Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyber”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Leveraging graph clustering techniques for cyber‐physical system analysis to enhance disturbance characterisation

Abstract Cyber‐physical systems have behaviour that crosses domain boundaries during events such as planned operational changes and malicious disturbances. Traditionally, the cyber and physical systems are monitored separately and use very different toolsets and analysis paradigms. The security and privacy of these cyber‐physical systems requires improved understanding of the combined cyber‐physical system behaviour and methods for holistic analysis. Therefore, the authors propose leveraging clustering techniques on cyber‐physical data from smart grid systems to analyse differences and similarities in behaviour during cyber‐, physical‐, and cyber‐physical disturbances. Since clustering methods are commonly used in data science to examine statistical similarities in order to sort large datasets, these algorithms can assist in identifying useful relationships in cyber‐physical systems. Through this analysis, deeper insights can be shared with decision‐makers on what cyber and physical components are strongly or weakly linked, what cyber‐physical pathways are most traversed, and the criticality of certain cyber‐physical nodes or edges. This paper presents several types of clustering methods for cyber‐physical graphs of smart grid systems and their application in assessing different types of disturbances for informing cyber‐physical situational awareness. The collection of these clustering techniques provide a foundational basis for cyber‐physical graph interdependency analysis.

97 MATHEMATICS AND COMPUTING↗

Cyber Conservative Operations

In an era of increasingly sophisticated and pervasive cyber threats, robust cyber resilience strategies are more critical than ever. This paper introduces the concept of Cyber Conservative Operations, a proactive approach designed to assist critical infrastructure owners and operators in managing risk and maintaining resilience in the face of imminent, yet not occurring, cyber events. By leveraging the principles of Cyber-Informed Engineering (CIE) and the energy sector’s practice of conservative operations, Cyber Conservative Operations offer a framework for planning and executing coordinated active defense and resilience-oriented actions ahead of cyber events. This approach aims to minimize the consequences of digitally-enabled hazards and ensure swift recovery from anticipated cyber threats. Cyber Conservative Operations enhance the ability of owners and operators to execute pre-planned defense and resilience actions, thereby reducing the impact of digitally-enabled hazards. These operations are crucial for addressing impacts that cannot be precisely quantified or forecasted and for preparing organizations for rapid recovery from imminent digital threats. The paper begins with a discussion of conservative operations as applied to the bulk power system (BPS), a current mechanism allowing BPS entities to enact defensive operating plans to mitigate impending grid unreliability. Building on this model, we present a concept for implementing cyber conservative operations at asset owner facilities. The paper concludes with two case studies of cyber conservative operations drawn from high-profile cyber events, illustrating the practical application and benefits of this proactive approach.

42 - ENGINEERING↗

Deep Cyber-Physical Situational Awareness for Energy Systems: A Secure Foundation for Next-Generation Energy Management

This document provides the final report for the CYPRES project. The purpose is (1) to highlight and summarize its major accomplishments and (2) to provide guidance on how its outcomes have informed and can inform important additional research and technology transfer. The goal of CYPRES was the research, development, and demonstration of a security-oriented next generation cyber-physical EMS for electric power systems that detects malicious and abnormal events through the fusion of cyber and physical data. To achieve this, the CYPRES project team researched, developed, and built a prototype of the solution, referred to as the CYPRES EMS. The CYPRES EMS is a proof-of-concept cyber-physical platform that demonstrates the management of the energy system, communications, security, and cyber-physical grid modeling and analytics. As part of the capabilities of the CYPRES EMS, the team designed and developed a suite of power system applications for monitoring, risk analyses, detection, and control that are inherently cyberaware. At its core, the project aimed to research, develop, and demonstrate a security-oriented next-generation cyber-physical Energy Management System (EMS) capable of detecting malicious and abnormal events through the innovative fusion of cyber and physical data. This approach represents a fundamental shift from traditional EMS, reimagining how critical infrastructure can be protected through unified cyber-aware and physics-aware secure data flow pipelines. The project’s cornerstone deliverable, the CYPRES EMS, serves as a proof-of-concept cyber-physical platform that revolutionizes the management of energy systems, communications, security, and cyber-physical grid modeling and analytics. This prototype implements a comprehensive suite of power system applications for monitoring, risk analyses, detection, and control, all designed with inherent cyber awareness. The system’s architecture extends from end-devices in the field through to control center applications, establishing a secure and resilient control framework that addresses the challenges posed by diverse devices of unknown trustworthiness connecting to modern power systems. Through this innovative approach to deep cyber-physical situational awareness, the CYPRES project not only advances the state-of-the-art in energy infrastructure protection but also establishes a new paradigm for how EMS can be designed, deployed, and operated in an increasingly complex threat landscape. The findings and developments from this project provide crucial insights for stakeholders across the energy sector, offering a blueprint for enhancing the reliability and resilience of our nation’s critical energy infrastructure in the face of evolving cyber threats.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Tale of Two Domains: Cyber - Physical

