Your solar inverter talks to a server far away so you can watch an app. Multiply that by millions and a country may have built something dangerously close to an off switch.
Strange traffic on my own network
A few years ago we had solar panels installed on our roof in the Netherlands. The installer clicked the inverter onto the wifi and from that day I could watch my panels produce power in an app. A green graph on every sunny day. A small hit of pride, every single morning. Until one evening, out of professional curiosity, I looked at the traffic on my own home network and saw something I had not switched on. My inverter had spent the entire day talking to a server on the other side of the world.
Nobody had told me. The panels sat on the roof, the box hung in the meter cupboard and meanwhile it was cheerfully sending data out into the world. No malice. Just the default setting. Most modern, cloud-connected inverters work this way, because that is what makes the app possible. And that is how millions of Dutch homes ended up with a device on the internet that can do far more than draw a graph.
To understand why this matters far beyond one Dutch living room, you need to know what my country did to its energy system in the past ten years. Because we did something remarkable. We built one of the most electrified, most connected energy systems on earth. And we did it fast.
How the Netherlands electrified everything in ten years
For two decades the Dutch government made rooftop solar an offer you could hardly refuse. Under the net metering scheme, every kilowatt-hour you exported was credited at the full retail rate, energy tax included. Since 2023 solar panels carry zero percent VAT. Payback times dropped below six years. The result: the Netherlands became Europe’s solar champion per capita. Roughly a third of Dutch households now has panels on the roof, installed inverter capacity sits around 26 gigawatts and nearly one fifth of the electricity produced in the Netherlands in 2025 came from solar.
We did the same with driving. The Netherlands ended 2025 with about 210,000 public charging points, the most of any country in Europe and the densest network per capita in the world. Well over half a million fully electric cars draw from it. Heat pumps are replacing gas boilers street by street.
And now the home battery has exploded. Net metering ends on 1 January 2027, so storing your own solar power suddenly pays. Add negative electricity prices on sunny afternoons and the result is a gold rush: roughly 88,000 home batteries were installed in 2025 and the total number of systems in Dutch homes doubled in a single year to around 167,000. Energy companies increasingly steer panels, inverters and batteries automatically, switching them on and off to trade on power markets. Smart. It relieves a congested grid. But notice what just happened. The cloud connection stopped being a convenience. It became load-bearing.
Wired to clouds nobody here controls
Here is the uncomfortable part. The inverter is the heart of every solar installation. It converts the DC from your panels into AC for the grid and most modern ones can be monitored or controlled remotely: throttle the power, change settings, switch off. Useful for maintenance. Just as useful for someone else.
The Dutch digital infrastructure authority RDI tested nine widely used inverters back in 2023. None of the nine met the cybersecurity standard it applied. Default passwords nobody changes. Updates that rarely arrive. Traffic routed through the manufacturer’s cloud.
And that market is extraordinarily concentrated. According to the European Solar Manufacturing Council, citing research by DNV commissioned by SolarPower Europe, more than 200 gigawatts of European solar capacity already runs on inverters made in China, which the council compares to the output of more than 200 nuclear power plants. Seventy percent of all inverters installed in Europe in 2023 came from Chinese vendors, mainly Huawei and Sungrow, and those two companies alone hold remote access to 168 gigawatts of European capacity. By late 2025 the council put the Chinese share of new European solar systems at around 80 percent and the European Union’s new Economic Security Doctrine now flags this dependence as high-risk. The ESMC represents European manufacturers, so it has skin in this game. But the underlying numbers come from DNV and the direction is difficult to dismiss: the remotely reachable fleet is large, concentrated and growing, projected to exceed 400 gigawatts in Europe by 2030.
Is anyone abusing that access? Honesty requires nuance here. In May 2025 Reuters reported that US experts had found undocumented communication devices in some Chinese inverters and batteries, components that could in theory talk past a firewall. A follow-up analysis by the US Department of Energy found no definitive evidence of deliberately malicious hidden functions in the inverters it examined. So the most dramatic spyware claim remains unproven. What has not cooled is the incident of November 2024, when inverters in the United States and elsewhere were switched off remotely from China. Scale, motive and impact were never fully established. But it happened. Lithuania did not wait for the debate to settle: in November 2024 it adopted legislation restricting remote access from Chinese manufacturers to its larger solar, wind and battery installations.
One vulnerable box in one meter cupboard is a household problem. Millions of identical boxes, sharing the same firmware and the same clouds, are something else entirely. They stop being separate devices. They become one button. The only open question is whose hand is on it.
