Sep 17, 2026 · 29 min · 13 segments
Deployment is surging across the country for distributed energy resources, such as rooftop solar panels and battery storage systems, as well as EVs and their charging infrastructure. These assets can…
Carter ManucyGuest
Cooper CashGuest
Molly ChristianHost
I know more and more businesses and households have distributed energy resources such as rooftop solar and EV chargers.

What does that mean in terms of cybersecurity for co-ops and how does that change the cybersecurity picture for that broadly?

The short answer to your question is that it changes the threat surface in ways that a lot of co-ops have not fully mapped out yet.

For decades, the co-op cybersecurity conversation was largely about protecting systems you own and operate directly like SCADA, which is, well, that's a mouthful.

They're still very important, but DERs, which are distributed energy resources and electric vehicles or EV chargers, they kind of add a new category of risk for us.

What makes these DVRs and the EV systems different is they introduce a third-party dependency right at the edge of a co-op grid.

Rooftop solar system that a member installed is connected to an inverter that talks to a cloud platform.

It's monitored and controlled through software that runs through somebody else's infrastructure often.

The co-op may have the equipment, but they don't own the full data path or the management layer where all that goes.

First, what does a co-op actually have on its system and who manages it and what connection does it maintain? Second, what happens operationally if one of those third party platforms goes down and gets breached? And third, does a co-op have a plan for responding to a cybersecurity incident involving these assets that it doesn't fully control? For a lot of co-ops right now, the answer to all three questions is we're not sure.

So you think there's room there to maybe understand the risks better? What do you think a co-op dealing with more of these assets coming under the grid, what do you think they need to understand better?

If a co-op's EV network is managed through a third party platform and that platform experiences an outage or a breach, the co-op loses visibility and control over the assets to its own system.

A lot of co-ops just haven't thought through what that scenario looks like operationally or even who they'd call.

A lot of the agreements that these co-ops have signed with their DER developers or their EV vendors or demand management system platforms were negotiated without cybersecurity provisions in the contracts.

That means when something goes wrong, the co-op may have no contractual right to notification, no clarity on who's responsible for remediation, and sometimes no leverage to demand answers.

I know more and more businesses and households have distributed energy resources such as rooftop solar and EV chargers.

What does that mean in terms of cybersecurity for co-ops and how does that change the cybersecurity picture for that broadly?

The short answer to your question is that it changes the threat surface in ways that a lot of co-ops have not fully mapped out yet.

For decades, the co-op cybersecurity conversation was largely about protecting systems you own and operate directly like SCADA, which is, well, that's a mouthful.

They're still very important, but DERs, which are distributed energy resources and electric vehicles or EV chargers, they kind of add a new category of risk for us.

What makes these DVRs and the EV systems different is they introduce a third-party dependency right at the edge of a co-op grid.

Rooftop solar system that a member installed is connected to an inverter that talks to a cloud platform.

It's monitored and controlled through software that runs through somebody else's infrastructure often.

The co-op may have the equipment, but they don't own the full data path or the management layer where all that goes.

First, what does a co-op actually have on its system and who manages it and what connection does it maintain? Second, what happens operationally if one of those third party platforms goes down and gets breached? And third, does a co-op have a plan for responding to a cybersecurity incident involving these assets that it doesn't fully control? For a lot of co-ops right now, the answer to all three questions is we're not sure.

So you think there's room there to maybe understand the risks better? What do you think a co-op dealing with more of these assets coming under the grid, what do you think they need to understand better?

If a co-op's EV network is managed through a third party platform and that platform experiences an outage or a breach, the co-op loses visibility and control over the assets to its own system.

A lot of co-ops just haven't thought through what that scenario looks like operationally or even who they'd call.

A lot of the agreements that these co-ops have signed with their DER developers or their EV vendors or demand management system platforms were negotiated without cybersecurity provisions in the contracts.

That means when something goes wrong, the co-op may have no contractual right to notification, no clarity on who's responsible for remediation, and sometimes no leverage to demand answers.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.