Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Cyber Risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

IBR Digital Supply Chain Gap Analysis and Recommendations

The adoption of clean energy technologies, including solar photovoltaics, continues to introduce non-traditional stakeholders to the operations and planning of the electric system. Stakeholders such as manufacturers, vendors, owners, aggregators, and others are enabling the adoption, integration, and optimum operations of solar technologies at accelerated rates. Inverters form the foundation of many digitally controlled energy sources for clean energy technologies, including Solar, Battery Energy Storage Systems, Hybrid Systems, and Hydrogen Fuel Cells. Their supply chain is complex, a series of microchips, electronic switches and other components making up its primary functions. The complexity of this space and the growing digitization associated with these components can create supply chain cyber risks. One measure to mitigate cybersecurity attacks is proper digital supply chain security. The U.S. Department of Energy (DOE) Solar Energy Technologies Office (SETO), in partnership with the Cybersecurity, Energy, Security, and Emergency Response (CESER) office, is hosting a workshop to bring together solar vendors and services providers to discuss digital supply chain security for solar systems and challenges and opportunities in the transitioning to a fully domestic supply chain for solar energy in the U.S. This workshop will support the Securing Solar for the Grid (S2G) and Energy Cyber Sense program activities. During the workshop, industry experts and researchers from DOE National Laboratories will discuss the current solar supply chain landscape and the transition to domestic manufacturing of solar components in the U.S. Tools and techniques to better manage and secure the digital supply chain of solar devices and systems will be discussed.

cybersecurity

Security of DERs and Grid Edge Technologies [Slides]

Distributed energy resources (DERs) offer significant value for incorporating diverse generation technologies and improving reliability. They also present a new set of cybersecurity challenges. The move of generation to the grid edge can also mean more distributed control systems and expanded communication networks, resulting in an increase in attack surface. This presentation will discuss definitions and essential terms related to DERs; developments and deployment trends for DERs; recent cyber attacks on operational technology and industrial systems; cyber risk arising from distributed grid resources; and ways in which standards may help mitigate some of these risks.

24 POWER TRANSMISSION AND DISTRIBUTION

VPP Cybersecurity: Stakeholder Roles and Responsibilities

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. This presentation outlines a framework for assessing the roles and responsibilities of virtual power plant stakeholders in mitigating cyber risk to virtual power plant projects and the overall power grid.

24 POWER TRANSMISSION AND DISTRIBUTION

Integrating Cyber-Informed Engineering into Process Automation

As organizations increasingly automate their core missions and essential functions to address business risks and enhance efficiency, process automation becomes pivotal. This shift, involving minimal or no manual intervention, significantly impacts an organization's cyber-risk landscape. While automation drives efficiencies, it also introduces new cyber risks if not properly managed. Cyber-Informed Engineering (CIE) provides a proactive framework for managing these digital risks, enhancing cyber-resilience in process automation. This document supports organizations in applying CIE principles to mitigate the cyber risks associated with automation. The outlined approach can be independently implemented to improve any organization’s cyber-resilience, ensuring that the advantages of automation do not result in unaddressed or unmanaged digital risks. It serves as a starting point, offering considerations for integrating CIE principles and practices into organizational processes. CIE is presented as an iterative process, fostering continuous improvement and reinforcing the engineering and operational cultures to manage digital risks effectively. The document is structured as follows: Section 1 provides background on CIE and process automation, and their integration. Section 2 explores the twelve CIE principles in the context of process automation, highlighting key questions, engineering considerations, and implications for digital risk management. Section 3 synthesizes the findings and offers recommendations to advance resilience by design.

42 - ENGINEERING

Obstacles to Practical Digital Supply Chain Risk Management in the Energy Sector

Cyber supply chain risk management (C-SCRM) programs must consider operations that depend on the lifecycles of digital components such as hardware, firmware, software, and services. We integrate academic literature, historical incidents, and existing standards to identify obstacles faced by C-SCRM programs.

Business Process Management & Integration

Encrypted Control Using Modified Learning With Errors-based Schemes

Cyber-physical systems (CPSs) require reliable, safe, and secure control of critical infrastructure, combining computational and networking capabilities, which heighten the risk of cyber attacks. These attacks can disrupt the physical process, causing unforeseen consequences. One solution is the use of fully homomorphic encryption (FHE) to protect the control loop, allowing for secure computations and communications without compromising signal and control system privacy. The challenge with FHE, however, is its requirement for inputs to be integers. This paper introduces a modified Learning With Errors (LWE) FHE approach that encodes control system dynamics and signals into integers. Our proposed scheme leverages a generalized LWE encoding function and modifies the Gentry-Sahai-Waters (GSW) gadget decomposition tool to encrypt the control system. Using the modified LWE scheme, we formalize a fully encrypted control system, supported by simulated results.

