Full text
Corresponding author: Kehinde Adedapo Ogunmoye Copyright © 2025 Author(s) retain the copyright of this article. This article is published under the terms of the Creative Commons Attribution License 4.0. Protecting the Grid: Cybersecurity strategies for renewable energy integration Kehinde Adedapo Ogunmoye 1, *, Chijioke Paul Agupugo 2, Emmanuella Ejichukwu 3, Pedro Barros 4 and Mario David Hayden 4 1 Department of Physics and Astronomy, Appalachian State University, Boone, NC, USA. 2 Department of Sustainability Technology and Built Environment, Appalachian State University, Boone, North Carolina, USA. 3 University of Michigan, Dearborn, USA. 4 University of Hoston, Clear Lake, USA. 5Inti International University, Malaysia. World Journal of Advanced Research and Reviews, 2025, 26(03), 1302-1319 Publication history: Received on 26 April 2025; revised on 11 June 2025; accepted on 13 June 2025 Article DOI: https://doi.org/10.30574/wjarr.2025.26.3.2234 Abstract The global transition toward renewable energy sources, such as solar and wind, is reshaping modern power systems and introducing new vulnerabilities within the electrical grid. As distributed energy resources (DERs) and smart grid technologies become increasingly interconnected through digital communication networks, cybersecurity emerges as a critical component of resilient and sustainable energy infrastructure. This paper explores the unique cybersecurity challenges posed by renewable energy integration, including increased attack surfaces, insecure legacy systems, and vulnerabilities in supervisory control and data acquisition (SCADA) systems and Internet of Things (IoT)-enabled devices. The study analyzes recent incidents and threat vectors, such as malware attacks, data breaches, and supply chain compromises, that highlight the urgent need for robust security mechanisms across the energy value chain. Through a comprehensive review of current cybersecurity frameworks, this research proposes a multi-layered defense strategy that combines risk assessment, network segmentation, intrusion detection systems, blockchain for secure energy transactions, and artificial intelligence-driven threat intelligence. The role of regulatory compliance, workforce training, and stakeholder collaboration is emphasized as a prerequisite for ensuring grid integrity. Additionally, the study evaluates advanced cryptographic protocols and zero-trust architectures as proactive measures for safeguarding digital assets and operational technologies. Case studies from various global regions illustrate how countries are addressing cybersecurity in their renewable energy deployment plans, offering practical insights into scalable and adaptive defense models. The findings underscore the necessity of embedding cybersecurity in the planning, design, and operation phases of renewable energy projects. As power grids become more decentralized and dynamic, protecting them from cyber threats is no longer optional but essential for national security, economic stability, and public safety. The study concludes with strategic policy recommendations and a call for international cooperation to establish standardized cybersecurity benchmarks tailored to the evolving needs of renewable energy systems. Keywords: Renewable Energy; Cybersecurity; Smart Grid; Distributed Energy Resources; SCADA; Internet of Things; Intrusion Detection; Zero Trust; Blockchain; Grid Resilience; Critical Infrastructure Protection 1. Introduction The global energy landscape is currently experiencing a significant transformation aimed at reducing carbon emissions and combating climate change. This transformation is characterized by the accelerated integration of renewable energy sources including solar, wind, and hydro into both national and regional power grids. Such a shift necessitates substantial technical and operational adjustments to existing electricity infrastructures. The growing reliance on
World Journal of Advanced Research and Reviews, 2025, 26(03), 1302-1319 1303 renewable energy introduces considerable variability into electricity generation, which traditional power grids were not designed to handle efficiently (Krause et al., 2021; Baimel et al., 2016). The move towards renewable energy systems is accompanied by a shift towards decentralized energy generation, which requires the adoption of advanced digital technologies. These technologies include smart meters, Internet of Things (IoT) devices, and Supervisory Control and Data Acquisition (SCADA) systems that allow for better management and optimization of electricity flow (Saleem et al., 2019; Attia, 2019; Sakhnini et al., 2021). The digitalization of energy systems enhances grid efficiency but also expands the attack surface for potential cyber threats (Kim et al., 2019; Mohammed et al., 2024). Vulnerabilities in these interconnected systems can be exploited by malicious actors, leading to disruptions in energy delivery, data manipulation, and severe economic consequences (Ahmed et al., 2019; Jahromi et al., 2020). With the emerging reliance on digital platforms, the threats to the stability and reliability of critical energy infrastructure have escalated. Research indicates that traditional cybersecurity measures may not suffice in safeguarding against the sophisticated and evolving nature of cyber threats aimed at modern energy systems (Alekseichuk et al., 2023; Adegbite et al., 2023; Wu et al., 2018) . The necessity for robust cybersecurity strategies becomes critical, focusing on the unique vulnerabilities introduced through the integration of renewable energy sources and the deployment of smart technologies in power grids. The identification of key vulnerabilities, along with an assessment of emerging threats, is crucial in developing a comprehensive framework for cybersecurity specific to energy sectors (Tanyıldız et al., 2024; Sani et al., 2024). Furthermore, the pressing need for innovative defense strategies arises from the complexities of securing grids that are increasingly decentralized and digitally interconnected (Galinec, 2023; Suciu et al., 2019). The proposal of multi-layered defense mechanisms, which incorporate best practices and regulatory frameworks, is essential for enhancing grid resilience against cyberattacks (Abdulwahid and Ateeq, 2019; Ko et al., 2015). Stakeholders, including grid operators and technology developers, must focus on actionable recommendations that not only address current security weaknesses but also anticipate future challenges in the ever-evolving energy landscape. In conclusion, as power grids transition towards a more sustainable energy model, the integration of renewable sources presents both opportunities and significant cybersecurity challenges. It is imperative for energy sector stakeholders to collaboratively craft strategies that will protect vital infrastructure while facilitating a smooth transition to a low-carbon economy. 