Skip to main content

Power Grid Sabotage: How Grid Operators Can Detect Physical Tampering Early

|articles

20 min

Power Grid Sabotage: How Grid Operators Can Detect Physical Tampering Early

Germany’s power grid is among the most reliable in Europe. In 2024, average supply unavailability for end consumers was just 11.7 minutes. Nevertheless, 830 grid operators reported a total of 164,645 supply interruptions in low- and medium-voltage networks to the Bundesnetzagentur, Germany’s Federal Network Agency.

This high level of reliability is the result of redundancy, professional grid operations and fault-response processes that have been optimised over decades.

However, the risk landscape is changing.

Alongside technical failures, weather-related incidents and unintended third-party interference, grid operators increasingly need to consider deliberate physical attacks.

Recent events in September 2026 demonstrate just how tangible this scenario has become. In Brandenburg, perpetrators attempted to use improvised devices to introduce conductive material into extra-high-voltage lines near a substation in order to cause short circuits. At almost the same time, authorities in North Rhine-Westphalia investigated a suspected deliberate act following a short circuit at a substation. Public electricity supply remained stable in both cases.

The potential impact of such attacks had already become apparent in Berlin on 9 September 2025. Following a targeted attack on two 110 kV line systems, around 50,000 customers temporarily lost their electricity supply. It took approximately 60 hours for all customers to be reconnected.

For grid operators, this raises a new question: How can physical tampering be detected before it develops into an operational disruption?

Why Targeted Attacks Present a Particular Challenge for Power Grids

Power grids are designed to withstand technical failures. A single piece of equipment can fail without automatically causing an interruption to supply. Redundancy, protection concepts and switching options are designed precisely for this purpose.

Targeted attacks, however, follow a different logic. An attacker can select specific vulnerabilities, target several components simultaneously or deliberately attempt to circumvent existing redundancy. The Berlin example illustrates this particularly clearly: the affected network was designed according to the N-1 principle. However, because both supplying 110 kV line systems were damaged at the same time, the intended redundancy was no longer available.

This is what fundamentally distinguishes sabotage from many random failures: the attacker adapts to the protection architecture; a technical fault does not. Attackers may understand existing safeguards, take their functionality into account and deliberately attempt to bypass them.

The same applies to conventional physical security measures. A door contact, for example, can reliably report that a door has been opened. For a prepared attacker, however, its presence is neither unexpected nor necessarily an obstacle. The attacker may choose an approach that avoids the monitored door altogether, or the alarm may only be triggered once the attack is already under way.

This is precisely the challenge: safeguards designed to detect individual events are not automatically designed to stay ahead of an intelligent and adaptable attacker. A purely reactive approach is therefore insufficient. The Critical Metric Is Not Only Resilience to Failure, but Detection Time.

Traditional grid management understandably focuses heavily on availability:

  • How quickly can switching take place?

  • What redundancy is available?

  • How quickly can the fault-response team react?

  • Which spare parts are required?

  • How long will restoration take?

When deliberate interference is involved, an additional metric becomes important: How much time passes between physical tampering and its detection? This period determines whether a physical intervention can be investigated at an early stage or only becomes visible once a technical fault has already occurred. Consider a simplified example: If a technical component at an unmanned distribution substation is tampered with during the night and the change is only discovered during the next maintenance visit, a considerable period may pass between the intervention and its detection.

If, by contrast, the change is detected immediately, operators can investigate:

  • Which asset is affected?

  • Is this part of scheduled maintenance?

  • Does the site need to be inspected?

  • Is an operational response required?

  • Are other locations affected?

  • Does a security process need to be initiated?

What Are the Potential Consequences of a Successful Attack for Grid Operators?

An immediate interruption to supply is only one possible consequence. Depending on the asset affected, additional impacts may include:

  • Operational impacts: Fault response, switching operations, deployment of on-call personnel, repairs, spare-parts procurement and restoration all consume operational resources.

  • Loss of redundancy: Even if customers initially remain supplied, an attack may compromise reserves or alternative supply routes. The grid remains operational but temporarily has a reduced safety margin.

  • Secondary impacts: Electricity supply underpins numerous other critical services, from telecommunications and transport to healthcare and water supply.

  • Regulatory impacts: Under certain circumstances, supply interruptions are included in assessments of network reliability.