What one bad afternoon looks like
If you want to know what happens when a modern grid takes a sudden hit, you no longer need a simulation. On 28 April 2025, at 12:33 in the afternoon, the lights went out across Spain and Portugal. It was not a cyberattack. European grid operators concluded the blackout was triggered by cascading overvoltage, a chain of voltage-control failures in which generation tripped offline in rapid succession. Within about twenty seconds the Iberian grid collapsed.
Some 60 million people lost power, many of them for around ten hours. Mobile networks failed. Card payments dropped sharply, so shops that were open often could not sell. Trains stopped between stations. Hospitals switched to emergency generators. Several deaths were linked by authorities and media to circumstances around the outage, such as generator fumes and candle fires. Spain’s main business federation CEOE estimated the cost of that single day at 1.6 billion euros. The meat industry alone reported losses of up to 190 million euros as refrigeration failed.
Now connect this to the inverters. Researchers at SolarPower Europe and DNV calculated that a targeted compromise of just 3 gigawatts of solar capacity could have significant implications for European grid stability. That number is not arbitrary. Three gigawatts is exactly what continental Europe can absorb within 30 seconds using its primary reserve, the fast-reacting buffer of batteries, hydro and gas plants. Lose more than that, faster than that, and you are beyond the safety net. Dutch grid operator TenneT’s senior advisor Jan Vorrink put the governance problem in one sentence: you do not want to depend on the goodwill of ethical hackers.
And this is not just theory living in my head. In a study commissioned by the Dutch government, security firm Secura and the Top Sector Energy worked out three scenarios in the report Secure Solar Power: a criminal who breaches a cloud portal and holds the inverters behind it to ransom, a poisoned software update that hijacks an entire fleet in one move and a state actor that plants a backdoor in the supply chain and waits. The researchers added a telling technical recommendation: build a maximum switching frequency into inverters, a brake on how often a device may flip on and off in rapid succession. Because rapid switching, not the off state itself, is what hurts a grid most.
The island mirror
I spend a lot of time on the ABC islands, Aruba, Bonaire and Curaçao. Power interruptions there are part of life in a way they simply are not in the Netherlands. Nobody enjoys them. They cost money, they spoil food, they stop work. But people expect them. Hotels have generators that start within seconds. Households keep water, cash and charged power banks. Businesses know which processes stop and which must not.
Curaçao got a brutal reminder on 26 and 27 August 2025, when an island-wide blackout left it without power for roughly half a day. The trigger was a sudden change in wind strength that set off voltage swings, after which the island’s installations shut down in sequence. Aqualectra’s chief technical officer later told parliament that 25 separate incidents occurred within half an hour. Read that again next to the Iberian timeline. A small Caribbean grid and the European mainland failed in exactly the same way: a sudden disturbance, a cascade, a collapse in seconds. The physics does not care how big you are.
Here is the difference that should worry the Netherlands. After its blackout, Curaçao held parliamentary hearings, started monthly resilience meetings between the utility, government and business sector and accelerated a battery storage system and a new power plant. The island is building muscle on top of muscle it already had. The Netherlands, meanwhile, runs one of the most reliable grids on earth. More than 99.99 percent uptime. The average Dutch customer lost power for 21.8 minutes in all of 2023 and 23.9 minutes in 2024, one brief interruption every three to four years. That is a magnificent achievement. It is also why we have no muscle memory at all.
The Dutch government knows it. In March 2025 it raised the self-reliance norm from 48 to 72 hours, telling citizens they should be able to cope for three days without help. A national campaign followed, explicitly citing the Spanish blackout. The result so far: by April 2026, 44 percent of Dutch people had an emergency kit at home, according to the government’s own campaign survey. Real progress. And still a majority that has nothing. A think tank of prominent Dutch economists now proposes national practice days on which the country deliberately rehearses life without power, water or internet. On Curaçao they do not need to schedule that. Reality runs the exercise for them.
The business blind spot
Most of the resilience conversation focuses on households, candles and canned soup. The bigger exposure sits in business, and in the Netherlands specifically in the SME segment that forms the backbone of the economy.
Walk through what twelve dark hours actually do to a small or medium-sized company. Card payments are gone, and in the Netherlands hardly anyone carries cash, so revenue stops at the door. Refrigeration fails, so a restaurant, butcher or pharmacy starts writing off stock by the hour. Production lines stop and some, like ovens and process installations in Spain, are damaged by the stop itself. Phone and internet follow within hours as backup batteries in the telecom network drain. Staff cannot work, customers cannot reach you and your cloud-based administration is exactly as available as your power socket. Spain’s numbers give the scale: 1.6 billion euros in one day, and that pain was not spread evenly. Large companies had generators and insurance teams. The corner businesses absorbed the hit directly. For an SME running on thin margins, a long outage at the wrong moment is not an inconvenience. It is a solvency event.