2. Methodology This study adopted a mixed-methods approach comprising a systematic literature review, qualitative analysis, and conceptual modeling to develop robust cybersecurity strategies for renewable energy integration. The research began by identifying core vulnerabilities associated with integrating renewable energy systems into smart grids. Key sources included peer-reviewed literature from 2020–2024, focusing on artificial intelligence, zero-trust architectures, Internet of Things (IoT), and blockchain-based solutions. A systematic review methodology was utilized to collect and screen relevant studies from indexed databases. The inclusion criteria centered on publications that provided empirical, theoretical, or simulation-based insights into protecting smart grid infrastructure. Duplicate entries and articles lacking full-text access or methodological transparency were excluded. Data extraction focused on identifying key cybersecurity challenges and mitigation techniques, such as threat modeling frameworks, machine learning approaches to intrusion detection, endpoint protection algorithms, and encryption practices. The extracted data were synthesized using a thematic coding approach to align technological strategies with grid resilience goals. The core analytical step involved comparative analysis across different cybersecurity models particularly zero-trust frameworks, AI-driven anomaly detection, and blockchain-enhanced access controls highlighting strengths, trade-offs, and contextual applications. A conceptual model was developed to visualize how these technologies could be integrated into a unified cybersecurity strategy for renewable grids. Scenario-based validation techniques were proposed to assess the resilience and feasibility of the model in protecting against cyber-physical attacks. Simulation data from grid systems and IoT-enabled infrastructures were recommended for future trials.
World Journal of Advanced Research and Reviews, 2025, 26(03), 1302-1319 1304 The research concluded with actionable recommendations for policymakers, grid operators, and cybersecurity engineers on best practices for securing next-generation power infrastructure. Emphasis was placed on developing context-sensitive protocols, strengthening regulatory compliance, and fostering international collaboration to futureproof renewable energy networks. Figure 1 The flowchart for the Study Methodology 3. The Evolving Power Grid Landscape The modernization of the power grid signifies a substantial transformation in electricity generation, transmission, and consumption. This shift is primarily driven by the increasing deployment of distributed energy resources (DERs), including rooftop solar panels, small-scale wind turbines, and residential battery storage systems. These DERs enable consumers to assume the dual role of "prosumers," actively engaging in both energy production and consumption. This decentralization creates a model of energy production that diverges from the traditional centralized framework characterized by large power plants (Sousa et al., 2019; Yang et al., 2022; Morstyn and McCulloch, 2019). Such a decentralized model not only enhances energy resilience and reduces transmission losses but also facilitates the better integration of renewable energy sources into the grid, promoting sustainability and overall efficiency (Tushar et al., 2020; Espe et al., 2018). However, the transition toward a distributed energy model introduces complexities and vulnerabilities that need addressing. The emergence of the smart grid, which incorporates digital technologies and interconnected systems, represents a transformative evolution. The modern grid is not merely a network of physical infrastructure but functions as an intelligent system driven by digitalization. This enables real-time monitoring, automated control, and improved energy management (Marron et al., 2019; Szczepaniuk and Szczepaniuk, 2022). Innovations such as smart meters and advanced sensors support enhanced load management and reliability of the energy supply, demonstrating the dynamic nature of contemporary electricity networks (Castellini et al., 2021; Milanezi et al., 2020). While these advancements increase operational efficiency, they also elevate the grid's exposure to cyber threats and emphasize the necessity for robust cybersecurity measures (Bouramdane, 2023; Brambati et al., 2022). Figure 2 shows Schematic diagram for grid integration of HRES. PandC: Protection and Control presented by Eltamaly, et al., 2021.
World Journal of Advanced Research and Reviews, 2025, 26(03), 1302-1319 1305 Figure 2 Schematic diagram for grid integration of HRES. PandC: Protection and Control (Eltamaly, et al., 2021) Digitalization plays a pivotal role in accommodating the growing penetration of variable renewable energy sources. Technologies such as smart inverters and automated demand response systems enable utilities to balance supply and demand in an increasingly bidirectional energy flow context (Tushar et al., 2018; Taik, 2021). Data analytics and cloud computing support the processing of vast amounts of information generated by these distributed assets, aiding predictive maintenance and operational optimization. Nonetheless, this expanding digital footprint introduces significant cybersecurity concerns, as key grid components, particularly Supervisory Control and Data Acquisition (SCADA) systems, may lack robust security features necessary to withstand contemporary cyber threats (Le et al., 2020; Bouramdane, 2023). Furthermore, the proliferation of Internet of Things (IoT) devices within the energy sector presents additional vulnerabilities. While these devices can enhance grid interconnectivity, they also create numerous entry points for cyber intrusions. Devices such as smart thermostats and connected appliances are often deployed with minimal security, potentially leading to larger-scale disruptions in energy management systems (Szczepaniuk and Szczepaniuk, 2022; Milanezi et al., 2020). The reliance on cloud computing for data storage and processing introduces further critical vulnerabilities, as misconfigured settings and insecure access controls can compromise sensitive data (AVCI, 2021; Annuk et al., 2021). Smart Grid Architecture: Components and Functions Across Energy Sectors presented by Zaman and Mazinani, 2023 is shown in figure 3. As the power grid architecture becomes increasingly complex and diverse, establishing a comprehensive cybersecurity framework is essential. The integration of distributed resources and digital systems often outpaces the development of corresponding cybersecurity policies and standards. This highlights the need for adaptive security measures that encompass all endpoints, interfaces, and data streams (Adelana, et al., 2024; Bouramdane, 2023). Adopting zero-trust architectures, where every component within the network is treated as a potential target, necessitates stringent access controls and continuous monitoring to mitigate threats in real time (Bouramdane, 2023; Brambati et al., 2022). The evolution of the power grid towards a digitalized, distributed system is vital for meeting future energy demands while enhancing sustainability and operational efficiency. However, these advancements must be paired with robust strategies to address cybersecurity risks, as failures in this area could result in significant disruptions, economic losses, and threats to public safety. Therefore, safeguarding the power grid is not just a technical challenge but a matter of national security, requiring coordinated efforts across public and private sectors (Bouramdane, 2023; Brambati et al., 2022).
