Note 01
Why battery security is a cyber-physical problem
The instinct in most organisations is to treat a storage site as another set of assets to bring under the existing security programme: inventory them, segment them, patch them, monitor them. All of that is worth doing and none of it answers the question that actually matters.
In an IT system, the worst outcome of a compromise is usually about data — it is exfiltrated, encrypted, or altered. In a storage system the worst outcome is a physical state: a cell outside its safe operating window, a contactor in the wrong position, a converter pushing power in a direction the grid connection was not expecting. The compromise is the means; the physical state is the damage.
That difference changes what an assessment must produce. It is not enough to enumerate reachable services. You have to be able to say, for each reachable interface, which physical behaviours it can influence — and then ask what independent mechanism refuses an instruction that is validly formed but operationally wrong.
The word independent is doing the heavy lifting. Most systems have protection. The question is whether that protection would still function if the thing that issued the bad instruction were fully controlled by someone else. Where protection logic runs on the same controller, or trusts the same telemetry, or is configured through the same interface, defence in depth is thinner than the architecture diagram suggests.
This is also why security recommendations for storage sites fail more often than they do in IT. A recommendation that would trip a site, void an equipment warranty or breach a grid code will not be implemented, no matter how correct it is about the risk. Assessments that do not account for that produce documents rather than change.