<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ludovic DEGRE, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/ludovic-degre/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Mon, 20 Jul 2026 16:53:35 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Ludovic DEGRE, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Plug &#038; Charge and ISO 15118: what are the new cyber risks for charging stations? </title>
		<link>https://www.riskinsight-wavestone.com/en/2026/06/plug-charge-and-iso-15118-what-are-the-new-cyber-risks-for-charging-stations/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/06/plug-charge-and-iso-15118-what-are-the-new-cyber-risks-for-charging-stations/#respond</comments>
		
		<dc:creator><![CDATA[Ludovic DEGRE]]></dc:creator>
		<pubDate>Wed, 17 Jun 2026 15:26:09 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<category><![CDATA[ChargingStations]]></category>
		<category><![CDATA[ConnectedVehicles]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[ElectricVehicles]]></category>
		<category><![CDATA[ISO15118]]></category>
		<category><![CDATA[PlugAndCharge]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=30152</guid>

					<description><![CDATA[<p> As highlighted in our previous article, Electric vehicle charging infrastructures: Energy performance and new cybersecurity challenges, charge point operators (CPOs) operate within a demanding business model, where profitability depends on their ability to drive recurring usage of their networks. In this context, user experience becomes a key...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/06/plug-charge-and-iso-15118-what-are-the-new-cyber-risks-for-charging-stations/">Plug &amp; Charge and ISO 15118: what are the new cyber risks for charging stations? </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0}"> </span><span style="font-size: revert; color: initial;" data-contrast="auto">As highlighted in our previous article, </span><a style="font-size: revert;" href="https://www.riskinsight-wavestone.com/en/2026/04/electric-mobility-charging-infrastructure-evolution-between-energy-optimization-and-emerging-cybersecurity-challenges/"><i><span data-contrast="none">Electric vehicle charging infrastructures: Energy performance and new cybersecurity challenges</span></i></a><span style="font-size: revert; color: initial;" data-contrast="auto">, charge point operators (CPOs) operate within a demanding business model, where profitability depends on their ability to drive recurring usage of their networks. In this context, </span><b style="font-size: revert; color: initial;"><span data-contrast="auto">user experience becomes a key lever</span></b><span style="font-size: revert; color: initial;" data-contrast="auto">: the smoother the charging journey, the fewer failures and friction points it involves, ultimately helping build customer loyalty.</span><span style="font-size: revert; color: initial;" data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="auto">Plug &amp; Charge</span></b><span data-contrast="auto"> is being promoted precisely to address this challenge. Enabled by the </span><b><span data-contrast="auto">ISO 15118 standard</span></b><span data-contrast="auto">, this mechanism allows the charging station to automatically authenticate the user and initiate charging without the need for a badge or mobile application. Originally designed to standardize communication between the vehicle, the charging station and the grid, ISO 15118 paves the way for a more seamless charging experience—often summed up by the promise: “plug in and it charges.”</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">However, this apparent simplification on the user side actually relies on a </span><b><span data-contrast="auto">significant increase in complexity across the underlying trust chain </span></b><span data-contrast="auto">and technical mechanisms: digital certificates, Public Key Infrastructure (PKI), ISO 15118 communications, new authentication flows, and dependencies on trusted third parties. In other words, behind a frictionless charging experience, Plug &amp; Charge introduces new points of failure and expands the attack surface that operators must now address as critical cybersecurity concerns.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">In this article, we take a closer look at</span><b><span data-contrast="auto"> three risks directly associated with the deployment of Plug &amp; Charge and ISO 15118</span></b><span data-contrast="auto">:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><b><span data-contrast="auto">availability loss</span></b><span data-contrast="auto"> resulting from a compromise of the </span><b><span data-contrast="auto">V2G (Vehicle-to-Grid) PKI;</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">availability loss</span></b><span data-contrast="auto"> caused by the exploitation of </span><b><span data-contrast="auto">vulnerabilities on the ISO 15118 interface</span></b><span data-contrast="auto">;</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><span data-contrast="auto">the theft of charging station certificates and its implications in terms of </span><b><span data-contrast="auto">fraud</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<h1><span data-contrast="none">Risk 1: availability loss resulting from a compromise of the V2G PKI</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h1>
<p><span data-contrast="auto">To understand this risk, it is first important to recall that Plug &amp; Charge relies on a digital trust chain that enables the vehicle and the charging station to automatically authenticate each other using certificates and then initiate charging without any manual action from the user.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">As illustrated in Figure 1, a Plug &amp; Charge session follows a multi-step sequence:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol style="list-style-type: upper-roman;">
<li><span data-contrast="auto">Establishment of the ISO 15118 communication channel between the vehicle and the charging station, along with mutual authentication, </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><span data-contrast="auto">Verification of the mobility contract followed by authorization,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><span data-contrast="auto">Start of charging session.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ol>