World Journal of Advanced Research and Reviews, 2025, 26(03), 1302-1319 1306 Figure 3 Smart Grid Architecture: Components and Functions Across Energy Sectors (Zaman and Mazinani, 2023) 4. Cybersecurity Challenges in Renewable Energy Systems The transition toward integrating renewable energy sources into power grids has become imperative for enhancing environmental sustainability and achieving energy independence. However, this shift from centralized to decentralized energy systems, featuring distributed energy resources (DERs) such as wind farms and solar arrays, also introduces significant cybersecurity challenges. The proliferation of these interconnection points expands the potential attack surface for cyber threats dramatically compared to traditional power systems, which relied on a few high-capacity plants (Krause et al., 2021; Sen et al., 2022). The decentralized nature of modern power grids, while offering benefits like increased flexibility and resilience, comes with intricate cybersecurity issues. Each DER can act as a vulnerability point for malicious actors, particularly as many of these assets ranging from commercial solar installations to residential battery systems require internet connectivity for their operations. This inherent connectivity can expose them to unauthorized access, facilitating cybercriminal activities like data tampering or manipulation of energy flows (Adeoba and Fatayo, 2024; Krause et al., 2021). Specific evidence points to instances where inadequately secured solar inverters have been accessible via unsecured internet interfaces, exemplifying the extent to which these vulnerabilities can threaten grid stability (Rekeraho et al., 2024; Jahromi et al., 2020). Legacy infrastructure compounds these complications. Many existing Supervisory Control and Data Acquisition (SCADA) systems and other grid management technologies were developed without contemporary cybersecurity considerations. They often lack essential features like encryption and proper authentication, which makes them susceptible when connected to modern networks. This lack of backward compatibility further complicates cybersecurity retrofitting efforts (Krause et al., 2021; Jahromi et al., 2020). Moreover, the fragmented landscape of proprietary communication protocols among DER manufacturers leads to inconsistent security measures, complicating the establishment of a uniform response strategy across the renewable energy sector (Adeoba, et al., 2024; Sen et al., 2022). Additionally, the rise of Internet of Things (IoT) technologies marks another frontier for cybersecurity vulnerabilities. IoT devices, widely deployed across energy systems for monitoring and control, often possess limited processing power to implement robust security features. Many are shipped with default credentials and outdated firmware, making them easy targets for attackers who could leverage these devices for broader assaults on the network (Rekeraho et al., 2024). Alongside, the trend of deploying edge computing technologies essential for autonomy and efficiency in energy management also raises risks. Compromised edge devices can disrupt local operations or corrupt data sent upstream, thereby amplifying threats to overall system reliability (Sen et al., 2022; Boyaci et al., 2021).
World Journal of Advanced Research and Reviews, 2025, 26(03), 1302-1319 1307 Remote monitoring and control systems essential for maintaining renewable energy assets also present critical security concerns. Technicians commonly access these systems through VPNs and web portals, which can serve as entry points for attackers if not secured with adequate measures like multi-factor authentication Jahromi et al., 2020). Historical incidents, such as the 2015 cyberattack on Ukraine's power grid, underscore the physical ramifications of digital breaches, wherein attackers were able to manipulate operational technology to cause real-world disruptions Jahromi et al., 2020). Cavus, 2024 presented Data and power flow in SG infrastructure with renewable energy integration as shown in figure 4. Figure 4 Data and power flow in SG infrastructure with renewable energy integration (Cavus, 2024) To confront these cybersecurity challenges, a comprehensive approach is essential for the renewable energy sector. Stakeholders need to prioritize the modernization of aging systems and enforce stringent cybersecurity standards for new technologies. Furthermore, collaboration among energy providers, governmental agencies, and cybersecurity experts is vital to develop resilient architectures capable of withstanding potential threats (Krause et al., 2021; Jahromi et al., 2020). By understanding these multifaceted vulnerabilities, society can ensure that the transition to renewable energy does not compromise the security and reliability of critical infrastructure. 5. Threat Vectors and Risk Assessment The integration of renewable energy technologies into modern power grids is reshaping the landscape of energy generation and distribution. While these advancements offer significant sustainability and efficiency benefits, they introduce considerable cybersecurity challenges that are critical to address. Ekechukwu and Simpa highlight that the intersection of renewable energy systems with cybersecurity reveals a pressing need for robust frameworks to secure these essential infrastructures against a variety of evolving threats (Ekechukwu and Simpa, 2024). They identify a range of cyber threats, such as malware and ransomware, that pose substantial risks to the operational integrity and reliability of energy systems. Malware has become a pervasive threat within the energy sector, infiltrating grid systems through vectors including infected devices and software updates, potentially leading to severe operational disruptions. Ransomware, particularly virulent malware, encrypts critical operational data and can lock out energy operators from essential systems, jeopardizing grid stability (Rahim et al., 2023). Such attacks could have cascading effects, impacting not just isolated
