Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cybersecurity risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

A Survey of Cyber Threats and Security Controls Analysis for Urban Air Mobility Environments

Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.

Cyber Threats↗

Poster: Responsible Adoption of Artificial Intelligence (AI) in Electric Grid Operations

The rapid integration of artificial intelligence (AI) in the utility transmission and distribution (T&D) sector is revolutionizing traditional grid management practices. As utilities encounter complexities from evolving consumer behaviors and energy integration, AI becomes a critical solution for enhancing grid monitoring, fault detection, and operational optimization. However, increased reliance on interconnected technologies introduces significant cybersecurity risks, regulatory compliance challenges, and human factors concerns. This study proposes a strategic, responsible and consequence-driven approach to AI implementation, examining the dual nature of AI adoption by highlighting its transformative benefits for utilities and associated risks. It provides utilities with a framework for evaluating AI integration, enabling them to navigate challenges and capitalize on opportunities to achieve greater reliability, efficiency, and resilience in an increasingly complex energy landscape.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Data Center Cybersecurity, Supply Chain Risk Management, and Emerging Regulation Cohort Summary: Takeaways and Action Plans

This report summarizes the outcomes of the Data Center Cohort under the Department of Energy’s Technical Assistance for Digital Assurance (TADA) initiative, aimed at enhancing grid resilience through cybersecurity, supply chain risk management (SCRM), and Cyber-Informed Engineering (CIE). The cohort engaged 17 organizations across utilities, data center operators, vendors, and technology providers in three sessions combining presentations, discussions, and exercises. Key topics included AI-driven load behavior, cybersecurity vulnerabilities in UPS/BESS and cooling systems, governance gaps at utility–data center boundaries, and supply chain integrity. Five cross-cutting themes emerged: interconnection architecture vulnerabilities, fragmented governance, AI-driven stability risks, lack of regulatory frameworks, and long-term supply chain concerns. Actionable recommendations were developed, including implementing DMZ segmentation, formalizing vendor access agreements, designing AI workload limits, and advancing standards through NERC and state-level programs. These strategies aim to strengthen resilience, clarify responsibilities, and ensure secure integration of data centers into the grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Supply Chain Risk Management: Forge Institute Presentation

In this talk, INL will discuss how to develop a cyber supply chain risk management program, to include assessment of vendor risk and applying appropriate mitigations. INL will discuss key risk factors and the challenges of securing supply chain in complex and dynamic vendor environments. Finally, INL will share example language that can be adopted in RFPs and procurement contracts to promote supply chain security.

battery energy storage system↗

Tale of Two Domains: Cyber - Physical

As devices and systems continue to modernize and adopt integrated circuits, the use of cyber technology to deploy an application is the expectation. This deployment through cyber assets brings new cyber risk and cybersecurity is the practice of managing this risk. Cyber-risk is constantly changing due to the speed of technology advancement and the changing quality of the adversary. Cyber-Informed Engineering (CIE) mitigates cyber-risk through engineering controls where as the traditional practice of cybersecurity mitigates cyber-risk through cybersecurity controls. By clearly defining the cyber-physical boundary, engineering controls and cybersecurity controls can clearly demonstrate their complementary nature to provide layered defenses and successfully mitigate cyber-risk through independent controls. In this paper, a layered model of device decomposition of the the cyber-physical boundary is presented to provide clarity where engineering controls are used to reduce cyber-risk within the physics, functional materials, electronic, or integrated circuit layers and where cybersecurity controls are used to reduce cyber-risk within the machine code and application layers. By implementing both traditional cybersecurity controls and engineering controls, a more holistic approach to cybersecurity is achieved in protecting modern devices and systems, as well as a clear awareness in identifying, documenting, and authorizing the system’s cybersecurity protection scheme is achieved.

42 - ENGINEERING↗

The Cybersecurity Value-at-Risk Framework

Hydropower remains one of the strongest forms of renewable energy generation methods. It is crucial to address the increasing risks associated with the rapid digitization. The push towards decarbonization also factors in the need to ensure security and resilience for grid-connected renewable energy resources. This report summarizes the U.S. Department of Energy's Water Power Technologies Office's effort to develop a cybersecurity valuation methodology that assists hydropower stakeholders in assessing risks associated with plan operations and gathers valuation guidance through a web-based applicaiton. The Hydropower Cybersecurity Value-at-Risk Framework delivers a platform for industry members to perform self assessments and make informed decisions on their cybersecurity investments.

