Securing commercial EV chargers against theft and cyberattack


EV charger security for commercial sites rests on three pillars: physical protection against theft and vandalism, controlled access and payment integrity, and network defences that stop remote tampering. Get all three right and you satisfy the Electric Vehicles (Smart Charge Points) Regulations 2021 at the same time. Facility managers can act today with three moves.
Demand a statement of compliance. Ask every vendor for written proof of secure update capability before signing.
Specify physical hardening. Bollards, impact ratings and tamper-resistant mounts belong in the tender, not the snag list.
Lock down admin access. Named accounts, role separation and multi-factor authentication (MFA) stop one stolen password becoming a portfolio-wide incident.
Swiftcharging builds all three into every commercial installation from the feasibility stage onward.
TL;DR:
Ensure vendors provide a written statement of compliance and technical documentation before contract signing, covering secure update and encryption protocols.
Specify physical protections such as impact-rated enclosures, tamper-resistant mounts, and underground cabling, verified through on-site checks before energization.
Use authentication methods suited to each site, like offline RFID for depots and app-based login for public chargers, with rapid revocation processes.
Build network segmentation based on zero-trust principles to prevent a compromised charger from accessing back-office or billing networks.
Prioritize governance controls, including named accounts, MFA, detailed logs, and regular testing of emergency shutdown procedures, over physical hardening alone.
Table of Contents
What does EV charger security mean under UK regulations?
Schedule 1 of the Electric Vehicles (Smart Charge Points) Regulations 2021 sets out six technical obligations for any charge point sold or installed commercially: secure update capability, secure boot verification, encrypted communications, a defined tamper-protection boundary, security event logging, and disclosure of security information at the point of sale. These aren’t aspirational. They’re the legal floor for any unit you procure.
Government guidance mapping the Regulations to ETSI EN 303 645 makes each requirement testable and recommends operators request a formal statement of compliance plus access to the vendor’s technical file, both of which the IoT Code of Practice also treats as baseline evidence. Build these into your procurement checks:
Request the statement of compliance and technical file before contract signature, not after delivery.
Confirm the stated update period covers your expected asset lifespan, which is generally several years for commercial hardware.
Ask for evidence of secure boot testing and encrypted communication protocols, not just a vendor’s assurance.
Retain sales records for 10 years, as the government guidance recommends for compliance audits.
Build acceptance testing into commissioning, so non-compliant units are rejected before they go live.
How do you physically protect chargers from vandalism and theft?
Security-minded site design should start at feasibility, not after your first vandalism incident. BSI’s guidance on security-minded design confirms that impact protection, cable containment and clear camera sightlines are cheaper to specify upfront than to retrofit later. That means raised kerbs, correctly rated bollards, defined approach lanes that discourage ram-raid attempts, and undergrounded cable runs so nothing tempting is left exposed at ground level.
Hardware specification matters just as much as layout. The government’s minimum technical specification for commercial chargepoints sets ingress protection expectations aligned with BS EN 61851-1 and BS 7671, and most commercial sites should specify at minimum IP54 ingress protection with an IK10 impact rating on exposed enclosures. Look for tamper-protection boundaries with concealed fasteners, secure wall or pedestal mounting torqued to manufacturer specification, and MID-certified meters if you’re billing by the kilowatt hour, since disputed billing is its own security failure.
Write physical hardening into your tender language explicitly:
Specify anchor torque values and require documented on-site verification.
Require enclosure inspection sign-off before energisation.
Confirm cable burial depth and conduit routing match the design drawings, not just the spec sheet.
Pro Tip: Walk the site with your installer before groundworks begin and mark camera sightlines with tape on the ground. It’s the cheapest way to catch a blind spot before concrete gets poured.
How do access control and payment systems affect security?
Ad-hoc access rules and payment obligations aren’t separate from security. They determine who can start a charge and whether your revenue is protected once they do. Public charge points of sufficient power must offer contactless payment, and operators face roaming connection timelines to at least one roaming provider under secondary legislation. For fleet depots, this matters less; for destination and public-facing sites, it shapes hardware choice from day one.
Authentication method should match your use case rather than default to whatever the vendor bundles in:
RFID whitelists work well for fleet depots because they function offline, with no dependency on network connectivity at the point of use.
App-based authentication gives richer usage data but needs a locally cached authorisation list, so a card still works if the connection drops.
Rapid revocation matters for both. A lost fob or a departing employee’s app credential should be disabled within minutes, not days.
Payment integrity is a security issue as much as a commercial one. Where card acceptance is offered, terminals must be PCI-compliant, and billing accuracy depends on MID-certified metering to avoid disputes that can escalate into chargebacks or regulatory complaints. Merchant category coding and settlement pathways also need checking before go-live. A misconfigured merchant account can silently misroute revenue for months before anyone notices.
