Pick Your Poison: Navigating a secure clean energy transition

Emma Stewart

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

Emma Stewart's DEF CON 32 talk, "Pick Your Poison: Navigating a secure clean energy transition," delivers a stark warning about the often-overlooked national security implications of the global shift towards renewable energy. While the imperative to combat climate change drives a rapid expansion of solar, wind, and energy storage technologies, this transition is inadvertently creating profound vulnerabilities within critical infrastructure. Stewart highlights the overwhelming reliance on foreign, predominantly Chinese, manufacturing for the digital components that form the backbone of these new energy systems, posing a significant and immediate threat to grid stability and national security.

Watch on YouTube

Visual summary for Pick Your Poison: Navigating a secure clean energy transition by Emma Stewart
Visual summary for Pick Your Poison: Navigating a secure clean energy transition by Emma Stewart

Key moments

  1. 20:00 Energy storage: immediate grid stabilization examples
  2. 22:00 Discovering Chinese dominance in renewable energy supply chain
  3. 24:00 Camp Lejeune battery: a clear national security concern
  4. 26:00 Traditional vs. modern power grid explained
  5. 28:00 The transition's critical security challenge: foreign manufacturing

Pick Your Poison: Navigating a secure clean energy transition

Speakers: Emma Stewart

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=PZfM1ehcfmU

Overview

Emma Stewart's DEF CON 32 talk, "Pick Your Poison: Navigating a secure clean energy transition," delivers a stark warning about the often-overlooked national security implications of the global shift towards renewable energy. While the imperative to combat climate change drives a rapid expansion of solar, wind, and energy storage technologies, this transition is inadvertently creating profound vulnerabilities within critical infrastructure. Stewart highlights the overwhelming reliance on foreign, predominantly Chinese, manufacturing for the digital components that form the backbone of these new energy systems, posing a significant and immediate threat to grid stability and national security.

The core of Stewart's presentation reveals a critical paradox: the very solutions designed to secure our environmental future are introducing new vectors for cyber and geopolitical risk into the power grid. She meticulously details how the energy sector's modernization efforts, driven by both climate necessity and economic efficiency, are leading to a fundamental architectural change in the grid. This shift from large, traditionally manufactured, centralized generators to a vast network of distributed, digitally controlled, and often foreign-made solid-state devices creates a complex web of supply chain vulnerabilities that demand urgent attention from defenders, policymakers, and industry leaders alike.

This talk is crucial for anyone involved in cybersecurity, critical infrastructure, energy policy, or national defense. It provides a grounded, real-world perspective on the challenges of securing a rapidly evolving energy landscape, moving beyond theoretical threats to highlight tangible examples of compromised supply chains and geopolitical tensions. Stewart’s insights underscore the urgent need to balance environmental goals with robust security considerations, ensuring that the clean energy future is not only sustainable but also resilient against state-sponsored threats.

Background

▶ Watch: Energy storage: immediate grid stabilization examples (20:00)

The global energy landscape is undergoing a profound transformation, driven primarily by the urgent need to address climate change. The energy sector, responsible for approximately 28% of global emissions, is actively transitioning towards cleaner, more digital, and affordable systems. This involves a massive deployment of renewable energy sources like solar and wind, coupled with increasingly vital energy storage solutions. For instance, Stewart notes that the MGM Grand in Las Vegas boasts the world's largest solar rooftop, while regions like Texas and California have seen over 17 emergency dispatches of battery storage in recent years to prevent blackouts, demonstrating the immediate and critical role of these new technologies in grid stability. In January of this year, a gigawatt of batteries rapidly ramped up in Texas to stabilize the grid during an emergency, showcasing their pivotal role.

Historically, the power grid has operated on a centralized model, with electricity flowing from large, often US-manufactured, spinning generators through transmission lines down to consumers. These traditional systems, built on robust, long-standing infrastructure, have offered a high degree of reliability and a relatively secure supply chain. However, the clean energy transition is fundamentally altering this architecture. The new paradigm involves a vast number of distributed energy resources (DERs), such as solar panels, electric vehicles (EVs), and especially energy storage systems (ESS) like batteries, all interconnected and digitally controlled. This shift means that where there was once one large generator, there might now be 10,000 smaller, digitally integrated devices contributing to the grid.