CVF↗

Hydropower Cybersecurity Value-at-Risk Framework

Hydropower remains one of the strongest forms of renewable energy generation methods. It is crucial to address the increasing risks associated with the rapid digitization. The push towards decarbonization also factors in the need to ensure security and resilience for grid-connected renewable energy resources. This report summarizes the U.S. Department of Energy's Water Power Technologies Office's effort to develop a cybersecurity valuation methodology that assists hydropower stakeholders in assessing risks associated with plan operations and gathers valuation guidance through a web-based application. The Hydropower Cybersecurity Value-at-Risk Framework delivers a platform for industry members to perform self-assessments and make informed decisions on their cybersecurity investments.

13 HYDRO ENERGY↗

Cybersecurity Value-at-Risk Framework

As more variable renewable energy sources are added to the grid, the role of hydropower as a reliable baseline and firming resource is growing more critical. However, the U.S hydropower fleet is not fully prepared to face modern issues such as cybersecurity threats. Hydropower accounts for 37% of U.S. utility-scale renewable electricity but is challenged by diverse infrastructure and legacy devices that predate modern security practices. While new cybersecurity solutions cannot simply be added to current hydropower generation and operation technologies, custom cybersecurity assessments can reveal system-specific threats and risk probabilities and identify mitigating enhancements.

cybersecurity valuation methodology↗

Cybersecurity Value-at-Risk Framework: Preprint

As more variable renewable energy sources are added to the grid, the critical role of hydropower as a reliable baseline and firming resource is rapidly growing. However, the U.S hydropower fleet is not fully prepared to face modern issues such as cybersecurity threats. Hydropower accounts for 37% of U.S. utility-scale renewable electricity but is challenged by diverse infrastructure and legacy devices that predate modern security practices. While new cybersecurity solutions cannot simply be added to current hydropower generation and operation technologies, custom cybersecurity assessments can reveal system-specific threats and risk probabilities and identify mitigating enhancements.

cybersecurity valuation↗

Performing Numerical Analysis of Cybersecurity Options Using Dynamic Risk Analysis Tool EMRALD

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Considering a cyber threat should involve defense-in-depth methods and a quantitative or numerical evaluation of overall effectiveness against dynamic, time-dependent attacks to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related safety is a requirement set by North American Electric Reliability and the U.S. Nuclear Regulatory Commission. They are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks may focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want to know business reliability and recovery from those threats, and that requires modeling physical behavior of the targets. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with different tools having issues such as state-base explosion. Dynamic modeling enables time and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic numerical risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies. Keywords: cyber modeling; cyber-physical systems; numerical cyber modeling

97 - MATHEMATICS AND COMPUTING↗

Progress on the MARVEL Cybersecurity by Design Model-Based Systems Engineering Project

Formal model-based systems engineering (MBSE) combines a model, systems thinking, and systems engineering to visually depict the boundaries, context, and behavior of interconnected systems, facilitating effective design, development, and utilization of engineered systems throughout the systems engineering lifecycle. Although nuclear reactor vendors employ these tools to integrate functionality, performance, and safety, they are not yet addressing digital risk concerns introduced by use of operational technology, such as digital instrumentation and control systems. To accomplish this objective, the Microreactor Applications Research Validation and EvaLuation (MARVEL) microreactor was used as an MBSE case study. This real-world application provides a first-of-a-kind opportunity to demonstrate the benefits of integrating digital risk and cybersecurity into the MBSE design process of a nuclear reactor. This paper provides an update of the ongoing MARVEL Cyber MBSE project as it specifically relates to the integration of digital risk management and cybersecurity by design.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Smart manufacturing maturity models and their applicability: a review