<p><span data-contrast="auto">If any of these steps fails due to a breakdown in digital trust, the charging session cannot be initiated.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:300}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0}"><img fetchpriority="high" decoding="async" class="size-full wp-image-30114 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borne_EV_en1.png" alt="" width="2012" height="1056" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borne_EV_en1.png 2012w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borne_EV_en1-364x191.png 364w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borne_EV_en1-71x37.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borne_EV_en1-768x403.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borne_EV_en1-1536x806.png 1536w" sizes="(max-width: 2012px) 100vw, 2012px" /></span><i><span data-contrast="auto">Figure 1: Steps of a Plug &amp; Charge session</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="auto">This mechanism relies on a shared PKI across the ecosystem, known as the </span><b><span data-contrast="auto">V2G PKI</span></b><span data-contrast="auto">, whose role is to ensure interoperability between vehicles, charging stations, and operators. This architecture is built on root and intermediate certificate authorities that issue and validate the certificates used throughout the charging session (Figure 2).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"><img decoding="async" class="size-full wp-image-30116 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en2.png" alt="" width="1698" height="1100" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en2.png 1698w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en2-295x191.png 295w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en2-60x39.png 60w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en2-768x498.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en2-1536x995.png 1536w" sizes="(max-width: 1698px) 100vw, 1698px" /></span><i><span data-contrast="auto">Figure 2: V2G PKI architecture</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="auto">In Europe, this ecosystem currently relies on a limited number of key trusted players—such as </span><b><span data-contrast="auto">Hubject</span></b><span data-contrast="auto">, </span><b><span data-contrast="auto">Gireve</span></b><span data-contrast="auto">, and </span><b><span data-contrast="auto">Irdeto</span></b><span data-contrast="auto">—which combine the role of root certification authority (V2G Root CA) with Plug &amp; Charge certificate management and interoperability services.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Within this architecture, the CPO holds a pivotal position: charging stations must be integrated into this trust chain and, depending on the chosen model, the operator may run certain PKI components in-house (</span><i><span data-contrast="auto">make</span></i><span data-contrast="auto">) or rely on a specialized provider (</span><i><span data-contrast="auto">buy</span></i><span data-contrast="auto">). In both cases, the CPO becomes dependent on a trust infrastructure whose compromise, misconfiguration, or unavailability can have a </span><b><span data-contrast="auto">direct impact on service availability</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">The risk, therefore, lies in a </span><b><span data-contrast="auto">loss of service availability</span></b><span data-contrast="auto"> caused by an incident affecting the V2G PKI. Several scenarios are plausible: compromise of a root or intermediate authority, expired certificates that were not renewed, corruption of a trust store, or unavailability of a component involved in the certificate lifecycle. In all these situations, the operational outcome is the same: the charging station or the vehicle can no longer establish a valid trust relationship, and the Plug &amp; Charge session fails before charging even starts.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2><span data-contrast="none">Key takeaways</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p><span data-contrast="auto">With Plug &amp; Charge, PKI no longer only secures communications, it becomes a </span><b><span data-contrast="auto">critical production component</span></b><span data-contrast="auto">. An incident affecting the trust infrastructure is therefore not just a security or compliance issue, but a potential source of partial or large-scale service disruption.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">The choice between </span><i><span data-contrast="auto">make</span></i><span data-contrast="auto"> and </span><i><span data-contrast="auto">buy</span></i><span data-contrast="auto"> does not eliminate this risk; it shifts where control lies. A </span><i><span data-contrast="auto">make</span></i><span data-contrast="auto"> strategy provides greater control to the CPO, but requires mature PKI governance, robust operational capabilities, and strict discipline over certificate lifecycle management. A </span><i><span data-contrast="auto">buy</span></i><span data-contrast="auto"> strategy accelerates deployment but increases dependence on a third party for what has become a critical function, implying stronger requirements in terms of contractual oversight, auditability, and monitoring.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">From a cybersecurity standpoint, the implication is clear: the </span><b><span data-contrast="auto">V2G PKI must be treated as a critical operational asset within the charging stations information system</span></b><span data-contrast="auto">. This entails explicit governance of trust roles, continuous monitoring of certificate lifecycles, regular resilience and continuity testing, and the definition of degraded operating modes to prevent a PKI incident from escalating into large-scale service disruption.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1><span data-contrast="none">Risk 2: loss of charging infrastructure availability through the exploitation of vulnerabilities in ISO 15118 communication</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h1>
<p><span data-contrast="auto">This risk stems directly from the increasing complexity of the communication channel. Where charging historically relied on relatively simple interactions—primarily based on electrical signaling and a limited set of basic messages—ISO 15118 introduces a high-level dialogue built on a much richer protocol stack (Figure 3).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><img decoding="async" class="alignnone size-full wp-image-30118 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3.png" alt="" width="1664" height="1016" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3.png 1664w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-313x191.png 313w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-64x39.png 64w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-768x469.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-1536x938.png 1536w" sizes="(max-width: 1664px) 100vw, 1664px" /><br /><i><span data-contrast="auto">Figure 3: OSI model applied to ISO 15118</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
