Engineering PapersSearch

SEARCH · Engineering Papers

Results for “CIE Principles”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

33 records · Page 2

Utility-Scale Operational Consequences for Solar Grid Services

This report delves into the critical aspects of grid services provided by solar inverter-based resources (IBRs), with an emphasis on the evolving landscape of microgrids, virtual power plants (VPPs), aggregators, and distributed energy resource management systems (DERMS). As the energy sector undergoes a transformative shift towards more decentralized and resilient grid architectures, understanding the multifaceted risks associated with these technologies becomes paramount. The report categorizes these risks into organizational, technical, and procedural domains, providing a thorough risk assessment framework that stakeholders can utilize to anticipate and mitigate potential issues. In addressing the increasing complexity of grid interconnections, the report highlights the importance of Cyber-Informed Engineering (CIE). By embedding engineering controls and cybersecurity measures into the early stages of system design, this approach aims to fortify grid infrastructure against emerging cyber threats. The analysis includes an exploration of best practices and strategies for integrating CIE principles to enhance grid security and resilience. To provide practical insights, the report conducts a detailed consequence analysis of various grid services and cyber mitigations that can be applied through the interconnection process. This analysis evaluates the potential impacts of different failure modes and vulnerabilities, offering a clear understanding of the consequences that could arise from disruptions within the energy grid. The findings are further enriched by a series of case studies that illustrate real-world scenarios and lessons learned from past incidents. Through this comprehensive examination of grid services and their criticality, the report aims to prepare industry professionals with the knowledge and tools necessary to navigate the complexities of modern energy systems. By providing a comprehensive approach that includes risk assessment, cybersecurity, and consequence analysis, solar stakeholders can more effectively guarantee the reliability, efficiency, and security of the energy grid.

14 SOLAR ENERGY

Securing the Modern Grid: Federal Investments, Digitization, and Supply Chain Strategy

Across the United States (U.S.) grid expansion and modernization is underway, paving the way for accelerated load growth and intelligent resource management. Digitization of the grid is supported by several state and federal programs, providing support for utilities installing advanced metering infrastructure (AMI), AI-powered analytics systems, battery energy storage systems (BESS), and distributed energy resource management systems (DERMS) to transform the grid from a one-way power delivery system into an intelligent, responsive network that will enable faster load growth and power expansion of data centers for advanced artificial intelligence (AI) applications. The digital transformation of America's grid presents opportunity for increased efficiency and resiliency but also introduces new digital risks that require careful management. Digital equipment often contains several vulnerabilities such as unencrypted communication protocols, and persistent remote access capabilities that could be exploited to manipulate device settings, coordinate service disruptions, or inject false data into grid operations. These digital risks become particularly important as the grid must rapidly scale to support AI-driven data centers, which the administration has identified as essential for maintaining U.S. technological leadership and economic competitiveness. These vulnerabilities are compounded by supply chain realities: Chinese manufacturers currently produce 70-90% of essential grid components including inverters, batteries, and control systems, with the U.S. lacking domestic manufacturing capacity for critical assets like extra-high voltage transformers. Recent federal legislation has established Foreign Entity of Concern (FEOC) restrictions to address these risks, requiring projects to achieve escalating thresholds of non-FEOC content to receive tax credits while utilities work to expand sourcing channels for their supply chains and strengthen security measures. These restrictions arrive precisely when utilities face unprecedented electricity demand growth driven by the rapid growth in data centers, creating a considerable challenge: rapidly expanding infrastructure while navigating complex compliance requirements while lacking viable alternatives for many critical components. Idaho National Laboratory (INL) and its partners have developed practical approaches to help utilities navigate these intersecting challenges as they leverage federal investment to strengthen and grow the grid. These solutions include Cyber-Informed Engineering (CIE) principles that build resilience directly into systems, the Cirrus tool for secure cloud migration, and enhanced procurement guidance that embeds security requirements throughout equipment lifecycles. Federal initiatives, such as the Technical Assistance for Digital Assurance (TADA) project, provide direct support to utilities implementing these approaches while facilitating knowledge sharing across the industry. While these tools and frameworks cannot eliminate all risks inherent in foreign supply chain dependencies, they offer pragmatic pathways for strengthening security posture without sacrificing the deployment momentum essential to meeting surging electricity demand. Ultimately, securing America's digital energy infrastructure demands dedicated coordination across multiple fronts: building domestic supply chains, implementing robust digital assurance practices, and maintaining the aggressive modernization timeline necessary for reliability, resilience, and energy independence.

