Engineering Papers⌕ Search

Engineering topics

Egan, Megan Mincemoyer

Publications and source records attributed to Egan, Megan Mincemoyer.

Trends in Cybersecurity Threats to Clean Energy

As deployments of clean energy generation and storage assets continue to grow, the increased attack surface creates a greater risk for cyber threats, but is clean energy truly a target for cyber adversaries? This poster will present research on the trends in cyber incidents that have affected clean energy companies and assets as well as the trends in disclosed and exploited vulnerabilities. From a series of ransomware attacks on European wind manufacturers, to vulnerabilities exploited in solar assets to turn controllers into botnets, to attacks on communication infrastructure that have resulted in extended outages of remote control and monitoring, we explore the techniques used and the impacts to the clean energy sector. Key takeaways include understanding of how OT-focused malware is becoming more flexible and more destructive, how known vulnerabilities are being exploited, the growing number of IT and OT attacks that use built in tools and functionalities. Additionally, we highlight the presumed motivations and targeted sectors for various identified cyber adversaries. Viewers will leave with an understanding of how recent headlines fit into the development of cyberattack trends and what preventions they may need to take to protect against increasingly popular tactics.

14 SOLAR ENERGY↗

Attack Surface of Renewable Energy Technologies

This slide deck presents an overview of the threat landscape for renewable energy technologies. It highlights he growing penetration of renewable resources and potential impact of an attack. Standard architectures are shared to highlight where vulnerabilities may exist and attack paths to reach critical infrastructure. We discuss threat actors and attack paths. Several recent events impacting renewable energy assets or companies are explained.

14 SOLAR ENERGY↗

Attack Surface of Wind Energy Technologies in the United States

Low cost, reliable electrical energy production from wind relies upon automation and control systems, arguably more so than traditional thermal generation. These same systems, however, can serve as the target of adversaries’ cyber-attacks. Idaho National Laboratory (INL), at the request of the Department of Energy’s (DOE’s) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) and Energy Efficiency and Renewable Energy’s (EERE’s) Wind Energy Technologies Office (WETO), evaluated a generalized wind plant architecture to understand the classes of potential threat actors and the vectors that could enable a cyber-attack. This evaluation explores the attack surface of a representative wind plant, identifying potential methods and vectors that an adversary could leverage to conduct a cyber-attack. Included in this assessment are some recommended mitigations and approaches. Each recommendation requires a full security evaluation, cost/benefit analysis, and risk analysis by each owner and operator.

17 WIND ENERGY↗

Attack Surface of Wind Energy Technologies in the United States [Slides]

This slide deck presents an overview of the threat landscape for wind energy technologies. It highlights unique cybersecurity considerations for wind, the growing penetration and potential impact of an attack. Standard architectures are shared to highlight where vulnerabilities may exist and attack paths to reach critical infrastructure. We discuss threat actors and attack paths. Several recent events impacting wind assets or wind companies are explained.

17 WIND ENERGY↗