  • Reputational and communications impact: Major outages increase the need for information and communication with authorities, municipalities, customers and the wider public.

For precisely this reason, security considerations should not begin only once a blackout has occurred.

Does a Power Outage Automatically Result in a Penalty?

No. A common misconception in discussions about critical infrastructure security is that a power outage automatically leads to a fine. That is not how the regulatory framework works.

For electricity distribution grid operators, however, supply interruptions can have financial implications through quality regulation. The Bundesnetzagentur assesses indicators including SAIDI and ASIDI. Deviations from the relevant reference values can result in uplifts or deductions to the operator’s revenue cap.

One relevant point is that SAIDI figures under the EnWG include, among other things, unplanned supply interruptions caused by “third-party interference”. Grid operators report supply interruptions lasting more than three minutes to the Bundesnetzagentur, including information on their timing, duration, scale and cause.

In addition, operators are subject to security, documentation and reporting obligations. Regulatory sanctions are therefore not simply triggered by the existence of a power outage, but may result, for example, from a failure to comply with specific statutory obligations.

This distinction is important when developing a security strategy: The primary objective of physical security should not be to avoid fines. It should be to manage risks to safe and resilient grid operations appropriately.

How well are your critical assets protected against physical tampering today?


Which locations should you prioritize? Where are there gaps in detection? And which measures actually make sense for your infrastructure?

Discuss your specific situation in person with our expert.

Schedule a personal meeting

The KRITIS-Dachgesetz Makes Physical Resilience a Management Responsibility

This development is particularly evident in the KRITIS-Dachgesetz, which entered into force on 17 March 2026.

For operators of critical facilities, the legislation establishes a risk-based approach. Operators must conduct risk assessments and implement proportionate technical, security-related and organisational measures to strengthen resilience. Examples of potential measures referred to in the legislation include structural and technical protection, monitoring of the surrounding environment, detection devices and access controls. Measures are also to be documented in a resilience plan.

The key message is not that every distribution substation will need to be equipped with the same security technology in future. Quite the opposite. The legislation explicitly follows a risk-based and proportionate approach. The effort and benefits associated with protective measures should be proportionate to the relevant risk. This means operators need to address a different question: Which assets require which level of protection?

Not Every Distribution Substation Is Equally Critical

For operators managing hundreds or thousands of decentralised assets, providing maximum security for every individual location is unlikely to be economically viable.

Prioritisation should therefore consider factors such as the following:

1. What Would Be the Impact of a Failure?

The key consideration is not only the technical importance of a component, but also its impact on supply. How many customers would be affected? Are there particularly critical consumers? What level of capacity or which grid function depends on the asset?

2. What Redundancy Is Available?

Can a failure be compensated for automatically or through operational measures? Particular attention should be given to assets where the failure of multiple components could eliminate shared redundancy.

3. How Exposed Is the Location?

A technical installation located on a controlled operational site has a different risk profile from a freely accessible or remote substation. Relevant considerations include accessibility, visibility and the frequency of routine inspections.

4. How Quickly Would Tampering Be Detected?

A regularly staffed location benefits from natural detection mechanisms. At unmanned facilities, by contrast, a physical change may remain unnoticed for an extended period.

5. How Complex Would Restoration Be?

Not every technical component can be replaced at short notice. Lead times, specialist personnel, civil engineering work or specialised repair procedures can significantly extend restoration times. These factors can be used to develop a risk-based protection concept rather than deploying security technology indiscriminately across the entire grid.

6. Is a Door Contact Sufficient for Tamper Detection?

For many applications, a door contact is a simple and effective security measure. It answers one clearly defined question: Has a specific door or hatch been opened?

That is also where its limitations lie. A door contact monitors a defined point of access. This does not automatically mean that every possible physical change to the protected asset must take place through that access point.

Depending on the design of the installation, relevant attack scenarios may also include changes to the enclosure, drilling or cutting attempts, access through other openings or manipulation of externally mounted components. The choice of detection method should therefore be based on the relevant threat model.

 

Security Question

Appropriate approach

Who is authorised to access a site?Access control
Has a defined door been opened?Door contact
What is happening within the monitored area?Video or motion monitoring
Has the physical condition of an asset changed?Integrity or tamper detection

 

These technologies do not necessarily compete with one another. They address different security questions. For operators, the relevant issue is therefore not which system is “better”. The key questions are: What type of tampering do I need to detect, and would my existing sensors actually detect it?