A critical challenge emerging from this transition is the overwhelming reliance on foreign manufacturing for these new digital components. Stewart recounts a pivotal observation at a major renewable energy conference, where she noted that "about 95 to 100% of our digital components available right now have a Chinese made, owned or derived control or software component in it." This isn't a hidden or covert issue; it was plainly evident on the expo floor, where the vast majority of exhibitors were Chinese companies. This supply chain dominance creates a significant national security risk, particularly given known adversarial intentions. A stark example cited was the April 2023 commissioning of a large battery system on Camp Lejeune, a major US military base, which involved CATL, one of the world's largest battery manufacturers and a Chinese company. Despite a public ribbon-cutting ceremony, this deployment quickly raised security concerns, leading to the utility announcing the disconnection of the battery in December of the same year due to these very issues. This incident, along with the broader supply chain observations, highlights the profound and immediate security challenges inherent in the ongoing clean energy transition.

Key Findings

▶ Watch: Discovering Chinese dominance in renewable energy supply chain (22:00)

The central and most critical finding of Emma Stewart's talk is that the global clean energy transition, while imperative for climate action, is simultaneously introducing profound and systemic national security vulnerabilities into critical infrastructure. This is primarily due to an overwhelming and largely unaddressed reliance on foreign, specifically Chinese, manufacturing for the digital components underpinning renewable energy technologies.

Stewart's key findings can be summarized as follows:

  1. Dominance of Chinese Supply Chain: A staggering "95 to 100% of our digital components available right now have a Chinese made, owned or derived control or software component in it." This observation, made directly on the expo floor of the world's largest renewable energy conference, indicates a near-monopoly on critical hardware and software components vital for solar, battery storage, and other distributed energy systems.
  2. Architectural Shift and Increased Attack Surface: The grid is transitioning from a system of large, centralized, typically US-manufactured spinning generators to a vast, distributed network of "massive distributed connected solid-state devices" (e.g., solar inverters, battery management systems). This shift from a few large, robust, and often mechanically controlled points to thousands of smaller, digitally interconnected, and remotely managed devices exponentially increases the potential attack surface and complexity for defenders.
  3. Critical Role of Energy Storage and Associated Risks: Energy storage, particularly large-scale batteries, is becoming indispensable for grid stability, capable of rapidly deploying gigawatts of power to prevent outages, as demonstrated in Texas and California. However, these systems, often sourced from dominant Chinese manufacturers like CATL, represent a significant vector for supply chain compromise, as evidenced by the Camp Lejeune incident where a battery system from a Chinese company was ultimately disconnected due to security concerns.
  4. Known Adversarial Intent: Stewart explicitly states that "Chinese hackers are preparing to attack our attack our infrastructure. That is known." This established threat, combined with the deep penetration of Chinese components into the clean energy supply chain, creates a direct and immediate risk of espionage, sabotage, or disruption to critical power systems.
  5. Digitalization and Cloud Adoption Risks: Smaller utilities, in their efforts to modernize, are increasingly adopting cloud-based applications due to the impracticality of maintaining on-premise data centers. While offering operational benefits, this introduces new cybersecurity risks, particularly when these cloud platforms manage geographically dispersed, foreign-manufactured energy assets.

In essence, Stewart argues that the clean energy transition, without a robust and secure supply chain strategy, is inadvertently "picking our poison" by exchanging one set of problems (climate change) for another (national security vulnerability to critical infrastructure).

Technical Deep Dive

▶ Watch: Camp Lejeune battery: a clear national security concern (24:00)

The technical core of Emma Stewart's talk revolves around the fundamental architectural and component-level shifts occurring in the power grid as it transitions to clean energy. This transformation introduces a new paradigm of digital control, distributed assets, and a highly concentrated, foreign-dominated supply chain.

