Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cybersecurity risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Development of an Assessment Methodology That Enables the Nuclear Industry to Evaluate Adoption of Advanced Automation

Nuclear power has a crucial role in providing safe, reliable, and economical carbon-free electricity for today and the future. For continued operation, many of the existing United States nuclear power plants will begin the subsequent license renewal process for extending their operating license periods. As plants extend their expected operating lifetimes, there is a significant opportunity to modernize. These plants have a much stronger business case with these extended mission periods to modernize and significantly enhance their economic viability in current and future energy markets by implementing digital technologies that support innovation, efficiency gains, and business-model transformation. Ensuring continued safety and reliability is crucial. Transformative digital technologies—including automation—that fundamentally change the concept of operation for the nuclear power plant operating model requires a critical focus on the human and technology integration element. Further, the nuclear industry has historically been reluctant to modernize due to having a risk adverse culture and lack of clarity for a transformative new state vision (Joe & Remer, 2019; Thomas et al., 2020). Common barriers include (1) the perceived value and return on investment (ROI) of digital technology, (2) the perceived risk associated with licensing, regulatory, and cybersecurity, and (3) insufficient guidance for performing digital modifications to power generation systems. This work presents a methodology to address these barriers and support the industry in adopting advanced automation and digital technology through developing a transformative vision and implementation strategy that will address the human and technology integration element. This research leverages previous LWRS Program and industry results. It draws specifically on previous LWRS Program research in the areas of advanced alarm systems, computer-based procedures, model informed decision support, and advanced human-system interface displays (e.g., overviews and task-based). The modernization methodology can be used to guide transformative thinking when integrating a set of vendor-specific capabilities to support a new concept of operations and a utility’s end-state vision. The results of this research are organized into six major sections: - Section 1 introduces the need for supporting large-scale digital modifications that will renew the technology base for extended operating life beyond 60 years - Section 2 describes the challenges that the nuclear industry is enduring with modernizing. - Section 3 summarizes the primary standards and guidance. - Section 4 presents earlier work from the LWRS Program regarding the development of a transformative conceptual design for an advanced control room of a hybrid plants. - Section 5 presents a methodology that is designed at addressing the challenges in the industry today in achieving a transformative new state vision and concept of operations. - Conclusions and next steps of this research are provided in Section 6.

99 GENERAL AND MISCELLANEOUS↗

Immutable Secure Data Exchange and Storage for Urban Air Mobility Environments

Urban air mobility (UAM) is a concept that proposes to develop short-range aerial vehicles to overcome increasing surface congestion. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within the UAM environment. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. To address these challenges, this research focuses on the secure data exchange and storage of this decentralized UAM environment. The intent of this research is to leverage a permissioned blockchain approach to address cybersecurity threats that may impact a UAM environment.

Urban Air Mobility↗

Immutable Secure Data Exchange and Storage for Urban Air Mobility Environments

Urban air mobility (UAM) is a concept that proposes to develop short-range aerial vehicles to overcome increasing surface congestion. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within the UAM environment. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. To address these challenges, this research focuses on the secure data exchange and storage of this decentralized UAM environment. The intent of this research is to leverage a permissioned blockchain approach to address cybersecurity threats that may impact a UAM environment.

Urban Air Mobility↗

Advanced Transmission Technologies –GETs and HPCs Session 3: HPCs and Building Actions Plans to Digital Assurance Risks