42 - ENGINEERING

Advanced Research on Integrated Energy Systems (ARIES) Cyber Range Overview and Threat-to-Consequence Demonstration

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. The threat-to-consequence demonstration showcases NREL's capability to model, simulate, test, and evaluate cyberattacks targeting energy systems that coincide with natural hazards, as well as the ramifications for the energy grid as a whole.

24 POWER TRANSMISSION AND DISTRIBUTION

Navigating United States Standards and Regulation for Digital Energy Systems

This report provides an analysis of the U.S. standards and regulatory landscape for digital energy systems, focusing on cybersecurity, safety, and reliability requirements. It examines the interplay between federal mandates, state regulations, voluntary industry standards, and utility-specific policies, highlighting critical gaps between compliance and real-world risk mitigation. While NERC CIP standards enforce cybersecurity for Bulk Electric System assets, distribution-level infrastructure and emerging technologies often fall outside mandatory oversight, creating vulnerabilities. The report identifies systemic challenges such as reliance on self-attestation, uneven state adoption of safety codes, and lagging standards for advanced technologies like battery energy storage and inverter-based resources. Through a detailed gap analysis, it underscores the urgency of proactive risk-based approaches, independent verification, and strategic engagement with state and federal entities. Recommendations include adopting tiered security frameworks, strengthening procurement practices, and addressing emerging technology risks to ensure resilient and secure digital energy infrastructure. This guidance is intended for utilities, regulators, and stakeholders navigating compliance obligations and seeking to enhance cybersecurity and safety beyond minimum standards.

24 - POWER TRANSMISSION AND DISTRIBUTION

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 - ENERGY PLANNING, POLICY AND ECONOMY

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 ENERGY PLANNING, POLICY, AND ECONOMY

Engineering Against Digital Risk in CIP Applications: Cyber-Informed Engineering Use Cases

Cyber-Informed Engineering (CIE) addresses the reality that cyber attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This presentation discusses engineered controls of 7 categories and the CIE database of controls that provides clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design.

99 - GENERAL AND MISCELLANEOUS

Cybersecurity Supply Chain Risk Management: Forge Institute Presentation

In this talk, INL will discuss how to develop a cyber supply chain risk management program, to include assessment of vendor risk and applying appropriate mitigations. INL will discuss key risk factors and the challenges of securing supply chain in complex and dynamic vendor environments. Finally, INL will share example language that can be adopted in RFPs and procurement contracts to promote supply chain security.

battery energy storage system

RESCue Model (RESCue Experiment and Model) [SWR-24-84]

The Renewable Energy and Storage Cybersecurity Research (RESCue) project is a collaborative effort aimed at securing the rapidly growing deployment of transmission-connected hybrid renewable energy systems, consisting of a combination of wind, solar, and/or energy storage equipment, against escalating cyber threats. This project brings together major original equipment manufacturers (OEMs) of wind, solar, and energy storage, along with major asset owners and DOE National Laboratories, to collectively identify cyber threats, assess risks, and develop robust cybersecurity strategies and solutions. The development of hybrid reference architectures has provided comprehensive blueprints for the secure design and integration of hybrid renewable energy systems, accounting for their unique characteristics and interdependencies. Additionally, NREL has created a cyber-resilient design framework that integrates cybersecurity considerations from the start of the system lifecycle, ensuring security is "baked in" from the initial design phase. The research thrusts for the project included (i) development of hybrid reference architectures and (ii) a cyber-resilient design framework for hybrid energy systems. The reference architectures has provided comprehensive blueprints for the secure design and integration of hybrid renewable energy systems, accounting for their unique characteristics and interdependencies. Additionally, NREL has created a cyber-resilient design framework that integrates cybersecurity considerations from the start of the system lifecycle, ensuring security is "baked in" from the initial design phase. A demonstration experiment was developed for one of the architectures using NREL's Cyber Range resources. This experiment configuration, deployable using open-source tools, is provided here in this repository. Additional models were developed for the wind and solar architectures as well, however the configurations for only the Energy Storage scenario are provided here: https://www.nrel.gov/docs/fy24osti/89921.pdf

Hasandka, Adarsh

Intern Deliverable Poster 2025

An Incident Response Plan (IRP) is a document that is created and maintained by an organization that provides guidance in the event of a cyber incident. The primary objectives of an IRP are to aid in the detection, response, and recovery from incidents, as well as to enhance preparation and preventative measures. An IRP should outline specific procedures at each stage of an incident, with the goal of minimizing asset damage, data leakage, and operational impact. By investing in a well-defined IRP, organizations can better manage and mitigate risks associated with cyber threats, ensuring business continuity and resilience. This poster summarizes incident response guidelines for wind energy, which faces unique cybersecurity and physical challenges.