World Journal of Advanced Research and Reviews, 2025, 26(03), 1302-1319 1308 systems but also the broader grid, potentially causing widespread outages and public safety threats. This is echoed in the findings of Mohamed et al., who outline the increasing sophistication of cyber threats targeting renewable energy systems (Adeoba, et al., 2025; Mohamed et al., 2023). Phishing attacks represent another significant vector of cyber threat, primarily targeting individuals with access to sensitive operational information. Attackers often create deceptive communications to extract credentials or deploy malware. Ekechukwu and Simpa describe this tactic as particularly nefarious in the energy sector, where employees holding administrative controls are prime targets for infiltration attempts that can escalate into deeper network attacks (Ekechukwu and Simpa, 2024). The human element in cybersecurity remains a critical vulnerability, emphasizing the need for robust training and awareness initiatives to fortify defenses against such social engineering tactics. Insider threats further complicate the cybersecurity landscape in renewable energy. Insiders, whether disgruntled employees or negligent contractors, possess unique access that can be exploited maliciously or unintentionally. Rahim et al. present organized frameworks for threat modeling and risk assessment that can highlight the nuances of insider threats, fostering the development of more effective mitigation strategies (Rahim et al., 2023). The complexity of security challenges is heightened by third-party access, which can amplify the risk of exploitation if security protocols are not meticulously established and managed. Moreover, the emergence of sophisticated adversaries including state-sponsored actors and hacktivists introduces additional challenges. The targeted nature of these threats can lead to prolonged undetected breaches that might destabilize essential infrastructure (Ekechukwu and Simpa, 2024). The NIST Cybersecurity Framework serves as a critical tool for navigating these threats, guiding organizations in identifying vulnerabilities, managing risks, and establishing comprehensive defensive measures (Rahim et al., 2023). Ekechukwu and Simpa argue that tailoring such frameworks for renewable energy systems is essential for effectively responding to the sector-specific vulnerabilities (Ekechukwu and Simpa, 2024). With the pressing need for robust cybersecurity measures, energy sector organizations must prioritize threat modeling and risk assessment processes. Such frameworks are invaluable in identifying potential attack vectors and evaluating the implications of various threat scenarios on system integrity. Al-Sada et al. emphasize utilizing resources like the MITRE ATTandCK framework, allowing energy operators to systematically analyze adversarial tactics and improve their defensive strategies (Al-Sada et al., 2024). The focus on continuous risk assessment and improvement aligns well with the evolving nature of threats in the domain, requiring ongoing vigilance and adaptation of security measures to safeguard the integrity of renewable energy systems. In summary, while the shift toward renewable energy technologies heralds numerous benefits, it is crucial that cybersecurity is not sidelined. The multiplicity of cyber threats from malware and phishing to insider risks and organized crime mandates a comprehensive approach to secure renewable energy infrastructures. By leveraging advanced threat modeling frameworks and the collective knowledge of the cybersecurity community, organizations can build resilient defenses capable of protecting our increasingly digital and interdependent energy systems. 6. Cybersecurity Strategies for Grid Protection As the global energy sector increasingly adopts renewable energy sources, the integration of these technologies into the energy grid necessitates advanced cybersecurity measures. The transition towards decentralized and digitalized grid systems has revealed vulnerabilities that traditional security models primarily perimeter-based defenses fail to address adequately (Park et al., 2023; Shaikh, 2024). This inadequacy presents dire consequences for critical energy infrastructures, demanding a shift toward comprehensive cybersecurity strategies that incorporate multi-layered defenses, dynamic architectures, and continuous monitoring to safeguard against cyberattacks (Bassfar et al., 2023; Shaikh, 2024). Central to a resilient grid security model is a layered defense architecture based on the principle of defense-in-depth. This approach integrates a variety of security measures designed to mitigate risks even when some layers are breached, particularly in the context of renewable energy systems. Essential components include robust endpoint security for devices like solar inverters and wind turbine controllers, as well as fortified communication pathways between distributed assets and central control systems (Sharma et al., 2024; Paul and Rao, 2022). The application of technical measures such as firewalls, antivirus software, encrypted communications, and physical security significantly lowers the attack surface, which is crucial in enhancing detection chances and response times during potential cyber incidents (Adeoba, et al., 2025; Chamoli, 2020).