The third session of the Idaho National Laboratory’s (INL) Technical Assistance for Digital Assurance (TADA) program, held on November 11, 2025, centered on High Performance Conductors (HPCs) and the formulation of action plans to address digital assurance risks associated with Grid-Enhancing Technologies (GETs). This session convened experts from utilities, vendors, and government agencies to examine the technical, operational, and cybersecurity aspects of HPC deployment. Discussions highlighted the benefits of HPCs, such as their ability to rapidly increase transmission capacity using existing corridors, improve grid resilience, reduce system losses, and align with FERC Orders 2023 and 1920. Participants evaluated supply chain and digital assurance risks, including reliance on imported materials, limited domestic manufacturing capacity, workforce shortages, and traceability issues. The session also emphasized the importance of digital trust, integration-layer cybersecurity, and unified risk frameworks, introducing tools like intrusion detection systems, encryption, zero trust networking, and firmware integrity. Recaps of earlier workshops on Dynamic Line Ratings (DLRs), Advanced Power Flow Control (APFC), and Transmission Topology Optimization (TTO) underscored institutional barriers and integration challenges. Action plans were proposed to mitigate issues such as inconsistent cybersecurity practices, SBOM usage, supply chain visibility, operator trust, and misaligned incentives. Additionally, INL presented its supply chain risk management tools and Cyber-Informed Engineering (CIE) principles to support secure procurement and system design. The session concluded with a commitment to share key takeaways, incorporate cohort feedback into future policy development, and continue collaborative engagement through upcoming pilot activities. Session 3 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Assessing Cybersecurity Resilience of Distributed Ledger Technology in Energy Sector Using the MITRE ATT&CK® ICS Framework

Digitization in the power industry enables wide connectivity among multiple new entrants such as DERs, prosumers, and P2P counterparts within or outside the Distributed Ledger Technology (DLT). The use of DLT to improve resilience in the power grid has growing support, but new technology provides new opportunities for adversaries to cause harm. This work completed by the Cybersecurity- focused task force of IEEE SA P2418.5 evaluates the potential risks by applying the MITRE ATT&CK® ICS matrix to the DLT Engineering and Cybersecurity Stack designed for power systems applications

Gourisetti, Sri Nikhil Gupta↗

Engineering Out Industry 4.0 Cyber Risk

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

42 - ENGINEERING↗

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session Two

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. A comprehensive exploration of BESS cybersecurity supply chain risks, systematic vendor risk assessment through the BESS Procurement Guide, and practical application of the INL SCRM Chatbot for enhanced supply chain resilience. This is Session 2 of 3. (Full Version)

25 - ENERGY STORAGE↗

Utility-Scale Operational Consequences for Solar Grid Services

This report delves into the critical aspects of grid services provided by solar inverter-based resources (IBRs), with an emphasis on the evolving landscape of microgrids, virtual power plants (VPPs), aggregators, and distributed energy resource management systems (DERMS). As the energy sector undergoes a transformative shift towards more decentralized and resilient grid architectures, understanding the multifaceted risks associated with these technologies becomes paramount. The report categorizes these risks into organizational, technical, and procedural domains, providing a thorough risk assessment framework that stakeholders can utilize to anticipate and mitigate potential issues. In addressing the increasing complexity of grid interconnections, the report highlights the importance of Cyber-Informed Engineering (CIE). By embedding engineering controls and cybersecurity measures into the early stages of system design, this approach aims to fortify grid infrastructure against emerging cyber threats. The analysis includes an exploration of best practices and strategies for integrating CIE principles to enhance grid security and resilience. To provide practical insights, the report conducts a detailed consequence analysis of various grid services and cyber mitigations that can be applied through the interconnection process. This analysis evaluates the potential impacts of different failure modes and vulnerabilities, offering a clear understanding of the consequences that could arise from disruptions within the energy grid. The findings are further enriched by a series of case studies that illustrate real-world scenarios and lessons learned from past incidents. Through this comprehensive examination of grid services and their criticality, the report aims to prepare industry professionals with the knowledge and tools necessary to navigate the complexities of modern energy systems. By providing a comprehensive approach that includes risk assessment, cybersecurity, and consequence analysis, solar stakeholders can more effectively guarantee the reliability, efficiency, and security of the energy grid.

