# Executive Summary: From Cybersecurity to Cyber-Resilience

Version 1.0 (2026-10-07) — I-S3 Co., Ltd., Suomi Masuda

## In one sentence

The key to connecting tens of millions of distributed energy resources (DER) safely is not "never being breached" but **writing a cap on the MW that sit behind one credential and one firmware line**.

## The problem

- Japan has over 100 GW of solar PV, about 3.4 million residential systems and about 1 million home batteries. Almost all of them connect to some cloud.
- In 2024–25, Solarman/Deye (settings changeable on about 195 GW), SUN:DOWN (46 vulnerabilities across three vendors) and the Dutch RDI test (9 of 9 inverters non-compliant) were published. No harm has occurred yet. No grid attack through a DER cloud has been observed, but attacks on grids themselves have (Ukraine 2015/2016/2022, Volt Typhoon).
- Certification lowers the probability of compromise; it does not ask whether a legitimate command is large enough to break the grid.

## The metric

**Cyber Blast Radius (CBR)** = the capacity (MW) one successful compromise can move simultaneously within about 30 seconds. Decomposed by device, domain, firmware line, control plane and region. It is the logic of NERC CIP-002's 1,500/3,000 MW thresholds and the EU NCCS ECII, brought down to distribution-level DER and the device.

Systemic risk = the annual probability, for the whole fleet, of a wide-area event (under-frequency load shedding or worse), summing the control-plane channel and the vendor channel (cloud/OTA/firmware).

## Results (10 million × 5 kW = 50 GW on an East-Japan-sized grid)

| Configuration | Max CBR per compromise | Total systemic risk /yr |
|---|---|---|
| A: single control plane + certification | 35,000 MW | 9.4×10⁻³ |
| A+: A + server-side aggregate cap 1,500 MW | 1,050 MW (API compromise) | 3.1×10⁻³ |
| B: 100 domains + device floor 30% + 500 MW cap (software only) | 117 MW (plane) / 10,500 MW (firmware line) | 1.9×10⁻² |
| B5: B + floor held by an independent monitor circuit | 117 / 3,518 MW | 7.3×10⁻³ |
| B6: B5 + firmware-line reach cap 12% | 117 / 1,407 MW | 4.0×10⁻³ |
| B7: B5 + firmware-line reach cap 5% | 117 / 586 MW | 1.3×10⁻³ |

1. **For the same control-plane compromise**, B stops at 1/300 of A's capacity. Even counting B's 100-fold attack surface, control-plane-channel risk is about 1/7 (Monte Carlo median 1/14).
2. **In total, software-only B is no better than A.** A compromise of the largest firmware line (30% share = 10.5 GW) bypasses the authority cap and erases the floor and ramp limit implemented in firmware. This channel is shared by A and B and dominates the total.
3. **Two things lower the total:** an output floor held by a monitor circuit independent of the main firmware (the ramp limit does not survive), and a cap on the capacity one firmware line can reach remotely. To avoid load shedding in the reference grid: about 1,350 MW (11.5% of the fleet) if the floor survives, about 3.9% if software-only.
4. **Centralization gets to the same order.** A+ with an independent server-side safety monitor and aggregate cap lands in the same order as B6. What remains is a full-backend compromise.
5. **Monte Carlo (20,000 draws):** on the control-plane channel alone B is lower in 100% of draws. In total, B (software) vs A has a median ratio of 1.8; a B6-type design vs A is 9×; B6-type vs A+ is 3.3× (lower in 83%).
6. **Economics do not settle it.** The lost flexibility value of a 30% floor (¥12–74 bn/yr) and A's expected blackout cost (¥10–50 bn/yr) are the same order. The cheapest items are the independent monitor circuit (¥ hundreds of millions/yr) and the server-side safety monitor (¥ hundreds of millions to a billion/yr).

## When centralization wins

The fleet is small relative to the grid. The gain from splitting loses to the multiplied attack surface (x already small). The vendor channel is relatively more likely than the plane channel. The server-side cap is strongly protected and backend compromise is rare. Flexibility value must be maximised.

## Policy recommendations

1. Write **Maximum Remote Authority (MW per credential)** and **remote reach per firmware line** into grid-connection requirements.
2. Put three auditable attributes on the device label — remote-OFF class physically disabled, independent monitor circuit present, OTA path separated (added to JC-STAR stars).
3. Count **settings authority reach** (MW behind credentials that can rewrite schedules, protection settings or clocks) with the same weight as immediate commands.
4. The first CBR to measure is the per-area reach of the TSO/DSO online curtailment servers in Japan. They are not a precedent for B; they are an H-type single control plane.
5. Measure, publish and cap "how many GW one attacker can move at once in Japan".

## Published materials

Long-form article (JA/EN), CBR model (Python), grid simulation, correlated-failure and Monte Carlo runs, 12 figures, interactive simulator (JavaScript, matches Python to 1e-9), assumptions and incident data, nine-perspective Red Team report with response matrix, open problems list. All CC BY 4.0.

**The secure grid is not the grid that can never be hacked. It is the grid that continues to function when something is hacked.**