World Journal of Advanced Research and Reviews, 2025, 26(03), 1302-1319 1309 Moreover, network segmentation and strict access control are fundamental to this layered defense strategy. By isolating operational technology (OT) systems from less critical information technology (IT) environments, organizations reduce the potential for lateral movement by attackers. Techniques such as role-based access, multi-factor authentication, and the principle of least privilege minimize the risk of both insider threats and accidental exposures related to system vulnerabilities (Wylde, 2021; Sultana et al., 2020). These measures create a fortified framework essential in scenarios where intrusion attempts can originate from various sources, thus demanding thorough validation of all network interactions (Greenwood, 2021). The incorporation of Artificial Intelligence (AI) and Machine Learning (ML) into cybersecurity processes is transforming threat detection and incident response capabilities. Traditional methods of monitoring systems are becoming insufficient given the sheer volume of data produced by smart grid components and IoT devices. AI-driven analytics can identify deviations from expected behavior, allowing for the detection of cyber threats such as unusual data transmissions or unauthorized access attempts (Bradatsch et al., 2023; Alevizos et al., 2021). Machine Learning models adapt over time, continually improving their accuracy and efficacy against evolving threats, thereby enabling faster and more effective responses to potential cyber incidents (Lv et al., 2022). Blockchain technology also emerges as a revolutionary layer of security in decentralized energy networks, particularly in ensuring data integrity and transparent transactional operations. By creating immutable records validated by consensus mechanisms, blockchain facilitates secure interactions among numerous independent energy producers and consumers (prosumers) (Kang et al., 2023; Pop et al., 2018). Smart contracts can enhance the security of energy trading and operational agreements, mitigating reliance on centralized entities and bolstering trust among participants in peerto-peer energy markets (Adeoba, Ukoba and Osaye, 2024; Hireche et al., 2022). In light of these advancements, the implementation of zero-trust architectures is critical in modern grid cybersecurity. Unlike traditional systems that presume internal networks are secure, a zero-trust model mandates continuous verification of all users, devices, and applications (Braghin et al., 2002; Chen et al., 2021). This strategy is instrumental in preventing insider threats and unauthorized access, reinforcing a culture of skepticism toward implicit trust within network systems (Chen et al., 2022). Adopting components such as real-time behavioral analysis, micro-segmentation, and identity management systems can significantly streamline the security processes across utility organizations (Sallam et al., 2019). To effectively combat cyber threats within renewable energy systems, organizations must employ intrusion detection and response systems (IDRS) as front-line defenses. These systems, utilizing both signature-based and anomaly-based methodologies, are crucial for real-time monitoring and responding to suspicious activities (Alagappan et al., 2022). With operational continuity paramount in energy systems, deploying IDRS at various levels including edge devices and centralized control units provides essential visibility and rapid response capabilities needed to neutralize threats before they escalate (Adeoba, Shandu and Pandelani, 2025: Han, 2023). The success of these strategies is contingent upon seamless integration, active monitoring of threats, and adaptive management of cybersecurity measures. Continuous security assessments, investment in security orchestration platforms, and collaborative training exercises for IT and OT personnel cultivate an environment capable of dynamically responding to evolving cyber threats (Munsing et al., 2017; Bartakke and Kashyap, 2024). Furthermore, fostering security awareness and adherence to regulatory standards, such as the NIST Cybersecurity Framework and ISO/IEC 27001, ensures a comprehensive foundation for maintaining rigorous cybersecurity controls across the energy sector (Yang et al., 2018). In conclusion, as the energy sector evolves toward more intelligent and decentralized infrastructures, cybersecurity must keep pace with innovation and emerging threats. The fusion of technologies like AI, blockchain, and zero-trust architecture, combined with proactive strategies for threat detection, offers a robust defense against a range of cyber risks. However, technology alone cannot secure the grid; a holistic approach intertwining technical defenses, human vigilance, and regulatory compliance is paramount for achieving a resilient and secure energy landscape (Sultana et al., 2020). 7. Regulatory and Policy Frameworks The integration of renewable energy sources (RES) into modern power grids has become increasingly prevalent, contributing to the transformation of energy systems globally. However, this rise has simultaneously introduced significant cybersecurity concerns due to the digitization and interconnectivity of energy infrastructures. These vulnerabilities threaten the reliability and functionality of power systems and pose risks to national security and public
