Cybersecurity Of Smart Metering Infrastructure
Cybersecurity of Smart Metering Infrastructure
1. Introduction
Cybersecurity of smart metering infrastructure refers to the legal and regulatory measures used to protect smart meters, communication networks, data-management systems and related platforms from cyberattacks. Smart meters are an important part of modern electricity systems because they allow the collection and exchange of electricity-consumption information and can support remote energy-management functions.
However, smart metering also creates cybersecurity risks. A compromised system may expose consumer data, manipulate meter information, disrupt communications or provide an entry point into wider electricity networks. Therefore, smart-meter cybersecurity involves energy law, data-protection law, cybersecurity regulation and consumer protection.
2. Meaning of Smart Metering Infrastructure
Smart metering infrastructure is broader than the physical meter. It can include:
smart electricity meters;
communication networks;
data concentrators;
meter-data management systems;
supplier platforms;
distribution-network systems;
customer portals; and
software used to manage meters remotely.
The system can therefore be understood as:
Smart Meter → Communication Network → Data System → Energy Supplier/Network Operator → Consumer
Every part of this chain requires appropriate security controls.
3. Main Cybersecurity Risks
Smart metering infrastructure faces several risks.
Unauthorised Access
Attackers may attempt to access meters or supporting systems.
Data Manipulation
Incorrect meter readings could affect billing and electricity-market settlement.
Privacy Breaches
Detailed consumption information can reveal patterns of household activity.
Service Disruption
A cyberattack may interrupt communication between meters and energy companies.
Wider Grid Risk
A large number of compromised devices could potentially create wider operational problems.
Therefore, security must protect confidentiality, integrity and availability.
4. Electricity Directive 2019/944
The Electricity Directive 2019/944 provides an important legal foundation for smart-meter cybersecurity in the EU.
It requires smart-metering systems to comply with relevant Union security requirements and requires appropriate levels of cybersecurity, while also protecting final customers' privacy and personal data.
This demonstrates that smart-meter regulation is not limited to accurate measurement. It also involves security and privacy protection.
5. GDPR and Smart-Meter Data
Smart meters can collect detailed electricity-consumption information.
Where the information relates to an identified or identifiable individual, it may constitute personal data under the GDPR.
Article 32 GDPR requires appropriate technical and organisational measures to ensure security appropriate to the risk. These can include:
encryption;
pseudonymisation;
access controls;
confidentiality measures;
integrity protection;
system resilience;
recovery procedures; and
regular security testing.
Thus, cybersecurity and privacy must operate together.
6. Data Minimisation
Smart-meter operators should collect and retain only information necessary for legitimate purposes.
For example, detailed consumption data may be required for some billing or network-management purposes, but unnecessary collection can increase privacy and security risks.
Data minimisation therefore reduces the quantity of information that could be compromised.
7. Security by Design
Cybersecurity should be incorporated into smart meters and their supporting infrastructure from the design stage.
Important measures include:
secure software architecture;
strong authentication;
encryption;
secure communication protocols;
protected firmware;
tamper detection;
controlled interfaces; and
secure update mechanisms.
Security should not depend entirely on consumers changing technical settings after installation.
8. Authentication and Access Control
Smart-meter infrastructure can involve access by:
consumers;
energy suppliers;
network operators;
meter operators;
technicians;
manufacturers; and
contractors.
Each user should receive only the access necessary for their legitimate function.
Useful measures include:
multi-factor authentication;
role-based access;
unique credentials;
privileged-access management;
secure remote access; and
access logging.
Access rights should be regularly reviewed and removed when no longer necessary.
9. Communication Security
Smart meters continuously communicate with other systems.
These communications should be protected against:
interception;
manipulation;
impersonation;
replay attacks;
unauthorised commands; and
disruption.
Encryption and authentication help ensure that only authorised parties can communicate with the system.
10. Integrity of Meter Information
Data integrity is particularly important.
If meter readings are manipulated, consequences may include:
incorrect customer bills;
inaccurate market settlement;
incorrect demand forecasts;
distorted network information; and
regulatory reporting errors.
Operators should therefore use:
audit trails;
validation procedures;
secure communication;
access restrictions;
tamper detection; and
integrity monitoring.
11. Availability and Resilience
Smart-meter systems should remain available during cyber incidents.
Operators should maintain:
secure backups;
redundant systems;
alternative communication arrangements;
disaster-recovery procedures;
emergency operating processes; and
regular recovery exercises.
The objective is to prevent a cybersecurity incident from unnecessarily disrupting essential energy services.
