Summary
Exercise Windshield was presented as the first supply-chain cyber crisis exercise for Dutch offshore wind, designed to test whether the sector could coordinate under a severe, sophisticated attack scenario. The moderator framed the stakes with concrete energy-system numbers: The Netherlands currently has 4.7 gigawatts of installed offshore wind capacity in the Dutch North Sea, and over the next twenty-five years offshore wind is expected to grow enough to supply half of Dutch energy demand. In that context, the panel emphasized that taking out three gigawatts could be sufficient to cause a blackout not only in The Netherlands but in the Northwestern part of Europe, making offshore wind resilience a national-security issue rather than only an operational concern.
Luke Fletcher of Bureau Veritas described how his team designed the exercise over roughly eight months, using crisis managers, hackers, incident responders, operational technology experts, and other specialists. The scenario placed participants in a hypothetical December 2025 environment where tensions between The Netherlands and a nation state had escalated for six to twelve months. In the exercise, that nation state had embedded an insider in a critical offshore wind supply-chain organization and launched an attack that blinded remote systems, affected wind-park sensors, and targeted original equipment manufacturers. This design was intended to be both realistic and engaging, forcing operators, suppliers, and public-sector stakeholders to coordinate under pressure.
The public-sector role was explained by Jaap Noordhoek from the NCSC, who said the organization participated because three gigawatts of disrupted generation would affect national security, including digital national security. NCSC wanted to observe how organizations managed resilience and crisis processes, how reporting to NCSC worked, and how information could be shared with other NCSCs and energy-sector partners abroad. He also noted that although the new Cybersecurity Act was not yet enforced during the exercise, incident reporting obligations have since become relevant, making the practice valuable preparation.
Nicoleta Dragan, speaking from the owner-operator perspective, highlighted that owners carry accountability for resilient operations while operators are “in the heat” when incidents happen. She said the exercise challenged assumptions about information sharing and made clear what NCSC could and could not provide, including indicators of compromise but not “supermen” services for the whole industry. Christoph Kroack of Siemens Energy stressed the supplier perspective: offshore wind assets run for around thirty years, and OEM involvement continues through long service and maintenance contracts. The panel’s practical conclusion from the excerpt was that trust, shared collaboration, known contact points, and repeated ecosystem-level practice are essential because no single party understands or controls the whole response alone.
Key Topics
5 key topics from Arjan Hofmann, Nicoleta Dragan, Luke Fletcher, Christoph Kroack and Jaap Noordhoek at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Practice cyber crisis response across the full offshore wind supply chain.
- Clarify NCSC reporting and support expectations before incidents occur.
- Include suppliers and TSOs in sector-level exercises from the start.
- Map decision rights for stopping or restoring wind-farm supply.
- Build operational contact points before a real cyber crisis.
“this exercise also show us how much we don't know”
Up Next

Next in agenda
Humor, The Secret Weapon for Cybersecurity Awareness
Rosanne Pouw


Also on cybersecurity
European Security: Technological Innovation in Warfare



Also on cybersecurity
