Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Utility Cybersecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Master Services Agreement - Flexible Feeder/Distribution System Support: Cooperative Research and Development (Final Report)

PGE will engage NREL on a broad range of projects related to the integration of distributed energy resources (DERs) into the utility's operations. This portfolio of work could include projects focused on DER adoption models, advanced distribution management system (ADMS) and distributed energy management system (DERMS) design, DER dispatch strategy development, and DER valuation framework development. Additional topics could include long-term energy planning, renewable energy, energy efficiency and demand-side management. As well as technology evaluations and design guidance for building retrofits and new construction projects, energy and energy infrastructure planning, policies, and markets (and their analysis), energy storage, energy security and resilience (including energy system-related cybersecurity), transportation and mobility, technology integration analysis. Additionally, other assistance as requested by PGE consistent with NREL’s expertise.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Pathways to commercial building plug and process load efficiency and control

Abstract To accomplish net-zero carbon emissions in the built environment by 2050, we must equitably decarbonize commercial buildings, including reducing plug and process loads (PPLs). PPLs are plug-in or hardwired electric and gas loads that are not associated with major building end uses like lighting and HVAC. Research shows PPL energy reduction strategies and control technologies have the potential to save energy. But even when implemented, these savings have rarely been achieved and there has not been widespread uptake in U.S. commercial buildings. We investigate why these technologies and strategies have not seen widespread adoption and identify behavior and technology pathways to increase PPL reduction in U.S. commercial buildings. We examined behaviors of commercial building stakeholders through 44 interviews and cross-referenced qualitative analysis findings with in-depth technical knowledge of existing PPL control technologies and reduction strategies. PPL control implementation must be paired with management strategies, such as occupant engagement and training, to achieve optimal savings, and best practices should be disseminated across the industry. We found that increasing access to cost and energy savings data will promote uptake of PPL control technologies and allow designers to better incorporate PPLs into building design. Improving access to funding for PPL energy efficiency projects and addressing the split-incentive problem will increase adoption of PPL efficiency and control. Code bodies should continue to include PPL monitoring and reduction measures in energy codes. Key building stakeholders, including cybersecurity and information technology teams, should be involved in PPL monitoring and reduction strategy processes for successful implementation.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Energy Sector Threat Brief: Trends and Incidents

This is a threat brief of cyber incidents and trends affecting the global energy sector over the last 12 months and resources for threat sharing, targeting an audience of utility cyber and physical security stakeholders.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

SECURED: Simulator-Enhanced Control and Understanding of Reactor systems for cyber-Event Defense

The study discusses a learning approach for analyzing cyber-events in reactor systems using integrated hardware and personal computer simulator models. Key points include the rise in cyber-attacks and their sophistication in industrial control systems (ICS), the necessity for awareness, understanding, resource allocation, and preparation to combat these threats, and the digital transformation of old and new nuclear plants, increasing their exposure to cyber threats. It highlights the cyber vulnerabilities of advanced reactor systems, which rely on digital instrumentation and control for operations and safety functions, making them susceptible to cyber-attacks. The approach involves demonstrating reactor system plant ICS cyber-attacks under various operational conditions utilizing tools like simulator models and hardware-based kits. A strategic solution approach tailored to critical infrastructure is emphasized, along with community engagement for public and government support, adopting effective learning approaches, and the preparation for anticipated future challenges. The presentation concludes with a call to action to address challenges, leverage opportunities, and advance through lesson learning in cybersecurity for nuclear energy systems.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Modeling Grid Data Flows for Transmission and Distribution Operations: Review, Design, Next Steps

Operational scenarios of the power grids grow multifold to accommodate the diverse needs of both the utilities and end consumers, and the various other stakeholders in-between. To comprehensively model and apply analytics to support objectives and business functions of grid sectors, a reliable approach to characterize and design data flows is crucial. The flows bridge business functions with communications protocols, stakeholders such as the grid actors, and data interfaces comprising different data objects. Additionally, constraints applied to the flow such as cybersecurity, trust, privacy, and ownership among others intersect these entities, requiring the delineation of their interactions under different scenarios. This paper aims to not only highlight relevant research in the space of grid data flows, but also proposes, for the transmission-distribution sector, a novel modeling approach that marries the aforementioned entities: objectives, business functions, data interfaces, communication protocols, data stakeholders, and flow constraints. It elaborates on the design philosophy and the significance of each entity within the model and applies it to an example function of fault location, isolation and service restoration (FLISR). Finally, the next steps to extend the application of this data flow model for other practical operational scenarios are discussed.