24 POWER TRANSMISSION AND DISTRIBUTION

CIEPAT (Cyber-Informed Engineering Photovoltaic Analysis Tool) [SWR-25-171]

The Cyber-Informed Engineering Photovoltaic Analysis Tool (CIEPAT) was developed in collaboration with the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This tool is a energy source subcomponent integrated into the CIEMAT ecosystem and is developed to enhance the security and resilience of Photovoltaic installations by incorporating Cyber-Informed Engineering (CIE) principles into the deployment of PV systems.

Etigowni, Sriharsha [National Laboratory of the Ro

CIECAT (Cyber-Informed Engineering Commercial Buildings Analysis Tool) [SWR-25-172]

The Cyber-Informed Engineering Commercial Buildings Analysis Tool (CIECAT) was developed in collaboration with the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This tool is a energy source subcomponent integrated into the CIEMAT ecosystem and is developed to enhance the security and resilience of Commercial Buildings by incorporating Cyber-Informed Engineering (CIE) principles into the Commercial Buildings.

Etigowni, Sriharsha [National Laboratory of the Ro

Cyber-Informed Engineering (CIE) Integration into Model- Based Systems Engineering (MBSE)

Engineering design in the field of industrial engineering, such as designing automated factories or warehouses, is critical for the effective operation of facilities. Any design flaws introduced early can result in significant capital expenses to correct. However, early-stage engineering design is inherently complex. The systems are not yet built, requiring designers to integrate various aspects, including digital engineering and cybersecurity, to support virtual representations throughout the design process. In this study, we propose an approach to integrate Cyber-Informed Engineering (CIE) principles into model-based systems engineering (MBSE). This approach facilitates the development of a digital thread for engineering systems, ensuring secure digital artifacts in the design of industrial engineering systems.

42 - ENGINEERING

CIEPAT for Photovoltaic System Resilience

The Cyber-Informed Engineering Photovoltaic Analysis Tool (CIEPAT) was developed in collaboration with the U.S. Department of Energy's Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This tool is an energy source subcomponent integrated into the CIEMAT ecosystem and is developed to enhance the security and resilience of Photovoltaic installations by incorporating Cyber-Informed Engineering (CIE) principles into the deployment of PV systems.

14 SOLAR ENERGY

Cyber-Informed Engineering (CIE) Power Generation Guide [Slides]

This guide offers suggestions for applying CIE principles to technologies used to generate electric power. It addresses issues of design, implementation, and maintenance, preemptively addressing cybersecurity threats to electric generation. The intended audience for this guide includes practitioners across the energy and cybersecurity sectors, such as energy industry professionals (e.g., engineers, system designers, operators, and researchers) and cybersecurity experts (e.g., communication system designers, information technology/operational technology [IT/OT] administrators, and penetration testers).

13 HYDRO ENERGY

Advanced Transmission Technologies –GETs and HPCs Session 3: HPCs and Building Actions Plans to Digital Assurance Risks

