Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cybersecurity risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 343 records · Page 19

Risk Management for Distributed Energy Resources

The National Institute of Standards and Technology will be hosting on Tuesday, February 2 and Wednesday, February 3, 2021, the second workshop in a new series focusing on the Open Security Controls Assessment Language. NREL extended the scope of the DERCF to include the NIST Risk Management Framework (RMF), addressing the challenges faced by federal energy managers when complying with the NIST RMF for DER systems. The NIST RMF is a cyclical process designed to incorporate principles of security and risk management into an organization’s system policies and procedures. The DER-RM will be downloadable application that runs locally and documents all the major requirements for achieving Authority to Operate the DER.

cybersecurity↗

Data Centers and Digital Assurance Workshop 2 – Prioritizing Digital Assurance Challenges, Session 2

The second session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 10, 2025, focused on prioritizing digital assurance challenges at the intersection of data centers and the electric grid. Building on the foundational concepts introduced in Workshop 1, this session deepened the application of the Threat–Vulnerability–Consequence (TVC) framework and emphasized the urgency of addressing cybersecurity, supply chain integrity, and operational reliability. Participants explored the growing convergence of digital and physical systems, the expanding attack surface due to global supply chain dependencies, and the implications of AI-driven load behavior. Real-world incidents—including the Volt Typhoon campaign and vulnerabilities in Solarman and Deye platforms—were analyzed to illustrate the risks of unpatched systems, insecure APIs, and inadequate vendor oversight. Key themes included architecture and interface weaknesses, governance gaps, and human and procedural shortcomings. The workshop also examined the evolving regulatory landscape, highlighting new federal mandates around Foreign Entity of Concern (FEOC) compliance and large-load reliability standards. Through interactive exercises, stakeholders ranked and mapped digital assurance risks from their respective perspectives—utilities, operators, and vendors—laying the groundwork for mitigation strategies and shared accountability models to be developed in Workshop 3. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Cyber Threat Assessment of Solar PV Energy

This presentation discusses cyber threats to solar energy systems. Through a discussion of the cyber risk elements of threat, vulnerability, and consequence, we present examples of these risks in the solar industry. Then, we present 8 real-world events from the last 5 years that have affected the solar industry or solar companies.

14 SOLAR ENERGY↗

Securing Grid Communications Infrastructure: Addressing Gaps Beyond NERC CIP Facility Perimeters

The North American electric grid relies on a complex communications infrastructure that extends beyond facility perimeters traditionally covered by NERC Critical Infrastructure Protection (CIP) standards. While CIP requirements have significantly strengthened cybersecurity within Electronic Security Perimeters, many operational communications—such as those between control centers, substations, and third-party networks—fall outside current regulatory scope. As grid modernization introduces new technologies and connectivity models, these external pathways present evolving security challenges. This brief explores the nature of these challenges, including emerging attack vectors and supply chain considerations, and highlights how ongoing grid transformation increases exposure to sophisticated threats. It outlines practical strategies and policy options to complement existing standards, such as expanding secure communications practices, enhancing supply chain transparency, and fostering collaboration among federal, state, and industry stakeholders. Near-term actions like encryption, authentication, and contractual safeguards can help reduce risk while longer-term frameworks are developed to ensure resilient and secure grid operations.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Commercial integration of advanced nuclear energy with Artificial Intelligence (AI): Possible implications

The integration of advanced nuclear technologies (both fission and fusion) with artificial intelligence (AI) presents unprecedented national security challenges and opportunities. As fusion energy approaches commercial viability alongside advanced Small Modular Reactors (SMRs), their integration with AI and Artificial General Intelligence (AGI) systems could fundamentally transform the global energy and AI landscapes — two pillars of national security. This document briefly examines how AI could accelerate nuclear energy development and deployment while altering existing power structures, a lot could be done to deepen the discussions. Simultaneously, it observes how nuclear-powered AI may expedite advances toward AGI and beyond. These issues are deeply interconnected and thus need to be examined as a whole and more comprehensively than what’s being summarized here. For instance, AI-powered autonomous operation of nuclear facilities could reduce human error but introduce new cybersecurity vulnerabilities and uncertainties. Further investigation would also address how AI-enhanced nuclear technologies might complicate proliferation concerns through advanced fuel cycle management, nuclear materials production and safeguard. The strategic advantage gained by first entities achieving successful AI-nuclear integration could reshape global and national security framework. Timely analysis of these implications may be crucial for policymakers seeking to harness these technologies' benefits while effectively mitigating their potential risks.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