Sundararajan, Aditya [ORNL] (ORCID:000000033577854↗

Model-Based Detection of Coordinated Attacks (DCA) in Distribution Systems

The fast-paced growth in digitization of smart grid components enhances system observability and remote-control capabilities through efficient communication. However, enhanced connectivity results in heightened system vulnerability towards cybersecurity risks in the cyber-physical power system. Coordinated cyber-attacks (CCA), when undetected, lead to system-wide impact in terms of large disturbances or widespread outages. Detecting CCA in the cyber layer is critical to thwart cyber-attacks in real-time before the attack impacts the physical system. The challenge of locating CCA stems from the complex grid dynamics, making it difficult to distinguish between normal operational variations and cyber-attack impact. CCA often employs multiple attack vectors targeting geographically distributed components, further complicating CCA identification. Existing research in intrusion detection is primarily focused on the transmission network and limited to detecting individual attacks. In this paper, a novel proactive DCA strategy is proposed for early detection of CCA by establishing correlations among distinct attack events through model-based reinforcement learning that utilizes abductive reasoning to conclude the attacker goal. The solution includes understanding the system model, learning the system dynamics, and correlating individual cyber-attacks to extract the attacker’s objective. The developed learning algorithm identifies the most probable attack path to reach the attacker’s objective by predicting the next attack steps. A DNP3-based cyber-physical co-simulation testbed is developed to test the proposed algorithm using the IEEE 13-node test feeder.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Robotic automation of maintenance work in nuclear power plants a cross-sector survey and roadmap

Nuclear power plants face increasing cost pressures, workforce constraints (aging workforce and skilled labor shortages), and safety requirements that are accelerating interest in robotic systems for inspection and maintenance. We conducted semi-structured interviews with personnel from seven U.S. nuclear utilities and compared deployment models, operational use cases, and integration practices with those reported by participants in the oil, gas, and petrochemical sector. In nuclear plants, robotic use remains concentrated in inspection—particularly indoor unmanned aerial vehicles and submersible remotely operated vehicles—with limited application to physical maintenance tasks. Reported near-term value includes reduced radiological and industrial risk, reduced outage labor, and improved data for planning and condition assessment. Key barriers include integration and data-interoperability constraints, operator qualification requirements, cybersecurity review burden, and difficulty demonstrating reliability in plant-representative environments. Cross-sector benchmarking highlights organizational and deployment practices that may help nuclear plants scale from pilots to routine use. We propose a deployment-oriented roadmap emphasizing modular payload strategies, representative qualification pathways and testing environments, and improved data governance to support safe and economically justified expansion of robotics in operating nuclear power plants.

11 - NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Advanced Conductor Testing – 1431 kcmil Prysmian ACSS with E3X

Advanced conductors represent a significant evolution in transmission line technology. These conductors utilize innovative materials, such as composite cores, ultra-high-strength steel, and heat-dissipating coatings, to offer improved performance compared to traditional Aluminum Conductor Steel Reinforced (ACSR) designs. However, the deployment of these technologies has so far been limited. As each conductor comes with nuances in test setup and specifications, a standard test is not readily available to apply to all advanced conductors. Idaho National Laboratory’s (INL) Advanced Conductor Testing project, sponsored by the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) and Office of Electricity (OE), focuses on developing and implementing testing protocols and plans for advanced conductor technologies to assess and demonstrate physical performance under varying operational conditions, including extreme environmental stressors such as wildfires. This report contains the fire testing results of a 1431 kcmil Prysmian ACSS with E3X conductor.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

Equipment Self-Assessment Guide Checklist

This Equipment Self-Assessment Checklist is designed for asset owners and operators (AOOs) responsible for the deployment, operation, maintenance, or cybersecurity oversight of grid systems and digital energy technologies. It provides a structured inspection checklist for evaluating the security, integrity, and operational trustworthiness of equipment across substations, generation sites, distributed energy resources (DERs), and control environments.

