
Chinese-made connected devices used in critical infrastructure, transportation and energy systems could create security vulnerabilities in Western countries if their risks are not assessed through a common framework, a new report by the Center for European Policy Analysis (CEPA) has warned.
The report points to a range of connected products, from port cranes and public buses to surveillance equipment and solar inverters, arguing that their internet connectivity and remote-management capabilities can create potential avenues for data collection, disruption or unauthorised access.
According to CEPA, Chinese-made ZPMC cranes deployed at US ports have been found to contain cellular modems that could potentially bypass existing network security controls, collect information and interfere with cargo-handling operations.
The report also cites Yutong electric buses supplied to Oslo, saying their connected battery and power-management systems could potentially give the manufacturer the ability to disable or otherwise affect the operation of the vehicles.
It further raises concerns about connected Chinese-made vehicles and cameras equipped with microphones, cameras and location sensors that can collect large amounts of information. The report also points to Chinese applications, including Hikvision's Hik-Connect, which it says transmit phone and SIM-card identifiers to servers in China.
CEPA argues that the risks become more significant when large numbers of individually purchased devices are connected to critical systems. It gives the example of solar inverters, saying that a vulnerability affecting thousands of remotely connected units could potentially have consequences for electricity networks.
The International Energy Agency has separately warned that modern inverters are increasingly connected to the internet and can therefore become potential targets for cyberattacks. It said compromised devices, supply-chain vulnerabilities or malicious software updates could allow attackers to alter equipment operation, with consequences ranging from local disruption to potentially lengthy power outages.
The CEPA report recommends that EU countries and their allies develop a common framework, which it calls Digital Strategic Exposure (DSE), to evaluate risks across connected devices, cloud infrastructure, subcontractors and jurisdictions.
According to the report, such a methodology could help governments assess whether security risks associated with a particular product can be contained, while allowing allied countries to compare their assessments without necessarily disclosing sensitive information.
The think tank also cautions against blanket sovereignty requirements that could create unnecessary barriers to technology from allied countries. Instead, it calls for a coordinated approach aimed at reducing exposure to what it describes as potentially dangerous forms of digital leverage.
The debate comes as governments increasingly examine cybersecurity risks in technology supply chains. The IEA noted in July that China accounted for about 80 per cent of global inverter manufacturing capacity in 2025, highlighting the degree of concentration in a technology that has become an important control point in modern power systems.
The concerns raised by CEPA are part of a broader policy debate over how Western governments should balance the cost and availability of Chinese-made technologies against cybersecurity, supply-chain resilience and national-security considerations.