Electric Vehicle Charging - Where's The Cyber
Susan Howard
S4x24 - ICS Security Conference · Day 3 · Main Stage
Overview
In this insightful S4 conference talk, Susan Howard, a prominent voice in critical infrastructure cybersecurity, dissects the significant and often overlooked cybersecurity vulnerabilities within the burgeoning Electric Vehicle (EV) charging ecosystem. As governments worldwide, particularly in the United States, commit billions to rapid EV infrastructure deployment, Howard highlights a critical disconnect: the urgent need for robust cybersecurity standards and practices is being outpaced by the rush to market and a fragmented regulatory landscape. Her presentation serves as a stark warning, revealing that despite massive investments, the foundational security of EV charging stations and their underlying communication protocols remains alarmingly weak, posing risks not just to financial transactions but to the stability of the electric grid and public safety.

Key moments
- 1:45 NEVI funding: Cybersecurity not a 2024 priority
- 2:40 NEVI's 12 cyber requirements lack certification body
- 3:30 NIST 800 series unsuitable for EV IoT/OT
- 4:50 EV charging security extends beyond payment systems
- 6:09 OCPP's application layer role in EV charging
- 8:50 OCPP 1.6 intentionally released without cybersecurity
Electric Vehicle Charging - Where's The Cyber
Speakers: Susan Howard
Conference: S4
YouTube: https://www.youtube.com/watch?v=Kqa_SSeuwBY
Overview
In this insightful S4 conference talk, Susan Howard, a prominent voice in critical infrastructure cybersecurity, dissects the significant and often overlooked cybersecurity vulnerabilities within the burgeoning Electric Vehicle (EV) charging ecosystem. As governments worldwide, particularly in the United States, commit billions to rapid EV infrastructure deployment, Howard highlights a critical disconnect: the urgent need for robust cybersecurity standards and practices is being outpaced by the rush to market and a fragmented regulatory landscape. Her presentation serves as a stark warning, revealing that despite massive investments, the foundational security of EV charging stations and their underlying communication protocols remains alarmingly weak, posing risks not just to financial transactions but to the stability of the electric grid and public safety.
Howard's work stems from her involvement with Department of Defense projects and the U.S. National Electric Vehicle Infrastructure (NEVI) policy, which allocates $5 to $7.5 billion for EV infrastructure. She critically examines the policy's cybersecurity requirements, exposing their limitations and the systemic challenges in their implementation. The talk emphasizes that the current state of EV charging security is akin to the "Wild Wild West," characterized by a lack of a unified reference architecture, an over-reliance on outdated or insufficient security measures, and a disturbing prevalence of basic security flaws like hardcoded credentials and direct internet exposure.
The talk is crucial for anyone involved in critical infrastructure, cybersecurity, automotive, and energy sectors. It underscores that while the convenience and environmental benefits of EVs are celebrated, the underlying infrastructure is a ripe target for cyberattacks with potentially severe consequences. Howard not only identifies these pressing issues but also offers tangible recommendations for policymakers, vendors, and system integrators to secure an infrastructure vital to future transportation and energy resilience.
Background
▶ Watch: NEVI funding: Cybersecurity not a 2024 priority (1:45)
The rapid expansion of electric vehicle infrastructure is a global priority, driven by environmental concerns and technological advancements. In the United States, this push is significantly influenced by the National Electric Vehicle Infrastructure (NEVI) policy, released in February 2022. This policy earmarks between $5 and $7.5 billion in funding, with the ambitious goal of establishing EV charging stations every 50 miles along major transportation corridors, within one mile of a major intersection. To facilitate this, NEVI created a joint office between the Department of Energy (DOE) and the Department of Transportation (DOT), marking the first time these agencies have had to jointly support a combined infrastructure. Alarmingly, cybersecurity was not listed as a priority for this joint office in 2024, a critical oversight given the scale and importance of the deployment.
