Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cybersecurity risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Informing Cybersecurity Decisions With the Value-at-Risk Framework

Security at every site is critical to making hydropower a strong contributor to the country's grid, but with ongoing development and expanding capabilities, the diversity of the existing hydropower fleet makes across-the-board investment decisions difficult. The threat of cyberattacks naturally increases as the interconnection of Information Technology and Operational Technology networks broadens. Hydropower plants require custom analyses that are specific to the unique challenges and characteristics of any given facility. Facilities, however, often do not have the necessary resources for managers to make informed decisions on investments based on assessed capabilities and risks.

50 EE - Wind and Water Power Program - Water (EE-4↗

Survey of Space Professionals’ Perception of Satellite Cybersecurity from 2012 to 2022: Decision-Makers’ Thoughts on Satellite Cybersecurity Evolving

Cyberattacks on space assets are often portrayed in vague terms of doubt and mystery. Several claims depict satellites being compromised or attacked, but little corroboration has been published or made publicly available. As the commercial space industry is growing, commercial satellite decision makers will need to analyze the unacknowledged risk of cyberattacks against satellites. This paper identifies and characterizes what a cybersecurity risk to a space asset could look like and why space professionals might not prioritize cybersecurity. Additional information was captured from a decadal survey of space professionals in 2012 and 2022. Comparing the decadal results shows a rise in the perceived risk of satellites to cybersecurity threats from a sample of space professionals. This growing notable shift of perspective is not fully defined or agreed upon.

97 MATHEMATICS AND COMPUTING↗

Digital risk analysis in nuclear engineering projects: Designing for safety, performance, reliability, and security

Cyber-informed engineering and security-by-design frameworks are important in promoting the need to identify cybersecurity concerns early in the systems engineering lifecycle so risks from adversarial cyber-attacks can be eliminated or reduced through engineering design practices. In addition to adversarial risk, risk in operational technology systems also includes non-adversarial and unintentional risk from other factors such as human performance errors, environmental conditions, design flaws, and device degradation or failure. This paper introduces a new concept for characterizing digital risk, both adversarial and non-adversarial, and provides the basis for initial research into a novel digital risk analysis approach focused on incorporating attack difficulty into a multi-attribute analysis technique using robust decision-making. This digital risk characterization is also used to frame a discussion on the challenges of competing objectives and competing stakeholder requirements in an integrated energy system project that incorporates a small modular reactor and industrial facility.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cybersecurity Framework Profile for Electric Vehicle Extreme Fast Charging Infrastructure

This document is the Cybersecurity Framework Profile (Profile) developed for the Electric Vehicle Extreme Fast Charging (EV/XFC) ecosystem, including the four domains that relies on the ecosystem (i) Electric Vehicles (EV); (ii) Extreme Fast Charging (XFC); (iii) XFC Cloud or Third-Party Operations; and (iv) Utility and Building Networks. This Profile utilizes the NIST Cybersecurity Framework Version 1.1 and provides voluntary guidance to help relevant parties develop Profiles specific to their organization to understand, assess, and communicate their cybersecurity posture as a part of their risk management process. The Profile is intended to supplement, not replace, an existing risk management program or cybersecurity standards, regulations, and industry guidelines that are in current use by the EV/XFC industry.

33 ADVANCED PROPULSION SYSTEMS↗

US Department of Energy, Office of Science High Performance Computing Facility Operational Assessment 2021: Oak Ridge Leadership Computing Facility