14 SOLAR ENERGY↗

NASA Blue Team: Determining Operational Security Posture of Critical Systems and Networks

Emergence of Cybersecurity has increased the focus on security risks to Information Technology (IT) assets going beyond traditional Information Assurance (IA) concerns: More sophisticated threats have emerged from increasing sources as advanced hacker tools and techniques have emerged and proliferated to broaden the attack surface available across globally interconnected networks.

cybersecurity↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Attack Surface of Wind Energy Technologies in the United States

Low cost, reliable electrical energy production from wind relies upon automation and control systems, arguably more so than traditional thermal generation. These same systems, however, can serve as the target of adversaries’ cyber-attacks. Idaho National Laboratory (INL), at the request of the Department of Energy’s (DOE’s) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) and Energy Efficiency and Renewable Energy’s (EERE’s) Wind Energy Technologies Office (WETO), evaluated a generalized wind plant architecture to understand the classes of potential threat actors and the vectors that could enable a cyber-attack. This evaluation explores the attack surface of a representative wind plant, identifying potential methods and vectors that an adversary could leverage to conduct a cyber-attack. Included in this assessment are some recommended mitigations and approaches. Each recommendation requires a full security evaluation, cost/benefit analysis, and risk analysis by each owner and operator.

17 WIND ENERGY↗

An Integrated Framework for Risk Assessment of Safety-related Digital Instrumentation and Control Systems in Nuclear Power Plants: Methodology Refinement and Exploration

This report documents activities performed by Idaho National Laboratory (INL) during Fiscal Year (FY) 2023 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) risk assessment project. In FY 2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a technical basis to support effective, and secure DI&C technologies for digital upgrades/designs. A risk assessment-informed framework was proposed for this strategy, which aims to (1) provide a best-estimate, risk informed capability to quantitatively estimate the safety margin obtained from plant modernization, especially for safety-related DI&C systems, (2) support and supplement existing risk informed DI&C design guides by providing quantitative risk information and evidence, (3) offer a capability of design architecture evaluation of various DI&C systems, (4) assure the long-term safety and reliability of safety-related DI&C systems, and (5) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals, the LWRS-developed framework provides a means to address relevant technical issues by: (1) defining a risk informed analysis process for DI&C upgrade that integrates hazard analysis, reliability analysis, and consequence analysis, (2) applying risk informed tools to address common cause failures (CCFs) and quantify corresponding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the component level, system level, and plant level, and (4) providing insights and suggestions on designs to manage the risks, thus to support the development and deployment of advanced DI&C technologies in nuclear power plants (NPPs). Adding diversity within a system or components is the primary means to eliminate and mitigate CCFs, but diversity also increases system complexity and may not address all sources of systematic failures. Optimization of diversity and redundancy applications for the safety-critical DI&C systems remains a challenge. To deal with the technical issues in addressing potential software CCFs in safety-related DI&C systems of NPPs and supporting relevant design optimization, the proposed framework provides: (a) A best-estimate, risk informed capability to address new technical digital issues quantitatively, focusing on software CCFs in safety-related DI&C systems of NPPs; (b) A common and a modularized platform for DI&C designers, software developers, cybersecurity analysts, and plant engineers to predict and prevent risk in the early design stage of DI&C systems; (c) Technical bases and risk informed insights to assist users address the risk informed alternatives for evaluation of CCFs in safety-related DI&C systems of NPPs; and (d) A risk informed tool that offers a capability of design architecture evaluation of various DI&C systems to support system design decisions in diversity and redundancy applications. The research and development efforts of this project in FY 2023 are focused on refining current methods on software CCF modeling and estimation and exploring additional innovative approaches to risk assessment of DI&C systems to enable a more comprehensive and complete assessment of various safety-related DI&C design architectures. The primary audience of this report are DI&C designers, engineers, and probabilistic risk assessment (PRA) practitioners. This includes stakeholders, such as the nuclear utilities and regulators who consider the deployment and upgrade of DI&C systems, DI&C software developers and reviewers, and cybersecurity specialists. It should be noted that all the analyses are performed for the demonstration of the methodology, not for the evaluation of an actual digital control system. Results are obtained based on limited design information and testing data.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Integrating Cybersecurity with System Operations and Restoration

This presentation covers the interaction of the discipline of system operations with the discipline of cybersecurity. First is discussion of a number of fundamental concepts for system operators - organizational division of responsibilities, human and machine cooperation, goals, and priorities. The next section covers the importance of cybersecurity for a system operator organization and explains different risk management approaches based on the consequence and frequency of events. Finally the role of system operators in the security of the grid categorized by the NIST Cybersecurity Framework is discussed to present recommendations and ideas for future work.

