Firmware failures touched nearly every corner of the UK’s EV charging sector over the past year, and the update pipeline itself now reads as the industry’s biggest security worry. Charge point developer Versinetic polled engineers who design chargers, run charge point networks, fit fleet and site equipment, and service installations for its September report, When Charging Updates Go Wrong. Barely one respondent in 25 came through the previous 12 months without firmware bugs disrupting at least one charging session.
When engineers named the capabilities they need most over the next half-decade, 59% led with cybersecurity backed by signed firmware, the survey’s most popular answer by a clear margin. Immediate concerns run deeper still: 64% are at least moderately worried about software vulnerabilities inside chargers today, and 47% say weak or missing signing or verification of updates troubles them very or extremely.
The survey ties those fears to frequent failures. More than two-thirds of teams report that at least 5% of the firmware updates they shipped caused a visible problem in the past year, and 57% blame update trouble for a certification or launch delay somewhere in the last two years. Even so, only 11% judge their own update readiness as well ahead of peers, with 54% claiming a more modest edge.
The report arrives as charger software keeps drawing attacker interest, from unsigned firmware builds that skip independent checks to tooling that weaponizes open charging protocol flaws. Analyst Julian Skidmore argues the answer is process discipline: security built into the update path itself, staged rollouts, real-world testing, and a rollback procedure proven before it is needed. A charger is a connected product with a software lifecycle now, he says, and a mismanaged one damages uptime, safety confidence and driver trust as networks scale.