Who Really Controls Your Solar Power System

Who Really Controls Your Solar Power System

October 2, 2026

Who Really Controls Your Solar Power System

Starting November 1, 2026, EU-funded energy projects can no longer use inverters from “high-risk suppliers” – meaning manufacturers from China, Russia, Iran and North Korea – and equipment that is already installed will have to be phased out. In late September, the European Commission refused to push back the deadline despite appeals from investors and the industry. Ursula von der Leyen signed off on the plan back in March at a closed-door meeting.

To be clear, this is a restriction on funding. So far, there is no outright ban on selling Chinese inverters at the EU level.

For owners of villas and hotels in Phuket, these European rules change nothing. But they raise a question that applies to every modern solar power system: who controls it – the owner or the manufacturer’s server?

Why Europe Is Worried

In her State of the Union address on September 16, von der Leyen spoke of Europe’s “dangerous dependencies” on China. The issue goes beyond raw materials and extends to equipment.

As for inverters, about 70% of those in Europe are Chinese-made. And an inverter is an internet-connected device: the manufacturer sees its data and can change its settings and push updates to it. The European Commission justifies the new measures by pointing to the risk of remote access: changing how inverters operate on a mass scale could destabilize the grid.

Where the Real Vulnerabilities Lie

Independent research shows that the picture is somewhat more complicated. In 2025, Forescout found 46 vulnerabilities in products from Sungrow, Growatt and Germany’s SMA that could be used to hijack accounts and take control of other people’s inverters. In particular at SMA researchers found a security hole in the cloud portal used by more than 900,000 systems. A year earlier, Bitdefender uncovered similar flaws in the Solarman and Deye cloud platforms that made it possible to take over any account and change a device’s settings. All of these vulnerabilities have since been fixed.

What does this mean for an inverter owner? Most often, the weak spot turns out to be the cloud layer: servers, accounts and apps. A scenario in which a foreign government cuts the power to a private villa is unlikely. The real risks are far more mundane: a cyberattack on vulnerable software, the manufacturer’s server going down, the app being replaced or discontinued, the system account being registered to an installer who no longer responds, a firmware update that changes how the equipment behaves, or a commercial dispute between the distributor and the factory. An incident in the US  showed what this can look like in practice: in November 2024 multiple Deye inverters shut down and displayed an error. The manufacturer hadn’t switched anything off remotely – the authorization mechanism on the devices had simply malfunctioned. But that is cold comfort to the owner. Their system was stopped by logic they had no control over.

So, for a private user, the country of manufacture matters less than how deeply the system is tied to the cloud and whether it can run on its own.

For Thailand, Chinese inverters and energy storage systems remain a logical choice, and the key question is how to connect them.

Cloud or Local Control?

An inverter doesn’t need the internet to do its core job: it converts energy, charges the battery and switches the house over to backup power during a grid outage. The cloud is there for remote monitoring, manufacturer support, some warranty diagnostics and updates. Giving it up entirely would be unwise, since without updates you don’t get bug fixes.

A reasonable compromise is to keep the cloud but make sure the system doesn’t depend on it. Data and commands travel within the property’s own network, and the cloud is given access as an additional channel for monitoring and updates. The owner can restrict or shut off that channel without affecting the system’s core operation.

What to Demand from the Equipment

There are four things worth checking with your supplier.

- Is there local access via Modbus, and does it let you control the system as well as read data from it?

- Can the manufacturer’s remote access be disabled?

- Can firmware updates be installed manually, after they have been vetted?

- Who is the system account registered to? It should belong to the property owner.

Modbus on its own provides no security: it has neither passwords nor encryption. That is why the system’s equipment is placed on a separate network segment behind a firewall, and remote access is set up through a VPN. The default passwords for the communication modules’ web interfaces are changed during commissioning.

In Plain English

Logger – a small communication module that sends the inverter’s data to the local network or to the cloud.

Modbus – a widely used industrial protocol: the “language” that equipment uses to exchange data. Modbus RTU runs over a dedicated communication cable, while Modbus TCP runs over an ordinary computer network, either wired or Wi-Fi.

Firmware – the software built into a device. Updating it can change how the equipment behaves.

VLAN – a separate network segment. The system’s equipment runs on it in isolation from the guest Wi-Fi and the property’s other devices.

Firewall – a network filter that lets through only authorized connections.

VPN – a secure channel for connecting to a network remotely.

What Chinese Inverters Can Do

Take Solis, Sungrow, Deye, GoodWe and Huawei. All five brands make local control possible, but the mechanism differs from brand to brand. In almost every case, the installer is the one who enables it during commissioning, so this needs to be agreed on in advance.

On Sungrow inverters, local Modbus TCP is switched on through the cloud app; on Huawei, through the installer account. By the way Huawei has a history of changing the local access port in firmware updates. Technically, Deye works well without the cloud, and Deye’s own history shows why that capability is worth using. Some Solis loggers stop sending data to the cloud once they are connected locally, while others work only with the cloud, so on commercial sites a wired connection to the inverter is more reliable. With GoodWe, what local data exchange is possible depends on the model and the version of the communication module. All of this needs to be checked with the distributor for each specific model.

Where Local Architecture Reaches Its Limits

In May 2025, Reuters, citing anonymous sources, reported that communication devices not listed in the documentation had been found in some Chinese inverters and batteries. No brands were named, and there has been no official confirmation. But if such channels do exist, the property’s network security offers no protection against them, because their traffic bypasses the property’s network. So it is important to understand that a local architecture closes off the main documented risks, but not every conceivable one.

The Key Procurement Question

Choosing a brand still matters, but there is one more question worth adding to the list: who will control the system if the manufacturer’s cloud goes offline tomorrow?

Energy independence isn’t only about generating your own power. It’s also about having control over the system that manages that power.

‍

Request a consultation

Tell us about your property: number of buildings, approximate size, and your goals for autonomy and comfort. We will propose a solution with clear KPIs and no unnecessary engineering complexity.