12. NIS2 Cybersecurity Framework
The NIS2 Directive (EU) 2022/2555 establishes cybersecurity risk-management requirements for covered entities in critical sectors, including energy.
Relevant measures include:
risk analysis;
incident handling;
business continuity;
crisis management;
backup management;
disaster recovery;
supply-chain security;
vulnerability management;
access control; and
secure communications.
The exact application to an individual smart-meter operator depends on the organisation and activity covered by NIS2 and its national implementation.
13. Electricity Cybersecurity Network Code
Commission Delegated Regulation (EU) 2024/1366 establishes a network code concerning cybersecurity aspects of cross-border electricity flows.
It addresses matters such as:
cybersecurity risk assessment;
cybersecurity management;
security controls;
monitoring;
reporting;
crisis management; and
supply-chain security.
Although its specific scope concerns cross-border electricity activities, it demonstrates the movement toward more detailed sector-specific cybersecurity regulation.
14. Supply-Chain Security
Smart-metering infrastructure normally depends on several organisations:
Manufacturer → Installer → Meter Operator → Supplier → Network Operator
A vulnerability in one part can affect the wider system.
Contracts should therefore address:
security standards;
software updates;
vulnerability disclosure;
incident notification;
remote access;
security testing;
audit rights; and
secure decommissioning.
NIS2 specifically recognises supply-chain security as part of cybersecurity risk management.
15. Vulnerability Management and Updates
Smart meters may remain operational for many years.
Therefore, manufacturers and operators should establish procedures for:
identifying vulnerabilities;
assessing their seriousness;
developing security patches;
safely testing updates;
distributing updates; and
monitoring whether updates are successfully applied.
An unsupported smart meter can become a continuing cybersecurity vulnerability.
16. Incident Reporting
Smart-meter operators should maintain an incident-response process:
Detection → Assessment → Containment → Notification → Recovery → Investigation
If an incident involves personal data, GDPR breach-notification requirements may apply.
For entities covered by NIS2, significant cybersecurity incidents may trigger separate reporting requirements, including an early warning generally within 24 hours and an incident notification generally within 72 hours.
17. Relevant Case Laws
Direct reported cases specifically dealing with smart-meter cybersecurity remain limited. However, broader privacy and cybersecurity cases provide useful legal principles.
Digital Rights Ireland, Joined Cases C-293/12 and C-594/12
The Court of Justice examined extensive data retention and fundamental rights.
The decision demonstrates the importance of necessity and proportionality when large amounts of information are collected and retained.
This principle is relevant to detailed smart-meter consumption records.
Tele2 Sverige AB v Post- och telestyrelsen, Joined Cases C-203/15 and C-698/15
The Court examined communications-data retention.
The judgment reinforced the importance of necessity and proportionality in extensive data processing.
This is relevant where smart meters create detailed records over long periods.
Schrems II, Case C-311/18
The Court of Justice considered international transfers of personal data.
This is relevant where smart-meter data are processed through international cloud providers or technology companies.
The case demonstrates the importance of adequate safeguards for international data transfers.
Warren v DSG Retail Ltd [2021] EWHC 2168 (QB)
The UK High Court considered claims following a cybersecurity incident.
The case illustrates that a cyberattack does not automatically establish every possible legal claim. The relevant legal duty and breach must be established.
This is useful when considering responsibility between smart-meter manufacturers, suppliers and operators.
18. Consumer Transparency
Consumers should receive clear information concerning:
what smart-meter information is collected;
why it is collected;
who can access it;
how long it is retained;
how it is protected; and
what rights consumers have.
Transparency supports consumer confidence and regulatory accountability.
19. Conclusion
Cybersecurity of smart metering infrastructure requires protection throughout the complete lifecycle:
Secure design → installation → authentication → encrypted communication → data protection → monitoring → vulnerability management → incident response → recovery → secure retirement.
The Electricity Directive 2019/944 specifically connects smart-meter systems with cybersecurity and consumer privacy. GDPR provides security obligations where smart-meter information constitutes personal data, while NIS2 establishes broader cybersecurity requirements for covered energy-sector entities.
The cases Digital Rights Ireland, Tele2 Sverige, Schrems II and Warren v DSG Retail provide useful principles concerning proportionality, privacy, international data transfers and cybersecurity responsibility.
Ultimately, smart metering infrastructure should be treated as both critical energy infrastructure and a large-scale data-processing environment. Effective regulation must therefore protect the physical meter, communication networks, consumer information and wider electricity system from cyber risks.

comments