The third session of the Idaho National Laboratory’s (INL) Technical Assistance for Digital Assurance (TADA) program, held on November 11, 2025, centered on High Performance Conductors (HPCs) and the formulation of action plans to address digital assurance risks associated with Grid-Enhancing Technologies (GETs). This session convened experts from utilities, vendors, and government agencies to examine the technical, operational, and cybersecurity aspects of HPC deployment. Discussions highlighted the benefits of HPCs, such as their ability to rapidly increase transmission capacity using existing corridors, improve grid resilience, reduce system losses, and align with FERC Orders 2023 and 1920. Participants evaluated supply chain and digital assurance risks, including reliance on imported materials, limited domestic manufacturing capacity, workforce shortages, and traceability issues. The session also emphasized the importance of digital trust, integration-layer cybersecurity, and unified risk frameworks, introducing tools like intrusion detection systems, encryption, zero trust networking, and firmware integrity. Recaps of earlier workshops on Dynamic Line Ratings (DLRs), Advanced Power Flow Control (APFC), and Transmission Topology Optimization (TTO) underscored institutional barriers and integration challenges. Action plans were proposed to mitigate issues such as inconsistent cybersecurity practices, SBOM usage, supply chain visibility, operator trust, and misaligned incentives. Additionally, INL presented its supply chain risk management tools and Cyber-Informed Engineering (CIE) principles to support secure procurement and system design. The session concluded with a commitment to share key takeaways, incorporate cohort feedback into future policy development, and continue collaborative engagement through upcoming pilot activities. Session 3 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION

Data Centers and Digital Assurance Workshop 3 – Mitigations for Digital Assurance Risks

The third session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 18, 2025, focused on developing mitigation strategies for digital assurance risks identified in previous workshops. Hosted by Idaho National Laboratory (INL) and ScottMadden, the session emphasized the application of Cyber-Informed Engineering (CIE) to data center infrastructure, particularly at the utility–data center interface. Participants revisited and ranked key digital assurance risks, including architecture and interface weaknesses, governance gaps, and AI-enabled threats. The workshop introduced the 12 principles of CIE, advocating for consequence-focused design, engineered controls, and secure information architecture to proactively reduce cyber-physical vulnerabilities. These principles were applied to critical data center systems such as power distribution, UPS, cooling, SCADA/BMS, and grid-forming batteries. The session also addressed governance challenges at the interconnection boundary, highlighting the need for clear roles in telemetry sharing, firmware management, and trip settings. Special attention was given to emerging risks from behind-the-meter (BTM) generation, including reverse-power flow and the integration of small modular reactors (SMRs), which shift data centers from large loads to complex generation nodes. Participants explored how interconnection agreements can serve as enforceable instruments for digital assurance, and reviewed gaps in current standards such as NERC CIP, IEC 62443, and IEEE 1547. The workshop concluded with pathways to standardization, including model agreement language, state-level programs, and expanded NERC guidance. INL also presented tools and frameworks for secure procurement and supplier risk management, reinforcing the need for integrated engineering and policy solutions to secure the evolving data center–grid ecosystem. Session 3 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION

Cyber-Informed Engineering Workbook: SCADA (VoltVAR)

This case study workbook provides a hypothetical project to support discussion and application of Cyber-Informed Engineering principles. Participants in the workshop are encouraged to use the workbook to capture insights and lessons learned.

42 - ENGINEERING

Cyber-Informed Engineering (CIE) Workbook: End-of-Train (EoT) / Head-of-Train (HoT) Communications

This workbook presents a vulnerability (CVE-2025-1727 ) found in train applications and guides a digital risk assessment and mitigation analysis and application of Cyber-Informed Engineering principles to mitigate the potential consequences and ultimately the hazard through the engineering discipline because of exploiting this vulnerability. Workshop participants are encouraged to use the workbook to capture insights and lessons learned. The workbook guides the participant to: • Understand the HE communication vulnerability • Map digital threats to physical consequences • Use bowtie analysis to illustrate both “security” and “engineering” barriers • Apply CIE principles to ensure that even if communications are compromised, the physical engineered system still behaves safely. • Produce an actionable set of engineered and infosec controls for implementation

