Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Integrating Cybersecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

HOP and Cybersecurity: Leveraging safety and reliability experience to improve digital security culture

This presentation will introduce participants to key mental models on how to think about and understand safety and the organizational attributes that support it from three of the leading voices in the discipline – David Marx, Dr. Erik Hollnagel and Dr. Todd Conklin – and from there we ask the simple question of “how can we apply this to cybersecurity?” Opportunities, similarities, and differences from the history of accomplishment applying human and organizational performance principles to safety and reliability can be collectively leveraged to the meet the challenge of cybersecurity for OT/ICS/cyber-physical systems. This is the same intent as the "Cybersecurity Culture" principle of Cyber-Informed Engineering (CIE).

42 ENGINEERING↗

Survey of Cyber Risk Analysis Techniques for Use in the Nuclear Industry

Using traditional probabilistic risk analysis methods for severe accident safety risk management on non-digital systems, structures, and components at nuclear power plants is well-established. In contrast, cyber risk analysis of digital assets is still an immature field with unproven techniques due, in part, to the continuously changing threat environment and the challenge of digital assets failing in unexpected ways. As the nuclear fleet continues to adopt digital instrumentation and control systems, it is increasingly important to have effective and efficient cyber risk analysis techniques to support risk management decisions, such as risk elimination by system redesign or risk mitigation by implementation of prioritized security controls. To understand the state of the art in cyber risk analysis for future research, we surveyed 36 publications across ten application domains. We describe our survey methodology and rate each technique based upon scope, adoptability, and repeatability. In this work, we examine the unique constraints of the nuclear industry and outline the strengths and weaknesses of using the cyber risk analysis techniques in the industry, highlighting gaps with current techniques. We also discuss challenges and potential research directions for advancing the science for both existing and new advanced reactors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

The Energy Transition: Advanced Nuclear Needed but Address Climate Vulnerabilities Now

The term “Energy Transition” is an attempt to capture an elaborate set of activities related to the modernization and decarbonization of energy grids. Performed concurrently and often in an ad hoc manner across local, state, regional and national boundaries, it is bringing chaos to what should arguably be one of the most conservatively managed of all critical infrastructure sectors. What’s more, with climate change producing an increasing tempo of extreme events, confidence in the intended resilient and redundant structure of the electric grids is likely to ebb. Even without these climate induced stressors, the nation’s electric grid was built for an earlier century. In addition to a drive towards greater efficiency via digitization and a continuing price decline in distributed energy resources (DERs), one could argue that climate change concerns are the primary driver of the energy transition. Non-CO2 emitting generation sources like wind and solar have become an important part of the overall generation fleet, albeit ones that cannot be counted upon to provide dispatchable power. Current projections indicate deployment of even larger percentages of DERs in coming years. Until far better storage capabilities arrive, the variability of wind and solar, inconsistent performance of traditional thermal generation plants, and energy delivery failures associated with natural gas pipelines will reinforce mounting reliability concerns. This pertains to both electric transmission and distribution. The recent shuttering of nuclear power plants in Germany, Japan, the US and elsewhere are also putting more downward pressure on dispatchable generation. Russia’s attack on Ukraine has roiled energy markets worldwide and forced some countries to return to coal as a primary fuel. In view circumstances such as these, it is essential that significant changes be made to policies and planning criteria, and to the standards and code on which they are based. Given the accelerating pace of extreme weather events, this needs to occur as soon as possible.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Informed Engineering Research and Development Guide

This document provides guidance on incorporating Cyber Informed Engineering (CIE) principles into the research and development (R&D) of operational technology systems and tools, facilitating the creation and adoption of innovative technologies that are secure and resilient by design. As technological innovation and research are becoming pivotal for economic and national security, cybersecurity has emerged as a paramount concern across industries and sectors. The challenge of integrating robust cybersecurity measures is imperative to safeguard critical infrastructure, protect sensitive data, and preserve national security interests.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Informed Engineering for Nuclear Reactor Digital Instrumentation and Control

As nuclear reactors transition from analog to digital technology, the benefits of enhanced operational capabilities and improved efficiencies are potentially offset by cyber risks. Cyber-Informed Engineering (CIE) is an approach that can be used by engineers and staff to characterize and reduce new cyber risks in digital instrumentation and control systems. CIE provides guidance that can be applied throughout the entire systems engineering lifecycle, from conceptual design to decommissioning. In addition to outlining the use of CIE in nuclear reactor applications, this chapter provides a brief primer on nuclear reactor instrumentation and control and the associated cyber risks in existing light water reactors as well as the digital technology that will likely be used in future reactor designs and applications.