Dragonstone Strategy – State of Cybersecurity in the Oil & Natural Gas Sector

The oil & natural gas (ONG) system touches every corner of the nation and increased communications & control capabilities have not only allowed for greater efficiency of system operation, but have also created a massive target for adversaries to launch cyber-attacks. Like any other heavy industrial process, the ONG system relies on a complex system of information technology (IT) and operational technology (OT) devices. The current state of cyber-preparedness across the ONG industry varies from organization to organization. Among the most common challenges that ONG companies face are remote locations, longlived field assets, and lacking capabilities to find and track malware on their systems. ONG companies tend to be concerned with lack of cyber-awareness from employees, risk stemming from remote access for operations & maintenance, and software vulnerabilities within third-party equipment. Various industry and government organizations are performing research and development activities to address some of these challenges, but in many cases industry stakeholders are not aware of solutions that already exist. It is clear that a need exists for a coherent, comprehensive, multi-layered strategy for assuring the security and resilience of the nation's pipeline infrastructure against cyber threats. For a variety of reasons, the general consensus from stakeholders interviewed by LLNL is that the state of cyber-security within the electric grid is currently outpacing its ONG cousin. Existing strategies for the resilience and cyber-security of the electric grid can and should be leveraged to provide immediate benefits to the ONG system. In LLNL’s view, there are two key factors currently limiting the development of necessary cyber-practices within the ONG industry: The sheer number of differing regulatory bodies and trade groups offering both standards and best-practice recommendations for ONG cyber-security makes it difficult to create a comprehensive, directed, and coherent strategy that is applicable to all players within the ONG industry. The ONG industry is unaware of potentially useful technologies that have been developed for ensuring cyber-security of other infrastructure systems, such as the electric grid. Leveraging these technologies—and the science and engineering behind them—can provide some low-hanging fruit that can greatly improve cyber-security in the ONG industry without significant investments in terms of time and money. In the months following this report, LLNL will continue to perform outreach to key oil & gas industry stakeholders in a continual effort to identify the most pressing cyber-resilience issues in the industry. This outreach will be supplemented with LLNL’s threat intelligence capabilities to begin painting a clearer picture of the overall threat landscape faced by this sector. This assessment will be threat-informed and while the strategy itself will not be classified we will leverage intelligence analysis and adversary capabilities to identify gaps in current cybersecurity practices for oil & gas pipeline systems. Recommended efforts will be compiled into a cyber-resilience roadmap for the oil & gas pipeline sector, in which LLNL will highlight priority activities to immediately improve the state of cyber-resilience in the industry.

02 PETROLEUM↗

Systems and methods for detecting and mitigating cyber attacks on power systems comprising distributed energy resources

Extensive deployment of interoperable distributed energy resources (DER) on power systems is increasing the power system cybersecurity attack surface. National and jurisdictional interconnection standards require DER to include a range of autonomous and commanded grid-support functions which can drastically influence power quality, voltage, and the generation-load balance. Investigations of the impact to the power system in scenarios where communications and operations of DER are controlled by an adversary show that each grid-support function exposes the power system to distinct types and magnitudes of risk. The invention provides methods for minimizing the risks to distribution and transmission systems using an engineered control system which detects and mitigates unsafe control commands.

97 MATHEMATICS AND COMPUTING↗

Systems and methods for detecting and mitigating cyber attacks on power systems comprising distributed energy resources

Extensive deployment of interoperable distributed energy resources (DER) on power systems is increasing the power system cybersecurity attack surface. National and jurisdictional interconnection standards require DER to include a range of autonomous and commanded grid-support functions which can drastically influence power quality, voltage, and the generation-load balance. Investigations of the impact to the power system in scenarios where communications and operations of DER are controlled by an adversary show that each grid-support function exposes the power system to distinct types and magnitudes of risk. The invention provides methods for minimizing the risks to distribution and transmission systems using an engineered control system which detects and mitigates unsafe control commands.

