A note from Val: Before Second Desk Consulting, much of my work involved advising on complex infrastructure and energy projects — including battery energy storage systems (BESS) and the national security questions tied to how they’re built and secured. I’m sharing this white paper as an example of the kind of deep, technical analysis our team’s background is built on. While Second Desk’s day-to-day work is focused on helping business owners offload admin, media, and client-facing tasks, the same rigor and business judgment behind pieces like this is what shapes how we approach every client’s needs, at every scale.
Introduction
Battery Energy Storage Systems (BESS) are a foundational component of modern electric grids. By storing energy for later use, BESS enable utilities to balance supply and demand, support the integration of renewable energy sources, and enhance grid resilience during disruptions. As grid operators increasingly rely on these systems, their security — both physical and cyber — has become a matter of national importance.
The growing complexity and interconnectedness of BESS, combined with extensive reliance on foreign-manufactured components, introduce significant cybersecurity and supply chain risks. These risks are especially acute when critical components originate from countries with strategic interests that may conflict with those of the United States.
Supply Chain Dependencies and Cybersecurity Risk
At a recent hearing before the U.S. House Select Committee, Dr. Emma Stewart, Chief Power Grid Scientist at Idaho National Laboratory (INL), underscored a major structural vulnerability in the global battery supply chain: more than 90 percent of Chinese battery manufacturers rely on at least one critical component produced domestically within China. This concentration of manufacturing and component sourcing raises concerns related to embedded vulnerabilities, limited software transparency, and exposure to state-sponsored cyber operations.
Because BESS are tightly integrated with grid management and supervisory control systems, a compromise — whether through malicious firmware, unauthorized software updates, or covert remote access — could degrade grid reliability, disrupt energy delivery, or enable adversarial actors to exert influence over U.S. critical infrastructure.
The Chinese-Dominated Battery Market and National Security Implications
Economic pressures continue to drive reliance on Chinese-manufactured batteries despite mounting security concerns. Chinese manufacturing costs for BESS are estimated to be approximately 60 percent lower than those of U.S.-based production, with battery packs alone costing roughly 31 percent less. These price advantages have positioned Chinese suppliers as dominant actors in the global battery market.
Notably, the United States remains the largest importer of Chinese-manufactured lithium-ion batteries, accounting for approximately 25 percent of China’s $60 billion battery export market in 2023. This dependency illustrates the tension between short-term economic efficiency and long-term national security considerations.
In response, U.S. trade policy has increasingly focused on reducing strategic dependency. Planned tariff increases on Chinese lithium-ion batteries — from 7.5 percent to 25 percent by January 2026 — along with additional tariff actions announced in 2024 and 2025, are reshaping market dynamics. While these measures aim to encourage domestic manufacturing and supply chain diversification, the cost advantages of Chinese production remain difficult to offset in the near term.
Vulnerabilities in Foreign-Manufactured BESS
The U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) has emphasized that mitigating risks associated with foreign-manufactured BESS requires a proactive and layered cybersecurity approach. Key areas of concern include:
Firmware and software integrity within control systems
Embedded communication modules with undocumented or persistent remote access
Limited visibility into software provenance and update mechanisms
Contractual provisions that grant foreign vendors operational influence over critical assets
Left unaddressed, these vulnerabilities may enable adversarial actors to disrupt operations, manipulate system behavior, or access sensitive operational data during periods of heightened geopolitical tension.
Proactive Security Measures for Grid Protection
To mitigate these risks, utilities and grid operators should adopt a comprehensive security framework that extends beyond perimeter-based defenses. Recommended measures include:
Comprehensive Vulnerability Assessments — Conduct in-depth evaluations of all BESS components, including firmware, software dependencies, hardware elements, and communication protocols. Assessments should prioritize operational impact and exploitability within real-world grid environments.
Cyber-Informed Engineering (CIE) — Integrate cybersecurity considerations directly into system design and engineering processes. Embedding security controls during development reduces the likelihood of latent vulnerabilities emerging during deployment.
Revised Supplier Contracts and SLAs — Service-level agreements should be reviewed and amended to prevent foreign suppliers — particularly those with ties to strategic competitors — from retaining control over system updates, diagnostics, or remote access. Procurement leverage must not override cybersecurity requirements.
Strategic Component Replacement — In high-risk environments such as substations, grid control centers, and critical energy storage installations, operators should consider replacing vulnerable control components with alternatives sourced from trusted suppliers.
Strict Sourcing and Due Diligence Requirements — Utilities should prioritize suppliers that meet established cybersecurity standards, including those issued by the National Institute of Standards and Technology (NIST) and DOE CESER. Comprehensive due diligence should precede all procurement and contracting decisions.
Software Bill of Materials (SBOM) Requirements — All BESS stakeholders should be required to generate and maintain a comprehensive Software Bill of Materials (SBOM). SBOMs should document component origins, versioning, licenses, and dependencies to improve transparency and enable rapid vulnerability response.
Access Controls and Network Segmentation — Access to BESS environments must be restricted to authorized personnel. Communications between BESS components and external systems — particularly those involving foreign-sourced components — should occur over segmented, encrypted networks to reduce the risk of unauthorized access or data exfiltration.
Strengthening Critical Infrastructure Through Policy and Technology
Recent efforts by federal agencies and legislative bodies reflect a growing consensus that energy storage systems represent a critical attack surface within the U.S. power grid. Effective risk reduction will require coordinated action across policy, regulation, procurement, and system engineering.
Advanced cybersecurity capabilities — such as automated software vetting, continuous vulnerability monitoring, SBOM lifecycle management, and audit-ready reporting — can support compliance with evolving regulatory requirements while improving operational resilience. When applied systematically, these capabilities enhance visibility across the BESS supply chain and enable more informed risk-based decision-making.
Conclusion
As Battery Energy Storage Systems become increasingly integral to grid operations, their cybersecurity and supply chain integrity must be treated as national security priorities. While economic realities complicate rapid decoupling from foreign manufacturing, meaningful risk reduction is achievable through disciplined procurement practices, engineering-driven security, and comprehensive supply chain transparency.
By aligning policy initiatives with technical safeguards and standardized cybersecurity frameworks, the United States can strengthen grid resilience, reduce exposure to adversarial influence, and ensure the long-term security of its energy infrastructure.