42 ENGINEERING↗

Cyber-Resilient Design Methodology for Microgrids

Recent advancement in tools has helped with microgrid design, development, planning and operation. Microgrids offer a unique application based on users with different requirements for tools. The process of designing, constructing, commissioning, and assessing a microgrid is not always straightforward due to these distinct requirements. Additionally, metrics are needed for performance evaluation. This panel will offer an overview and description of tools that helps with microgrid design, construction, planning, operation, cyber security, and metrics-driven performance assessment driven by multiple diverse applications and use cases.

CCE↗

Distributed Energy Resource Cybersecurity Framework and Cyber Range Integration

Distributed energy resource (DER) systems feature complex, data-driven communications networks that require careful system coordination and constant vigilance to ensure that grid assets are secure. Because DERs are an important component of the decarbonization strategy, agencies need to secure energy data that could implicate issues of national security if compromised. To help federal energy managers assess, monitor, and manage cybersecurity while achieving decarbonization, the National Renewable Energy Laboratory's (NREL's) Distributed Energy Resource Cybersecurity Framework (DER-CF) offers a comprehensive, web-based assessment tool focusing on cyber governance or policies, technical management, and physical security. The DER-CF currently presents users with a series of pertinent cybersecurity questions that are used to generate a site-specific report and recommendations. This paper outlines a plan to integrate the DER-CF with another key asset-NREL's cyber range-to visualize cybersecurity resilience and compliance and to enhance the usability and accessibility of the DER-CF for federal facility energy managers and planners. This integration will result in a visualization environment to interpret and interact with compliance data. Its development will include regular conversations with stakeholders to assess the effectiveness of these efforts, refine the visualization capability, and ensure its value to our partners.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Cyber-Resilience Risk Management Architecture for Distributed Wind

Distributed wind is an electric energy resource segment with strong potential to be deployed in many applications, but special consideration of resilience and cybersecurity is needed to address the unique conditions associated with distributed wind. Distributed wind is a strong candidate to help meet renewable energy and carbon-free energy goals. However, care must be taken as more systems are installed to ensure that the systems are reliable, resilient, and secure. The physical and communications requirements for distributed wind mean that there are unique cybersecurity considerations, but there is little to no existing guidance on best practices for cybersecurity risk management for distributed wind systems specifically. This research develops an architecture for the consideration of cyber risks associated with distributed wind systems. The architecture takes into account the configurations, challenges, and standards for distributed wind to create a risk-focused perspective that considers of threats, vulnerabilities, and consequences, with special emphasis on what sets distributed wind systems apart from other distributed energy resources (DER). We discuss common distributed wind architectures and how they are interconnected to larger power systems. Because cybersecurity cannot exist independently, the cyber-resilience architecture must consider the system holistically. Finally, we discuss the implementation of a risk assessment process that uses the cyber-resilience framework to address challenges specific to distributed wind.

17 WIND ENERGY↗

Advanced Transmission Technologies –GETs and HPCs Session 3: HPCs and Building Actions Plans to Digital Assurance Risks