Oak Ridge National Laboratory’s (ORNL’s) Leadership Computing Facility (OLCF) continues to surpass its operational target goals of supporting users; delivering fast, reliable computational ecosystems; creating innovative solutions for high-performance computing (HPC) needs; contributing to the community to build the next generation HPC workforce, and managing risks, safety, and security associated with operating some of the most powerful computers in the world. The results can be seen in the cutting-edge science conducted by users and the praise from the research community. Calendar year (CY) 2021 saw continued excellence in research supported by the OLCF’s leadership-class computing resources, including Summit (the nation’s most powerful supercomputer), the global scratch file system Alpine, the Scalable Protected Infrastructure (SPI), the Exploratory Visualization Environment for Research in Science and Technology (EVEREST), and the archival mass-storage resource High-Performance Storage System (HPSS). While maintaining access and exceptional user support for Summit, the OLCF continued to make progress on the installation and deployment of Frontier, which will be the nation’s first exascale system when it comes online at the start of CY 2023. Users have already begun running and optimizing scientific codes on Crusher, the OLCF test and development system equipped with Frontier’s architecture. Throughout the year, the OLCF maintained a strong culture of operational excellence, including risk management, workplace safety, and cybersecurity. The OLCF’s rigorous risk management strategy anticipated and mitigated risks, and at this time there are no high-priority operational risks. Similarly, ORNL and the OLCF were committed to operating under the US Department of Energy’s (DOE’s) safety regulations that ensure a safe workplace. Technical staff tracked and monitored existing threats and vulnerabilities within the OLCF while continually developing tools and practices to enhance operations without increasing the facility’s risk. CY 2021 was filled with outstanding results and accomplishments, including a very high rating from users on overall satisfaction for the eighth consecutive year; a tremendous number of node hours delivered to 1,671 researchers on Summit; and the successful delivery of the allocation split of roughly 60%, 20%, and 20% of core-hours offered for the Innovative and Novel Computational Impact on Theory and Experiment (INCITE), Advanced Scientific Computing Research Leadership Computing Challenge (ALCC), and Director’s Discretionary (DD) programs, respectively (Section 2). COVID-19 research remained a focus in 2021, and the ALCC and DD programs allocated over 1 million Summit hours to the COVID-19 High Performance Computing Consortium. These accomplishments, coupled with the high utilization rates (i.e., overall and capability usage), represent the fulfillment of the promise of leadership class machines: efficient facilitation of leadership-class computational applications.

97 MATHEMATICS AND COMPUTING↗

Case Study: Applying the INL Resilience Framework to Iowa Lakes Electric Cooperative Distributed Wind Systems

Traditional metrics and evaluation methods for resiliency are not sufficient to evaluate the effect that distributed wind systems will have, particularly in light of the challenges described above. While the concept of resiliency is not new, its application to the electric grid is neither standardized nor well-defined, and there is little to no guidance on how to evaluate resilience specifically for distributed wind systems. To fill this gap, the Idaho National Laboratory (INL), as part of the multi-laboratory Microgrids, Infrastructure Resilience, and Advanced Controls Launchpad (MIRACL) project, has developed a resilience framework for electric energy delivery systems (EEDS). The framework provides detailed steps for evaluating resiliency in the planning, operational, and future stages, and encompasses five core functions of resilience. It allows users to evaluate the resilience of distributed wind, taking into consideration the resilience of the wind systems themselves, as well as the effect they have on the resiliency of any systems they are connected to. In this study, we evaluate the resilience of the distributed wind systems at Iowa Lakes Electric Cooperative to cybersecurity hazards. We show that the wind resource can benefit the overall system resilience during some hazards. We show that the practices in place make the wind subsystems resilient against some cybersecurity hazards but that there are still significant risks associated with other cybersecurity hazards

17 WIND ENERGY↗

Overview and Recommendations for Cyber Risk Assessment in Nuclear Power Plants

Digital instrumentation and control (I&C) systems are being deployed in nuclear power plants (NPPs) for both existing and advanced reactor designs. As I&C systems become more digitized to allow features like near autonomous control and remote operation, they introduce greater cyber risk to NPPs. Cyberattacks targeting industrial control systems (ICSs) are growing in both qualities and capabilities, which indicates that cybersecurity needs to be an integral part of risk assessment in the industry. Although there are some risk assessment methods in traditional information technology (IT) cybersecurity, the differences between IT and ICS cybersecurity make it infeasible to apply these risk assessment methods directly to ICSs. Some research has focused on risk assessment methods for ICSs, but few studies focus on applications to NPPs. Ideal risk frameworks for the nuclear industry are dynamic and account for system dependencies; this survey review focuses on such risk assessment methods both in and outside the nuclear field. In this article, the major challenges in cybersecurity risk assessment research are pointed out, and further research suggestions and considerations for cyber risk assessment in I&C systems are identified.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Guide to the Distributed Energy Resource Risk Management Framework

The emergence of distributed energy resources (DERs) has transformed the electric power sector and will likely have even more profound impacts on the future evolution of the United States energy sector as it modernizes and becomes more reliant upon complex informatics programming and systems to ensure that our power grid remains safe from malicious interference. To mitigate risks associated with the increased and diversified use of DERs, the Distributed Energy Resource Cybersecurity Framework (DER-CF) was developed in 2019. The National Renewable Energy Laboratory extended the scope of the DER-CF to include the RMF. To address the challenges faced by federal energy managers and energy system stakeholders in applying the RMF to DER systems, the Distributed Energy Resource Risk Manager (DER-RM) is a six-step process to proactively manage cybersecurity risk in a methodical manner. The DER-RM is independent of the DER-CF's existing assessment, allowing users to focus specifically on the RMF steps. The tools are targeted to different processes - DER-CF enables organizations to perform self-assessments to improve their cybersecurity posture, while DER-RM assists organizations in achieving compliance with specific requirements. This document provides an overview of the DER-RM. The RMF process outlined in this report serves as a guide to diagnose information and operational system threats, gather required materials to comply with industry standards, and document plans for achieving Authority to Operate. Using the DER-RM, federal agencies and other organizations can easily and intuitively follow the RMF process, manage the risks to their grid-edge infrastructure through the integration of their on-site DERs, and comply with appropriate requirements.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Securing Digital Energy Infrastructure: Procurement, Contracting, and Supply Chain Risk Management Guidance