World Journal of Advanced Research and Reviews, 2025, 26(03), 1302-1319 1310 safety (Ekechukwu and Simpa, 2024; (Ekechukwu and Simpa, 2024). As a result, robust regulatory and policy frameworks have emerged as crucial tools to address these challenges and enhance the resilience of the energy sector (Mikac, 2023; Ekechukwu and Simpa, 2024). Governments worldwide have initiated the development and enforcement of various cybersecurity regulations aimed at safeguarding energy infrastructures. For instance, the European Union has implemented the Network and Information Security (NIS) Directive, which mandates enhancing national cybersecurity capabilities and obligates operators of essential services, including energy providers, to adopt stringent security measures (Adeoba, Odjegba and Pandelani, 2025). The evolution of this directive into NIS2 has expanded its reach, integrating stricter enforcement mechanisms to bolster the cybersecurity frameworks across member states (Mikac, 2023). Additionally, the International Telecommunication Union (ITU) provides global standards and guidelines for critical infrastructure protection, while the International Electrotechnical Commission (IEC) offers specific standards like IEC 62443 that address cybersecurity in industrial automation and control systems, which are integral to energy systems (Bhusal et al., 2020; (Ekechukwu and Simpa, 2024; . In the United States, one prominent framework is the North American Electric Reliability Corporation’s Critical Infrastructure Protection (NERC CIP) standards. These enforce mandatory cybersecurity protocols for entities managing the bulk electric system, encompassing risk management and incident response strategies aimed at shielding the electric grid from both cyber and physical threats (Tuyen et al., 2022; Ekechukwu and Simpa, 2024). The standards undergo strict oversight by the Federal Energy Regulatory Commission (FERC), with non-compliance potentially leading to penalties, indicating the vital importance of these frameworks (Sheikh et al., 2020; Mikac, 2023). Complementing NERC CIP, broader cybersecurity models such as the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) facilitate organizations in assessing and enhancing their security posture (Ekechukwu and Simpa, 2024; Tuyen et al., 2022). Furthermore, internationally recognized standards like ISO/IEC 27001 provide a systematic approach to managing sensitive information, thereby establishing a baseline for cybersecurity maturity in the energy domain (Manowska et al., 2024; Mikac, 2023). Despite these frameworks, energy providers encounter significant hurdles in achieving compliance amid rapid technological advancements and evolving cyber threats. The decentralized nature of renewable energy systems, characterized by dispersed assets such as solar panels and wind turbines, complicates the implementation of comprehensive security measures (Lee et al., 2023; Rekeraho et al., 2023). Additionally, the dynamic nature of cyber threats can outpace regulatory frameworks, leading to a reactive compliance orientation where organizations may prioritize meeting regulatory requirements over proactive security enhancements (Tuyen et al., 2022; Mikac, 2023). The inconsistency of regulatory environments across jurisdictions further complicates compliance for transnational energy operators, resulting in fragmented efforts that are difficult to synchronize (Ekechukwu and Simpa, 2024; Mikac, 2023). A critical factor in safeguarding the energy sector against cybersecurity threats is the existing shortage of skilled cybersecurity professionals. This shortage adds pressure on current teams and could create compliance gaps, emphasizing the necessity for continuous investment in workforce development (Ekechukwu and Simpa, 2024; Tuyen et al., 2022). In this context, public-private partnerships (PPPs) can be instrumental. Collaboration between government entities and private sector stakeholders fosters the sharing of threat intelligence and resources, enhancing the overall cybersecurity posture of energy systems (Sheikh et al., 2020; Tuyen et al., 2022). Moreover, initiatives such as the Electricity Information Sharing and Analysis Center (E-ISAC) exemplify how these partnerships can facilitate timely responses to cyber threats within the energy domain (Lee et al., 2023; Sheikh et al., 2020). To address the existing compliance challenges, many frameworks are shifting towards emphasizing maturity models and risk-based approaches, thereby promoting flexibility and innovation in security practices. This evolving mindset reflects the understanding that cybersecurity is an ongoing process, requiring continuous adaptation and improvement (Ekechukwu and Simpa, 2024; Sheikh et al., 2020). A more sophisticated approach towards compliance can enable energy organizations to better navigate the complexities associated with the cybersecurity landscape. In conclusion, while regulatory and policy frameworks play a pivotal role in securing the infrastructure supporting renewable energy integration, challenges related to complexity, regulatory inconsistency, workforce shortages, and rapid technological evolution persist. A comprehensive approach encompassing regulatory imperatives, collaborative strategies, and flexibility in compliance initiatives will be essential for effectively safeguarding the energy sector against emerging cyber threats and ensuring a secure transition to sustainable energy systems.