What network and cybersecurity controls matter most?
Firmware and network governance carry more risk than most facility managers assume, because a single compromised admin account can affect an entire portfolio at once, not just one charger. That’s the core lesson from operator-focused cybersecurity guidance, which treats charging networks as operational technology deserving the same discipline as industrial control systems.
Build your specification around these controls:
Require TLS encryption for all charger communications, and confirm which party (you or the vendor) owns certificate issuance and renewal.
Support OCPP 1.6J or 2.0.1, with the vendor stating explicitly how OCPP messages are authenticated and logged.
Demand secure boot and signed firmware, so unauthorised code can’t be pushed to a unit even with physical access.
Insist on staged over-the-air rollouts with rollback capability, so a bad update affects a test group before it reaches your whole estate.
Segment chargers from corporate IT using the same deny-by-default logic recommended in zero-trust research for EV charging infrastructure, which found micro-segmentation the most effective way to stop lateral movement between charging systems and back-office networks.
Rotate certificates and tokens on a defined schedule rather than leaving them static for the life of the installation.
Export security logs contractually, not as a favour, so forensic history survives a platform migration.
Pro Tip: Ask your vendor to demonstrate a staged firmware rollout during commissioning, not just describe it in a datasheet. If they can’t show you the test group logic live, it probably doesn’t exist yet.
Restricting external endpoints to only what the charger genuinely needs (the charging station management system, firmware server and payment processor) removes most of the attack surface that opportunistic attackers rely on. Zero-trust researchers call this an allow-list approach, and it’s far easier to specify at procurement than to bolt-on afterwards.
How should you govern access and plan incident response?
Security fails operationally long before it fails technically. Most incidents trace back to shared logins, undocumented configuration changes, or nobody knowing who owns the decision when a charger goes offline mid-shift.
Fix identity first:
Issue named accounts for every user, never shared logins, with role-based or attribute-based access control enforcing least privilege.
Require MFA for any privileged role, including third-party maintenance engineers who need remote access.
Log every configuration and firmware change with an approval trail, so you can answer “who changed this and why” without guesswork.
Recovery planning deserves the same rigour as prevention. Operational playbooks should prioritise degraded-mode fallbacks, including locally cached authorisation lists and manual meter reading procedures, so a cloud outage doesn’t strand your fleet at the depot gate.
A charging network that only works when every system is online isn’t secure, it’s fragile. The test of good governance is what happens the moment connectivity fails, not how well the dashboard looks on a normal Tuesday.
Contractually secure your right to exportable logs and a documented data handover checklist before you sign with any platform provider. When you eventually migrate systems, and most operators do within a decade, you want your certificates, whitelists and forensic history to move with you.
How Swift Charging builds security into every installation
Swiftcharging treats security as part of design, not an add-on bolted after commissioning. Every project starts with a feasibility and site assessment that maps physical risk (approach angles, lighting, sightlines) alongside electrical capacity.
From there, the build includes:
Physical protection design and supply, including bollards, IK-rated enclosures and secure mounting specified to the site’s actual risk profile.
Hardware procurement from manufacturers who provide statements of compliance and technical files aligned to Schedule 1.
A management platform with over-the-air updates, monitoring and security logging built in, not retrofitted.
Ongoing maintenance contracts covering firmware governance and physical inspection, not just fault callouts.
Support identifying and applying for available EV charging grants to offset installation costs, including compliance documentation needed for grant applications.
Recent projects, including the Werit UK installation, show this approach applied to live fleet and commercial sites, with security specifications built into the original site design rather than added after the fact.
What threats should you model before you install?
Threat modelling for EV charging infrastructure means asking a specific question for each asset: what happens if this component fails, is stolen, or is compromised remotely, and what’s the actual cost? That’s different from a generic security audit because charging infrastructure has three distinct attack surfaces that rarely get assessed together: the physical hardware, the payment and access layer, and the network connection back to your management platform.

Start by categorising your sites by risk profile. A gated fleet depot with controlled access faces a different threat model to a public-facing destination charger in an unattended car park. The depot’s biggest risk is usually insider misuse or credential sharing; the public site’s biggest risk is unauthorised physical access and vandalism. Treating both with an identical checklist wastes budget on controls that don’t match the actual exposure.
Zero-trust research into charging infrastructure recommends assuming compromise is possible at every layer rather than trusting network boundaries alone. Practically, that means asking: if this charger’s local software were compromised, could it reach your back-office billing system? If a fob is cloned, how quickly can it be revoked? If a firmware update is intercepted, is it cryptographically signed so a tampered version gets rejected automatically?
Run this exercise annually, or after any significant change to your estate. A threat model written once at commissioning and never revisited misses the risks that come with scaling from five chargers to fifty.
