The UK’s public electric vehicle (EV) charging infrastructure has rapidly transformed from an experimental green initiative into a vital pillar of critical national infrastructure. With 116,052 operational chargers projected to drive a $638.3 million Charge Point Operator (CPO) market in 2026, the sector is experiencing unprecedented growth. This rapid physical deployment inevitably brings severe structural and cyber-physical risks that need to be addressed.
Cyber-Physical Threats
Public charging systems merge operational technology, distributed embedded hardware, and financial payment pipelines, creating a highly exposed attack surface.
- Embedded Vulnerabilities: Independent disclosures at events like Pwn2Own Automotive reveal that EV supply equipment across major global brands often harbours fundamental flaws. Verified exploits include unauthenticated Bluetooth Low Energy (BLE) command injections (e.g., CVE-2024-23921), granting adversaries root-level access to the underlying operating systems.
- Protocol Exploitation: Complex vehicle-to-charger exchanges governed by ISO 15118 over Power Line Communication (PLC) remain susceptible to memory-corruption attacks.
- Network Interception: A large proportion of fielded UK estates still rely on legacy OCPP 1.6J configurations, frequently exposing administrative credentials to interception over basic HTTP authentication.
For a broader understanding of how to protect critical operational technology, take a look at the 🔗National Cyber Security Centre (NCSC) guidance on securing OT environments.
The Regulatory Enforcement Triad
Cybersecurity in the EV sector has escalated to a board-level fiduciary responsibility, driven by a stringent UK regulatory structure.
- Public Charge Point Regulations 2023: Operators of rapid infrastructure (≥50 kW) are legally obligated to maintain a 99% annual reliability average. Unpatched zero-day flaws or unstable firmware updates that trigger outages can result in civil fines of up to £10,000 per unit.
- Smart Charge Points Regulations 2021: Schedule 1 mandates device-level security controls based on ETSI EN 303 645, requiring cryptographic updates and the elimination of default credentials.
- Cyber Security and Resilience Bill: By classifying Large Load Controllers (aggregate loads ≥300 MW) as Operators of Essential Services, this legislation introduces punitive fines for major CPOs that can reach up to 4% of global turnover in the event of a disruptive breach.
Aligning Security with Stakeholder Value
To successfully navigate this landscape, commercial networks benefit from looking security testing as a statutory compliance mechanism that protects operational licences.
| Stakeholder Persona | Primary Anxieties & Liabilities | Key Performance Metrics (KPIs) |
| CISO | Enterprise liability; supply chain compromise; public data breaches. | Zero critical breaches; 100% verifiable regulatory compliance. |
| CTO | OCPP 2.0.1 migration risks; API vulnerabilities breaking integrations. | Zero production zero-days; accelerated release velocity. |
| COO | OPSS financial penalties; driver churn due to network downtime. | Fleet availability ≥99.0%; reduced mean time to repair (MTTR). |
Proactive Security as a Commercial Advantage
Transitioning from reactive maintenance to proactive vulnerability management can help prevent widespread field failures and costly hardware interventions. Dispatching field engineers to manually recover compromised rapid chargers is exceptionally expensive. By proactively auditing legacy estates, conducting protocol fuzzing, and ensuring cryptographic resilience, operators can safeguard their networks and definitively protect their balance sheets.
If you’re struggling to navigate the complex cyber and regulatory issues outlined in this article, Mondas specialises in securing critical EV infrastructure. Contact our team today to ensure your network remains resilient, compliant, and operational.
Article brought to you by Lance Nevill, Cyber Security Director, Mondas, connect with Lance on 🔗LinkedIn
Article First Published: 15 September 2026


