This paper presents an integrative treatment of smart grid cybersecurity, combining a synthesis of architecture, attack taxonomy, and countermeasures with an original, reproducible benchmark of detection methods, emphasising renewable integration and inverter-based resources. False-data-injection, denial-of-service, and replay attacks are placed on a common analytical footing through the weighted-least-squares estimator, the stealth condition \(\textbf{a}=\textbf{H}\textbf{c}\), and Kalman filtering. Seven detector families are benchmarked on the IEEE 14-, 30-, and 118-bus systems under one controlled protocol using 250, 000 labelled samples per system. All metrics are means over ten Monte-Carlo runs, reported with the empirical across-run standard deviation and a \(95\%\) Student-t interval, the estimator appropriate to run-to-run variability. On a balanced test set the \(\chi ^2\) residual test attains \(64.3\%\) accuracy and the hybrid convolutional-plus-long-short-term-memory detector \(99.2\pm 0.07\%\), at a 4.8 ms GPU latency within the 20 ms wide-area state-estimation budget. Zero-shot transfer and architecture reuse are reported separately, as they answer different questions. Applied without weight update, the detector attains only \(72.4\%\) accuracy on the Oak Ridge National Laboratory dataset and \(79.8\%\) on the Canadian Institute for Cybersecurity dataset; retraining the same architecture raises these to \(94.1\%\) and \(96.8\%\), establishing reusability but not operational transfer. The zero-shot figures are the honest measure, and a per-class breakdown concentrates the loss on integrity classes, the command-injection F1 falling to \(61.4\%\).