42 - ENGINEERING

Cyber-Informed Engineering for Strategic Planning

The CIE Guide for Engaging Organizational Leadership: Board and C-Suite describes how to apply CIE at the senior-level of organizational management. This guidance integrates CIE concepts into theory and practice of guiding coalition leadership to improve permeation of CIE concepts throughout organizational culture. This guide incorporates feedback from CIE community of practice volunteers in a study of how business administrative and strategic planning and management guidance and course materials can be applied to CIE implementation throughout an organization's principles and processes. This guide defines the interests guiding senior leadership, managers and supervisors, and technicians and workers involved in creating and operating and maintaining systems, and cultural/ historical/ political assumptions or influences shaped the landscape that could facilitate or impede development of CIE. The included guidance for organizational strategic management and leadership can be imbedded into contract guidance based on the CIE implementation guide and lessons learned from industry application.

97 MATHEMATICS AND COMPUTING

Cyber Conservative Operations

In an era of increasingly sophisticated and pervasive cyber threats, robust cyber resilience strategies are more critical than ever. This paper introduces the concept of Cyber Conservative Operations, a proactive approach designed to assist critical infrastructure owners and operators in managing risk and maintaining resilience in the face of imminent, yet not occurring, cyber events. By leveraging the principles of Cyber-Informed Engineering (CIE) and the energy sector’s practice of conservative operations, Cyber Conservative Operations offer a framework for planning and executing coordinated active defense and resilience-oriented actions ahead of cyber events. This approach aims to minimize the consequences of digitally-enabled hazards and ensure swift recovery from anticipated cyber threats. Cyber Conservative Operations enhance the ability of owners and operators to execute pre-planned defense and resilience actions, thereby reducing the impact of digitally-enabled hazards. These operations are crucial for addressing impacts that cannot be precisely quantified or forecasted and for preparing organizations for rapid recovery from imminent digital threats. The paper begins with a discussion of conservative operations as applied to the bulk power system (BPS), a current mechanism allowing BPS entities to enact defensive operating plans to mitigate impending grid unreliability. Building on this model, we present a concept for implementing cyber conservative operations at asset owner facilities. The paper concludes with two case studies of cyber conservative operations drawn from high-profile cyber events, illustrating the practical application and benefits of this proactive approach.

42 - ENGINEERING

Data Centers and Digital Assurance Introduction to Supply Chain and Cybersecurity for Data Centers, Session 1

The first session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort Workshop, held on October 30, 2025, introduced foundational concepts of Digital Assurance in the context of data center and grid integration. Sponsored by the U.S. Department of Energy, the workshop brought together utilities, data center operators, developers, and vendors to address cybersecurity and supply chain vulnerabilities. The session emphasized the growing criticality of data centers within the electric grid and the need for secure, real-time, bidirectional communication. Participants explored the principles of Digital Assurance, including cybersecurity, cyber-informed engineering (CIE), and lifecycle security, and applied a threat-vulnerability-consequence framework to identify and mitigate risks at the data center–grid interface. Discussions covered a range of threats such as spoofed dispatch signals and insider threats, architectural vulnerabilities like SCADA interfaces and insecure protocols, and potential consequences including cascading grid failures. The session also raised strategic questions about business value, vendor assurance, and defining cyber boundaries and responsibilities. This foundational workshop set the stage for deeper technical analysis and the development of actionable frameworks in subsequent sessions. Session 1 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION

Moving from Information Assurance to Functional Assurance with Engineered Controls

Cyber threats to operational technology demand more than traditional IT defenses—they require full-spectrum mission assurance. Cyber-Informed Engineering (CIE) is an approach that embeds engineered controls into system design to ensure critical functions remain safe and reliable, even under attack. Unlike conventional cybersecurity tools, engineered controls act directly on physical processes to prevent unacceptable outcomes such as equipment damage or mission failure. This session will outline the CIE framework and share examples of consequence-based design that deliver true resilience, not just fail-safe behaviors. Attendees will learn how to integrate these principles into the engineering lifecycle to support resilient-by-design architectures and inform emerging standards. This talk sets the stage for the panel discussion on advancing CIE across sectors as digital and physical systems converge.

24 - POWER TRANSMISSION AND DISTRIBUTION