NEVI does, however, stipulate 12 cybersecurity requirements for states to qualify for funding. Key among these is the mandate for the Open Charge Point Protocol (OCPP), which serves as the de facto application layer protocol for communication between EV charging stations and their back-end management systems. The policy also requires the Open Charge Point Interface (OCPI), the roaming version of OCPP. Crucially, this means that proprietary networks, such as Tesla's, which do not utilize OCPP, are ineligible for NEVI funding. This creates a dichotomy, as the Society of Automotive Engineers (SAE) recently adopted the J3400 standard, essentially Tesla's charger design, as the North American Charging Standard (NACS), acknowledging its efficiency and reliability, even though Tesla operates a closed network. Tesla also notably does not participate in the ISO 15118-2 communications protocol, which governs the interaction between the EV and the charging station itself.
Further complicating the security landscape, NEVI requires third-party testing and certification for charging stations. Yet, as Howard points out, there is currently no established certification body or definitive standard for EV charging infrastructure in the United States. This leaves a significant gap, as entities seeking to certify their networks lack clear guidance or an authoritative benchmark. Other NEVI requirements include cryptographic agility, a recognition of the dynamic nature of cryptographic algorithms, and compliance with the NIST 800 series guide specifications. However, most NIST 800 standards are IT-specific, with limited relevance to the Operational Technology (OT) or Internet of Things (IoT) environments prevalent in EV charging, with the notable exception of NIST 800-82. The policy also mandates PCI DSS (Payment Card Industry Data Security Standard), which is vital for securing payment systems but falls short of addressing the broader cybersecurity challenges of the EV ecosystem, particularly its interaction with the electric grid.
The complexity is compounded by the sheer number of disparate standards groups involved, including the Open Charge Alliance (OCA) (responsible for OCPP), the United Nations (Regulation 155) for EV mobility cybersecurity, IEEE (1547), and IEC (61851). These bodies represent diverse sectors—automotive, electric utility, and IT—necessitating unprecedented cooperation to forge a cohesive security framework. Physically, most EV charging stations deploy cell modems for connectivity, while other options like IEEE 1901 HomeFi (communications over electric) are rarely observed. Older standards like CHAdeMO from Japan are expected to be phased out in favor of the newly adopted J3400 (Tesla) standard. This fragmented, multi-stakeholder environment, coupled with the rapid deployment timelines, sets the stage for significant cybersecurity challenges.
Key Findings
▶ Watch: NIST 800 series unsuitable for EV IoT/OT (3:30)
Susan Howard's presentation unveils a series of critical cybersecurity findings that underscore the precarious state of the EV charging infrastructure:
- Intentional Insecurity of OCPP 1.6: Perhaps the most alarming discovery is that OCPP 1.6, the most widely deployed version of the Open Charge Point Protocol, was intentionally delivered without any cybersecurity features. This egregious oversight, which Howard describes as the Open Charge Alliance (OCA) "not getting the memo" on secure by design principles, was attributed to a "rush to market." While a subsequent firmware update did introduce security features like TLS 1.2 (which was already outdated upon release), event logging, and secure firmware updates via hash checking, there is no compelling mechanism to force vendors to implement these updates. This creates a vast legacy of insecure systems, leaving the ecosystem in a "Wild Wild West" state.
- Lack of Unified Reference Architecture: A fundamental flaw in the NEVI policy and the broader EV charging rollout is the complete absence of a unified reference architecture. This means that each state or region is effectively building its infrastructure in isolation, leading to inconsistent security postures and making comprehensive assessments or standardized deployments impossible. Howard likens it to "trying to build an entire housing development without an architect."
- Over-reliance on TLS and Absence of Zero Trust: The current security paradigm for EV charging stations heavily relies on TLS alone, which is insufficient. There is a glaring lack of zero trust principles and defense-in-depth strategies, leaving the systems vulnerable once the perimeter is breached.
- Prevalence of Hardcoded Credentials: A basic yet pervasive security flaw identified is the widespread use of hardcoded credentials in EV charging station software. Howard, drawing on her experience as a software developer, emphasizes that this practice is unacceptable outside of lab environments and represents a severe risk in production systems.