As devices and systems continue to modernize and adopt integrated circuits, the use of cyber technology to deploy an application is the expectation. This deployment through cyber assets brings new cyber risk and cybersecurity is the practice of managing this risk. Cyber-risk is constantly changing due to the speed of technology advancement and the changing quality of the adversary. Cyber-Informed Engineering (CIE) mitigates cyber-risk through engineering controls where as the traditional practice of cybersecurity mitigates cyber-risk through cybersecurity controls. By clearly defining the cyber-physical boundary, engineering controls and cybersecurity controls can clearly demonstrate their complementary nature to provide layered defenses and successfully mitigate cyber-risk through independent controls. In this paper, a layered model of device decomposition of the the cyber-physical boundary is presented to provide clarity where engineering controls are used to reduce cyber-risk within the physics, functional materials, electronic, or integrated circuit layers and where cybersecurity controls are used to reduce cyber-risk within the machine code and application layers. By implementing both traditional cybersecurity controls and engineering controls, a more holistic approach to cybersecurity is achieved in protecting modern devices and systems, as well as a clear awareness in identifying, documenting, and authorizing the system’s cybersecurity protection scheme is achieved.

42 - ENGINEERING↗

A critical review of cyber-physical security for building automation systems

Modern Building Automation Systems (BASs), as the brain that enable the smartness of a smart building, often require increased connectivity both among system components as well as with outside entities, such as the cloud, to enable low-cost remote management, optimized automation via outsourced cloud analytics, and increased building-grid integrations. As smart buildings move towards open communication technologies, providing access to BASs through the building's intranet, or even remotely through the Internet, has become a common practice. However, increased connectivity and accessibility come with increased cyber security threats. BASs were historically developed as closed environments with limited cyber-security considerations. As a result, BASs in many buildings are vulnerable to cyber-attacks that may cause adverse consequences, such as occupant discomfort, excessive energy usage, and unexpected equipment downtime. Therefore, there is a strong need to advance the state-of-the-art in cyber-physical security for BASs and provide practical solutions for attack mitigation in buildings. However, an inclusive and systematic review of BAS vulnerabilities, potential cyber-attacks with impact assessment, detection & defense approaches, and cyber resilient control strategies is currently lacking in the literature. This review paper fills the gap by providing a comprehensive up-to-date review of cyber-physical security for BASs at three levels in commercial buildings: management level, automation level, and field level. The general BASs vulnerabilities and protocol-specific vulnerabilities for the four dominant BAS protocols (i.e., BACnet, KNX, LonWorks, and Modbus) are reviewed, followed by a discussion on four attack targets and seven potential attack scenarios. Furthermore, the impact of cyber-attacks on BASs is summarized as signal corruption, signal delaying, and signal blocking. The typical cyber-attack detection and defense approaches are identified at the three levels. Cyber resilient control strategies for BASs under attack are categorized into passive and active resilient control schemes. Open challenges and future opportunities are finally discussed.

97 MATHEMATICS AND COMPUTING↗

CPES-QSM: A Quantitative Method Towards the Secure Operation of Cyber-Physical Energy Systems

Power systems are evolving into cyber-physical energy systems (CPES) mainly due to the integration of modern communication and Internet-of-Things (IoT) devices. CPES security evaluation is challenging since the physical and cyber layers are often not considered holistically. Existing literature focuses on only optimizing the operation of either the physical or cyber layer while ignoring the interactions between them. This paper proposes a metric, the Cyber-Physical Energy System Quantitative Security Metric (CPES-QSM), that quantifies the interaction between the cyber and physical layers across three domains: electrical, cyber-risk, and network topology. A method for incorporating the proposed cyber-metric into operational decisions is also proposed by formulating a cyber-constrained AC optimal power flow (C-ACOPF) that considers the status of all the CPES layers. The C-ACOPF considers the vulnerabilities of physical and cyber networks by incorporating factors such as voltage stability, contingencies, graph-theory, and IoT cyber risks, while using a multi-criteria decision-making technique. We note that simulation studies are conducted using standard IEEE test systems to evaluate the effectiveness of the proposed metric and the C-ACOPF formulation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Secure and Safe Operation of Solar Photovoltaic Power Distribution Systems

