Charging stations: when a simple piece of equipment becomes an IT risk
When an executive thinks about their organization’s cybersecurity, they generally picture servers, computers, the network, applications, cloud environments and, increasingly, artificial intelligence systems. They probably think far less about the charging station installed in the parking lot.
Yet that charging station is also a computer system. It contains electronic components, runs software, communicates with vehicles and various services, uses network protocols and can take part in authentication and payment mechanisms. Some stations can be administered remotely and receive software updates. Behind a function as familiar as charging a car, then, lies a genuine digital infrastructure.
A documented vulnerability in XCharge C6 fast chargers illustrates this reality remarkably well. Researchers discovered that the CCS2 interface used to connect the vehicle to the station also exposed, under certain conditions, a network surface that made it possible to reach services that should never have been accessible in that way.
The significance of this discovery goes well beyond the manufacturer involved, and even beyond the electric charging industry. It forces us to ask a far more important question: how many pieces of equipment in our companies, our buildings, our factories and our government organizations do we still consider to be simple devices when they have in fact become full-fledged connected computer systems?
At first glance, a charging station has a fairly simple function: to supply electricity to a vehicle. The technological reality is far more sophisticated. With the Combined Charging System, or CCS, the vehicle and the station communicate in order to coordinate charging. Mechanisms such as Plug & Charge, associated with the ISO 15118 standard, also make it possible to take part in automatic vehicle authentication and transaction authorization. Digital certificates and a public key infrastructure can therefore be involved in something as seemingly mundane as plugging in a car.
The electrical outlet thus becomes a digital interface. This transformation matters because an interface that allows information to be exchanged also becomes a potential surface of exposure. In the case of the XCharge C6 stations studied by researchers, the communication channel accessible from the CCS2 interface made it possible to reach the internal network of certain equipment. SSH and Telnet services were exposed, and particularly weak default credentials could allow significant privileges to be obtained. Another vulnerability concerned the ability to install firmware without adequate verification of its signature.
The vulnerabilities were fixed on the equipment concerned, and no active exploitation had been observed at the time they were disclosed. This point is worth emphasizing: discovering and fixing vulnerabilities is part of the normal cybersecurity cycle. The real lesson lies elsewhere. Researchers looked at a charging socket and saw a network interface.
That difference in perspective should be of interest to every executive. An organization generally represents its IT environment according to its own administrative structure: IT department, servers, workstations, applications, phones, network and certain specialized equipment. An attacker is under no obligation to respect that representation. Instead, they look for paths that lead to a resource, a piece of data or another system.
A surveillance camera can become such a path. A printer, an access control system, ventilation equipment, a display panel, an industrial controller, an environmental sensor, a connected vehicle or a charging station can also become one. The organizational distinction between IT, buildings, production, physical security, transportation and operations matters relatively little when a piece of equipment runs software, has an identity, exchanges data or communicates with other systems.
Digital transformation has gradually multiplied these situations. A camera that was once essentially optical has become an IP camera with an operating system, a web interface, authentication mechanisms and sometimes artificial intelligence functions. Heating and ventilation systems use connected controllers. Buildings integrate smart lighting, access control, video surveillance and energy management. Factories use robots, controllers and sensors. Vehicles are becoming distributed computing platforms. Elevators, irrigation systems, medical devices, solar panels and batteries now also have digital and communication capabilities.
The organization’s actual computing surface has thus extended well beyond the IT department. This evolution raises a governance problem that is particularly simple to state: how do you protect what you do not know you own?
A traditional inventory can list computers, servers and corporate software with precision while leaving in the shadows many connected systems administered by other functions. Facilities buy charging stations, operations acquire industrial equipment, physical security installs cameras, human resources may implement biometric systems and marketing may deploy interactive screens. A research team can connect new devices without necessarily considering that it has just added a new component to the company’s IT architecture.