World Journal of Advanced Research and Reviews, 2025, 26(03), 1302-1319 1317 [56] Lee, J., Shin, J., and Seo, J. (2023). Solar power plant network packet-based anomaly detection system for cybersecurity. Computers Materials and Continua, 77(1), 757-779. https://doi.org/10.32604/cmc.2023.039461 [57] Leszczyna, R. (2019). Standards with cybersecurity controls for smart grid a systematic analysis. International Journal of Communication Systems, 32(6). https://doi.org/10.1002/dac.3910 [58] Liu, J., Xiao, Y., Li, S., Liang, W., and Chen, C. (2012). Cyber security and privacy issues in smart grids. Ieee Communications Surveys and Tutorials, 14(4), 981-997. https://doi.org/10.1109/surv.2011.122111.00145 [59] Lv, P., Sun, X., Huang, H., Qian, J., Sun, C., and Dai, H. (2022). Dynamic trust continuous evaluation-based zerotrust access control for power grid cloud service. Journal of Physics Conference Series, 2402(1), 012008. https://doi.org/10.1088/1742-6596/2402/1/012008 [60] Manowska, A., Boroš, M., Hassan, M., Bluszcz, A., and Tobór–Osadnik, K. (2024). A modern approach to securing critical infrastructure in energy transmission networks: integration of cryptographic mechanisms and biometric data. Electronics, 13(14), 2849. https://doi.org/10.3390/electronics13142849 [61] Marron, J., Gopstein, A., Bartol, N., and Feldman, V. (2019). Cybersecurity framework smart grid profile.. https://doi.org/10.6028/nist.tn.2051 [62] Mikac, R. (2023). Protection of the eu's critical infrastructures: results and challenges. Applied Cybersecurity and Internet Governance, 2(1), 1-5. https://doi.org/10.60097/acig/162868 [63] Milanezi, J., Costa, J., Garcez, C., Albuquerque, R., Arancibia, A., Weichenberger, L., … and Sousa, R. (2020). Data security and trading framework for smart grids in neighborhood area networks. Sensors, 20(5), 1337. https://doi.org/10.3390/s20051337 [64] Mohamed, N., El-Guindy, M., Oubelaid, A., and Almazrouei, S. (2023). Smart energy meets smart security: a comprehensive review of ai applications in cybersecurity for renewable energy systems. International Journal of Electrical and Electronics Research, 11(3), 728-732. https://doi.org/10.37391/ijeer.110313 [65] Mohammed, S., Al-Jumaily, A., Singh, M., Jiménez, V., Jaber, A., Hussein, Y., … and Al‐Jumeily, D. (2024). A review on the evaluation of feature selection using machine learning for cyber-attack detection in smart grid. Ieee Access, 12, 44023-44042. https://doi.org/10.1109/access.2024.3370911 [66] Morstyn, T. and McCulloch, M. (2019). Multiclass energy management for peer-to-peer energy trading driven by prosumer preferences. Ieee Transactions on Power Systems, 34(5), 4005-4014. https://doi.org/10.1109/tpwrs.2018.2834472 [67] Munsing, E., Mather, J., and Moura, S. (2017). Blockchains for decentralized optimization of energy resources in microgrid networks., 2164-2171. https://doi.org/10.1109/ccta.2017.8062773 [68] Oyeyemi, B. B. (2022). Artificial Intelligence in Agricultural Supply Chains: Lessons from the US for Nigeria. [69] Oyeyemi, B. B., Akinlolu, M., and Awodola, M. I. (2025). Ethical challenges in AI-powered supply chains: A U.S.- Nigeria policy perspective. International Journal of Applied Research in Social Sciences, 7(5), 367–388. [70] Oyeyemi, B. B., John, A. O., and Awodola, M. I. (2025, May 13). Infrastructure and regulatory barriers to AI supply chain systems in Nigeria vs. the U.S. Engineering Science and Technology, 6(4), 155–172. [71] Park, U., Hong, J., Kim, A., and Son, K. (2023). Endpoint device risk-scoring algorithm proposal for zero trust. Electronics, 12(8), 1906. https://doi.org/10.3390/electronics12081906 [72] Paul, B. and Rao, M. (2022). Zero-trust model for smart manufacturing industry. Applied Sciences, 13(1), 221. https://doi.org/10.3390/app13010221 [73] Pop, C., Cioara, T., Antal, C., Anghel, I., Salomie, I., and Bertoncini, M. (2018). Blockchain based decentralized management of demand response programs in smart energy grids. Sensors, 18(1), 162. https://doi.org/10.3390/s18010162 [74] Powell, C., Hauck, K., Sanghvi, A., and Reynolds, T. (2020). Distributed energy resource cybersecurity framework best practices.. https://doi.org/10.2172/1598143 [75] Powell, C., Hauck, K., Sanghvi, A., Hasandka, A., Natta, J., and Reynolds, T. (2019). Guide to the distributed energy resources cybersecurity framework.. https://doi.org/10.2172/1581499 [76] Rahim, F., Ahmad, N., Magalingam, P., Jamil, N., Cob, Z., and Salahudin, L. (2023). Cybersecurity vulnerabilities in smart grids with solar photovoltaic: a threat modelling and risk assessment approach. International Journal of Sustainable Construction Engineering Technology, 14(3). https://doi.org/10.30880/ijscet.2023.14.03.018
World Journal of Advanced Research and Reviews, 2025, 26(03), 1302-1319 1318 [77] Rekeraho, A., Cotfas, D., Cotfas, P., Bălan, T., Tuyishime, E., and Acheampong, R. (2023). Cybersecurity challenges in iot-based smart renewable energy.. https://doi.org/10.21203/rs.3.rs-2840528/v1 [78] Rekeraho, A., Cotfas, D., Cotfas, P., Tuyishime, E., Bălan, T., and Acheampong, R. (2024). Enhancing security for iot-based smart renewable energy remote monitoring systems. Electronics, 13(4), 756. https://doi.org/10.3390/electronics13040756 [79] Sakhnini, J., Karimipour, H., Dehghantanha, A., Parizi, R., and Srivastava, G. (2021). Security aspects of internet of things aided smart grids: a bibliometric survey. Internet of Things, 14, 100111. https://doi.org/10.1016/j.iot.2019.100111 [80] Saleem, Y., Crespi, N., Rehmani, M., and Copeland, R. (2019). Internet of things-aided smart grid: technologies, architectures, applications, prototypes, and future research directions. Ieee Access, 7, 62962-63003. https://doi.org/10.1109/access.2019.2913984 [81] Sallam, A., Refaey, A., and Shami, A. (2019). On the security of sdn: a completed secure and scalable framework using the software-defined perimeter. Ieee Access, 7, 146577-146587. https://doi.org/10.1109/access.2019.2939780 [82] Salvaggio, S. and González, N. (2022). The european framework for cybersecurity: strong