At its most basic, the traditional power grid has relied on synchronous generators – large, spinning machines (e.g., coal, natural gas, nuclear, hydro turbines) that inherently provide rotational inertia and contribute to grid stability. These generators have historically been manufactured with a significant US industrial base. Power flows unidirectionally from these central generation points through high-voltage transmission lines, down to sub-transmission, distribution networks, and finally to end-users. This system, while robust, is centralized and less flexible for integrating intermittent renewable sources.

The clean energy transition is ushering in a new era dominated by solid-state power electronics. Devices such as solar inverters, battery energy storage systems (BESS), and electric vehicle (EV) charging infrastructure are fundamentally different. They do not rely on spinning mass but instead use semiconductors and digital controls to convert and manage electricity. This allows for highly flexible and rapid control, enabling functions like frequency regulation, voltage support, and fast ramp-up/ramp-down capabilities essential for grid stability with intermittent renewables. Stewart highlights that energy storage, in particular, has become a critical resource, capable of immediate control actions to discharge power and prevent blackouts. Examples include gigawatt-scale battery deployments in Texas and numerous emergency dispatches in California, demonstrating their speed and efficacy in mitigating grid emergencies.

However, this technological shift comes with a profound supply chain challenge. Stewart's direct observation at a major renewable energy conference revealed that "about 95 to 100% of our digital components available right now have a Chinese made, owned or derived control or software component in it." This includes not just the physical hardware but also the embedded firmware and software that dictate their operation. Key manufacturers like CATL (Contemporary Amperex Technology Co. Limited), a Chinese company, are global leaders in battery production, supplying critical components for these systems. The implication is that a vast portion of the digital brainpower controlling our future grid infrastructure originates from a nation identified as a significant cyber adversary.

The architectural change further exacerbates this. Instead of a few large, physically secure generators, the grid is moving towards "10,000 smaller devices connected together providing power." Each of these devices, from a residential solar inverter to a utility-scale battery container, is a potential point of entry for cyberattacks. These distributed energy resources (DERs) are increasingly interconnected, often communicating over standard IP networks and managed remotely. This creates a highly distributed and complex attack surface.

Furthermore, the modernization efforts of smaller utilities often involve adopting cloud-based applications for operational management. These utilities, lacking the resources for on-premise data centers, turn to cloud solutions for SCADA, energy management, and asset control. While offering scalability and reduced operational overhead, this introduces reliance on third-party cloud providers and potentially exposes operational technology (OT) data and control interfaces to new cyber risks. The convergence of IT and OT in this context, especially when dealing with foreign-sourced hardware, presents a complex challenge for maintaining cyber-physical security. The known threat of "Chinese hackers preparing to attack our infrastructure" directly intersects with this deep supply chain penetration, raising concerns about potential backdoors, remote manipulation, or data exfiltration capabilities embedded within critical grid components.

Demo / Proof of Concept

▶ Watch: Traditional vs. modern power grid explained (26:00)

The talk "Pick Your Poison: Navigating a secure clean energy transition" by Emma Stewart focused on presenting critical findings and analysis regarding supply chain security in the renewable energy sector. It did not include a live demonstration or a proof of concept of any specific exploit or vulnerability. Instead, the speaker relied on real-world examples and observed trends to illustrate the points made.

Defensive Implications

▶ Watch: The transition's critical security challenge: foreign manufacturing (28:00)

The insights presented by Emma Stewart carry profound defensive implications for critical infrastructure operators, cybersecurity professionals, and policymakers involved in the clean energy transition. The core message is that securing the future grid requires a multi-faceted approach that extends far beyond traditional network perimeter defense.