Solar photovoltaic (PV)-rich power distribution systems are networked Cyber-Physical Systems (CPS). These are control systems where multiple computing nodes and diverse intelligent agents interact with the physical world in real-time. However, the presence of networked components renders them vulnerable to potential cyber-attacks, cyber-intrusions, and other malicious events. This is because these systems depend on the measurements reported from their heterogeneous sensors. This makes them vulnerable to potential cyber-attacks where malicious agents can compromise the sensors or the communication networks carrying the sensor measurements. This paper proposes a novel methodology for enhancing the cyber-security and cyber-resilient post-attack safe operation of solar PV-rich power distribution systems against potential cyber-attacks through the Dynamic Watermarking (DW), using online system identification. The resiliency of the proposed technique is tested and validated with several attack scenarios on both a lab-scale 3kW grid-connected PV inverter and a Hardware-in-the-Loop (HiL) system. The proposed approach can be applied to other types of power distribution systems to enhance their cyber-secure and cyber-resilient safe operation. This paper thereby contributes to the field of cyber-security of Cyber-Physical Energy Systems (CPES).

Kim, Jaewon↗

Adapting Traditional Hazards Analysis Methods to Address Cyber Risks

Traditional hazards analysis (HA) methods, originally developed to address physical and operational risks, often fall short when it comes to identifying and mitigating cyber threats. These cyber threats pose unique and evolving risks to critical infrastructure and industrial control systems (ICS). This report explores the integration of Cyber-Informed Engineering (CIE) principles into existing HA methods to enhance their ability to address cyber-induced risks. CIE provides organizations with a practical, cost-effective approach to closing the gap between traditional HA methods and the need for cyber risk mitigation. By leveraging existing safety processes and controls, CIE allows users to examine and mitigate cyber vulnerabilities without overhauling existing HA methods. This report identifies areas where HA and CIE naturally align and where their approaches diverge. It emphasizes how CIE principles can be used to adapt HA methods, broadening their scope to include cyber risks and enabling the mitigation of cyber- induced impacts alongside traditional hazards and failure scenarios. This report examines how CIE can be applied across various HA methods—such as Hazard and Operability Studies (HAZOP), Probabilistic Risk Assessment (PRA), Failure Modes and Effects Analysis (FMEA), Systems-Theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), and Layers of Protection Analysis (LOPA). It provides strategies for integrating CIE to strengthen the identification, assessment, and mitigation of cyber-induced risks. The findings offer a structured entry point for organizations to embed CIE concepts into hazards and safety analyses, as well as broader engineering processes, ultimately supporting the design and operation of a more resilient infrastructure.

42 ENGINEERING↗

Adapting Traditional Hazards Analysis Methods to Address Cyber Risks

Traditional hazards analysis (HA) methods, originally developed to address physical and operational risks, often fall short when it comes to identifying and mitigating cyber threats. These cyber threats pose unique and evolving risks to critical infrastructure and industrial control systems (ICS). This report explores the integration of Cyber-Informed Engineering (CIE) principles into existing HA methods to enhance their ability to address cyber-induced risks. CIE provides organizations with a practical, cost-effective approach to closing the gap between traditional HA methods and the need for cyber risk mitigation. By leveraging existing safety processes and controls, CIE allows users to examine and mitigate cyber vulnerabilities without overhauling existing HA methods. This report identifies areas where HA and CIE naturally align and where their approaches diverge. It emphasizes how CIE principles can be used to adapt HA methods, broadening their scope to include cyber risks and enabling the mitigation of cyber- induced impacts alongside traditional hazards and failure scenarios. This report examines how CIE can be applied across various HA methods—such as Hazard and Operability Studies (HAZOP), Probabilistic Risk Assessment (PRA), Failure Modes and Effects Analysis (FMEA), Systems-Theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), and Layers of Protection Analysis (LOPA). It provides strategies for integrating CIE to strengthen the identification, assessment, and mitigation of cyber-induced risks. The findings offer a structured entry point for organizations to embed CIE concepts into hazards and safety analyses, as well as broader engineering processes, ultimately supporting the design and operation of a more resilient infrastructure.