Recognizing the scale of this industry challenge, the United States (U.S.) Department of Energy (DOE) Grid Deployment Office (GDO) and Cybersecurity Energy Security & Emergency Response office have launched a multi-year BESS supply chain security initiative to identify consequence-driven approaches to addressing BESS supply chain security and provide resources to support prioritization of supply chain security efforts associated with the procurement of BESS equipment and services. This guide is one element of the supporting resources to be provided and sets forth a framework and guidance for procurement bidding, selection, risk analysis, and agreements stakeholders can implement to mitigate cybersecurity risks across the entirety of battery system component ecosystem, including the interconnected software and hardware required for control and monitoring BESSs.

25 ENERGY STORAGE↗

Advanced Transmission Technologies – GETs and HPCs Session 2: Advanced Power Flow Control and Transmission Topology Optimization

The INL TADA GETs Cohort Session 2, held on November 7, 2025, conducted in collaboration with ScottMadden, focused on two core Advanced Transmission Technologies (ATTs): Advanced Power Flow Control (APFC) and Transmission Topology Optimization (TTO). These technologies are pivotal in enhancing grid flexibility, reliability, and cybersecurity resilience. APFC, particularly through modular FACTS devices like Modular Static Synchronous Series Compensators (M-SSSCs), enables dynamic voltage injection to reroute power flows. The session highlighted the deployment benefits of APFC, such as rapid installation, minimal civil works, and re-deployability. Regulatory drivers like FERC Order 2023 mandate the inclusion of Grid-Enhancing Technologies (GETs) in interconnection studies. Case studies from Central Hudson, CAISO, and National Grid (UK) demonstrated APFC’s effectiveness in congestion relief and cost savings. The session also addressed cybersecurity concerns, including firmware vulnerabilities, SCADA integration risks, and supply chain dependencies. Participants engaged in interactive exercises to rank cybersecurity and supply chain risks, emphasizing the need for robust digital assurance strategies. TTO involves software-based reconfiguration of transmission networks to optimize power flow without new infrastructure. The session showcased its operational value, with examples from SPP, PJM, and MISO showing significant congestion cost reductions. Cybersecurity vulnerabilities were discussed, particularly in API security and software supply chains, referencing incidents like SolarWinds and attacks on Danish utilities. Digital assurance exercises explored worst-case scenarios, attack paths, and mitigation responsibilities between vendors and utilities. Reliability challenges such as algorithm stability, vendor dependency, and operator trust were also examined. Cross-cutting themes emphasized the importance of digital assurance tools, including Software Bills of Materials (SBOMs) and hardware-in-loop testing. Human performance, training, and operational confidence were identified as critical enablers of technology adoption. The session concluded with a preview of Session 3, which will focus on High Performance Conductors (HPCs) and risk-based cybersecurity tools. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

On the Application of Cyber-Informed Engineering (CIE)

The 2023 National Cybersecurity Strategy has recommended a transition to secure-by-design methodologies in critical infrastructure. This paper presents the adoption of the National Cyber-Informed Engineering (CIE) Strategy as initiated by the U.S. DOE’s CESER office, advocating for the integration of cybersecurity at the earliest stages of system design. The strategy targets design engineers responsible for energy infrastructure to embed CIE principles within the engineering lifecycle, thus enhancing cyber resilience. This paper discusses the expansion of secure-by-design concepts to cyber-physical systems, moving beyond traditional IT security to include engineering considerations that can mitigate cyber risks through design choices. The paper introduces Digital Risk Management, balancing traditional cybersecurity with CIE to reduce both likelihood and impact of cyber threats. A set of CIE starter questions derived from 12 core principles is detailed, aiding engineers to consider cybersecurity in their designs and highlights the importance of CIE in anticipating and reducing the impacts of cyber attacks, suggesting that such integration is essential for national security and infrastructure resilience.