assets, intricate history. International Cybersecurity Law Review, 4(1), 137-146. https://doi.org/10.1365/s43439-022-00072-9 [83] Sani, A., Yuan, D., Lawal, Y., Loukas, G., and Dong, Z. (2024). A sustainable dispositional and situational security awareness model for smart grids., 135-140. [84] Sen, Ö., Schmidtke, F., Carere, F., Santori, F., Ulbig, A., and Monti, A. (2022). Investigating the cybersecurity of smart grids based on cyber-physical twin approach.. https://doi.org/10.1109/smartgridcomm52983.2022.9961061 [85] Shaikh, A. (2024). Zero trust security paradigm: a comprehensive survey and research analysis. jes, 19(2), 28-37. https://doi.org/10.52783/jes.688 [86] Sharma, S., Sharma, T., Tiwari, A., and Gupta, S. (2024). Streamlining iot-driven data using blockchain. Int Res J Adv Engg Mgt, 2(05), 1509-1514. https://doi.org/10.47392/irjaem.2024.0204 [87] Sheikh, A., Kamuni, V., Urooj, A., Wagh, S., Singh, N., and Patel, D. (2020). Secured energy trading using byzantinebased blockchain consensus. Ieee Access, 8, 8554-8571. https://doi.org/10.1109/access.2019.2963325 [88] Sousa, T., Soares, T., Pinson, P., Moret, F., Baroche, T., and Sorin, E. (2019). Peer-to-peer and community-based markets: a comprehensive review. Renewable and Sustainable Energy Reviews, 104, 367-378. https://doi.org/10.1016/j.rser.2019.01.036 [89] Suciu, G., Istrate, C., Vulpe, A., Sachian, M., Vochin, M., Farao, A., … and Xenakis, C. (2019). Attribute-based access control for secure and resilient smart grids.. https://doi.org/10.14236/ewic/icscsr19.9 [90] Sultana, M., Hossain, A., Laila, F., Taher, K., and Islam, M. (2020). Towards developing a secure medical image sharing system based on zero trust principles and blockchain technology. BMC Medical Informatics and Decision Making, 20(1). https://doi.org/10.1186/s12911-020-01275-y [91] Sultana, T., Almogren, A., Akbar, M., Zuair, M., Ullah, I., and Javaid, N. (2020). Data sharing system integrating access control mechanism using blockchain-based smart contracts for iot devices. Applied Sciences, 10(2), 488. https://doi.org/10.3390/app10020488 [92] Szczepaniuk, H. and Szczepaniuk, E. (2022). Applications of artificial intelligence algorithms in the energy sector. Energies, 16(1), 347. https://doi.org/10.3390/en16010347 [93] Taik, A. (2021). Empowering prosumer communities in smart grid with wireless communications and federated edge learning.. https://doi.org/10.48550/arxiv.2104.03169 [94] Tanyıldız, H., Şahin, C., and DİNLER, Ö. (2024). Enhancing cybersecurity through gan-augmented and hybrid feature selection machine learning models: a case study on evse data. Naturengs Mtu Journal of Engineering and Natural Sciences Malatya Turgut Ozal University. https://doi.org/10.46572/naturengs.1495489 [95] Tushar, W., Saha, T., Yuen, C., Azim, M., Morstyn, T., Poor, H., … and Bean, R. (2020). A coalition formation game framework for peer-to-peer energy trading. Applied Energy, 261, 114436. https://doi.org/10.1016/j.apenergy.2019.114436
World Journal of Advanced Research and Reviews, 2025, 26(03), 1302-1319 1319 [96] Tushar, W., Yuen, C., Mohsenian‐Rad, H., Saha, T., Poor, H., and Wood, K. (2018). Transforming energy networks via peer-to-peer energy trading: the potential of game-theoretic approaches. Ieee Signal Processing Magazine, 35(4), 90-111. https://doi.org/10.1109/msp.2018.2818327 [97] Tuyen, N., Quan, N., Linh, V., Vu, T., and Fujita, G. (2022). A comprehensive review of cybersecurity in inverterbased smart power system amid the boom of renewable energy. Ieee Access, 10, 35846-35875. https://doi.org/10.1109/access.2022.3163551 [98] Ukoba, K., Adeoba, M. I., Fatoba, S., and Jen, T. C. (2024). Blue Biomass Production for Renewable Energy. In Marine Bioprospecting for Sustainable Blue-bioeconomy (pp. 277-295). Cham: Springer Nature Switzerland. [99] Ukoba, K., Adeoba, M., Fatoba, O. S., and Jen, T.-C. (2024). Marine bioprospecting for sustainable blue-bioeconomy: Blue biomass production for renewable energy. In Marine Bioprospecting for Sustainable Blue-bioeconomy (pp. 277–296). Springer. [100] Uzondu, N. and Lele, D. (2024). Comprehensive analysis of integrating smart grids with renewable energy sources: technological advancements, economic impacts, and policy frameworks. Engineering Science and Technology Journal, 5(7), 2334-2363. https://doi.org/10.51594/estj.v5i7.1347 [101] Wallis, T., Paul, G., and Irvine, J. (2022). Organisational contexts of energy cybersecurity., 384-402. https://doi.org/10.1007/978-3-030-95484-0_22 [102] Wu, J., Ota, K., Dong, M., Li, J., and Wang, H. (2018). Big data analysis-based security situational awareness for smart grid. Ieee Transactions on Big Data, 4(3), 408-417. https://doi.org/10.1109/tbdata.2016.2616146 [103] Wylde, A. (2021). Zero trust: never trust, always verify., 1-4. https://doi.org/10.1109/cybersa52016.2021.9478244 [104] Yang, S., Hu, X., Wang, H., Li, H., Meng, L., Zhou, W., … and Zhou, H. (2022). A prosumer-based energy sharing mechanism of active distribution network considering household energy storage. Ieee Access, 10, 113839113849. https://doi.org/10.1109/access.2022.3217540 [105] Yang, T., Zhu, L., and Peng, R. (2018). Fine-grained big data security method based on zero trust model., 10401045. https://doi.org/10.1109/padsw.2018.8644614 [106] Ye, Y., Qian, Y., Sharif, H., and Tipper, D. (2012). A survey on cyber security for smart grid communications. Ieee Communications Surveys and Tutorials, 14(4), 998-1010. https://doi.org/10.1109/surv.2012.010912.00035 [107] Zaman, D., and Mazinani, M. (2023). Cybersecurity in smart grids: protecting critical infrastructure from cyber attacks. SHIFRA, 2023, 86-94.