42 - ENGINEERING↗

Spatio-Temporal Deep Graph Network for Event Detection, Localization, and Classification in Cyber-Physical Electric Distribution System

This work proposes a deep graph learning framework to identify, locate, and classify power, cyber, and cyber power events at the distribution system level. The proposed algorithm jointly exploits spatial, temporal, and node-level cyber and physical data features. The developed graph neural network, together with a deep autoencoder, utilizes physical measurements from distribution level phasor measurement units and cyber data from communication network logs. The spatial structure of the synchrophasor measurements and network is incorporated through a weighted adjacency matrix. The temporal structure is incorporated by defining a spatial operation in the gated recurrent unit. This spatio-temporal learning element resides inside a power event detection, localization, and classification module that provides the degree of confidence for an event label. To accurately pinpoint the location of an event to the nearest bus equipped with a measurement unit, a combination of squared error and proximity score is utilized. Also included is a cyber event detection module that employs heteroskedasticity to analyze the significance of various cyber features during different types of attacks. Finally, a dual-bit cyber-power decision table determines the nature of the event. The proposed method is validated on two distribution systems modeled in OPAL-RT/Hypersim with limited phasor measurement units for different possible physical and cyber events. Further analyses include comparison with other state-of-the-art methods and validation in the presence of measurement noise. As a result, our method outperforms existing approaches and achieves an average detection accuracy of 97.97%, F1-score of 96.88%, precision of 96.53%, and recall of 98.57%.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CP‐SyNet: A tool for generating customised cyber‐power synthetic network for distribution systems with distributed energy resources

Abstract The integration of distributed energy resources and advancement in information technology has enabled the transition of traditional power distribution systems to active cyber‐physical distribution systems. A growing amount of research has been done on the modelling, analysis, and optimisation of power distribution system behaviour. However, existing publicly available distribution test feeders are limited in numbers and have minimal features. Furthermore, these test feeders do not include cyber models and are not customisable. To bridge this gap, we propose and develop Cyber‐physical synthetic distribution system network (CP‐SyNet), a tool for generating customisable cyber‐physical synthetic distribution test feeders. CP‐SyNet generates three‐phase unbalanced test feeders according to users' requirements, while simultaneously considering both the cyber side and the physical side of the network for cyber‐physical analysis. The physical test network is developed using a graph‐theoretical approach that employs information from existing test feeders. The cyber side considers an equivalent communication network by transforming the physical topology into possible and feasible simulated network. Two examples are presented to demonstrate the feasibility of the proposed framework to generate cyber‐physical test feeders.

Wang, Lusha↗

Canada-US Blended Cyber-Physical Security Exercise (Final Report)

The Canada-US Blended Cyber-Physical Exercise was a successful, first of its kind, multiorganization and multi-laboratory exercise that culminated years of complex system development and planning. The project aimed to answer three driving research questions, (1) How do cyberattacks support malicious acts leading to theft or sabotage [at a nuclear site]? (2) What are aspects of an effective combined cyber-physical response? (3) How to evaluate effectiveness of that response? Which derived the following primary objectives, 1. The May 2023 Cyber-Physical Exercise shall present a cyber-attack scenario that supports malicious acts leading to theft or sabotage. 2. The May 2023 Cyber-Physical Exercise shall define aspects of an effective combined cyber-physical response. 3. Analysis of the May 2023 Cyber-Physical Exercise shall evaluate the effectiveness of the incident response against pre-established exercise evaluation criteria. 4. Analysis of the May 2023 Cyber-Physical Exercise shall assess the effectiveness of the evaluation criteria itself. 5. Exercises shall be performed in a real-life environment. The team believes these objectives were met, and the evidence will be presented in this report. Due to the novelty of the exercise, there were several lessons learned that will be presented in this report.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Cyber-Physical Tabletop Exercise for Small Modular Reactor Facilities