42 ENGINEERING↗

Talk Title: AI & Cybersecurity in ASEAN's Digital Future Venue: CyberForum: ASEAN Cyber Resilience Conference Hosted by: Indonesia Cyber Security Forum (ICSF) in coordination with US State Department's mission to ASEAN in Indonesia

The talk covers: * Quick orientation around AI * Quick review of relevant domains of Cybersecurity * The promise of AI in cybersecurity – applications * Discussion of the state of technology today, referencing Gartner Hype Cycle diagram * The peril of AI for cybersecurity – threats and risks * A roadmap for where to go from here, emphasizing a trained workforce, referencing published (ISC)^2 survey results

Benz, Zachary O.↗

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Cyber-Informed Engineering Overview: Joint NERC/INL/E-ISAC Webinar

In July, NERC, the Electricity Information Sharing and Analysis Center (E-ISAC), and Idaho National Laboratory (INL) will host a joint informational webinar to highlight areas focused on integrating cyber and physical security with conventional engineering practices (security integration). NERC's work on these topics represents one of the first focused applications of Cyber-Informed Engineering (CIE). INL is leading the development of philosophy and practices to identify and mitigate the inherent risks of digital technology by including cybersecurity as a core element of engineering risk management. This presentation will provide an overview of CIE, a discussion of how NERC's work represents one of the first new discipline-specific applications of CIE, and an update on significant milestones and resources from the CIE program.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Informed Engineering for Design and Operations

Pursuant to the National Cyber-Informed Engineering (CIE) Strategy published in 2022, INL is leading the development of philosophy and practices to identify and mitigate the inherent risks of digital technology by including cybersecurity as a core element of engineering risk management. This presentation will provide an overview of why we need CIE and what it is, a discussion of the major implications of CIE for electric power systems design and operations, and an update on significant milestones and resources from the CIE program.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Engineering in Cyber Resilience with Cyber-Informed Engineering

Engineers have super powers to provide cybersecurity resilience with deterministic engineering solutions and to protect systems from the most catastrophic consequences that a cyber saboteur could cause. Come to this session to learn how to use engineering risk management skills to harden your engineered systems from cyberattacks. Objective 1 Identify what system functions could be digitally induced to cause undesired high-impact consequences. Objective 2 Analyze how loss or instability of digital controls in a subsystem could lead to high-impact consequences. Objective 3 Analyze how loss or instability in the digital connectivity between systems could lead to high-impact consequences. Objective 4 Identify engineering controls which could build resilience by eliminating digital loss or instability pathways or reduce the impact of digital loss or instability. This presentation will introduce Cyber-Informed Engineering, described below, and walk participants through specific engineering use cases to show how engineers can consider the potential for cyber sabotage in their existing system designs and enact deterministic engineering-based controls which eliminate pathways for attack or mitigate specific consequences. A wide variety of application use cases will be considered so that audience members can align the material with familiar engineering applications. CIE is an engineering approach that integrates cyber resilience into the conception, design, build, and operation of any physical system that has digital connectivity, sensors, monitoring, or control. CIE offers the opportunity to use engineering to eliminate or mitigate avenues for cyber attack—starting from the earliest stage of design and continuing throughout the system’s lifecycle. Today, engineers and industrial control system (ICS) technicians build engineered systems with specific goals for safety, reliability, and functionality. While systems engineering includes considerable safety and failure mode analysis, cybersecurity risks are often not specifically addressed—particularly the risks of intentional cyber compromise, exploitation, and misuse. Cyber-Informed Engineering pairs well with traditional cyber defenses and offers an extra designed-in protection to eliminate the most catastrophic consequences which can be realized by an adversary should traditional cyber defenses fail.

42 ENGINEERING↗

Securing The Future: 2026 Manufacturing & Critical Infrastructure Threat Landscape

This report outlines the current state of manufacturing weaknesses introduced by the complexities of modern environments, including cloud services and Internet of Things (IoT) devices, with particular attention paid to the unique vulnerabilities encountered by SMMs. It also highlights CyManII’s strategic initiatives and collaborative solutions to mitigate these risks and strengthen the cybersecurity posture of the manufacturing ecosystem. Utilizing data from 2025 to inform forward-looking mitigation strategies, this report provides manufacturers with a clear understanding of both current and emerging cybersecurity threats, as well as practical opportunities to strengthen their cyber ecosystems. The following sections detail key vulnerabilities and threat vectors, along with actionable mitigation strategies, many of which have been developed or piloted through CyManII-led efforts. A thorough understanding of these risks and mitigation strategies is essential for manufacturers seeking to strengthen the security and resilience of their manufacturing operations.

3D Printing↗