- Inadequate Grid Monitoring: The electric grid, which underpins EV charging, lacks intelligent monitoring capabilities. Howard stresses the need for artificial intelligence algorithms to detect and respond to threats more effectively, lamenting the current reactive approach.
- Cyber-Physical Vulnerabilities in Extreme Fast Chargers: A specific and dangerous vulnerability exists in extreme fast charging stations, particularly those designed for heavy-duty vehicles. Their temperature sensors are easily manipulated, and successful exploitation in a lab environment has demonstrated that this can lead to fires and physical destruction.
- Buffer Overflow Attacks: Depending on the specific source code used for charging station software and how OCPP JSON data formats are processed, buffer overflow attacks are a viable threat vector.
- Massive Internet Exposure: A scan conducted by Howard's colleague, Fred Gordy, using Censys (and Shodan) revealed an astonishing 24,400 commercially exposed EV systems worldwide. This indicates a systemic failure by both vendors and, critically, system integrators who are deploying these devices directly onto the internet without adequate protection. This problem is not vendor-specific but an ecosystem-wide issue.
In summary, the key findings point to a critical infrastructure sector that is rapidly scaling without fundamental security principles embedded from design to deployment, leaving it susceptible to a wide range of cyber and cyber-physical attacks.
Technical Deep Dive
▶ Watch: EV charging security extends beyond payment systems (4:50)
The cybersecurity posture of Electric Vehicle (EV) charging infrastructure is critically dependent on several interlocking technical standards and protocols. At the heart of the communication between a charging station (EVSE) and its back-end management system lies the Open Charge Point Protocol (OCPP). This application layer protocol operates on a client-server model, where individual EV charging stations act as clients, communicating with a central management server. Managed by the Open Charge Alliance (OCA), a Netherlands-based organization, OCPP data is exchanged in JSON format, allowing OEMs flexibility to implement it using various programming languages like JavaScript or C++.
However, the most widely deployed version, OCPP 1.6, was notoriously released without any inherent security mechanisms. This deliberate omission, driven by what was perceived as a "rush to market," represents a fundamental failure in secure by design principles. A subsequent firmware update did attempt to retroactively add security, incorporating TLS 1.2 for encrypted communications, basic event logging, and secure firmware updates via hash checking. Yet, this update was problematic: TLS 1.2 was already considered outdated at the time of its introduction, and more critically, there was no regulatory or market-driven compulsion for EV charging station vendors to implement these security patches, leaving a vast number of deployed units vulnerable.
Beyond the station-to-management system communication, the interaction between the EV itself and the charging station is governed by ISO 15118. This is not a single standard but a series, with ISO 15118-2 being the current prevalent version, though ISO 15118-20 is also referenced. Notably, Tesla, despite its market dominance, does not utilize the ISO 15118 standard, opting for its proprietary communication protocols. This highlights a significant fragmentation in the technical landscape, where a leading manufacturer operates outside the common open standards, even as its physical charging connector (J3400) is adopted as the North American standard.
The NEVI policy, while requiring these protocols, also mandates compliance with a suite of other standards, often with mixed relevance. NIST 800 series guide specifications are required, yet many are tailored for traditional IT environments and have limited applicability to the unique characteristics of Operational Technology (OT) and Internet of Things (IoT) devices found in EV charging, with NIST 800-82 being a rare exception. Similarly, PCI DSS is mandated for payment security, but it does not encompass the broader cyber-physical security concerns related to the electric grid and the operational integrity of the charging process. The requirement for cryptographic agility is forward-thinking, acknowledging the evolving nature of encryption, but its effectiveness is undermined by the lack of a strong enforcement and certification framework.
At the physical layer, cellular modems are the predominant communication method for EV charging stations, connecting them to the internet. Other technologies, such as IEEE 1901 HomeFi (powerline communication), are available but have not seen significant adoption. This reliance on cellular connectivity, often without adequate segmentation or protection, contributes to the exposure of thousands of systems, as evidenced by public internet scans. The interoperability challenge is further magnified by the involvement of diverse standards bodies like the Society of Automotive Engineers (SAE), which focuses on automotive standards, and the International Electrotechnical Commission (IEC), which governs electric utility standards. Bridging these sectoral divides is essential for developing a truly secure and integrated EV charging ecosystem. The OCA's efforts to get OCPP adopted as an IEC standard is a strategic move to gain broader industry support, funding, and testing capabilities.