U.S. nuclear power facilities face increasing challenges in meeting dynamic security requirements caused by evolving and expanding threats while keeping costs reasonable to make nuclear energy competitive. This evolving threat landscape includes adversaries having offensive cyber capabilities to attack information technology (IT) systems and operation technology (OT) systems. These adversaries may have the ability to attack the physical protection system (PPS) networks with potential consequential impacts that could degrade the effectiveness of the PPS. These cyber attacks may also be used to attack the safety and operational systems used to operate and ensure the safety of the reactor. Additionally, adversaries may gain access to unmanned aerial systems (UAS) that may be used to provide reconnaissance and surveillance of the facility, provide information to the adversaries, and be equipped with kinetic capabilities such as explosives or weapons that can be used to directly attack the facility. The Department of Energy’s Office of Nuclear Energy’s Advanced Reactor Safeguards and Security (ARSS) program funded Sandia National Laboratories (SNL) and Idaho National Laboratory (INL) to develop a cyber-physical tabletop exercise (TTX). This exercise was conducted on a hypothetical small modular reactor (SMR) facility, and only considered a potential adversary cyber attack on the PPS to a physical attack on the hypothetical facility to achieve a radiological release. This cyber-physical TTX is meant to provide lessons learned to integrate the cyber security system design and the physical protection system (PPS) design to decrease design, operation, and maintenance costs as well as increase effectiveness for defending against design basis threat attacks at the facility. This TTX will also provide a framework and method for SMR and microreactor vendors to conduct their own cyber-physical TTX and gain impactful insights to improving the cyber and physical protection system design for their SMR or microreactor facility design.

42 ENGINEERING↗

Systems and methods for controlling an industrial asset in the presence of a cyber-attack

Systems and methods are provided for the control of an industrial asset, such as a power generating asset. Accordingly, a cyber-attack model predicts a plurality of operational impacts on the industrial asset resulting from a plurality of potential cyber-attacks. The cyber-attack model also predicts a corresponding plurality of potential mitigation responses. In operation, a cyber-attack impacting at least one component of the industrial asset is detected via the cyber-attack neutralization module and a protected operational impact of the cyber-attack is identified based on the cyber-attack model. The cyber-attack neutralization module selects at least one mitigation response of the plurality of mitigation responses based on the predicted operational impact and an operating state of the industrial asset is altered based on the selected mitigation response.

D'Amato, Fernando Javier↗

A Review of Visualization Methods for Cyber-Physical Security: Smart Grid Case Study

Cyber-Physical Systems (CPSs) are becoming increasingly complex and interconnected as they attempt to meet the demands of evolving society. As a result, monitoring and maintaining them becomes a more complex and demanding task for control system operators and cyber defenders. While the literature on visualization techniques in the context of cybersecurity is extensive, the same cannot be said for studies on visualization for the security of cyber-physical systems. This paper aims to fill that gap by: 1) defining the main features of a visualizations workflow for security visualizations in cyber-physical systems. The workflow includes the acquisition of cyber and physical data, processing of data, selection, and configuration of both visualization tools and end-user interactions. 2) Providing an overview of cyber-physical security visualization systems, with a focus on smart grids as a case study. Finally, we use the perspectives gained from this analysis to provide insights and directions for future research and design of cyber-physical visualization techniques.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Emulation and detection of physical faults and cyber-attacks on building energy systems through real-time hardware-in-the-loop experiments

The increasing use of remote or mobile access, integrated wearable technologies, data exchange, and cloud-based data analytics in modern smart buildings is steering the building industry towards open communication technologies. The increased connectivity and accessibility could lead to more cyber-attacks in smart buildings. On the other hand, physical faults (e.g., HVAC -heating, ventilation, and air-conditioning faults) may have similar adverse impacts as those from the cyber-attacks on building energy systems, such as occupant discomfort, energy wastage, and equipment downtime. However, current physical behavior-based anomaly detection methods fail to differentiate between cyber-attacks and physical faults in building energy systems. Moreover, the challenge in collecting real-world threat data with ground truth has led researchers to rely on numerical models with user-defined assumptions, which may not accurately reflect real-world conditions due to the lack of in-situ experimental datasets. To address these challenges and gaps, this paper presents a flexible hardware-in-the-loop (HIL) testbed for generating cyber-attack and physical fault datasets and demonstrating threat detection algorithms in a real building automation system (BAS) environment. This testbed combines hardware (i.e., real BAS with local HVAC controllers and a physical network) with software (i.e., high-fidelity models to represent behaviors of building envelope and HVAC energy systems), enabling emulations of realistic threats. Five HIL experiments, including one baseline without any threats, two with physical faults, and two with cyber-attacks, were conducted to generate datasets containing detailed network traffic and system states. A joint classification framework, incorporating a network analyzer and a physical HVAC fault detector, was proposed to automatically detect cyber-physical abnormalities on BAS at both the network and the physical HVAC levels. The network analyzer comprises a conditional random fields (CRF) based command validator and a statistics-based detection strategy. The fault detector employs a weather and schedule-based pattern matching and feature-based principal component analysis (WPM-FPCA) method. Evaluation of the classification using four metrics from the multi-class confusion matrix revealed an average accuracy of 90.2%, recall of 89.7%, precision of 88.5% and F1-score of 89.2%. Finally, these results demonstrate that the proposed joint classification framework can effectively differentiate between specific types of cyber-attacks (e.g., device reinitialization attack, network Denial-of-Service attack) and physical faults (e.g., air handling unit operational fault, cooling coil valve stuck) in real time for improved building energy management.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Securing Grid-interactive Efficient Buildings (GEB) through Cyber Defense and Resilient System (CYDRES)