What should staff and drivers know about charger security?
Most security failures at charging stations aren’t sophisticated attacks. They’re a shared PIN written on a whiteboard, a fob left in an unlocked car, or a driver ignoring a visibly damaged connector because nobody told them what to do about it.
Facility teams should train staff to recognise three things: physical tampering (forced enclosures, missing panels, exposed cabling), suspicious card reader modifications (a common target for skimming attempts on public terminals), and unusual charging behaviour (a session that runs far longer or shorter than expected). None of this requires technical expertise, just a clear reporting line and a habit of actually using it.
For drivers and fleet operators using your chargers, brief guidance matters more than a lengthy policy document nobody reads:
Report visible damage to a connector or enclosure before using it, not after.
Never share RFID fobs or app credentials between employees, since shared credentials break your audit trail completely.
Know who to call if a charger displays an error that isn’t a simple fault, in case it signals a tamper event rather than a technical glitch.
Signage matters too. The government’s minimum technical specification requires clear operating instructions displayed at commercial sites, and that same signage is your first line of user education. A driver who understands what normal operation looks like is far more likely to flag something wrong.
What’s the emergency shutdown procedure for a compromised charger?
Every commercial site needs a documented, rehearsed answer to one question: if a charger is compromised, physically or digitally, who has the authority to shut it down, and how fast can it happen?
Physical lockdown starts with isolation. Facility managers should know the exact breaker or isolator for each charging point without needing to consult a manual under pressure, and that information should be laminated on-site, not buried in a service contract. For DC rapid chargers in particular, isolation procedures need testing during commissioning, not assumed to work when actually needed.
Digital shutdown is a separate but equally urgent capability. Your management platform should let an authorised administrator remotely disable a specific charger or an entire site within minutes, not hours, without needing vendor support to action it. If disabling a compromised unit requires a support ticket and a 24-hour response window, that’s a governance gap worth fixing before it gets tested by a real incident.
Define escalation ownership in advance:
Name who can authorise a full-site shutdown and who can act on a single-charger isolation.
Document the manual charging fallback for fleet depots, so a network outage doesn’t halt operations entirely.
Rehearse the procedure at least annually, treating it the same way you’d treat a fire drill.
A shutdown procedure that exists only on paper isn’t a procedure. Test it before you need it, and fix whatever the test reveals.
Why most security checklists miss what actually matters
The conventional advice on EV charger security leans heavily on physical hardening: bollards, IK ratings, tamper-resistant enclosures. All of that matters, but it’s the easy part to specify and the easy part vendors will happily quote for. What most checklists underweight is governance: who holds admin credentials, how firmware updates are approved, and whether logs survive a platform migration.
That imbalance is worth correcting. A single shared admin login with no MFA is a bigger risk to a forty-charger estate than a slightly under-specified bollard at one site, yet procurement teams routinely spend more tender time on the concrete than on the credentials. Zero-trust segmentation and named-account discipline cost nothing in hardware and everything in discipline, which is precisely why they get skipped.
If you take one thing from this checklist, prioritise the statement of compliance and the technical file before you sign anything. Everything else, physical hardening, payment integrity, network segmentation, can be verified and tightened after installation. A vendor who can’t produce compliance evidence at procurement stage is unlikely to produce a security update three years into the contract, when it actually matters.
— Swift Charging
Ready for a security-focused site survey?
Swiftcharging designs physical protection, secure hardware procurement and network governance into every commercial installation from the first site visit, not as an afterthought once the concrete is poured. Where other suppliers treat Schedule 1 compliance as a box to tick after delivery, Swiftcharging builds statements of compliance, IK-rated hardware specification and segmented network architecture into the original design and tender documentation.

If you’re planning a new installation or auditing an existing one, the practical next step is a security-focused site survey. Swiftcharging’s team can assess physical risk, review your access control requirements and check your existing hardware against current compliance obligations. Businesses in the area can book a commercial EV charging installation in Chichester directly, or get in touch for a tender-ready security checklist tailored to your site.
Key Takeaways
Commercial EV charger security requires physical hardening, access and payment controls, and network governance working together, anchored by Schedule 1 compliance and named-account discipline.
Point | Details |
Demand compliance evidence first | Request a statement of compliance and technical file before signing any vendor contract. |
Specify physical hardening in the tender | Require IK10 impact rating, IP54+ ingress protection and documented anchor torque checks at commissioning. |
Match authentication to use case | Use offline RFID whitelists for depots and app-based auth with local caching for public sites. |
Segment chargers from corporate IT | Apply deny-by-default network rules so a compromised charger can’t reach billing or corporate systems. |
Choose a security-minded installer | Swiftcharging builds compliance, physical protection and network governance into design from feasibility stage. |
Sources
Recommended