The purpose of this paper is to review existing smart manufacturing (SM) maturity models' dimensions and maturity levels to assess their applicability and drawbacks. There are many maturity models available but many of them have not been validated or do not provide a useful guide or tool for applications. This gap creates the need for a review of the existing maturity model's applicability. Nineteen peer-reviewed maturity models related to “Digital Transformation,” “Industry 4.0” or “Smart Manufacturing” were selected based on a systematic literature review and five consulting firm models were selected based on the author's industry knowledge. The chosen models were analyzed to determine 10 categories of dimensions. Then they are assessed on a 1–5 scale for how applicable they are in the 10 categories of dimensions. The five “consulting firm” models have a first-mover advantage, are more widely used in industry and are more applicable, but some require payment, and they lack published details and validation. The 19 “peer reviewed” models are not as widely used, lack awareness in the industry and are not as easy to apply because of no web tool for self-assessment, but they are improving. The categories defined to characterize the models and facilitate comparisons for users include “Information Technology (IT) and Cyber-Physical System (CPS) and Data,” “Strategy and Organization,” “Supply Chain and Logistics,” “Products and Services,” “Culture and Employees,” “Technology and Capabilities,” “Customer and Market,” “Cybersecurity and Risk,” “Leadership and Management” and “Governance and Compliance.” The analyzed maturity models were particularly weak in the areas of cybersecurity, leadership and governance. Researchers and practitioners can use this review with consideration of their specific needs to determine if a maturity model is applicable or if a new model needs to be developed. The review can also aid in the development of maturity models through the discussion of each of the dimension categories. Finally, compared to existing reviews of SM maturity models, this research determines comprehensive dimension categories and focuses on applicability and drawbacks.

42 ENGINEERING↗

FEMP Cybersecurity Arsenal

The FEMP Cyber Security Arsenal is a family of cyber security tools for the federal facility owners and operators. Using these tools, facility owners can evaluate their overall cybersecurity posture. These tools are web-based front-end tools. The tools are meant to help federal owners and operators to evaluate their overall cybersecurity posture. These tools are developed based on the NIST Cybersecurity framework, risk management framework, and DOE C2M2 architectures. Version 3 provides significant updates and features in ten areas

Ashley, Travis [Pacific Northwest National Laborat↗

Attack Surface of Wind Energy Technologies in the United States [Slides]

This slide deck presents an overview of the threat landscape for wind energy technologies. It highlights unique cybersecurity considerations for wind, the growing penetration and potential impact of an attack. Standard architectures are shared to highlight where vulnerabilities may exist and attack paths to reach critical infrastructure. We discuss threat actors and attack paths. Several recent events impacting wind assets or wind companies are explained.

17 WIND ENERGY↗

Survey of Space Professionals’ Perception of Satellite Cybersecurity from 2012 to 2022: Decision-Makers’ Thoughts on Satellite Cybersecurity Evolving

Cyberattacks on space assets are often portrayed in vague terms of doubt and mystery. Several claims depict satellites being compromised or attacked, but little corroboration has been published or made publicly available. As the commercial space industry is growing, commercial satellite decision makers will need to analyze the unacknowledged risk of cyberattacks against satellites. This paper identifies and characterizes what a cybersecurity risk to a space asset could look like and why space professionals might not prioritize cybersecurity. Additional information was captured from a decadal survey of space professionals in 2012 and 2022. Comparing the decadal results shows a rise in the perceived risk of satellites to cybersecurity threats from a sample of space professionals. This growing notable shift of perspective is not fully defined or agreed upon.

97 MATHEMATICS AND COMPUTING↗

Digital risk analysis in nuclear engineering projects: Designing for safety, performance, reliability, and security

Cyber-informed engineering and security-by-design frameworks are important in promoting the need to identify cybersecurity concerns early in the systems engineering lifecycle so risks from adversarial cyber-attacks can be eliminated or reduced through engineering design practices. In addition to adversarial risk, risk in operational technology systems also includes non-adversarial and unintentional risk from other factors such as human performance errors, environmental conditions, design flaws, and device degradation or failure. This paper introduces a new concept for characterizing digital risk, both adversarial and non-adversarial, and provides the basis for initial research into a novel digital risk analysis approach focused on incorporating attack difficulty into a multi-attribute analysis technique using robust decision-making. This digital risk characterization is also used to frame a discussion on the challenges of competing objectives and competing stakeholder requirements in an integrated energy system project that incorporates a small modular reactor and industrial facility.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