Demo / Proof of Concept
▶ Watch: OCPP's application layer role in EV charging (6:09)
While the talk did not feature a live, interactive technical demonstration, Susan Howard presented compelling evidence and findings that served as a powerful "proof of concept" for the discussed vulnerabilities. These included:
- Lab-Environment Cyber-Physical Exploitation: Howard explicitly stated that the manipulation of temperature sensors on extreme fast charging stations has been successfully demonstrated in a lab environment. This manipulation, if executed in the real world, can lead to critical failures, specifically causing fires. This finding directly illustrates a severe cyber-physical vulnerability that transcends mere data compromise, posing a direct threat to infrastructure and safety.
- Internet Exposure Statistics via Shodan/Censys: Howard's colleague, Fred Gordy, conducted a five-minute reconnaissance scan using public search engines like Censys (and Shodan). This quick survey revealed a staggering 24,400 commercially exposed EV systems worldwide. This data serves as a stark, real-world "proof of concept" of the widespread lack of network segmentation and basic security hygiene. It highlights that a significant portion of the deployed EV charging infrastructure is directly accessible from the public internet, making it an easy target for attackers without requiring complex exploits. This finding underscores the systemic failure of system integrators and vendors to properly secure deployments.
These examples, though not live code demonstrations, effectively validated the theoretical vulnerabilities discussed, transforming them into tangible, observed risks with potentially severe consequences.
Defensive Implications
▶ Watch: OCPP 1.6 intentionally released without cybersecurity (8:50)
The findings presented by Susan Howard necessitate an urgent and multi-faceted defensive strategy to secure the rapidly expanding EV charging infrastructure. Without immediate action, the "Wild Wild West" scenario described will persist, exposing critical infrastructure to significant risks.
- Policy and Standards Overhaul: The NEVI policy must be updated to prioritize cybersecurity explicitly and robustly. This includes the immediate development and mandatory adoption of a unified reference architecture for EV charging deployments across states. This architectural consistency is fundamental to establishing a baseline security posture. Furthermore, the Open Charge Alliance (OCA)'s efforts to get OCPP integrated into IEC standards should be actively supported, as this would bring much-needed funding, expert collaboration, and rigorous testing capabilities to the protocol.
- Establishment of Certification Bodies: A critical gap identified is the absence of a third-party testing and certification body for EV charging infrastructure in the United States. Such an entity is essential to define clear security standards, provide independent validation, and ensure compliance across vendors and deployments. This body should go beyond payment security (PCI DSS) to encompass operational and cyber-physical aspects.
- Implement Defense-in-Depth and Zero Trust: Relying solely on TLS for security is insufficient. Defenders must adopt a comprehensive defense-in-depth strategy, layering multiple security controls across the entire EV charging ecosystem. Zero trust principles, which mandate verification for every access attempt regardless of origin, are crucial for mitigating the impact of compromised perimeters.
- Secure Software Development Lifecycle (SSDLC): Vendors and system integrators must integrate security throughout the entire software development lifecycle. The practice of releasing products like OCPP 1.6 without security, or deploying systems with hardcoded credentials, is unacceptable. This requires rigorous code reviews, vulnerability testing (including for buffer overflows), and secure configuration management.
- Enhanced Monitoring and Intelligence: The electric grid, which powers EV charging, requires more intelligent and proactive monitoring. Deploying artificial intelligence (AI) algorithms can help detect anomalous behavior, predict potential attacks, and respond more rapidly than traditional monitoring systems. This extends to monitoring the charging stations themselves for signs of compromise or manipulation.
- Network Segmentation and Protection: The revelation of 24,400 commercially exposed EV systems demands immediate action. Charging stations should never be directly exposed to the public internet without proper network segmentation, firewalls, and intrusion detection/prevention systems. System integrators, in particular, need to be educated and held accountable for secure deployment practices.