Johnson, Jay Tillay↗

Automatic Generation of Event Trees and Fault Trees: A Model-Based Approach

In the past few decades, the increasing complexity of modern engineering systems has been driven by the integration of a large number of components whose operations may involve many disciplines (e.g., thermal hydraulics, plant operations, cybersecurity). Most computational tools used by industry and regulators for system safety and reliability assessments are still based on the traditional fault tree (FT) and event tree (ET) approach, which may not be able to capture complex interactions among system constituents. The use of simulation tools has widely increased in the past few decades to improve the fidelity of the reliability and safety analyses. However, the direct use of simulation tools as part of dynamic probabilistic risk assessment (DPRA) methods is not getting traction since (1) modeling the whole system under consideration with DPRA methods may be computationally expensive and unnecessary, and (2) the manual integration of DPRA models into existing state-of-practice probabilistic risk assessment models (i.e., based on FTs and ETs) can be time consuming and prone to errors. Here, in this paper we propose a procedure to overcome this limitation by presenting several algorithms designed to automatically construct subsystem ETs and FTs from DPRA methods for integration into an existing ET/FT system model.

97 MATHEMATICS AND COMPUTING↗

Digital Infrastructure Industry Engagement

The commercial nuclear sector faces unprecedented financial challenges driven by low natural gas prices and subsidized renewables in a market that does not reward carbon-free baseload capacity. These circumstances, along with increasingly antiquated labor-centric operating models and analog technology, have forced the early closure of multiple nuclear facilities and placed a much larger population of nuclear stations at risk. Nuclear plant economic survival in current and forecasted market conditions requires an efficient and technology-centric operating model that harvests the native efficiencies of advanced technology. This is analogous to transformations that have occurred in other industries.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

BESSIE: Battery & Energy Storage Supply Chain Analysis, Mitigation Deployment, and Tools

Battery energy storage systems (BESS) and their associated power electronic interfaces are key components to delivering clean and more resilient energy, providing much-needed fast-ramping, emergency discharge, generation, and operations support to the electric grid. These services have grown to be invaluable over the past ten years and will soon be an irreplaceable element of energy delivery. The Idaho National Laboratory (INL) strives to address these challenges through a strategic approach to supply chain risk assessment and mitigation for BESS and related digital energy equipment through the BESSIE project under the Center for Securing Digital Energy Technology. Recognizing that decreasing dependence on a foreign supply chain will take significant time and investment, BESSIE’s focus is strategically addressing battery supply chain risks by pairing short-term steps to operate securely through today’s risks with long-term steps to shape the supply chain over the coming years.

25 ENERGY STORAGE↗

NARUC grid data sharing playbook

In 2022, the National Association of Regulatory Utility Commissioners (NARUC) launched an initiative to support its members in addressing issues related to grid data sharing. The Grid Data Sharing Collaborative was funded by the DOE’s Office of Electricity and Office of Cybersecurity, Energy Security, and Emergency Response (CESER). NARUC invited programmatic, policy, technical, and cybersecurity subject matter experts from public utility commissions, utilities, non-governmental organizations, energy service companies, and DOE to join the two-year Grid Data Sharing Collaborative to help develop a flexible framework for states to use as a starting point when navigating complex decision-making inherent in grid data sharing. The framework took shape through a series of intensive workshops during which Collaborative participants explored illustrative use cases to identify data needs, articulate the benefits and risks of sharing such data, and assess the trade-offs. Along the way, participants offered suggestions for how the framework could be used in practice. The purpose of this playbook is to describe the elements of the Grid Data Sharing Framework and to begin supporting its implementation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Lessons Learned for Responsible Use of Cloud in the Cirrus Project, Following the CrowdStrike Outage Event

A disruption in CrowdStrike’s Falcon cybersecurity platform on July 19th, 2024, caused worldwide chaos. This event highlights the imperative need for cloud security measures for networks that are critically reliant on cloud technology. This incident negatively impacted air travel, government networks, and critical infrastructure sectors such as hospitals and financial institutions. While no electric utilities had a physical impact, and few had an IT impact, there were issues created by loss of cloud services, and other interrelated industries. For utilities and energy distribution organizations, understanding and mitigating these risks is essential. The Cirrus tool offers a strategic solution engineered to weave cloud integration seamlessly into the fabric of operational management, thereby enhancing resilience and streamlining efficiency in the face of digital challenges.