The third session of the Idaho National Laboratory’s (INL) Technical Assistance for Digital Assurance (TADA) program, held on November 11, 2025, centered on High Performance Conductors (HPCs) and the formulation of action plans to address digital assurance risks associated with Grid-Enhancing Technologies (GETs). This session convened experts from utilities, vendors, and government agencies to examine the technical, operational, and cybersecurity aspects of HPC deployment. Discussions highlighted the benefits of HPCs, such as their ability to rapidly increase transmission capacity using existing corridors, improve grid resilience, reduce system losses, and align with FERC Orders 2023 and 1920. Participants evaluated supply chain and digital assurance risks, including reliance on imported materials, limited domestic manufacturing capacity, workforce shortages, and traceability issues. The session also emphasized the importance of digital trust, integration-layer cybersecurity, and unified risk frameworks, introducing tools like intrusion detection systems, encryption, zero trust networking, and firmware integrity. Recaps of earlier workshops on Dynamic Line Ratings (DLRs), Advanced Power Flow Control (APFC), and Transmission Topology Optimization (TTO) underscored institutional barriers and integration challenges. Action plans were proposed to mitigate issues such as inconsistent cybersecurity practices, SBOM usage, supply chain visibility, operator trust, and misaligned incentives. Additionally, INL presented its supply chain risk management tools and Cyber-Informed Engineering (CIE) principles to support secure procurement and system design. The session concluded with a commitment to share key takeaways, incorporate cohort feedback into future policy development, and continue collaborative engagement through upcoming pilot activities. Session 3 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Digital Engineering and Cybersecurity Decision Analysis in Early Phases of SMR-Driven IES Projects

Considerable efforts are underway to ensure cybersecurity is integrated into the systems engineering lifecycle. Cyber-informed engineering and security-by-design frameworks are intended to identify and engineer out cybersecurity risks throughout the lifecycle. While these approaches are valuable for promoting the need to include cybersecurity considerations in early design phases to create more secure systems, they may not consider the entirety of digital risks. Digital risks in a digital instrumentation and control system include adversarial and unintentional risks from internal and external factors, such as human performance errors, design flaws, environmental conditions, and equipment degradation or failure. This report provides a detailed discussion on digital risk prior to describing the background and concept of operations for a small modular reactor-driven integrated energy system connected to industrial applications. The challenges of competing objectives and competing stakeholder requirements are discussed and the impacts on digital engineering, security considerations, and interdependencies are evaluated for mission-level, facility-level, and system-level decisions.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

On the Application of Cyber-Informed Engineering (CIE)

The 2023 National Cybersecurity Strategy has recommended a transition to secure-by-design methodologies in critical infrastructure. This paper presents the adoption of the National Cyber-Informed Engineering (CIE) Strategy as initiated by the U.S. DOE’s CESER office, advocating for the integration of cybersecurity at the earliest stages of system design. The strategy targets design engineers responsible for energy infrastructure to embed CIE principles within the engineering lifecycle, thus enhancing cyber resilience. This paper discusses the expansion of secure-by-design concepts to cyber-physical systems, moving beyond traditional IT security to include engineering considerations that can mitigate cyber risks through design choices. The paper introduces Digital Risk Management, balancing traditional cybersecurity with CIE to reduce both likelihood and impact of cyber threats. A set of CIE starter questions derived from 12 core principles is detailed, aiding engineers to consider cybersecurity in their designs and highlights the importance of CIE in anticipating and reducing the impacts of cyber attacks, suggesting that such integration is essential for national security and infrastructure resilience.

42 ENGINEERING↗

Cybersecurity Workforce Training for SMR Integration into Distribution Grids: A Competency Framework and Containerized Hands-On Lab for the SMR/DER/Microgrid Boundary

Small modular reactors (SMRs) and microreactors are entering the U.S. distribution grid as synchronous generation on feeders designed for loads and inverter-based distributed energy resources (DERs). No existing cybersecurity training program addresses this intersection of nuclear operations, DER management, and operational technology security. As subcontractor to Iowa State University on the CyDERMS Center, Argonne analyzed the relevant standards and training landscape, translated the resulting gaps into a twelve-objective competency framework across distribution-operator and graduate-analyst role tracks, and built a containerized training lab using a ∼400-bus composite grid model behind a realistically simulated Modbus TCP SCADA stack. The analysis isolates the balance-of-plant / energy-management-system (BOP/EMS) boundary as the critical jurisdictional seam where, as of March 2026, neither NRC nor NERC CIP cleanly claims cybersecurity responsibility for distribution-connected SMRs. The framework maps each objective across NIST CSF 2.0, ISA/IEC 62443, NIST NICE Task–Knowledge–Skill statements, and NRC RG 5.71 awareness-and-training controls. The training lab implements operator-recognition assessment scenarios spanning grid-side disturbances and telemetry-layer anomalies.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Electrification FY2020 Annual Progress Report

The Electric Drive Technologies (EDT) program’s mission is to conduct early-stage research and development on transportation electrification technologies that accelerate the development of cost-effective and compact electric traction drive systems that meet or exceed performance and reliability requirements of internal combustion engine (ICE)-based vehicles, thereby enabling electrification across all light-duty vehicle types.