<p><span data-contrast="auto">This shift from a minimalist protocol to a full-fledged application layer—including device discovery, IPv6 address allocation, authentication, certificate management, and cryptographic operations—mechanically expands the attack surface. This is particularly true because the communication interface via the charging connector is inherently accessible, with no physical barriers. Any vulnerability in these exchanges (e.g., manipulation of application messages, injection into PLC traffic, improper certificate validation) </span><b><span data-contrast="auto">could disrupt the charging session—or, in a worst-case scenario, lead to a full compromise of the charging <a href="https://www.cve.org/CVERecord?id=CVE-2026-9038">station</a></span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Exploiting such vulnerabilities, however, </span><b><span data-contrast="auto">requires physical access to the charging point</span></b><span data-contrast="auto">: the attacker must be able to interact with the communication channel between the vehicle and the station. In practice, this involves specialized equipment to connect to the PLC network, such as a HomePlug Green PHY compatible interface and a physical adapter for the charging connector. While this constraint makes the exploit harder, it does not eliminate the risk. Several research efforts have demonstrated the feasibility of lab setups capable of observing, relaying, or disrupting ISO 15118 communications directly at the cable or <a href="https://www.sstic.org/media/SSTIC2019/SSTIC-actes/v2g_injector_playing_with_electric_cars_and_chargi/SSTIC2019-Article-v2g_injector_playing_with_electric_cars_and_charging_stations_via_powerline-dudek.pdf">connector level</a>.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><span data-contrast="auto"><img decoding="async" class="alignnone size-full wp-image-30118 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3.png" alt="" width="1664" height="1016" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3.png 1664w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-313x191.png 313w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-64x39.png 64w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-768x469.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-1536x938.png 1536w" sizes="(max-width: 1664px) 100vw, 1664px" /></span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0}"> </span><i><span data-contrast="auto">Figure 4: Equipment required to exploit a vulnerability on the ISO 15118 interface</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<h2><span data-contrast="none">Key takeaways</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p><span data-contrast="auto">To mitigate these risks, CPOs </span><b><span data-contrast="auto">must ensure the security level of their vendors’ products</span></b><span data-contrast="auto">, for example through audits, and assess their cybersecurity maturity, particularly regarding processes for maintaining security over time.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">They must also </span><b><span data-contrast="auto">implement vulnerability management processes</span></b><span data-contrast="auto"> across their asset base, including </span><b><span data-contrast="auto">maintaining inventories</span></b><span data-contrast="auto"> such as </span><b><span data-contrast="auto">SBOMs</span></b><span data-contrast="auto"> and </span><b><span data-contrast="auto">HBOMs</span></b><span data-contrast="auto"> (Software and Hardware Bills of Materials), as well as robust </span><b><span data-contrast="auto">patch management practices</span></b><span data-contrast="auto">. This enables operators to identify vulnerable assets and respond effectively when attackers attempt to exploit vulnerabilities on this new communication channel.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1><span data-contrast="none">Risk 3: theft of charging station certificates</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h1>
<p><span data-contrast="auto">The theft of a charging station certificate is not only a cryptographic incident: in an ecosystem built on digital trust, it amounts to a compromise of machine identity. For a CPO, such an incident directly impacts the integrity of exchanges and may open the door to </span><b><span data-contrast="auto">charging fraud</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Two attack scenarios must be distinguished here:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Extraction of the private key</span></b><span data-contrast="auto"> associated with the certificate, following a software compromise or a physical attack on an insufficiently protected component,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Impersonation of a charging station</span></b><span data-contrast="auto"> when obtaining a certificate, for example through an insufficiently authenticated enrolment process between the station and the CPMS (Charge Point Management System).</span>  </li>
</ul>
<p><img loading="lazy" decoding="async" class="size-full wp-image-30122 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en5.png" alt="" width="1991" height="1010" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en5.png 1991w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en5-377x191.png 377w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en5-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en5-768x390.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en5-1536x779.png 1536w" sizes="auto, (max-width: 1991px) 100vw, 1991px" /></p>
<p style="text-align: center;"><i><span data-contrast="auto">Figure 5: attack paths to obtain a charging station V2G certificate</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="auto">Once in possession of a valid certificate, an attacker can impersonate a legitimate charging station and abuse the ecosystem’s trust for malicious purposes. In a Plug &amp; Charge context, this could allow an attacker to make a vehicle believe it is establishing a normal session, and then relay the proof of possession of the victim’s contract certificate into another session—effectively charging a different vehicle at the victim’s expense. This </span><b><span data-contrast="auto">relay attack</span></b><span data-contrast="auto"> scenario has been demonstrated in <a href="https://arxiv.org/abs/2512.15966">academic literature</a> and illustrates how a single compromised charging station certificate can enable tangible, operational fraud.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0}"><img loading="lazy" decoding="async" class="size-full wp-image-30124 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6.png" alt="" width="2078" height="975" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6.png 2078w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6-407x191.png 407w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6-71x33.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6-768x360.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6-1536x721.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6-2048x961.png 2048w" sizes="auto, (max-width: 2078px) 100vw, 2078px" /></span><i><span data-contrast="auto">Figure 6: exploitation of fraud through relay of the EV’s proof of possession</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="auto">This type of attack is facilitated in implementations based on </span><b><span data-contrast="auto">ISO 15118-2</span></b><span data-contrast="auto">, where Plug &amp; Charge security relies on a more limited model, particularly in terms of end-to-end authentication and certificate handling. By contrast, </span><b><span data-contrast="auto">ISO 15118-20</span></b><span data-contrast="auto"> strengthens communication security—especially through the widespread use of TLS and a move toward mutual authentication—making such fraud more difficult to exploit, although not eliminating it if machine identities are not properly protected.