25 ENERGY STORAGE↗

Cyber-Informed Engineering

Briefings provided to Duke Energy during their visit to INL on January 25, 2023. This is following the process to release the slides to Duke Energy.

42 ENGINEERING↗

Battery Energy Storage Systems Report

Battery energy storage systems (BESS) are a critical component of grid reliability and resilience today, providing rapid response capabilities while enabling grid modernization and capacity expansion across the United States. As utilities, communities, and customers prepare to deploy significant BESS capacity over the next several years, the United States has an opportunity to build security into battery system design and deployments. This report provides a framework for assessing the current dominance of foreign-manufactured components in the supply chains for BESS, inverter-based resources, and transformers. It offers high-impact, actionable solutions to service partners, industry, and government to address supply chain risks for currently installed, in design, and future deployments.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Threat Landscape for BESS and IBR

The cyber risk landscape for BESS and IBR can be broken up by threats, vulnerabilities, and consequences for these systems. This presentation walks through the cyber risk landscape for BESS through the lens of consequence-informed awareness and mitigation for each risk factor. Threats with varying capabilities have been demonstrated in real-world events. Though threat actors can rarely be directly influenced by organizations, exposure of systems to adversaries can be limited (a known issue with IBR systems) to reduce likelihood of adversaries accessing systems with disruptive consequences. Common trends in disclosed IBR vulnerabilities include weak password generation or managements for various devices or services and web portal vulnerabilities that provide unauthorized access to data or capabilities or elevated user privileges. Understanding these common vulnerabilities and considering the consequences if these types of vulnerabilities were to occur can help mitigate risk. Consequences range from loss-of-view events that have no reliability impact to asset damage or grid stability impacts. Five case studies are briefly shared to highlight trends in real-world events affecting IBR.

14 - SOLAR ENERGY↗

Cybersecurity and Digital Components: Supply Chain Deep Dive Assessment

The report “America’s Strategy to Secure the Supply Chain for a Robust Clean Energy Transition” lays out the challenges and opportunities faced by the United States in the energy supply chain as well as the federal government plans to address these challenges and opportunities. It is accompanied by several issue-specific deep dive assessments, including this one, in response to Executive Order 14017 “America’s Supply Chains,” which directs the Secretary of Energy to submit a report on supply chains for the energy sector industrial base. The Executive Order is helping the federal government to build more secure and diverse U.S. supply chains, including energy supply chains. As the energy sector has become more globalized and increasingly complex, digitized, and even virtualized, its supply chain risk for digital components – the software, virtual platforms and services, and data – in energy systems has evolved and expanded. All digital components in U.S. energy sector systems are vulnerable and may be subject to cyber supply cha in risks stemming from a variety of threats, vulnerabilities, and impacts. This includes digital components in all systems within the ESIB, namely those systems operated by asset owners across different energy subsectors (e.g., electricity, oil and natural gas, and renewables) and the systems operated by a worldwide industrial complex with capabilities to perform research and development and design, produce, operate, and maintain energy sector systems, subsystems, components, or parts to meet U.S. energy requirements. Supply chain risks for digital components including software, virtual platforms and services, and data have grown in recent years as increasingly sophisticated cyber adversaries have targeted exploiting vulnerabilities in these digital assets. Supply chain risks for digital components in energy sector systems will continue to evolve and likely increase as these systems are increasingly interconnected, digitized, and remotely operated.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Advanced Reactor Safeguards & Security Program: Cybersecurity Scenarios

The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