← All sessions

Is Resilience a Lie We Tell Ourselves?

In short

A fleet of 100,000 energy assets can fail like one power plant

Till Stenzel and Katharina Beitz asked investors and founders whether distributed energy makes Europe safer, and found most had only begun to think about it.

Three weeks before The Drop, a carbon-capture start-up found out it was worth hacking. Its plants talk to each other so the company can tune their efficiency. Attackers cut that communication, stopped production for a day or two and left a hidden backdoor in the software that could have reached customers. "We're a startup, we're three years old, who's gonna hack us," the founder said. The fix was easy, but the damage would have been large had nobody noticed.

The founder told the story at the Ripple on energy resilience hosted by Katharina Beitz of Vireo Ventures and Till Stenzel of SET Ventures. Asked at the start whether distributed energy makes Europe safer, two people said yes and the rest of the circle had no opinion.

Decentralised hardware, concentrated control

Katharina laid out the worry. A few large power plants are being replaced by thousands of distributed assets, many controlled remotely. A single outage matters less, but the attack surface is far larger, and AI gives attackers powerful tools to find weak software. Energy has plenty of it, from old firmware to rarely patched controllers and small manufacturers without a security team. Work that once took an expert team months is now much faster and cheaper.

Till called the root cause common-mode failure. The hardware is spread over millions of devices, but firmware, communications and control run back through a few shared platforms. A fleet of 100,000 assets may look decentralised and still act like one large central asset for anyone with common access. The question, Till said, is whether Europe is decentralising only the hardware while concentrating the software and control.

The examples were not abstract. One scan of European systems found roughly 35,000 solar devices openly exposed at the management layer. On 24 February 2022, an hour before Russia invaded Ukraine, a hack of a satellite network cut one wind-turbine maker off from more than 5,000 of its turbines, and reconnecting them took several days. In 2025 an attack in Poland reached more than 30 wind and solar farms, and almost half a million people were at risk of losing energy. There was no blackout, because the grid operator could disconnect, reboot and reconnect. In Ukraine, where almost two-thirds of generating assets are damaged, destroyed or occupied, an International Energy Agency study favoured a much more decentralised system, secured in new ways.

We're a startup, we're three years old, who's gonna hack us

— a founder

What resilience costs

Till described a microgrid-software company going through ISO 27001 certification whose certifier wanted virus scanners on every device. The engineers saw the scanners as exactly the kind of common entry point attackers look for, and risked the certification over it before settling on an open-source workaround.

A desalination founder working in the Middle East broke resilience into layers. There is climate, energy, supply chains that break if the Strait of Hormuz closes and membranes cannot be imported, and conflict, in which large central plants are exposed to drones and missiles. Spreading the risk means a hundred smaller plants at a slightly higher unit cost instead of one plant at the lowest. The strategic value is hard to price, and people have short memories. When things return to normal, the founder said, nobody wants to pay the premium.

To a participant from a large South Korean company, there was no premium to argue about. Resilience means redundancy, which is never the most efficient choice, they said, but it is how things should be. South Korea has always had a geopolitical opponent, and their company has built accordingly. Its cybersecurity suppliers must be South Korean even when they cost more, so that in a political crisis it is clear whom to call, and some data may not leave the country. For Europe, they said, the question is "what is our baseline resilience level?" Till noted that Europe has started that debate over Chinese equipment in inverters.

Theses still forming

The investors were candid about how early they are. Katharina said Vireo had only just begun its deep dives on cybersecurity and resilience and, beyond the buzzword, had no thesis ready. Till saw start-ups gathering where operational technology on the asset meets commands from the internet, in protocols and security. Another investor sees cybersecurity firms specialising in renewable infrastructure, with certification and compliance starting to decide which energy-management product a buyer picks. Climate start-ups are finding defence buyers too. A maker of electric construction dumpers that took forever to sell now has the Ukrainian government asking for them for the front line.

A participant from advanced nuclear warned that buyers will want a proof that start-ups cannot give. At a recent conference, the buyers of small reactors were more worried about cyber risk than the notoriously conservative regulators, and remote operation makes such networks vulnerable by default. Start-up security will not be accepted on its own, they said. Europe should marry its start-ups to incumbents such as ABB, because anything built from scratch will not be ready within the five years that matter.

Till closed by saying awareness is only starting. Katharina took something sharper from the circle. Some had treated resilience as a strategy all along, Katharina said, while others, Vireo included, were only starting out. The baseline the Korean participant described may not yet be the baseline for some at the table.

This Ripple was hosted by Till Stenzel (SET Ventures) and Katharina Beitz (Vireo Ventures) at The Drop 2026 on 16 September.

More on energy and the grid

Live podcast3 min readThe New Nuclear Podcast: Sovereign power – nuclear as strategic European infrastructureEurope already has the fuel for nuclear sovereigntySam Floy · Klaus Nyengaard · Anton Steen · Johan Christian SollidLive podcast3 min readRaw Green: The 380 Exajoule OpportunityThe grid runs at half capacity while investors chase new powerFrancesco De Lieto · Emma Mee · Rushad NanavattyRipple4 min readSmarter power: Negawatts before megawattsThe grid's spare capacity is real, and hard to sellRushad Nanavatty · Duncan Turner
All 17 sessions in The Drop 2026 on energy and the grid →