What happens when a cyberattack not only disrupts a computer network but blacks out an entire region? For cybersecurity researcher Chris van 't Hof, co-founder of the Dutch Institute for Vulnerability Disclosure and crisis trainer at CCRC, this is no exciting movie scene. During the Industrial Cyber Security Event, he takes his audience through a scenario in which a cyberattack on energy systems escalates into a large-scale blackout.
Chris van 't Hof: ’Prepare for a European blackout“
With a surprising background as an electrician and sociologist, Van 't Hof has an above-average interest in the safety of energy systems. Think of solar panel inverters, home batteries, charging stations, heat pumps, and energy management solutions. According to him, such systems pose a growing risk to the industry.
“Every company is essentially a mini power plant. Most devices nowadays are connected to the internet and together contain enough power to affect large parts of the electricity grid. One small vulnerability in the chain can open the door to an attack that causes a power outage in the entire region. It is even possible to black out a country or parts of Europe.”
The impact of a hackout
The consequences of a blackout (Van 't Hof prefers to call it a 'hack-out') extend far beyond a few hours without light. ’Not only does the electricity go out, but eventually the internet and mobile communication as well. Many industrial control systems depend on that infrastructure.‘
He advises companies to have a backup protocol ready at all times. “Be prepared for an incident and consider multiple scenarios, including solutions. What happens, for example, if operators can no longer intervene remotely? How many processes are controlled manually, and how quickly can technicians be on-site when multiple systems fail simultaneously? I notice that many companies take this too lightly. They say: 'We have a guy on a tractor driving over there.' That is all well and good, but what if hundreds of incidents occur at the same time? Will hundreds of guys on tractors head out then?‘
Vulnerability is in the chain
Large companies are certainly aware of cyber risks and are investing heavily in security. The blind spot lies in the supply chain, with smaller companies and startups. “You can have your own security perfectly in order, but if a supplier is vulnerable, you will still suffer the consequences.”
Therefore, the hacking expert advocates for chain resilience rather than chain dependency. “Don’t just look at your own systems, but also at the systems of parties with which your organization is connected online. This applies to both industrial suppliers and the energy platforms that link energy demand, supply, storage, and trade. Every link in the chain is an interesting target for hackers, and believe me: they monitor continuously.”
From false sense of security to resilience
Van 't Hof is pleased with the new European regulations that provide governments and watchdogs with the tools to take action against companies that do not have their cybersecurity in order. Legislation such as the Cyber Resilience Act obliges manufacturers to design and maintain digital products securely. NIS2 forces critical parties to properly secure their systems and holds executives liable for the digital security of their organization.
But regulations alone are not enough, warns the hacking specialist. “In the event of a serious incident, a company must be able to immediately switch to an ‘island mode’. This means that certain parts of a network function independently when the power suddenly goes out. Industrial estates that generate, store, and consume their own energy can use this to absorb the initial impact, so they do not immediately go ‘dark’ in the event of a hack.”
Testing and practicing
He advises the industry to look from the outside in. “Continue continuous testing on all parts and links, down to the smallest component level. Where are systems unintentionally accessible from the internet? Which suppliers have access? What dependencies exist within the chain?”
Realistic crisis drills in which companies simulate a fictional cyberattack can help with this. “In such an exercise, we role-play a scenario, including a fictional escalation. Not only computer specialists participate, but also executives, communications departments, legal teams, and operational staff. During an exercise, you discover which processes are not working as you thought and where the actual danger lurks.”
A wake-up call for the industry
Chris van 't Hof's message is not a doomsday scenario, but a call for preparedness and realism. During the Industrial Cyber Security Event, he takes visitors into the world and mindset of hackers, digital vulnerabilities, and the risks of an increasingly connected energy system. Not to instill fear, but to make organizations reflect on a question that is becoming increasingly relevant: what do you do if not only your corporate network fails, but all of Europe goes dark?.
Chris van 't Hof's keynote presentation is free of charge for visitors to the Industrial Cyber Security Event 2026. Register via the website.