Three questions every owner and board member should be able to answer. Which of our processes must never stop, and what actually happens to them after hour six? Can we sell, communicate and pay salaries if the region around us goes dark for a day? And who decides what, in the first thirty minutes, when nobody can reach anybody? If those answers do not exist on paper, the plan is hope.
AI is the accelerant
There is one more curve bending upward, and it is the one that turns a slow problem into a fast one. Finding and exploiting software vulnerabilities used to be the craft of a small group of top specialists. That era is ending. According to Anthropic, its restricted model Claude Mythos found thousands of previously unknown vulnerabilities in major operating systems, browsers and other widely used software within weeks, and, in Anthropic’s own words, it surpasses all but the most skilled human experts at this specific craft. That is the maker’s own claim, which is exactly why the signal matters: even read conservatively, it means vulnerability research is becoming faster, cheaper and far more widely available. Anthropic keeps the model locked away and shares it only with vetted organisations. In early June 2026 that circle was expanded by roughly 150 new organisations to about 200 partners in more than fifteen countries, many of them operators of critical infrastructure. And the window is closing on exclusivity: Anthropic says it expects to bring Mythos-class models, with additional safeguards, to all its customers within weeks.
Now place that next to millions of remotely controllable inverters, batteries and charging points that share identical firmware and a handful of clouds. One discovered weakness is no longer one problem. It is instantly a problem on hundreds of thousands of devices at once. Engineers call it common-mode failure: many separate machines suddenly behaving as one big system. The risk does not grow neatly with the number of boxes. It can jump.
Resilience is a skill, and islands are ahead
So no, the answer is not to forbid citizens from connecting their inverter to the internet. That punishes the curious homeowner for a design flaw made far upstream, it is unenforceable and the connectivity now carries real functions, from grid balancing to trading. The answer is upstream: security requirements on the supply chain, open standards so no single vendor owns the off switch, clarity about who is accountable when it goes wrong. Europe is moving, with cybersecurity rules for new devices since August 2025 and the Cyber Resilience Act arriving end of 2027. Moving slowly, while the roofs fill faster than the policy.
But organisations cannot wait for Brussels, and the good news is that the most important layer was never technical. It is people and preparation. The chance that your company is hit by a grid-scale event tomorrow is small. The cost if it happens is enormous and the dependence grows every quarter. You do not reinforce a dike because you expect a flood every Tuesday. You reinforce it because the damage is unacceptable. That mindset, which every islander carries by default, is learnable. It is precisely what I train in my cyber resilience masterclasses: how social engineering really works on your people, how to write an emergency plan that survives first contact with a real incident, how to run the exercise before reality runs it for you, and how to make continuity a board topic instead of an IT footnote. Leaders from island utilities, tourism operators and mainland SMEs sit in the same room for a reason. One side has the muscle memory. The other has the scale. Both leave with a plan.
My inverter still hangs on the network, by the way. Segmented, monitored and with its default password long gone. I did not disconnect the future. I just stopped trusting it blindly. That, in one sentence, is the work.
In-house cyber resilience masterclass
Practical, no jargon and tailored to your organisation. By cyber expert and RESET! author Erik Jan Koedijk, trained by his late friend Kevin Mitnick, the world’s most famous hacker. In Curaçao, The Netherlands, Aruba, Bonaire, Barbados, Sint-Maarten, France, Belgium and the UK 3000+ professionals already joined the masterclasses hosted by Erik Jan.
Cyber resilience is not an IT topic. It is a team skill. In one inspiring four-hour session your people learn how attackers really work, how to recognise manipulation and how to protect the organisation and themselves, at work and at home. No technical background needed.
Tailored before we even start
Every masterclass begins with a thorough intake conversation. Together we map how your organisation communicates, where the human risks sit and what an attacker would try first. The social engineering exercises in the masterclass are then built on your reality, not on generic examples. Your people will recognise the situations, because these could happen tomorrow.
Learned from the master himself
Erik Jan was trained by his late friend Kevin Mitnick, the social engineer who proved that the easiest way into any organisation is through people. Those same techniques are demonstrated live in the masterclass, then turned into practical defences your team can apply the very same day.
You leave with more than awareness
Directly after the masterclass you receive a concrete overview of the processes in your organisation that can be tightened, based on what surfaced during the session. Not a generic checklist, but a starting point for real improvement, ready to discuss with your leadership team.
Included
✅ Intake conversation, so the social engineering exercises match your organisation
✅ Live demo: how freely available online tools reveal which systems expose your organisation, often without anyone knowing
✅ Inspirational knowledge quiz and a certificate for every participant
✅ Direct post-session overview of processes to tighten
✅ Private and in-house, exclusively for your organisation, with up to 20 participants per session
Book now: choose your preferred date and request more information.