  1. Supply Chain Risk Management (SCRM) Imperative: The most immediate and critical defensive action is to implement robust Supply Chain Risk Management (SCRM) frameworks specifically tailored for renewable energy components. This means going beyond basic vendor assessments to deeply scrutinize the origin of hardware, firmware, and software. Utilities must demand transparency from suppliers, requiring detailed bills of material (BOMs) and provenance information for all digital components.
  2. Diversification and Domestic Manufacturing: While challenging, efforts to diversify supply chains away from single-source or adversarial nation dependencies are crucial. This includes exploring and incentivizing domestic manufacturing capabilities for critical components like inverters, battery management systems, and control software. Government policies and funding should actively support the development of secure, trusted alternatives.
  3. Enhanced Component Vetting and Testing: All new renewable energy hardware, especially those with embedded digital controls, must undergo rigorous security testing and vulnerability assessment prior to deployment. This includes firmware analysis, hardware teardowns, and penetration testing to identify potential backdoors, hidden functionalities, or undisclosed components. Open-source hardware and software initiatives, where feasible, could offer greater transparency and auditability.
  4. Zero Trust Architecture for DERs: Given the distributed nature of the future grid and the inherent mistrust in many components, implementing Zero Trust principles for managing and communicating with DERs is essential. Every device, user, and application must be authenticated and authorized, regardless of its location or network segment. Strong encryption, secure boot, and tamper detection mechanisms should be standard.
  5. Intelligence-Driven Defense: Critical infrastructure operators must integrate geopolitical and threat intelligence into their cybersecurity strategies. Understanding the capabilities and intentions of state-sponsored actors, particularly those from nations dominating the supply chain, is vital for anticipating attack vectors and prioritizing defenses. The explicit mention of "Chinese hackers preparing to attack our infrastructure" should be a direct call to action.
  6. Policy and Regulatory Action: Governments and regulatory bodies need to establish clear security standards and procurement guidelines for renewable energy technologies in critical infrastructure. This could include mandating secure-by-design principles, requiring independent security audits, and potentially restricting components from high-risk geopolitical sources for sensitive deployments, as seen with the Camp Lejeune incident.
  7. Training and Awareness: Cybersecurity teams and operational staff within utilities must be educated on the unique risks associated with distributed, digitally controlled renewable energy assets and their supply chains. Awareness of potential insider threats or compromised components is paramount.
  8. Resilience Planning: Even with the best defenses, compromise is possible. Utilities must develop robust resilience and recovery plans that account for potential large-scale disruption of distributed assets. This includes strategies for isolating compromised components, manual override capabilities, and maintaining operational continuity during cyber incidents affecting renewable energy infrastructure.

The "pick your poison" dilemma means that while climate action is non-negotiable, the security implications of its execution cannot be ignored. Defenders must proactively integrate national security considerations into every stage of the clean energy transition to build a grid that is not only green but also genuinely secure and resilient.

Key Takeaways

  • The clean energy transition, while vital for climate, is introducing significant national security and cyber risks into critical infrastructure due to supply chain vulnerabilities.
  • A staggering 95-100% of new digital components for renewable energy (solar, storage) are manufactured, owned, or derived from Chinese companies, creating an overwhelming dependency.
  • The grid is shifting from centralized, US-manufactured spinning generators to a vast network of distributed, digitally controlled, solid-state devices, exponentially increasing the attack surface.
  • Energy storage systems are critical for grid stability but represent a major vector for supply chain compromise, as demonstrated by the Camp Lejeune incident involving a Chinese battery manufacturer.
  • Known adversarial intent from nations like China, coupled with deep supply chain penetration, poses a direct threat of espionage, sabotage, or disruption to future power systems.
  • Defenders and policymakers must prioritize robust Supply Chain Risk Management (SCRM), component vetting, and strategic diversification to secure the clean energy future.

About the Speaker(s)

Emma Stewart is an expert deeply involved in the security aspects of the renewable energy sector. Her background indicates a strong focus on renewable security and a comprehensive understanding of the power grid. She is known for giving talks on power grid topics, suggesting a blend of operational technology knowledge and cybersecurity expertise within the energy domain. Her work for the past few years has been predominantly on renewable security, placing her at the forefront of addressing the complex challenges at the intersection of energy transition and national security.

All talks from DEF CON 32 Creator Stage