Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyber Supply Chain Risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

SCA Tools - SCRM Value Add or Lossy Noise Machines

Software supply chain risk management (SCRM) depends upon accurate information regarding the software components that comprise any given software system. The collection of components included in a software package can be organized within a software bill of materials, or SBOM. SBOMs are ideally generated when the software components are put together, such as at compile time, but for many reasons that has not and is not always possible. For example, legacy or proprietary software packages often do not have SBOMs available to downstream consumers of that software. It’s not just end users that are affected, manufacturers themselves also must deal with this problem. To answer these questions, the market has seen the rise of several commercial software composition analysis (SCA) tools. These tools aim to peer into completed software systems, automatically identifying hidden software dependencies and looking up known vulnerabilities associated with those dependencies to enable end-users to enhance their cyber supply chain risk management processes. These tools are potentially a huge boon to end users of legacy and proprietary software – and a potential bane, depending on how accurate they are. This research asks that question – how accurate are currently available binary SCA tools – and provides answers to several other questions: What does it mean to be “accurate”? What limitations do the tools have in identifying common edge cases that take place in modern software development? Can they help you avoid a devastating supply chain attack, or is it all just noise? After researching SCA tools on the market, we identified three vendors that fit our use case and would provide analysis on compiled binaries. Using these tools, we submitted firmware for critical infrastructure devices for analysis and SBOM generation. The SBOM outputs were then cross referenced with SBOMs generated through manual analysis for comparison. In addition to the firmware samples, we also submitted edge case samples based off a popular open-source library that were specifically crafted to evaluate each tools’ ability to accurately identify components. These samples were customized to be consistent with modifications we have seen in modern software development as well as a couple that are representative of supply chain attacks.

97 MATHEMATICS AND COMPUTING↗

Modeling Cyber Supply Chain Incidents with Multilayered Graph Motifs

As noted within the literature, supply chain includes people and organizations---manufacturers, integrators, and third-party vendors---that are involved in one or more stages of a product lifecycle. Since supply chains, by definition, include organizations and people, supply chain risk management activities must consider dependencies between an organization's business processes and third-party resources. Just as adversarial tactics can be implemented via techniques implemented via networked computer systems, so can such tactics be expressed via legal business relationships. A cyber incident may have an exponential impact downstream, for example, by leveraging a product's distribution channel (e.g. malicious updates in SolarWinds, buggy updates in CrowdStrike). Similarly, legitimate and legal business relationships also affect the attack surface exposure of systems, enabling long-term persistence and/or unknown impacts to product quality that are hard to detect. This paper catalogs several recent digital supply chain incidents and applies a multilayered network formalism to develop structural indicators (graph motifs) that reflect potentially-adversarial behavior. Finally, we compare and contrast the characteristics of adversarial tactics (e.g. Loss of Availability, Data Collection) that leverage cyber-physical dependencies to those that leverage legal organizational relationships.

97 - MATHEMATICS AND COMPUTING↗

Data Center Cybersecurity, Supply Chain Risk Management, and Emerging Regulation Cohort Summary: Takeaways and Action Plans

This report summarizes the outcomes of the Data Center Cohort under the Department of Energy’s Technical Assistance for Digital Assurance (TADA) initiative, aimed at enhancing grid resilience through cybersecurity, supply chain risk management (SCRM), and Cyber-Informed Engineering (CIE). The cohort engaged 17 organizations across utilities, data center operators, vendors, and technology providers in three sessions combining presentations, discussions, and exercises. Key topics included AI-driven load behavior, cybersecurity vulnerabilities in UPS/BESS and cooling systems, governance gaps at utility–data center boundaries, and supply chain integrity. Five cross-cutting themes emerged: interconnection architecture vulnerabilities, fragmented governance, AI-driven stability risks, lack of regulatory frameworks, and long-term supply chain concerns. Actionable recommendations were developed, including implementing DMZ segmentation, formalizing vendor access agreements, designing AI workload limits, and advancing standards through NERC and state-level programs. These strategies aim to strengthen resilience, clarify responsibilities, and ensure secure integration of data centers into the grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Advanced Transmission Technologies –GETs and HPCs Session 3: HPCs and Building Actions Plans to Digital Assurance Risks