Yet each of these purchases can introduce hardware, software, administrative accounts, update mechanisms, cloud services, APIs, digital certificates and dependencies on external suppliers. The visible equipment is therefore only part of the architecture. Behind a charging station there may be a manufacturer, an operating system, firmware, several software libraries, a certificate infrastructure, a charging operator, payment systems, APIs, cloud services, mobile applications and remote administration mechanisms.
Dependence on this ecosystem is not inherently problematic. The modern digital economy necessarily relies on suppliers and technologies from many organizations. Maturity consists instead in knowing these dependencies, understanding which ones become critical and retaining enough control to be able to react when a supplier, a technology or a security mechanism changes.
Charging stations also illustrate another major transformation: the proliferation of non-human identities. With Plug & Charge, vehicles and infrastructure can use digital certificates to take part automatically in authentication and authorization mechanisms. The same phenomenon is occurring in the cloud, in IoT, in industry and now with artificial intelligence agents. Machines, vehicles, sensors, robots, applications, APIs, cloud workloads and agents are progressively acquiring their own digital identities.
An organization could therefore manage more non-human identities than employees. Traditional IAM principles must extend to this new population. Is this machine really the one it claims to be? Which systems can it contact? What data can it access? Who granted it those permissions? How is its certificate renewed? How is its identity revoked when it is compromised? What happens when it is replaced or taken out of service?
Identity then becomes a fundamental component of the architecture. Successful authentication should never, however, amount to permanent trust. A device’s state can change, its software can become vulnerable, its behavior can become abnormal or its usage context can evolve. The principles of Zero Trust and Continuous Trust become particularly relevant: identify, limit permissions and reassess trust based on context and risk.
A station installed in a company’s parking lot therefore has no reason to implicitly enjoy a trust relationship with the corporate network simply because it belongs to the organization. It should be able to communicate with the services needed for it to function, and nothing more. The same reasoning applies to cameras, access control systems, industrial equipment and other connected devices. Least privilege no longer concerns people alone: it must extend to machines.
This transformation also brings together two disciplines that have historically been treated separately: cybersecurity and physical security. A charging station is physically accessible while also having a digital interface. A person can therefore use physical access to attempt to reach a computer system. Conversely, a digital compromise can bring about consequences in the physical world.
This convergence becomes particularly important in industrial, energy, government, hospital and transportation environments. A vulnerability affecting a desktop computer mainly threatens an information system. A vulnerability affecting an industrial control system, energy equipment or an autonomous machine can potentially influence a physical process. As digital technology acquires the ability to act on the real world, risk management must incorporate both dimensions.
The case of charging stations becomes even more revealing when transposed to government organizations. A station installed in the parking lot of an administrative building may seem secondary. Infrastructure used daily by a fleet of municipal, police, government or military vehicles has a different operational importance. Its availability can then contribute directly to the organization’s ability to carry out its mission.
Earlier research on the Brokenwire attack had already shown that it was possible to wirelessly disrupt certain communications used by CCS infrastructure and to interrupt charging sessions. The stakes then go beyond data confidentiality or unauthorized access to a piece of equipment. As transportation becomes electrified, the digital infrastructure that makes it possible to charge vehicles progressively becomes a component of operational infrastructure. A seemingly mundane piece of equipment can become critical simply because a sufficient number of operations end up depending on it.
The charging station is ultimately one piece of a much broader phenomenon. Today we deploy millions of computers without always calling them computers. They take the form of sensors, cameras, vehicles, robots, controllers, medical devices, industrial machines and energy systems. This computing power is gradually moving toward the periphery of digital infrastructures, into what we call the Edge.
Artificial intelligence will accelerate this evolution further. Some equipment will no longer merely transmit its data to a central system. It will be able to analyze it locally, interpret a situation, communicate with other systems and potentially trigger an action. IoT, Edge and AI are thus beginning to create an immense computing infrastructure distributed all the way into the physical world.