The DOE CYDRES project is driven by the urgent need to address critical research gaps in the domain of cyber-physical security of smart buildings, including Grid-interactive Efficient Buildings (GEBs). CYDRES, a real-time advanced building resilient platform, aims to enhance the cyber-attack-immune capabilities of buildings through multi-layered prevention, detection, and adaptation mechanisms. CYDRES consists of five key modules: a multi-layer network analyzer, an Automatic Fault Detection, Diagnosis, and Prognosis (AFDDP) framework, an intelligent mode selector, a cyber-resilient control framework, and a situation awareness platform. The Network Analyzer employs a data-driven framework that includes a protocol state learning tool and a CRF (Conditional Random Field) command validator. In Hardware-In-the-Loop (HIL) testbeds, it achieved 100% detection accuracy with a false alarm rate of 3%, validating its efficacy in identifying selected cyber-attacks. The AFDDP framework leverages pattern matching, PCA (Principal Component Analysis)-based strategies, and a DBN (Dynamic Bayesian Network)-based fault diagnosis approach to pinpoint the causes of physical system abnormalities using Building Automation System (BAS) data. In HIL experiments, the AFDDP module attained a detection accuracy of over 95% with a false alarm rate below 7%. Additionally, the fault detector utilized machine learning (Random Forest) and deep learning (Multi-Layer Perceptron) methods with acoustic sensor data to achieve a 100% fault detection accuracy in Heating, Ventilation, and Air-Conditioning (HVAC) equipment. The Mode Selector offered real-time impact analysis, allowing immediate actions to protect BASs in the face of emerging threats. The cyber-resilient control framework included an adaptive Model Predictive Control (MPC) and a measurement compensator, reducing temperature violations by up to 94% and improving the total demand flexibility by up to 70% in HIL experiments. Such HIL experiments covered a cyber-attack case and a physical fault case, showcasing CYDRES’ efficiency in maintaining operational continuity during threats. The situation awareness platform in Grafana enhanced real-time threat detection and response visualization, augmenting the operational awareness for building operators. CYDRES demonstrated high technical effectiveness in various test scenarios, particularly in HIL environments. The project's phased development approach ensured efficient use of resources, highlighting its practical feasibility and readiness for commercialization. By enhancing the security and resilience of building operations, CYDRES represents a significant advance in mitigating risks associated with cyber-physical systems, thereby enhancing public confidence in the safety of modern building infrastructure. Future directions for the project include expanding testing protocols, refining AFDDP methodologies, exploring more comprehensive resilient control strategies, and testing in real commercial buildings.

42 ENGINEERING↗

Cyber-Informed Engineering Implementation Guide

This Implementation Guide describes the principles of Cyber-Informed Engineering (CIE) and outlines questions that engineering teams should consider during each phase of a system’s lifecycle to effectively employ these principles. It describes what it means to engineer systems in a cyber-informed way, rather than offering a comprehensive, step-by-step process or procedure for CIE implementation. This guide complements—but does not replace—the application of cybersecurity standards or practices currently in place within an organization. Engineers and technicians that design critical energy infrastructure installations can use this Implementation Guide to integrate the 12 principles of CIE into each phase of the engineering lifecycle, from concept to retirement. The guide is aimed at system or design engineers, rather than software engineers or operational cybersecurity practitioners. The engineers who design, build, operate, and maintain the physical infrastructure are best positioned to leverage a system’s engineering design to diminish the severity of cyber attacks or digital technology failures. CIE expands cybersecurity decisions into the engineering space, not by asking engineers to become cyber experts, but by calling on engineers to apply engineering tools and make engineering decisions that improve cybersecurity outcomes. CIE examines the engineering consequences that a sophisticated cyber attacker could achieve and drives engineering changes that may provide deterministic mitigations to limit or eliminate those consequences.

42 ENGINEERING↗