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">This risk is all the more realistic because </span><b><span data-contrast="auto">it does not require large compromise</span></b><span data-contrast="auto">: a single valid certificate can be sufficient. An attacker may therefore target the least protected charging station or attempt to fraudulently obtain a certificate through a weak enrolment process or inadequately secured backend. For the CPO, the challenge is not only to protect already deployed certificates, but to secure the entire lifecycle of charging station identities from issuance to storage and renewal.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2><span data-contrast="none">Key takeaways</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p><span data-contrast="auto">To mitigate the risk of private key compromise, CPOs must ensure that charging stations provide </span><b><span data-contrast="auto">secure storage capabilities for cryptographic material</span></b><span data-contrast="auto">, for example by integrating a TPM (Trusted Platform Module).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Preventing impersonation during certificate issuance requires a different approach. CPOs must guarantee the authenticity of certificate requests processed by the V2G PKI.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">This relies on </span><b><span data-contrast="auto">authenticating the charging station when establishing the communication channel with the CPMS</span></b><span data-contrast="auto">. In practice, the protocol used on this channel, OCPP, supports mutual certificate-based authentication (mTLS) from version 2.0.1 onwards. The charging station therefore presents a certificate to authenticate itself to the CPMS. Once the session is established, certificate enrolment requests (including ISO 15118 certificates) are authenticated, significantly reducing the risk of impersonation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">However, this architecture introduces a prerequisite: </span><b><span data-contrast="auto">deploying a dedicated certificate used to authenticate the charging station on the CPO network</span></b><span data-contrast="auto">. This certificate is distinct from the ISO 15118 certificate used for Plug &amp; Charge, as it serves a different scope and purpose.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">It is therefore necessary to implement </span><b><span data-contrast="auto">a dedicated PKI</span></b><span data-contrast="auto">, operated by the CPO, which can be referred to as a “Product PKI.” This PKI issues the certificates used to secure OCPP communications. The certificate management challenges described earlier also apply to this PKI. CPOs must therefore establish the organizational and technical capabilities required to operate such an infrastructure, including certificate lifecycle management, incident handling, and upskilling of teams.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">We thus arrive at a target architecture in which each charging station embeds multiple certificates issued by distinct PKIs, each serving a specific role in authentication across critical communication channels involved in the charging session (Figure 7).</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0}"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-30126 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en7.png" alt="" width="1982" height="738" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en7.png 1982w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en7-437x163.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en7-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en7-768x286.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en7-1536x572.png 1536w" sizes="auto, (max-width: 1982px) 100vw, 1982px" /> </span><i><span data-contrast="none">Figure 7: target architecture for Plug &amp; Charge deployment</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
<h2><span data-contrast="none">Risk summary</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:851}"> </span></h2>
<p><span data-contrast="auto">The introduction of Plug &amp; Charge and the ISO 15118 standard is progressively transforming charging infrastructures into a true digital trust chain, where service availability now depends as much on cybersecurity as on the electrical operation of the stations.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">The scenarios analyzed show that </span><b><span data-contrast="auto">the main risks no longer relate solely</span></b><span data-contrast="auto"> </span><b><span data-contrast="auto">to technical compromise of isolated components, but have broader impacts</span></b><span data-contrast="auto"> on:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></p>
<ul>
<li><span data-contrast="auto">Service continuity,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
<li><span data-contrast="auto">Charging fraud,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
<li><span data-contrast="auto">User trust,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
<li><span data-contrast="auto">And, ultimately, the operator’s reputation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
</ul>
<p><span data-contrast="auto">The table below summarizes the identified risks using an approach inspired by EBIOS Risk Manager, based on an assessment of:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></p>
<ul>
<li><span data-contrast="auto">The likelihood of each scenario (scale from 1 to 4),</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
<li><span data-contrast="auto">Its severity for the operator (scale from 1 to 4), with the highest impact being a nationwide loss of trust in the charging infrastructure, for instance, in a scenario where a significant portion of charging stations would no longer allow charging,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
<li><span data-contrast="auto">And the resulting overall risk level.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
</ul>
<table style="width: 100%;" data-tablestyle="MsoNormalTable" data-tablelook="1536" aria-rowcount="4">
<tbody>
<tr aria-rowindex="1">
<td style="width: 6.90477%;" data-celllook="69905">
<p style="text-align: center;"><b><span data-contrast="none">Ref.</span></b><b><span data-contrast="none">​</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
<td style="width: 51.6667%;" data-celllook="69905">
<p><b><span data-contrast="none">Risk scenarios</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
</td>
<td style="width: 14.5238%; text-align: center;" data-celllook="69905">
<p><b><span data-contrast="none">Likelihood</span></b><b><span data-contrast="none">​</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
<td style="width: 12.381%; text-align: center;" data-celllook="69905">
<p><b><span data-contrast="none">Severity</span></b><b><span data-contrast="none">​</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
<td style="width: 13.0952%; text-align: center;" data-celllook="69905">
<p><b><span data-contrast="none">Risk</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