32 - ENERGY CONSERVATION, CONSUMPTION, AND UTILIZA↗

Ground-motions site and event specificity: Insights from assessing a suite of simulated ground motions in the San Francisco Bay Area

This article presents the results of a research that is part of a larger collaborative effort between the Lawrence Berkeley National Laboratory and the Pacific Earthquake Engineering Research Center, funded by the US Department of Energy Office of Cybersecurity, Energy Security and Emergency Response. The main objective of this study is to assess a suite of near and far-field simulated ground motions obtained from 20 realizations of an M7 Hayward Fault earthquake in the San Francisco Bay Area, California USA, and inform the selection of rupture simulation parameters leading to strong motions. To this aim, comparisons are conducted with NGA-W2 and directivity ground-motion models and a selected population of records. An archetypal steel moment-resisting frame is utilized to assess infrastructure response distributions. The analyses carried out for each simulated event and subdomain with consistent properties in terms of shallow shear-wave velocity proved to be instrumental for better interpreting the differences between simulated motions and empirical models. The main reasons identified for variances between simulations and empirical relationships included (1) directivity effects fully captured by the simulations across the full breadth of rupture models; (2) site vicinity to ruptures that incorporate large-slip patches, particularly if these are in the forward-directivity direction; and (3) presence of geologic structures that can “trap” seismic waves and produce ground motions with large amplitude and long signal duration. The analyses carried out in this work provide a path for interpreting ground-motion site and event specificity obtained from a suite of physics-based simulations, differing only in the rupture model characterization, to inform the selection of simulation scenarios for site-specific engineering analyses under strong excitations. Evidence from this work points to the possibility that current hazard models may underestimate ground-motion intensities in areas where the combined effect of directivity and site conditions results in large ground-motion amplitudes.

58 GEOSCIENCES↗

Network Security Challenges and Countermeasures for Software-Defined Smart Grids: A Survey

The rise of grid modernization has been prompted by the escalating demand for power, the deteriorating state of infrastructure, and the growing concern regarding the reliability of electric utilities. The smart grid encompasses recent advancements in electronics, technology, telecommunications, and computer capabilities. Smart grid telecommunication frameworks provide bidirectional communication to facilitate grid operations. Software-defined networking (SDN) is a proposed approach for monitoring and regulating telecommunication networks, which allows for enhanced visibility, control, and security in smart grid systems. Nevertheless, the integration of telecommunications infrastructure exposes smart grid networks to potential cyberattacks. Unauthorized individuals may exploit unauthorized access to intercept communications, introduce fabricated data into system measurements, overwhelm communication channels with false data packets, or attack centralized controllers to disable network control. An ongoing, thorough examination of cyber attacks and protection strategies for smart grid networks is essential due to the ever-changing nature of these threats. Previous surveys on smart grid security lack modern methodologies and, to the best of our knowledge, most, if not all, focus on only one sort of attack or protection. This survey examines the most recent security techniques, simultaneous multi-pronged cyber attacks, and defense utilities in order to address the challenges of future SDN smart grid research. The objective is to identify future research requirements, describe the existing security challenges, and highlight emerging threats and their potential impact on the deployment of software-defined smart grid (SD-SG).

