Solarig Standardizes on CrowdStrike to Protect Renewable Energy Operations
A major cyberattack against the energy sector could start with a stolen identity, a phishing email, or an unsecured AI agent quietly accessing sensitive systems behind the scenes. For Solarig, a fast-growing renewable energy company, defending against those threats is imperative.
Headquartered in Spain, Solarig develops, constructs, and operates large-scale renewable energy infrastructure across Europe, Latin America, Japan, and Australia. The company manages photovoltaic assets and battery energy storage systems for customers around the world, while also preparing for a major expansion into biomethane production facilities.
For Paolo Vozzella, CIO and CISO at Solarig, modernizing cybersecurity became an immediate priority after joining the company in 2024.
“When I joined, cybersecurity was at an early stage of development,” he explained. “There were solutions in place, but mainly point products focused on endpoints.”
At the time, Solarig operated separate endpoint security solutions for office employees and plant personnel. While those tools provided baseline protection, they lacked the visibility, scalability, and integration needed to support Solarig’s long-term cybersecurity strategy. Vozzella wanted something fundamentally different.
“My strategy was to have as few cybersecurity solutions as possible,” he said. “I preferred to concentrate security into one platform and one strategic provider.”
Building a Cybersecurity Foundation for a Critical Industry
Solarig started with CrowdStrike Falcon® Complete for managed endpoint and identity security. The company initially wanted to validate CrowdStrike’s capabilities before expanding further, but the deployment quickly gave Solarig confidence in the platform approach.
“Onboarding was very good,” noted Vozzella. “We implemented the Falcon sensor quickly, and everything worked smoothly.”
According to Vozzella, the combination of platform capabilities and managed services aligns with Solarig’s long-term vision for cybersecurity operations.
“We didn’t want a large cybersecurity department,” he said. “We were looking for a combination of services and platform capabilities that could give us strong protection with a smaller team.”
After the early success with Falcon Complete, Solarig rapidly expanded its use of CrowdStrike by adding CrowdStrike Falcon® Next-Gen SIEM, CrowdStrike Falcon® Shield, and CrowdStrike Falcon® Adversary Intelligence using CrowdStrike’s flexible licensing model: Falcon Flex.
“The Flex model gives us the ability to grow and adopt new solutions quickly,” Vozzella said.
CrowdStrike now protects both Solarig’s office and plant environments under a single platform. The unified approach also supports Solarig’s broader compliance strategy, including NIS2, GDPR, and cybersecurity obligations tied to the company’s operations in Australia.
Lower Complexity and Faster Response
By consolidating security telemetry, detection, response, and managed services into the unified Falcon platform, Solarig reduced complexity while improving visibility across the business.
“CrowdStrike became our master platform,” said Vozzella. “All the information, all the logs, all the transactions from our other platforms are combined into CrowdStrike.”
This centralized visibility has helped Solarig improve remediation efficiency and streamline security operations. “The response time is reduced,” Vozzella said. “If you concentrate everything into one platform, remediation becomes easier and faster.”
The benefits became clear during a phishing incident that resulted in a compromised user identity. An employee opened a malicious attachment, triggering an immediate alert from CrowdStrike. Solarig quickly blocked the compromised identity and remediated the issue.
“With our previous solutions, we may not have received the alert,” Vozzella said. “The identity leakage could have continued without us knowing.”
For Vozzella, the incident reinforced the value of CrowdStrike’s managed detection and response capabilities. “We feel our company is more protected now,” he said.
Securing the Future of Renewable Energy
As Solarig continues to grow, identity protection remains one of the company’s highest cybersecurity priorities. Vozzella sees identity threats evolving beyond traditional user accounts. In addition to protecting employee identities, the company is increasingly evaluating the future risks associated with machine identities and AI agents.
“Attackers will increasingly target leaked identities,” he said. “Not only human identities, but also machine identities and AI agent identities.”
That concern is becoming more important as employees adopt AI tools and agents at a rapid pace. Solarig is now actively evaluating how to secure AI-driven environments and prevent unauthorized access to sensitive company information.
The company is also preparing for the operational technology security challenges that will come with its expansion into biomethane production facilities. The company expects to operate as many as 60 biomethane plants over the next several years.
“In the future, cybersecurity will be important for plant uptime and production,” said Vozzella. “If production is impacted, that directly affects revenue.”
For Solarig, futureproofing its cybersecurity ultimately comes down to resilience, trust, and confidence in the company’s ability to protect critical operations and sensitive information in an increasingly hostile threat landscape.
“CrowdStrike is money well spent because we can rely on it,” Vozzella concluded. “We can sleep knowing someone is helping us protect the company around the clock.”