The third session of the Idaho National Laboratory’s (INL) Technical Assistance for Digital Assurance (TADA) program, held on November 11, 2025, centered on High Performance Conductors (HPCs) and the formulation of action plans to address digital assurance risks associated with Grid-Enhancing Technologies (GETs). This session convened experts from utilities, vendors, and government agencies to examine the technical, operational, and cybersecurity aspects of HPC deployment. Discussions highlighted the benefits of HPCs, such as their ability to rapidly increase transmission capacity using existing corridors, improve grid resilience, reduce system losses, and align with FERC Orders 2023 and 1920. Participants evaluated supply chain and digital assurance risks, including reliance on imported materials, limited domestic manufacturing capacity, workforce shortages, and traceability issues. The session also emphasized the importance of digital trust, integration-layer cybersecurity, and unified risk frameworks, introducing tools like intrusion detection systems, encryption, zero trust networking, and firmware integrity. Recaps of earlier workshops on Dynamic Line Ratings (DLRs), Advanced Power Flow Control (APFC), and Transmission Topology Optimization (TTO) underscored institutional barriers and integration challenges. Action plans were proposed to mitigate issues such as inconsistent cybersecurity practices, SBOM usage, supply chain visibility, operator trust, and misaligned incentives. Additionally, INL presented its supply chain risk management tools and Cyber-Informed Engineering (CIE) principles to support secure procurement and system design. The session concluded with a commitment to share key takeaways, incorporate cohort feedback into future policy development, and continue collaborative engagement through upcoming pilot activities. Session 3 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

IEEE PES GM Poster - Cyber-Informed Engineering Approach to Mitigating BESS Supply Chain Concerns

Battery energy storage systems (BESS) are increasingly important to meet the needs of grid resilience and reliability. BESS provide critical grid services, maintaining stability of the grid with increased variable conditions. However, there are significant geopolitical and security concerns regarding their operation in critical infrastructure, due to lack of a domestic supply chain and prevalence of foreign entity of concern (FEOC) components in BESS and associated inverter-based resources. The supply chain challenge is dually exacerbated by a lack of alternative suppliers who can meet the economic targets for energy delivery and a potentially adversarial supply chain. Solutions are needed to secure components, addressing mixed layers of risk and engineering controls. This paper presents a specific application of Cyber-Informed Engineering (CIE) principles for BESS and recommends an alternative strategy to blocking the supply chain, ensuring that grid modernization targets can be met despite lack of a validated or secure supply chain. This study focuses on the United State (U.S.) use case, but the process can be applied globally to address supply chain security challenges. CIE practices represent the next step in functional assurance and risk mitigation, ensuring optimal resource allocation and enhancing security measures to safeguard the future of energy in the U.S. and beyond.

25 - ENERGY STORAGE↗

Grid Communications Supply Chain & Emerging Regulation Challenges Session 1

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem.

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Grid Communications: Digital Assurance and Supply Chain Challenges and Emerging Regulation Session Two

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem. This is Session 2 of 3 (Full Version).

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Grid Communications: Cybersecurity and Supply Chain Challenges and Emerging Regulation Session Three

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem. This is Session 3 of 3 (Full Version).

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Component Criticality in BESS for Cybersecurity

Battery energy storage systems (BESS), inverters, and associated digital equipment are integral pieces of interdependent energy delivery systems. When considering the supply chain security of such systems, there is often a misplaced focus on the origin of energy generation and storage materials like battery cells, overlooking the more significant cyber risks that stem from digital power electronics control systems. Part of this misplaced focus is due to the relative costs of these components, with more attention given to expensive raw materials rather than the impactful digital elements themselves. The Idaho National Laboratory (INL) is addressing this gap in supply chain security through a systems-of-systems approach that considers the impact various components in digital energy systems can have should misoperation occur. Therefore, INL assigns a cyber criticality score based on quantitative analysis, which enables informed prioritization of mitigations and allows operators to reduce risk in light of the prevalence of a BESS and associated systems foreign supply chain.

25 ENERGY STORAGE↗

DER Digital Supply Chain Gap Analysis

Solar photovoltaic (PV) cybersecurity is a growing field of research. As deployments of solar PV have increased, cyber risk has also increased. Utility solar PV installations, however, are not required to comply with the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) plan unless they meet a minimum generation threshold of 75 MW. Individual residential-scale solar PV deployments will not meet that generation threshold and are therefore excluded from the NERC CIP requirements. With most solar installations less than 75 MW, solar PV has been deployed with minimal oversight and highly variable cybersecurity maturity. The resources that comprise the digital supply chain can include software, code, data, and other digital components. But as clean energy technologies advance, cybersecurity threats and vulnerabilities continue to evolve and grow in sophistication. Supply chain cybersecurity represents a critical area for ensuring safe operations as the U.S. moves toward a clean energy future.

cybersecurity↗

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session Two

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. A comprehensive exploration of BESS cybersecurity supply chain risks, systematic vendor risk assessment through the BESS Procurement Guide, and practical application of the INL SCRM Chatbot for enhanced supply chain resilience. This is Session 2 of 3. (Full Version)