</tr>
<tr aria-rowindex="2">
<td style="text-align: center; width: 6.90477%;" data-celllook="69905">
<p><b><span data-contrast="auto">R1</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
<td style="width: 51.6667%;" data-celllook="69905">
<p><span data-contrast="auto">Reputational/financial impact caused by loss of charging station availability following a compromise of the V2G PKI</span></p>
</td>
<td style="text-align: center; width: 14.5238%;" data-celllook="69905">
<p>2​ </p>
</td>
<td style="text-align: center; width: 12.381%;" data-celllook="69905">
<p>4 </p>
</td>
<td style="text-align: center; width: 13.0952%;" data-celllook="69905">
<p>Medium </p>
</td>
</tr>
<tr aria-rowindex="3">
<td style="text-align: center; width: 6.90477%;" data-celllook="69905">
<p><b><span data-contrast="auto">R2</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
<td style="width: 51.6667%;" data-celllook="69905">
<p><span data-contrast="auto">Reputational/financial impact caused by loss of charging station availability following large-scale exploitation of a vulnerability in ISO 15118 communication</span></p>
</td>
<td style="text-align: center; width: 14.5238%;" data-celllook="69905">
<p>2 </p>
</td>
<td style="text-align: center; width: 12.381%;" data-celllook="69905">
<p>3 </p>
</td>
<td style="text-align: center; width: 13.0952%;" data-celllook="69905">
<p>Medium </p>
</td>
</tr>
<tr aria-rowindex="4">
<td style="text-align: center; width: 6.90477%;" data-celllook="69905">
<p><b><span data-contrast="auto">R3</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
<td style="width: 51.6667%;" data-celllook="69905">
<p><span data-contrast="auto">Reputational/financial impact related to fraud resulting from certificate theft</span></p>
</td>
<td style="text-align: center; width: 14.5238%;" data-celllook="69905">
<p>2 </p>
</td>
<td style="text-align: center; width: 12.381%;" data-celllook="69905">
<p>2 </p>
</td>
<td style="text-align: center; width: 13.0952%;" data-celllook="69905">
<p>Low</p>
</td>
</tr>
</tbody>
</table>
<p style="text-align: center;"><i><span data-contrast="auto">Table 1: Summary of risks related to Plug &amp; Charge on charging infrastructure</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="auto">This analysis, however, should be nuanced: </span><b><span data-contrast="auto">the scenarios presented deliberately take a cautious, even pessimistic, view of likelihood</span></b><span data-contrast="auto">. In practice, such attacks remain difficult to carry out. They often require advanced technical skills, specific physical or logical access, a deep understanding of ISO 15118, and the capability to exploit or manipulate complex trust mechanisms.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">As such, these </span><b><span data-contrast="auto">risks should be seen as plausible scenarios to anticipate</span></b><span data-contrast="auto">, rather than threats that are currently trivial or widely observed in real-world operations. Their “medium” to “low” risk level reflects this balance: a still-limited probability, but potentially significant impacts if such attacks were to scale.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1><span data-contrast="none">Conclusion</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h1>
<p><b><span data-contrast="auto">Plug &amp; Charge simplifies the charging experience but introduces a strong dependency on a digital trust chain built on ISO 15118, the V2G PKI, and charging station certificates. This dependency creates new risks for charging infrastructures, potentially leading to service disruptions and, ultimately, a loss of trust from users toward the CPO.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="auto">While these attack scenarios remain difficult to execute, their potential impact justifies addressing them early starting from the design phase. For CPOs, the challenge is therefore no longer limited to securing charging stations but extends to securing the entire identity and trust chain that underpins the charging process.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/06/plug-charge-and-iso-15118-what-are-the-new-cyber-risks-for-charging-stations/">Plug &amp; Charge and ISO 15118: what are the new cyber risks for charging stations? </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/06/plug-charge-and-iso-15118-what-are-the-new-cyber-risks-for-charging-stations/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Electric vehicle charging infrastructure: energy performance and new cybersecurity challenges</title>
		<link>https://www.riskinsight-wavestone.com/en/2026/04/electric-mobility-charging-infrastructure-evolution-between-energy-optimization-and-emerging-cybersecurity-challenges/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/04/electric-mobility-charging-infrastructure-evolution-between-energy-optimization-and-emerging-cybersecurity-challenges/#respond</comments>
		
		<dc:creator><![CDATA[Ludovic DEGRE]]></dc:creator>
		<pubDate>Wed, 29 Apr 2026 15:56:17 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=29885</guid>

					<description><![CDATA[<p>Electric mobility is experiencing rapid growth in France and across Europe: in January 2026, registrations of fully electric vehicles in France increased by more than 50% compared with January 2025, bringing their market share to nearly one third of total vehicle sales. This trajectory confirms a structural transformation of...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/04/electric-mobility-charging-infrastructure-evolution-between-energy-optimization-and-emerging-cybersecurity-challenges/">Electric vehicle charging infrastructure: energy performance and new cybersecurity challenges</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><b><span data-contrast="auto">Electric mobility is experiencing rapid growth in France and across Europe:</span></b><span data-contrast="auto"> in January 2026, registrations of fully electric vehicles in France increased by more than 50% compared with January 2025, bringing their market share to nearly one third of total vehicle sales. This trajectory confirms a structural transformation of the automotive sector, which appears to be entering a phase of massive electrification, particularly for light-duty vehicles. This momentum is fully aligned with the orientations set out in France’s Multiannual Energy Program (PPE), which translates national ambitions for the energy transition into operational targets. As such, the growth of electric vehicles can no longer</span><b><span data-contrast="auto"> </span></b><span data-contrast="auto">be considered short-term, but rather as a trajectory set to strengthen further.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="auto">This trajectory, however, relies on the availability of a dense, reliable, and properly dimensioned charging network across the entire territory.</span></b><span data-contrast="auto"> Whether for public charging (motorways, public roads, shopping centers) or private charging (homes, businesses), this infrastructure forms the backbone of the electric mobility ecosystem. At the heart of this ecosystem, Charging Point Operators (CPOs) play a structuring role, being responsible for the installation, operation, and maintenance of charging stations.