DOE OSTI · 2997948
Threat Landscape for BESS and IBR
Abstract
The cyber risk landscape for BESS and IBR can be broken up by threats, vulnerabilities, and consequences for these systems. This presentation walks through the cyber risk landscape for BESS through the lens of consequence-informed awareness and mitigation for each risk factor. Threats with varying capabilities have been demonstrated in real-world events. Though threat actors can rarely be directly influenced by organizations, exposure of systems to adversaries can be limited (a known issue with IBR systems) to reduce likelihood of adversaries accessing systems with disruptive consequences. Common trends in disclosed IBR vulnerabilities include weak password generation or managements for various devices or services and web portal vulnerabilities that provide unauthorized access to data or capabilities or elevated user privileges. Understanding these common vulnerabilities and considering the consequences if these types of vulnerabilities were to occur can help mitigate risk. Consequences range from loss-of-view events that have no reliability impact to asset damage or grid stability impacts. Five case studies are briefly shared to highlight trends in real-world events affecting IBR.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Culler, Megan Jordan [Idaho National Laboratory] (ORCID:0000000331297823). 2025-01-23. Threat Landscape for BESS and IBR. https://www.osti.gov/biblio/2997948
Cite the original work for its findings. Save a collection to share your selection of sources.