Standards Australia is nearing completion of its work on cybersecurity standards specifically tailored for solar inverters, according to representatives from the Department of Climate Change, Energy, the Environment, and Water (DCCEEW) who provided an update during recent Senate estimates.
The primary objective of this project is to address the potential risk associated with solar inverters serving as a potential entry point for cyberattacks on energy networks.
Solar inverters play a pivotal role in converting the direct current (DC) generated by rooftop solar panels into usable electricity. They are increasingly interconnected with energy provider control networks through the internet, enabling providers to manage the flow of electricity from distributed energy resources (DERs) into the electricity grid.
However, this connectivity has raised concerns about the security of solar inverters. Poorly secured inverters or systems with security vulnerabilities could potentially serve as an attack vector.
DCCEEW’s Dr. Martin Squire, who heads the energy security and crisis response branch, explained that the initiative to develop these cybersecurity standards for inverters began after the department allocated a budget for the project in October 2022.
According to Squire, Standards Australia is currently in the final stages of preparing a report for the department. Once this report is completed, they will be in a position to collaborate with Standards Australia to propose additional cybersecurity standards tailored for rooftop inverters.
DCCEEW Secretary David Fredericks stated that the department is working closely with the Australian Energy Market Operator to explore options for enhancing technical solutions. He also emphasized the importance of this work given that the energy sector is categorized as critical infrastructure.
Squire also mentioned that the Cyber Security Cooperative Research Centre (CRC) had submitted a report in August, highlighting potential cybersecurity risks associated with solar inverters. This report raised concerns about the misuse of rooftop inverters and the potential issues this could create for the national electricity market, particularly in terms of incorrect signals received by the Australian Energy Market Operator.
As a result, discussions are underway with the Australian Energy Market Operator to explore potential technical solutions that could be implemented in the event of a successful cyber attack on rooftop inverters, aimed at restoring functionality and stability to the grid.