The more intelligence and autonomy are distributed, the more security must become distributed as well. It is precisely here that the notion of Hypersecurity becomes relevant. Cybersecurity remains essential for protecting equipment, software, communications, identities and data. Hypersecurity extends that protection to all interactions among humans, machines, AI agents, applications, Edge infrastructure, cloud, suppliers and physical systems. It also seeks to connect these protections to governance, resilience, sovereignty and the organization’s ability to evolve as its environment changes.
In this kind of architecture, the physical or network perimeter is no longer enough to define what belongs to the computer system. Hypersecurity requires a more global view of what actually takes part in the organization’s digital operations. A camera managed by facilities, a robot under operations and a station purchased by the real estate department may administratively belong to three different functions while technically being part of the same distributed digital environment.
This reality must ultimately reach procurement processes. When an organization buys connected equipment, its criteria can no longer relate solely to price, features, service life and warranty. It must also understand the software technologies used, the update method, firmware signing, the available network interfaces, the exposed services, the authentication mechanisms, where the data goes, the supplier’s cloud services, its method for disclosing and fixing vulnerabilities, and how long security updates will be provided.
End of life also becomes a security issue. What happens when the manufacturer stops supporting the equipment? Can it keep working without depending on a cloud service that no longer exists? Can its certificates be renewed? Can it be isolated? Can certain suppliers be changed? How will the data and identities it used be deleted or revoked? The organization is no longer simply buying a machine: it is introducing into its environment a new computer system that comes with a life cycle and a chain of dependencies.
This broader view also explains the value that complementary expertise can bring. IT and cybersecurity teams generally know very well the environments they are officially responsible for. The challenge appears when digital technology gradually spreads across operations, buildings, engineering, transportation and other functions. A cross-functional perspective can help identify the organization’s true digital surface, understand dependencies and determine where investments in security and resilience will produce the most value.
Quantum Beyond can work alongside internal teams from this perspective. Hypersecurity architecture, IAM, Zero Trust and Continuous Trust, segmentation, cyber resilience, Edge infrastructure, governance, cryptography, post-quantum readiness and knowledge of dependencies can be brought together in order to build a coherent view of the environment. This approach also brings closer together teams that sometimes work separately—IT, cybersecurity, operations, engineering, buildings, procurement, risk management and leadership—even though the systems they are responsible for are now deeply interconnected.
The point, then, is not to treat every piece of equipment as a new threat requiring yet another accumulation of security tools. It is to understand what has genuinely become digital, what interactions exist among these components, which of them are critical and which measures make it possible to limit the consequences when one of them becomes vulnerable. This is where Hypersecurity takes on its full meaning: connecting expertise, technologies and governance in order to protect an organization whose computer system has virtually no visible boundary left.
The story of this charging station contains a lesson far more important than the specific vulnerabilities discovered in one model of equipment. It reminds us that the boundary of the company’s computer system has expanded considerably. An outlet can carry data. A charging station can have a digital identity. A camera can run artificial intelligence. A vehicle can communicate with a cloud infrastructure. A building can contain hundreds of connected systems, and a factory thousands of pieces of equipment, each with its own software, interfaces and dependencies.
For companies and government organizations alike, the first step may therefore be to change the question. Asking whether the IT network is secure remains necessary. From now on, we must also ask: do we really know everything in our organization that has become computerized?
That question is a natural starting point on the way to Hypersecurity. Before continuously protecting systems, data, identities, knowledge and operations, you have to know the components involved and understand their interactions. This knowledge must go beyond the traditional IT inventory to include connected equipment, its software, its identities, its communications, its suppliers and the physical processes it may depend on.
Quantum Beyond can support internal teams through this evolution by bringing a cross-functional perspective on assets, dependencies, human and non-human identities, Edge architectures, segmentation, resilience and the capacity to evolve. The objective remains to strengthen the skills and mechanisms already in place so as to make the digital environment more visible, more manageable and more adaptable.
Because the next cyber risks will not necessarily come from a server everyone knew was critical. They may also begin in a piece of equipment no one had thought to consider a computer.