33 ADVANCED PROPULSION SYSTEMS↗

SDN-Based Smart Cyber Switching (SCS) for Cyber Restoration of a Digital Substation

In recent years, critical infrastructure and power grids have increasingly been targets of cyber-attacks, causing widespread and extended blackouts. Digital substations are particularly vulnerable to such cyber incursions, jeopardizing grid stability. This paper addresses these risks by proposing a cybersecurity framework that leverages software-defined networking (SDN) to bolster the resilience of substations based on the IEC- 61850 standard. The research introduces a strategy involving smart cyber switching (SCS) for mitigation and concurrent intelligent electronic device (CIED) for restoration, ensuring ongoing operational integrity and cybersecurity within a substation. The SCS framework improves the physical network’s behavior (i.e., leveraging commercial SDN capabilities) by incorporating an adaptive port controller (APC) module for dynamic port management and an intrusion detection system (IDS) to detect and counteract malicious IEC-61850-based sampled value (SV) and generic object-oriented system event (GOOSE) messages within the substation’s communication network. The framework’s effectiveness is validated through comprehensive simulations and a hardware-in-the-loop (HIL) testbed, demonstrating its ability to sustain substation operations during cyber-attacks and significantly improve the overall resilience of the power grid.

Liu, Chen-Ching (ORCID:0000000289417958)↗

Advanced Reactor Control and Operations (ARCO): A University Research Facility for Developing Optimized Digital Control Rooms

The Advanced Reactor Control and Operations (ARCO) facility was constructed in January 2018 to serve as a test bed for advanced reactor control rooms and operator support systems. Since then, it has supported human-machine interface user experience research, fault detection and mitigation technology development, control room concept of operations development, and remote operations research. ARCO serves as the control room for the Compact Integral Effects Test (CIET) facility, which replicates the primary-side flow paths and thermal-hydraulic behavior of a fluoride-salt-cooled high-temperature reactor (FHR) using simulant fluids and scaling principles. New reactor designs feature different operating conditions and scenarios than those in existing reactors. ARCO supports the research and development of digital tools for operator communications, intuitive real-time data analysis, online health monitoring and prognostics, and control room cybersecurity. By integrating these different technologies, ARCO acts as a prototypical control system to iteratively develop methods and tools of operation in advanced small modular nuclear reactors. This paper describes the features of and challenges to operating advanced small modular reactors underlying the design basis for ARCO and its operator support systems.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Smart Packaging for Critical Energy Shipment (SPaCES)

Recent technical advances have brought forth revolutionary Smart Packaging (SP) technology. SP incorporates multiple electronics, chemical, and mechanical sensing technologies into packaging materials, and utilizes them to monitor and display package content status. SP can also employ embedded micro actuators to react to undesirable package conditions such as moisture/temperature anomalies or harmful chemical reactions and neutralize it. When further integrated with wireless sensing and secure networking, SP provides wholistic system-wide remote situation awareness capability for real-time crisis management. Finally, we also see that SP can be further integrated with 3D printing technology to offer form-factor customization and application specific solutions suitable for DOE (Department of Energy) NNSA’s (National Nuclear Security Administration) R/N (radiological/nuclear) material shipment and management needs; this has the potential to improve safety, security, and overall operation process quality. This report surveys SP technology as the state of the art (SOTA) and analyzes how it can integrate with cybersecurity and 3D printing to address NNSA’s critical R/N material shipment and storage requirements. This report further presents our FY23/24 investigation plan describing project background, goal, motivation, proposed work, and statement of work and cost.

47 OTHER INSTRUMENTATION↗

Cybersecurity Considerations for Hydrogen Infrastructure in Airport Environments

This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.

08 HYDROGEN↗