes and access by installers or grid operators. The source does not specify which measures Swissolar wants included, leaving regulators to define the technical framework.
The challenge spans several parts of the Swiss energy system. Federal authorities need reliable inventory data. Distribution network operators need procedures for detecting abnormal commands and restoring affected installations. Manufacturers and installers need to explain how remote access works throughout a product’s lifespan. Owners also need practical guidance, especially when systems are managed through vendor platforms.
Switzerland has expanded renewable electricity quickly, ranking fifth in Europe for renewable electricity generation per capita according to a related Swissinfo report. Solar’s continued growth will add more connected equipment. The NTC findings give policymakers a reason to address inverter security while the market is still expanding, rather than after a major disruption.