EIES Report: Protecting Europe’s Critical Energy Infrastructure

The Cyber-Physical Security of Germany’s Offshore Wind

09 September 2026

Author: Rosa Melissa Gehrung, EIES

Download the report here

Read the German language summary here.

The expansion of offshore wind is transforming the North and Baltic Seas into a strategic energy backbone for Germany and Europe, critical to industrial competitiveness and energy security. Yet, with growing evidence of cyber, hybrid and physical attacks, security and resilience measures have not kept pace with the sector’s growing importance.  

As North Sea countries prepare to build 300 GW of offshore-wind capacity by 2050, ensuring security keeps pace with deployment is a challenge for its energy security and industrial resilience. This EIES report examines the cyber, physical and supply chain vulnerabilities of offshore wind in Germany specifically and sets out how to prevent them, mitigate disruption and strengthen response and recovery. 

Executive Summary

Wind energy is a pillar of Europe’s energy mix. In Germany, offshore wind assets have become a cornerstone of its economic competitiveness and energy security. In 2025, Germany was the largest offshore wind market in the European Union (EU), and second largest in Europe after the United Kingdom (UK). Germany’s offshore capacity is scheduled to more than triple to at least 30 GW by 2030 and rise to 70 GW by 2045. Safeguarding these wind farms, most of which are located outside Germany’s territorial waters in the North and Baltic Seas, is a critical task.

Yet, in an era of geopolitical conflict and growing hybrid and kinetic threats, security has not kept pace. Offshore wind farms are highly digitalised cyber-physical systems. This makes them attractive targets for state and non-state actors using tactics like cyberattacks, sabotage and espionage. Many existing wind installations require up-to-date cyber and physical security upgrades to meet the evolving security environment. As disruptions at a few critical nodes can trigger cascading effects across multiple sectors, this creates a serious risk of failure for Germany’s energy network, with possible repercussions across Europe.    

Laws and regulations at EU level and in Germany have been strengthened to respond to these challenges, notably through the EU Network and Information Security 2 (NIS2) and the Critical Entities Resilience (CER) Directives and their national implementation in Germany. While the NIS2 Implementation Act strengthens cybersecurity, governance and incident reporting for a wide set of entities in Germany, the KRITIS Umbrella Act, which transposes CER, focuses more narrowly on the protection and reliable operation of designated critical infrastructure. In addition, a rich institutional landscape has evolved across the energy, cyber and maritime domains in Germany to improve the resilience of offshore assets.   

Despite these efforts, Germany’s framework for protecting offshore energy infrastructure remains fragmented and complex. Regulatory implementation varies across federal states, enforcement capacity is limited and there is no systematic security‑by‑design approach. At the same time, overlapping mandates, siloed situational awareness and unclear rules for data exchange hobble the development of a shared situational and threat picture in Germany, let alone with other European countries.

Key Recommendations

The paper recommends action in three core areas. While tailored to Germany’s offshore wind sector, these recommendations are equally relevant for other energy infrastructures across Europe, which are exposed to similar physical, cyber and hybrid threats. 

1) Prevention along the value chain 

Reduce vulnerabilities and exposure up front by strengthening European industrial capacity and trusted supply chains, embedding securitybydesign into offshore wind planning, investment and operations, and supporting these measures through resilient financing and stronger deterrence.

Use industrial policy instruments, including the EU Industrial Accelerator Act (IAA), to sustain and expand European manufacturing capacity for critical offshore wind and transmission infrastructure. This should include blades, towers, nacelles, inter-array and export cables, substations, inverters, permanent magnets and transformers. In parallel, develop European and allied supply chains for essential upstream inputs and specialised technologies, notably refined rare earth materials and power-electronic and digital control systems. Further invest in specialised installation capabilities and service vessels.  

Apply existing legal German tools more systematically to exclude high‑risk suppliers from offshore projects. Decisions should be based on security risks associated with original equipment manufacturer (OEM) remote access, ownership structures and exposure to third‑country control.  

Establish robust technical baselines, including stronger separation between operational and digital systems, strong encryption, strict remote‑access control, reliable update processes and deliberate heterogeneity in systems and suppliers. Harden physical offshore infrastructure by strengthening cable protection, reinforced substations and targeted retrofits, while carefully balancing security gains against costs and new vulnerabilities.  

Develop innovative public–private financing and risk- and cost‑sharing models, including strategic use of NATO’s 1.5% pledge, to fund infrastructure hardening and redundancies such as repair vessels, spare parts, backup systems and specialised workforces while easing the burden on industry. Incentivise resilience investments by recognising the long-term return on investment from avoided disruptions. 

Use NATO as a platform to strengthen coordination and communication between member states and increase deterrence in the North and Baltic Seas. Maintain a persistent maritime presence and clearly signal that deliberate interference will trigger coordinated political, economic, and, where appropriate, military consequences.

2) Mitigation within and across borders

Enable joint situational awareness by streamlining government functions, strengthening enforcement and fostering datasharing between operators and governments.

Streamline mandates and clarify lead functions for offshore energy protection across key ministries and agencies to ensure structured coordination between energy, cyber and maritime actors. Strengthen enforcement capacity by providing the Federal Office for Information Security (BSI) with sufficient staff to supervise NIS2‑relevant entities and support implementation.  

Improve two-way information sharing by establishing a clear legal basis and incentives for operators to share relevant data with public authorities, while ensuring the timely provision of operationally useful threat and situational information in return.  

Ensure national and sectoral cyber incident teams and situation centres have interoperable processes and technical interfaces that enable integrated, near‑real‑time situational pictures with appropriate levels of granularity. This should be supported by AI-enabled sensor data fusion, anomaly detection, and decision-support tools.  

Use the European Agency for Cybersecurity (ENISA) and NATO channels more systematically by feeding anonymised incident data and technical observations into European formats and integrating their analyses into national risk assessments and supervision.

3) Response and recovery 

Train for crisis and business continuity through joint scenarios, playbooks and exercises.

Regularly develop and update joint priority scenarios – for example sabotage of offshore substations or cyberattacks on wind farms – to anticipate failure modes, consequences and response options. Use scenarios to design and refine shared crisis playbooks that define concrete responsibilities, protocols, decision paths, and communication channels between authorities and operators.  

Strengthen the Maritime Safety and Security Centre (MSSC) as a central 24/7 incident‑reporting and coordination hub in Germany by providing additional resources. Once domestic structures are established and tested, further streamline reporting chains and cooperation mechanisms with other North Sea states to support a more integrated maritime security picture.  

Conduct regular wargames and tabletop exercises at national, EU and NATO level with North and Baltic Sea states to test and refine playbooks and improve business‑continuity. Exercises should adopt a whole-of-society approach by involving relevant public authorities, the military, critical infrastructure operators and civil society.


Security must keep pace with deployment. This is not solely a challenge for the offshore wind sector. Similar cyber-physical vulnerabilities, supply-chain exposure and lack of gaps in crisis preparedness also affect electricity grids, interconnectors, solar generation, subsea data cables and other critical infrastructure. 

EIES is calling for security by design to be embedded across Europe’s energy infrastructure as the continent expands renewable and low-carbon energy and reduces its dependence on imported fossil fuels.

Next
Next

EIES Report: ‘Jumpstarting Europe's Battery Industry’