- Physical Security Measures: Cyber-physical vulnerabilities, such as the manipulable temperature sensors on extreme fast chargers that can lead to fires, highlight the need for both physical and digital security. Measures to prevent tampering with physical components, alongside robust sensor data validation, are essential.
- Inter-sectoral Cooperation: The diverse array of standards bodies (SAE, IEC, IEEE, UN) involved in the EV ecosystem must enhance cooperation. Harmonizing standards and sharing best practices across automotive, energy, and IT sectors is vital for creating a cohesive and secure framework.
By addressing these defensive implications, stakeholders can move beyond a reactive stance to proactively build a resilient and trustworthy EV charging infrastructure.
Key Takeaways
- EV Charging Infrastructure is a Critical, Vulnerable Target: The rapid rollout of EV charging stations, fueled by billions in government funding, creates a new critical infrastructure sector that is currently poorly secured and highly susceptible to cyber and cyber-physical attacks.
- Security Debt from Insecure Protocols: The most widely deployed protocol, OCPP 1.6, was intentionally released without security, leading to a vast installed base of vulnerable systems. Subsequent patches are not universally mandated or applied, perpetuating significant security debt.
- Systemic Gaps in Standards and Policy: There is no unified reference architecture for EV charging, and existing cybersecurity requirements (e.g., NIST 800 series, PCI DSS) are often ill-suited or insufficient for the unique OT/IoT nature of the infrastructure. A critical lack of a third-party certification body exacerbates these issues.
- Widespread Exposure and Basic Flaws: Thousands of EV charging systems (24,400 identified by Censys) are directly exposed to the internet, often due to poor deployment practices by system integrators and the use of basic vulnerabilities like hardcoded credentials.
- Cyber-Physical Risks are Real and Severe: Beyond data compromise, vulnerabilities like easily manipulated temperature sensors on fast chargers can lead to physical destruction, including fires, posing direct threats to safety and infrastructure.
- Urgent Need for Comprehensive Security: A shift towards defense-in-depth, zero trust principles, secure software development, intelligent grid monitoring, and mandatory security standards is desperately needed to secure this vital ecosystem.
About the Speaker(s)
Susan Howard is a recognized expert in cybersecurity, particularly within critical infrastructure domains. Her work extends to significant government initiatives, including projects for the Department of Defense and active engagement with the U.S. National Electric Vehicle Infrastructure (NEVI) policy. Howard brings a pragmatic perspective, having firsthand experience in analyzing and proposing solutions for securing nascent critical infrastructure. She is actively involved with groups like ITS America, where she advocates for improved cybersecurity in EV charging infrastructure, and has co-authored white papers on the topic. Howard also mentors emerging talent, having collaborated with graduate student Emily Kesler on electric vehicle infrastructure research. Her insights are grounded in a deep understanding of both policy and technical realities, making her a crucial voice in the effort to secure our future transportation and energy systems.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
Dr. Howard's S4 talk is a critical, no-nonsense exposé on the alarming cybersecurity state of the rapidly expanding EV charging infrastructure. She meticulously uncovers the intentional insecurity of OCPP 1.6, the glaring absence of a unified reference architecture, and the widespread deployment of systems with basic flaws like hardcoded credentials and direct internet exposure, as evidenced by a staggering 24,400 exposed systems. Most disturbingly, she highlights a demonstrated cyber-physical vulnerability in extreme fast chargers that can lead to fires, underscoring the severe risks beyond mere data compromise to public safety and grid stability. This is a must-see for anyone involved in…
Heather Calloway (CISO) — STRONG ACCEPT
Susan Howard's S4 talk delivers a sharp, unsentimental assessment of the critical cybersecurity failures in EV charging infrastructure. She meticulously exposes the systemic governance gaps, the alarming lack of secure-by-design principles in widely deployed protocols like OCPP 1.6, and the widespread operational negligence leading to thousands of exposed systems. This is not a technical deep dive for its own sake, but a clear articulation of institutional accountability and the severe cyber-physical risks that demand immediate, executive-level action.