From Access Monitoring to Integrity Monitoring

For decentralised technical assets in particular, an additional perspective can be valuable.

Rather than focusing exclusively on monitoring how someone gains access to an asset, operators can also monitor whether the asset itself has changed.

This approach is commonly referred to as tamper detection or integrity monitoring.

Its advantage is that detection is not tied exclusively to one specific attack vector.

This can be particularly relevant for exposed and unmanned facilities where physical tampering needs to be identified as early as possible.

One technical solution for this type of monitoring is PHYSEC SEAL. Using an anti-tamper radio sensor, the system creates an electromagnetic reference state for the monitored asset and compares it with subsequent measurements. Physical changes can therefore be detected and reported to central monitoring systems or SIEM/SOC environments.

SEAL does not replace access control or door contacts. Instead, it complements these measures where the requirement is not only to monitor access, but also the integrity of the asset itself.

The response following detection is critical. A sensor alone does not increase resilience. Detection becomes a genuine security mechanism only when an identified change triggers a defined process. Grid operators should therefore establish, for relevant assets:

  • What constitutes an event? Which changes in condition need to be investigated?

  • Where is the information received: the control centre, grid operations, the Security Operations Centre or the on-call service?

  • How is scheduled maintenance distinguished from an unauthorised intervention?

  • Who assesses the incident?

  • When is an on-site inspection required?

  • When is a cybersecurity or critical infrastructure incident process triggered?

  • How is the incident documented?

This makes one point clear: physical tamper detection is not an isolated hardware issue. It forms part of risk, operational and incident management.

Physical Security Should Start with Risk, Not Technology

The current threat landscape demonstrates that power grid operators should incorporate physical attacks as a realistic scenario within their risk assessments. The answer, however, is not to apply the maximum possible level of security to every facility.

What is required is a structured assessment:

  1. Which assets are particularly important to grid operations?

  2. Which attack scenarios are realistic at those locations?

  3. Which existing safeguards already address these scenarios?

  4. Where are the detection gaps?

  5. How quickly would a physical intervention currently be detected?

  6. What response would that detection trigger?

Only after these questions have been answered should decisions about specific technologies be made. A fence solves a different problem from a camera. A camera addresses a different problem from a door contact. And a door contact answers a different security question from integrity monitoring.

Making these distinctions is essential to developing a cost-effective and robust protection concept. For power grid operators, physical security is therefore evolving from a traditional site-protection function into an increasingly important component of technical risk management.

The central question is no longer simply: “Can we manage an outage?” It is also: “Can we detect at an early stage when someone is attempting to compromise our ability to operate the grid safely?” Operators that can answer this question for their critical assets have taken a significant step from reactive fault remediation towards genuine resilience.

Frequently Asked Questions About the Physical Security of Power Grids

Recent incidents demonstrate that targeted attacks on electricity infrastructure in Germany are a realistic scenario. In September 2026, authorities investigated attacks or suspected deliberate interference involving electricity infrastructure in Brandenburg and North Rhine-Westphalia, among other cases.

 

The KRITIS-Dachgesetz provides for risk-based physical protection measures for operators of critical facilities. Potential measures include site protection, monitoring of the surrounding environment, detection devices and access controls. The specific measures considered appropriate depend on the individual risk assessment and the principle of proportionality.

 

No. A power outage does not automatically trigger a fine. Financial implications may arise, for example, through quality regulation. Sanctions may also become relevant where operators fail to comply with specific statutory security, documentation or reporting obligations.

 

That depends on the threat model. A door contact detects the opening of a defined access point. If operators also need to detect whether the asset itself has been physically altered, additional detection mechanisms may be required.

 

Priority should be given in particular to locations where a failure would have significant consequences, where redundancy is limited, physical exposure is high, inspection intervals are long or restoration would be complex. Equipping every asset with the same security measures is not necessarily appropriate.

 

Access control addresses the question of who is authorised to enter an area or access or open an installation. Tamper detection focuses on whether the physical condition of an asset has changed. Both approaches can form part of the same security architecture.

 

Back