25 - ENERGY STORAGE↗

Supply Chain Cybersecurity Recommendations for Solar Photovoltaics

Solar photovoltaic (PV) cybersecurity is a growing field of research. As deployments of solar PV has increased, cyber risk has also increased. However, utility solar PV installations are not required to comply with North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) unless they meet a minimum generation threshold of 75 Megawatts (MW). Individual residential scale solar PV deployments will not meet that generation threshold and are therefore excluded from NERC CIP requirements. With most solar installations below 75MW, solar PV has been deployed with minimal oversight and highly variable cybersecurity maturity. The resources that make up the digital supply chain can include software, code, data, as well as other digital components. However as clean energy technology advances, cybersecurity threats and vulnerabilities continue to evolve and grow in sophistication. Solar PV faces a unique challenge in which it can be deployed in residential buildings and purchased by a consumer directly. This makes the supply chain of PV a unique challenge, where responsible parties for cybersecurity vary widely depending on the type of solar PV being deployed. Supply chain cybersecurity for solar PV represents a critical area for ensuring safe operations as the U.S. moves towards a clean energy future.

14 SOLAR ENERGY↗

Smart Inverters, Dumb Risk: Taking Control of IBR Security in the Digital Age

This presentation addresses the security challenges posed by Inverter-Based Resources (IBRs) in the modern energy landscape. The presentation highlights the vulnerabilities and risks associated with IBRs, including the potential for cyber-attacks, the impact of insecure defaults, and the systemic risks posed by supply chain dependencies. Key topics covered include: 1) The increasing digital transformation in energy systems and the associated security risks. 2) Specific vulnerabilities in IBRs, including weak passwords, hardcoded credentials, and insecure web application interfaces. 3) The implications of persistent connectivity and the strategic risks posed by foreign-manufactured components. 4) The role of regulatory frameworks, such as NERC CIP, in addressing these challenges and the limitations of current oversight. 5) Practical solutions for mitigating risks, including secure design practices, vendor risk assessments, and the importance of strong passwords and role-based access control. The presentation underscores the necessity of a comprehensive, system-of-systems approach to securing IBRs, emphasizing the need for collaboration across various stakeholders, including operators, developers, and regulators, to ensure the resilience and security of the energy grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Responsible Adoption of Artificial Intelligence (AI) in Electric Grid Operations

The future of the grid will be powered by AI—or undermined by it. Artificial intelligence is rapidly reshaping grid operations, improving fault detection, forecasting accuracy, and real-time optimization. As AI systems move closer to operational decision loops, however, they introduce new consequence pathways: expanded attack surfaces, model integrity risks, regulatory exposure, and human-automation challenges. This talk presents a consequence-driven framework for deploying AI responsibly in the electric grid. Attendees will gain practical strategies to strengthen resilience, boost reliability, and deploy AI securely — ensuring the grid of the future is not only smarter but safer.

25 - ENERGY STORAGE↗

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session One

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. This is Session 1 of 3. (Full Version)

25 - ENERGY STORAGE↗

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session One - Abridged

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. This is Session 1 of 3.

25 - ENERGY STORAGE↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Smart manufacturing maturity models and their applicability: a review

The purpose of this paper is to review existing smart manufacturing (SM) maturity models' dimensions and maturity levels to assess their applicability and drawbacks. There are many maturity models available but many of them have not been validated or do not provide a useful guide or tool for applications. This gap creates the need for a review of the existing maturity model's applicability. Nineteen peer-reviewed maturity models related to “Digital Transformation,” “Industry 4.0” or “Smart Manufacturing” were selected based on a systematic literature review and five consulting firm models were selected based on the author's industry knowledge. The chosen models were analyzed to determine 10 categories of dimensions. Then they are assessed on a 1–5 scale for how applicable they are in the 10 categories of dimensions. The five “consulting firm” models have a first-mover advantage, are more widely used in industry and are more applicable, but some require payment, and they lack published details and validation. The 19 “peer reviewed” models are not as widely used, lack awareness in the industry and are not as easy to apply because of no web tool for self-assessment, but they are improving. The categories defined to characterize the models and facilitate comparisons for users include “Information Technology (IT) and Cyber-Physical System (CPS) and Data,” “Strategy and Organization,” “Supply Chain and Logistics,” “Products and Services,” “Culture and Employees,” “Technology and Capabilities,” “Customer and Market,” “Cybersecurity and Risk,” “Leadership and Management” and “Governance and Compliance.” The analyzed maturity models were particularly weak in the areas of cybersecurity, leadership and governance. Researchers and practitioners can use this review with consideration of their specific needs to determine if a maturity model is applicable or if a new model needs to be developed. The review can also aid in the development of maturity models through the discussion of each of the dimension categories. Finally, compared to existing reviews of SM maturity models, this research determines comprehensive dimension categories and focuses on applicability and drawbacks.

42 ENGINEERING↗