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Cyber risk is now emerging as a major threat to charging infrastructures, in a context where electrical networks are increasingly targeted by cybercriminal groups and state-sponsored actors</span><span data-contrast="auto">1</span><span data-contrast="auto">2</span><span data-contrast="auto">.  For CPOs, this reality is a game changer: mastering cyber risk becomes a prerequisite for service reliability and ecosystem protection. As charging networks expand and grow more complex, </span><b><span data-contrast="auto">cybersecurity challenges become central: data protection, service continuity, securing financial flows, and managing third</span></b>‑<b><span data-contrast="auto">party risks.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">This article is part of a series of three papers exploring three structuring challenges faced by electric mobility stakeholders, with the aim of analyzing their implications from a cybersecurity perspective.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1 aria-level="1"><span data-contrast="none">Rethinking charging infrastructure: balancing operational requirements and emerging cyber constraints</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></h1>
<p><span data-contrast="auto">In the context of strong growth combined with the gradual structuring of the market, </span><b><span data-contrast="auto">CPOs are facing a demanding economic equation</span></b><span data-contrast="auto">. The deployment of charging infrastructures requires significant upfront investments – land acquisition, grid connection, purchase and installation of charging points, supervision, and maintenance – while utilization rates remain heterogeneous across regions and site typologies. Added to this are the volatility of electricity prices, increasing competitive pressure, and the rapid evolution of technological standards, which require regular upgrades.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">As public subsidies tend to be streamlined and investors increasingly expect clearer profitability trajectories, optimizing the economic performance of assets becomes imperative. </span><b><span data-contrast="auto">Maximizing availability rates, fine</span></b>‑<b><span data-contrast="auto">tuning operating costs, improving utilization levels, and diversifying revenue streams are no longer secondary levers, but essential conditions for the long</span></b>‑<b><span data-contrast="auto">term sustainability of CPOs’ business models.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Charging infrastructures, as designed today, illustrated in Figure</span><span data-contrast="auto"> </span><span data-contrast="auto">1, generally rely on static power control managed by a central supervision system, the Charging Point Management System (CPMS). This operating model does not allow, or significantly limits, the CPO’s ability to adapt power distribution in real time to usage patterns and site-specific constraints.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-29868 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN1.png" alt="" width="679" height="262" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN1.png 679w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN1-437x169.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN1-71x27.png 71w" sizes="auto, (max-width: 679px) 100vw, 679px" /></span><em> Figure 1: Architecture of a conventional charging infrastructure </em></p>
<p><span data-contrast="auto">Therefore, several optimization levers can be implemented.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">First, it is possible to enhance the site’s energy flexibility, particularly to support fast charging without having to oversize the grid connection. To achieve this, the deployment of a </span><b><span data-contrast="auto">Battery Energy Storage System (BESS)</span></b><span data-contrast="auto"> proves to be an effective solution: this stationary battery storage acts as a buffer, capable of storing energy when it is available and releasing it during peak demand, thereby improving the site’s stability and resilience.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">The next step consists in integrating local, low</span>‑<span data-contrast="auto">carbon energy production directly at charging sites, making it available for immediate use or storage through the addition of </span><b><span data-contrast="auto">photovoltaic systems</span></b><span data-contrast="auto">. Solar panels, installed on rooftops or canopies, provide this renewable generation layer. Their effectiveness, however, relies on their integration with appropriate control and storage systems, ensuring the environmental coherence of electric mobility.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Finally, to enable the proper integration of these energy production and storage assets at charging sites, a global control system has emerged: the </span><b><span data-contrast="auto">Energy Management System (EMS)</span></b><span data-contrast="auto">. This system supervises and adjusts energy flows on site in real time, aligning them with demand, local constraints, and grid connection agreements. It controls power distribution, anticipates variable charging demand, and maximizes the use of local energy production, thereby transforming a conventional electrical installation into a dynamic and intelligent system.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">Thanks to intelligent energy management via an EMS, battery storage, and the integration of solar generation, this architecture (illustrated in Figure</span></b><b><span data-contrast="auto"> </span></b><b><span data-contrast="auto">2) enables performance optimization while keeping costs under control and thus represents a key step towards the next phase of the energy transition.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-29866 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN2.png" alt="" width="903" height="583" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN2.png 903w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN2-296x191.png 296w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN2-60x39.png 60w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN2-768x496.png 768w" sizes="auto, (max-width: 903px) 100vw, 903px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure </span></i><i><span data-contrast="none">2</span></i><i><span data-contrast="none">: Architecture of a next-generation charging infrastructure</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:360,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">In the remainder of this article, we will focus on </span><b><span data-contrast="auto">three new sources of cybersecurity risk</span></b><span data-contrast="auto"> introduced by the integration of Energy Management Systems (EMS) into CPOs’ charging infrastructures.