17 - WIND ENERGY

CIE Curriculum Guide (V.2.0)

The Cyber-Informed Engineering (CIE) Curriculum Guide offers a comprehensive framework, guidance, and resources for integrating CIE into university-level engineering programs and related educational activities. The primary goal is to help educators adopt CIE principles into their teaching to produce future engineers and technicians who understand digital risks in modern engineered systems, thereby addressing the nation’s infrastructure resilience needs. This guide outlines practical integration examples, links to resources to accelerate CIE adoption, and shares insights from partner academic institutions on various implementation strategies. CIE is a framework for embedding engineered controls that mitigate the impact of cyber-attacks in any cyber-physical system used in critical energy infrastructure and other sectors. Developed by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), the National Cyber-Informed Engineering Strategy emphasizes embedding CIE into formal education, training, and credentialing. This guide supports this strategic objective by providing examples of integrating CIE concepts into engineering curricula, from class activities to new courses and certificate programs. The importance of educating cyber-informed engineers is underscored by the evolving cybersecurity threats facing engineered systems. As industrial control systems (ICS) increasingly incorporate digital technologies, the responsibility for security extends to both cyber professionals and engineers. CIE addresses critical gaps in designing and protecting physical systems with digital components against cyber risks, ensuring engineers consider digital risk throughout the engineering design lifecycle. Currently, engineering education does not routinely include cyber-informed principles, highlighting a gap in addressing modern engineering system risks. This guide advocates for updating engineering curricula to include digital risk management as a fundamental element. By doing so, future engineers will be equipped to design resilient systems that mitigate digital risks from the outset. Through this guide, engineering faculty can integrate CIE into their curricula, bridging the gap between digital risk and engineering. This approach prepares a cyber-informed workforce capable of safeguarding the cyber-physical systems crucial to national security and public welfare. By embedding CIE into education and training, institutions can produce engineers and technicians who can effectively mitigate cyber impacts throughout the engineering design lifecycle, resulting in more secure critical infrastructures.

42 - ENGINEERING

SCA Tools - SCRM Value Add or Lossy Noise Machines

Software supply chain risk management (SCRM) depends upon accurate information regarding the software components that comprise any given software system. The collection of components included in a software package can be organized within a software bill of materials, or SBOM. SBOMs are ideally generated when the software components are put together, such as at compile time, but for many reasons that has not and is not always possible. For example, legacy or proprietary software packages often do not have SBOMs available to downstream consumers of that software. It’s not just end users that are affected, manufacturers themselves also must deal with this problem. To answer these questions, the market has seen the rise of several commercial software composition analysis (SCA) tools. These tools aim to peer into completed software systems, automatically identifying hidden software dependencies and looking up known vulnerabilities associated with those dependencies to enable end-users to enhance their cyber supply chain risk management processes. These tools are potentially a huge boon to end users of legacy and proprietary software – and a potential bane, depending on how accurate they are. This research asks that question – how accurate are currently available binary SCA tools – and provides answers to several other questions: What does it mean to be “accurate”? What limitations do the tools have in identifying common edge cases that take place in modern software development? Can they help you avoid a devastating supply chain attack, or is it all just noise? After researching SCA tools on the market, we identified three vendors that fit our use case and would provide analysis on compiled binaries. Using these tools, we submitted firmware for critical infrastructure devices for analysis and SBOM generation. The SBOM outputs were then cross referenced with SBOMs generated through manual analysis for comparison. In addition to the firmware samples, we also submitted edge case samples based off a popular open-source library that were specifically crafted to evaluate each tools’ ability to accurately identify components. These samples were customized to be consistent with modifications we have seen in modern software development as well as a couple that are representative of supply chain attacks.

97 MATHEMATICS AND COMPUTING

Grid Communications Supply Chain & Emerging Regulation Challenges Session 1

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem.

29 - ENERGY PLANNING, POLICY AND ECONOMY