24 POWER TRANSMISSION AND DISTRIBUTION↗

Advanced Reactor Safeguards & Security 2024 Program Roadmap

The Advanced Reactor Safeguards and Security (ARSS) program was established to provide research support addressing near term challenges that advanced nuclear reactor vendors face in meeting domestic Material Control and Accounting (MC&A), Physical Protection System (PPS), and Cybersecurity requirements for U.S. construction. The technical work in the program is meant to (1) support nuclear reactor vendors with advanced MC&A, PPS, and Cybersecurity designs for next generation reactors, (2) provide technical bases for the regulator, and (3) promote the integration of Safeguards and Security by Design early in the design process. Existing domestic regulations for safeguards and security, as outlined in the Code of Federal Regulations, were written for large light water reactors, and rule-making efforts are underway to develop regulations more suited to different reactor designs. The ARSS program seeks to remove roadblocks in the deployment of new and advanced reactors by solving regulatory challenges, reducing safeguards and security costs, and utilizing the latest technologies and approaches for robust plant monitoring and protection. This roadmap discusses the goals of the ARSS program, current research, and program plan for the next five years.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

FY25 Electric Grid Security Annual Report

Sandia’s Electric Grid Security program advances a national vision of energy dominance and accessibility, while applying our national security -emphasis on ensuring of a secure, resilient, and affordable electric system for all users. Our achievements reflect a strategic approach combining technology development; modeling, simulation, and data analytics; and partnered demonstrations and outreach to further the adoption of advanced grid and storage technologies. Our FY25 efforts leverage the strengths of our partnerships—spanning Sandia’s core science and technology competencies as well as external technology leaders—to develop the solutions today which enable the grid of tomorrow. Key accomplishments in this report that support our strategy span our technical program areas and include: • New open-source analytical tools for systems -level planning and optimization, including significant advances to the QuESt analytical environment; • Further advancement of artificial intelligence and machine learning to enhanced grid operations and planning as we rise to the challenge of new large loads; • Development of solid-state power conversion technologies and a new medium-voltage research lab; • New technologies to assess wildfire vulnerabilities and mitigate potential impacts; • Advanced applications of new cybersecurity technologies with industry partners; • Contributions to understanding the impacts of electromagnetic pulses and geomagnetic disturbances on grid components; and • Digital twin development for hybrid microgrids with multiple generators, storage, and loads. This report indicates key areas of research and engagement and summarizes the impact of Sandia’s contributions through notable accomplishments, journal publications, patents, and technical conferences and presentations. It is provided with the hope that readers discover ways we can further team to create our modern grid and apply the outcomes of our efforts. The bulk of work described herein is funded by several offices within the U.S. Department of Energy (USDOE), including the Office of Electricity (OE); Cybersecurity, Energy Security, and Emergency Response (CESER); former offices such as the Office of Energy Efficiency and Renewable Energy (EERE), the Grid Deployment Office (GDO), the Office of Clean Energy Demonstrations (OCED), and other key programs at USDOE. As we continue to state in these annual reports, the contributors to our successes are too numerous to name here, though our team wishes to express our deep gratitude to the numerous program and project sponsors at the US Department of Energy, who often function equally as technical collaborators; our many partners in industry, academia, utilities, and other national labs; and fellow researchers and business partners at Sandia whose leadership and creativity have enabled the accomplishments described herein.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Precursor Analysis Report: Blackmatter Ransomware Attack on New Cooperative 2021

The BlackMatter Ransomware Attack on New Cooperative 2021 Precursor Analysis Report leverages publicly available information about the New Cooperative cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. The BlackMatter ransomware was first identified in July 2021 and is reported to have infected more than 50 corporations around the world. , The Iowa-based grain cooperative, New Cooperative, was impacted by the BlackMatter ransomware on or before 18 September 2021. The adversary likely resided on New Cooperative’s networks for 15 days prior to encrypting its network and demanding New Cooperative pay $5.9 million in ransom by 25 September to unlock systems and prevent 1 terabyte (TB) of sensitive data from being publicly released. It is not clear if New Cooperative paid the ransom. The full impact of the ransomware attack is not known; however, according to New Cooperative’s general manager, the attack caused the company’s automated processes to revert back to processes used in the 1970s. , As of 6 October, only 50 percent of New Cooperative’s operations were utilizing automated processes. The company took eight weeks to rebuild the entire network and information technology (IT) systems from the ground up, which puts the date of fully recovery around 13 November. Researchers and analysts identified 20 unique techniques utilized during the attack with a total of 404 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Seventeen of the identified techniques used during the New Cooperative cyber attack were precursors to the triggering event. Analysis identified 360 observables associated with these precursor techniques, 284 of which were assessed to have an increased likelihood of being perceived in the 15 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Threat Hunt Guide for BESS Environments