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><span data-contrast="none">The EMS: an optimization lever that has become a critical risk point</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">EMS have become a key component of charging infrastructures, enabling CPOs to finely optimize power management and charging strategies. This central role makes EMS a </span><b><span data-contrast="auto">critical point in terms of cybersecurity </span></b><span data-contrast="auto">&#8211; their compromise can result in major operational impacts for a CPO:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Unavailability </span></b><span data-contrast="auto">of a part of the charging stations.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559738&quot;:240,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><b><span data-contrast="auto">Degradation </span></b><span data-contrast="auto">of energy optimization, resulting in direct financial impacts.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559738&quot;:240,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><b><span data-contrast="auto">Load imbalances</span></b><span data-contrast="auto"> that may lead to service limitations or outages at site level.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559738&quot;:240,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
</ul>
<p><span data-contrast="auto">Beyond these incident scenarios, the introduction of EMS also fundamentally reshapes the risk landscape to which charging infrastructures are exposed.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 aria-level="2"><span data-contrast="none">Increased reliance on third</span>‑<span data-contrast="none">party infrastructures</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">The deployment of EMS solutions is most often based on </span><b><span data-contrast="auto">turnkey offerings</span></b><span data-contrast="auto">, combined with </span><b><span data-contrast="auto">vendor</span></b>‑<b><span data-contrast="auto">operated management platforms hosted in cloud environments</span></b><span data-contrast="auto">. These platforms enable CPOs to centrally manage their entire EMS fleet and support a range of use cases, including optimization of available power, performance monitoring, and remote control of charging strategies.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></p>
<p><b><span data-contrast="auto">This architecture, however, introduces a direct dependency on third</span></b>‑<b><span data-contrast="auto">party infrastructures that lie outside the CPO’s perimeter of control. As a result, it expands the attack surface and increases CPOs’ exposure to supply</span></b>‑<b><span data-contrast="auto">chain</span></b>‑<b><span data-contrast="auto">related risks.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></p>
<p><span data-contrast="auto">This issue is further compounded by the fact that these vendors are often small, highly specialized players whose level of cybersecurity maturity can be heterogeneous. A compromise of these platforms may therefore lead to widespread impacts, potentially resulting in the unavailability of a significant share of the EMS fleet operated by a CPO and, by extension, a risk of charging station outages.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></p>
<p><span data-contrast="auto">In addition, the compromise of EMS cloud platforms may also lead to breaches of data confidentiality, as it could enable an attacker to collect sensitive operational information, which could notably be exploited for espionage purposes, including:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240}"> </span></p>
<ul>
<li><span data-contrast="auto">Detailed mapping of charging sites and deployed energy assets.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559740&quot;:278,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">Energy management strategies, revealing the optimization logics implemented by the CPO.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559740&quot;:278,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">Consumption and power data across the CPO’s entire portfolio of sites.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559740&quot;:278,&quot;335559991&quot;:357}"> </span></li>
</ul>
<h2 aria-level="2"><span data-contrast="none">Local communications relying on weakly secured protocols</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p><b><span data-contrast="auto">These new architectures also extend the attack surface at the local network level, particularly through communications with energy-related equipment, which still largely rely on weakly secured industrial protocols.</span></b><span data-contrast="auto"> </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Unlike exchanges between supervision systems (CPMS) and charging stations, which benefit from the standardization provided by OCPP, communications between the EMS and other components (BESS, charging points, etc.) still predominantly rely on Modbus.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Originally designed for closed industrial environments, this protocol does not natively implement security mechanisms such as authentication or encryption. In practice, each EMS vendor deploys its own protective measures, resulting in heterogeneous security levels. For CPOs, this diversity complicates the securing of the fleet and may introduce new exploitable weak points within the local network.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1 aria-level="1"><span data-contrast="none">Levers to secure next</span>‑<span data-contrast="none">generation charging infrastructure</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></h1>
<p><span data-contrast="auto">Securing next</span>‑<span data-contrast="auto">generation charging infrastructures relies on a structured approach that makes it possible to reconcile operational performance with effective cybersecurity risk management.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p aria-level="2"><span data-contrast="none">Ensuring the resilience of charging architecture</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></p>
<p><span data-contrast="auto">The evolution of charging infrastructures introduces a single point of failure for CPOs: the EMS. To address this risk, it is necessary to design resilient architectures capable of maintaining continuity even in the event of an EMS failure. This can notably be achieved through:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><span data-contrast="auto">The implementation </span><b><span data-contrast="auto">of monitoring and alerting mechanisms</span></b><span data-contrast="auto">, enabling rapid detection of EMS failures and activation of fallback mechanisms.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">The deployment of </span><b><span data-contrast="auto">degraded operating modes</span></b><span data-contrast="auto">, allowing charging stations to continue operating even in the event of EMS unavailability.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559739&quot;:120,&quot;335559740&quot;:300}"> </span></li>
<li><span data-contrast="auto">The definition of business continuity and disaster recovery strategies that explicitly include EMS failure scenarios.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559739&quot;:120,&quot;335559740&quot;:300}"> </span></li>