24 POWER TRANSMISSION AND DISTRIBUTION↗

ARCADE Technical Pathway and Industry Impact

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) simplifies the evaluation and assessment of robustness factor and cyber resilience that support secure-by-design for advanced reactor nuclear power plants. In this manner, ARCADE supports risk-informed performance based (RIPB) evaluations of cybersecurity through its integration of plant physics with high-fidelity emulations of control systems. This cross domain approach enables comprehensive analysis of control system sensitivities, cyber-attack scenarios, and their consequences. ARCADE has been custom developed to meet the demands identified in Tier 1 of the Tiered Cyber Analysis (TCA) as outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors.

97 MATHEMATICS AND COMPUTING↗

Managing Cyber Supply Chain Risk for Renewable Energy Technologies

On July 1, 2021, the U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) hosted a virtual workshop facilitated by the National Renewable Energy Laboratory (NREL). Cybersecurity supply chain experts, researchers, and leaders in government and industry came together to share information on current and future challenges in securing emerging technologies and technical architecture. From a cybersecurity perspective, we need to move from a cybersecurity approach that focuses principally on legacy asset owners to one that incorporates more emphasis on end-point device manufacturers and third-party integrators. Cybersecurity for the global digital supply chain for manufacturers of consumer end-point devices—such as smart solar inverters and smart electric vehicle (EV) chargers—will be critical to the future cyber health of the grid.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Advanced Research on Integrated Energy Systems (ARIES) Cyber Range Overview and Threat-to-Consequence Demonstration

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. The threat-to-consequence demonstration showcases NREL's capability to model, simulate, test, and evaluate cyberattacks targeting energy systems that coincide with natural hazards, as well as the ramifications for the energy grid as a whole.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Advance Reactor Operational Technology Architecture Categorization

Seven generation III+ and generation IV nuclear reactor types, based on twelve reactor concepts surveyed, are examined using functional decomposition to extract relevant operational technology (OT) architecture information. This information is compared to existing nuclear power plants (NPPs) OT architectures to highlight novel and emergent cyber risks associated with next generation NPPs. These insights can help inform operational technology architecture requirements that will be unique to a given reactor type. Next generation NPPs have streamlined OT architectures relative to the current generation II commercial NPP fleet. Overall, without compensatory measures that provide sufficient and efficient cybersecurity controls, next generation NPPs will have increased cyber risk. Verification and validation of cyber-physical testbeds and cyber risk assessment methodologies may be an important next step to reduce cyber risk in the OT architecture design and testing phase. Coordination with safety requirements can result in OT architecture design being an iterative process.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Understanding How Organizations Handle Cybersecurity

If there is anything we can learn from the media, it is the frequency and severity of cyber-attacks is increasing and there are not enough qualified people to combat the risk organizations are facing. Current estimates say there are 3.5 million available cybersecurity related jobs globally and there has been a 350% growth in cybersecurity jobs since 2013 (Group, 2020). The Idaho Cyber Research Project (ICRP) is focused on finding an implementing solution to the problems in the workforce development pipeline. Our team consists of Cohort 2 of the ICRP, we are tasked with solving issues faced by organizations hiring new cyber personnel. To provide solutions to these issues we focused our research on four components of workforce availability and competency: resume and transcript analysis, apprenticeships, cyber incident response plan development, and adversarial mindset training. From this research we have produced the following focus areas and subsequent steps for each component of workforce capability: transcript and knowledge skills abilities (KSA) focused analysis, cybersecurity apprenticeships programs, the value of an adversarial mindset, and a guide to setting up cyber incident response plans for underprepared organizations. These solutions can be further developed and implemented to reduce the gap in workforce demand and talent.

97 MATHEMATICS AND COMPUTING↗