The rapid digitalization of the electric grid - driven by the integration of inverter-based resources (IBRs), battery energy storage systems (BESS), and advanced grid control platforms - has significantly enhanced grid efficiency, visibility, and flexibility. However, this evolution also introduces new cybersecurity risks, particularly through supply chain dependencies and operational blind spots at the grid edge. To address these challenges, Idaho National Laboratory (INL), through the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) Rapid Risk initiative, conducted a series of rapid risk assessment engagements with energy organizations across the United States. Drawing on lessons learned from these engagements, INL developed the following threat hunting guide for asset owners and operators (AOOs) to enhance their cybersecurity visibility within BESS and IBR systems. The guide demonstrates how to use passive network monitoring to baseline device behavior, detect adversarial activity, and investigate anomalies without disrupting operations. By implementing these practices, energy sector stakeholders can improve coordination between cybersecurity and operations teams and strengthen the resilience of distributed energy resources (DERs) within the modern power grid. Prior to implementing any network monitoring, packet capture, or threat hunting activity described in this guide, AOOs are strongly advised to review applicable governance frameworks, legal requirements, and organizational policies. This guide is intended for informational and educational purposes only. It does not replace compliance with any federal, state, or local cybersecurity mandates or industry standards. Implementation of described configurations, technologies, or analytic workflows is performed at the discretion and responsibility of the asset owner and operator.

25 - ENERGY STORAGE↗

Cyber Resilience and Social Equity: Twin Pillars of a Sustainable Energy Future

This paper examines the intersection of security and accessibility within energy systems amidst the rise of grid modernization and digitization, especially considering the regulatory changes and the imperatives of inclusive energy strategies. It addresses the dual need for secure, resilient infrastructure and a commitment to mitigate energy poverty while maintaining equitable access to energy. Amid escalating cybersecurity and physical threats, the paper advocates for sustainable energy delivery systems that ensure robust defenses without compromising the goals of reducing energy poverty and ensuring energy security. This paper identifies the pressing need for Cyber-Informed Engineering (CIE) and Secure-by-Design (SbD) principles, highlighting how these strategies can protect critical infrastructure and democratize access to secure energy, particularly for disadvantaged communities. The analysis underscores the challenges presented by the expansion of attack surfaces, interoperability requirements, and grid-edge analytics, offering innovative solutions that leverage advanced technologies and data-driven insights. Furthermore, this paper addresses the workforce development gap, emphasizing the necessity for public-private partnerships and vendor engagement in creating a skilled cybersecurity workforce. This paper has a dual focus on both the technological aspect of cybersecurity and the social dimension of equity within the context of sustainable energy development. It suggests a comprehensive examination of how these two critical elements interact and support the overarching goal of a sustainable energy future.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Data Centers and Digital Assurance Workshop 2 – Prioritizing Digital Assurance Challenges, Session 2

The second session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 10, 2025, focused on prioritizing digital assurance challenges at the intersection of data centers and the electric grid. Building on the foundational concepts introduced in Workshop 1, this session deepened the application of the Threat–Vulnerability–Consequence (TVC) framework and emphasized the urgency of addressing cybersecurity, supply chain integrity, and operational reliability. Participants explored the growing convergence of digital and physical systems, the expanding attack surface due to global supply chain dependencies, and the implications of AI-driven load behavior. Real-world incidents—including the Volt Typhoon campaign and vulnerabilities in Solarman and Deye platforms—were analyzed to illustrate the risks of unpatched systems, insecure APIs, and inadequate vendor oversight. Key themes included architecture and interface weaknesses, governance gaps, and human and procedural shortcomings. The workshop also examined the evolving regulatory landscape, highlighting new federal mandates around Foreign Entity of Concern (FEOC) compliance and large-load reliability standards. Through interactive exercises, stakeholders ranked and mapped digital assurance risks from their respective perspectives—utilities, operators, and vendors—laying the groundwork for mitigation strategies and shared accountability models to be developed in Workshop 3. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