</ul>
<h2 aria-level="2"><span data-contrast="none">Securing dependencies on unmanaged third</span><span data-contrast="none">&#8211;</span><span data-contrast="none">party infrastructures</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">The evolution of charging infrastructure architectures requires CPOs to address both supply</span>‑<span data-contrast="auto">chain</span>‑<span data-contrast="auto">related risks and risks inherent to the interconnection between the CPMS and EMS vendors’ cloud infrastructures.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">To reduce supply</span>‑<span data-contrast="auto">chain risks, CPOs must implement robust vendor qualification processes, including in particular:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><span data-contrast="auto">Assessment of the vendor’s </span><b><span data-contrast="auto">cybersecurity maturity level.</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">Evaluation of product security, notably through </span><b><span data-contrast="auto">penetration testing</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">Contractual governance of supplier relationships, including, where appropriate, the implementation of </span><b><span data-contrast="auto">Security Assurance Plans (SAPs)</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
</ul>
<p><span data-contrast="auto">Beyond supply</span>‑<span data-contrast="auto">chain risk management, CPOs must also account for the risks introduced by the interconnection of their infrastructure with EMS vendors’ environments (EMS cloud). Securing these interconnections requires a strong control of data flows between the CPO infrastructure and these external environments. This can be achieved through three main levers:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><span data-contrast="auto">Implementing </span><b><span data-contrast="auto">traffic filtering and control mechanisms</span></b><span data-contrast="auto"> between the local charging infrastructure network and external networks, to restrict communications strictly to legitimate third</span>‑<span data-contrast="auto">party infrastructures.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">Formalizing </span><b><span data-contrast="auto">secure architectural standards</span></b><span data-contrast="auto"> and ensuring their effective implementation during EMS deployment in the field, guaranteeing a consistent application of cybersecurity best practices.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">Implementing </span><b><span data-contrast="auto">isolation mechanisms</span></b><span data-contrast="auto"> to contain potential EMS cloud failures and prevent their propagation across the entire charging infrastructure fleet.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
</ul>
<h2 aria-level="2"><span data-contrast="none">Securing communications relying on industrial protocols</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">Communications between EMS and energy</span>‑<span data-contrast="auto">related equipment, particularly BESS, still largely rely on industrial protocols such as Modbus, which do not provide native security mechanisms. In this context, securing these exchanges cannot rely on the protocols themselves, but must instead be addressed at the infrastructure architecture level.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">This notably involves:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559740&quot;:276}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Implementing strict network segmentation within the local network</span></b><span data-contrast="auto">, isolating EMS, BESS, and other components to limit exposure surfaces.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:276,&quot;335559991&quot;:357}"> </span></li>
<li><b><span data-contrast="auto">Applying fine</span></b>‑<b><span data-contrast="auto">grained control over communications</span></b><span data-contrast="auto"> by locally restricting data flows to strictly necessary exchanges (filtering, whitelisting, limitation of authorized commands).</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:276,&quot;335559991&quot;:357}"> </span></li>
<li><b><span data-contrast="auto">Deploying communication monitoring mechanisms</span></b><span data-contrast="auto"> to detect abnormal or unauthorized behavior.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:276,&quot;335559991&quot;:357}"> </span></li>
</ul>
<h2 aria-level="2"><span data-contrast="none">Establishing a structured cybersecurity governance</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">To address the diversity of components and infrastructures operated across their charging networks, it is essential for CPOs to structure their environment around clear governance, including in particular:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Clarification of</span></b><span data-contrast="auto"> </span><b><span data-contrast="auto">cyber roles and responsibilities</span></b><span data-contrast="auto"> across the entire value chain (CPOs, suppliers, service providers, etc.).</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
<li><span data-contrast="auto">Definition of security standards applicable to all projects and suppliers, ensuring overall architectural consistency</span><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:240,&quot;335559740&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">By combining rigorous supplier risk management, a solid governance framework, and strict control of data flows, CPOs can fully leverage the operational gains offered by EMS while securing their infrastructure in a sustainable manner.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:240}"> </span></p>
<h1 aria-level="1"><span data-contrast="none">Optimizing without compromising: the challenge of charging infrastructure</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></h1>
<p><span data-contrast="auto">To conclude, the rise of Energy Management Systems (EMS) is profoundly transforming charging infrastructures, providing essential optimization levers while also introducing new cybersecurity risks. For CPOs, the challenge is no longer limited to deploying these solutions but extends to securing them within a comprehensive approach that encompasses supplier risk management, the definition of secure architectures, and the establishment of structured cybersecurity governance. In this context, </span><b><span data-contrast="auto">cybersecurity is now emerging as a prerequisite for the sustainable performance of charging infrastructures.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/04/electric-mobility-charging-infrastructure-evolution-between-energy-optimization-and-emerging-cybersecurity-challenges/">Electric vehicle charging infrastructure: energy performance and new cybersecurity challenges</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/04/electric-mobility-charging-infrastructure-evolution-between-energy-optimization-and-emerging-cybersecurity-challenges/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
