Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Cyber Informed Engineering”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Engineering Against Digital Risk in CIP Applications: Cyber-Informed Engineering Use Cases

Cyber-Informed Engineering (CIE) addresses the reality that cyber attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This presentation discusses engineered controls of 7 categories and the CIE database of controls that provides clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design.

99 - GENERAL AND MISCELLANEOUS

Cyber-Informed Engineering: Incorporating CIE into Engineering Curricula

Cyber-Informed Engineering (CIE) is an engineering approach that mitigates the consequences of cyber risk to critical infrastructure by integrating engineered controls into system design and operation. CIE-focused education is necessary to prepare future engineers and technicians to understand and mitigate digital risk in modern engineered systems. This session explores how universities can incorporate CIE into their curricula, provides examples of how existing universities are already leveraging CIE in their programs, and highlights resources to support adoption.

99 - GENERAL AND MISCELLANEOUS

Cyber-Informed Engineering Briefing for ABET

Cyber-Informed Engineering (CIE) is an emerging method to integrate cybersecurity considerations into the conception, design, development, and operation of any physical system, energy or otherwise, to mitigate or even eliminate avenues for cyber-enabled attacks.?CIE concepts use design decisions and engineering controls to prioritize defense against the worst possible consequences of cyberattacks facing critical infrastructure systems and asset owners. These slides offer a deep dive into Cyber-Informed Engineering for engineering educators.

42 - ENGINEERING

Cyber-Informed Engineering (CIE) – Engineered Controls Database and Use

Cyber-Informed Engineering (CIE) addresses the reality that cyber-attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This database is meant to establish clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design. The goal is to ensure that resilience is engineered into systems from the outset. Unlike cybersecurity protections that defend the digital layer, engineered controls act directly at the physical and algorithmic levels to guarantee that unacceptable consequences are prevented or limited. CIE keeps the consequences of a cyber attack from impacting the safety, reliability, and performance of engineered systems.

42 - ENGINEERING

Cyber-informed Engineering Battery Analysis Tool

The Cyber-Informed Engineering Battery Analysis Tool (CIEBAT) leverages the Department of Energy’s Cyber-Informed Engineering to prompt engineering designers and operators through an analysis of the critical functions to be supported by a BESS installation, the criticality of those functions, the impacts of denial, disruption or misuse of those functions within the BESS system, and the mitigations which could best prevent impacts to those functions resulting from cyber attack. Through use of this tool, BESS designers and operators can quickly identify appropriate engineering mitigation opportunities to limit impacts from cyber attack and functions where engineering and operational staff can prioritize and guide the application of cybersecurity protections to best support the resiliency of the system.

Lampe, BenjaminR [Idaho National Laboratory (INL),

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 - ENERGY PLANNING, POLICY AND ECONOMY

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 ENERGY PLANNING, POLICY, AND ECONOMY

CIEPAT (Cyber-Informed Engineering Photovoltaic Analysis Tool) [SWR-25-171]

The Cyber-Informed Engineering Photovoltaic Analysis Tool (CIEPAT) was developed in collaboration with the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This tool is a energy source subcomponent integrated into the CIEMAT ecosystem and is developed to enhance the security and resilience of Photovoltaic installations by incorporating Cyber-Informed Engineering (CIE) principles into the deployment of PV systems.

Etigowni, Sriharsha [National Laboratory of the Ro

CIECAT (Cyber-Informed Engineering Commercial Buildings Analysis Tool) [SWR-25-172]

The Cyber-Informed Engineering Commercial Buildings Analysis Tool (CIECAT) was developed in collaboration with the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This tool is a energy source subcomponent integrated into the CIEMAT ecosystem and is developed to enhance the security and resilience of Commercial Buildings by incorporating Cyber-Informed Engineering (CIE) principles into the Commercial Buildings.

Etigowni, Sriharsha [National Laboratory of the Ro

Cyber-Informed Engineering: Standards Development Organization Quick Start Guide

Cyber-Informed Engineering (CIE) is an emerging methodology focused on identifying and reducing high-consequence events that may affect physical critical infrastructure systems as a result of their dependence on digital technology. CIE, developed by National Laboratories and promoted by the Department of Energy (DOE), incorporates consequence-focused planning into the design and engineering process from the earliest stages of a project. This guide provides a concise overview of CIE and offers practical insight into how Standards Development Organizations (SDOs) can interpret CIE principles and apply those concepts in updates to various standards. It is important to remember that CIE extends beyond a compliance checklist, emphasizing a broader, interpretive approach. Instead, it encourages an interpretive mindset - a "turning of 'what if' to 'even if'" approach that anticipates and engineers out high-consequence events. The authors encourage SDOs to establish and promote CIE principles as enhancements for more resilient-by-design outcomes across critical infrastructure energy sectors. The 12 core principles of CIE outline specific behaviors and actions that SDOs and engineers may adopt to enhance system resilience. This guide applies these principles in a manner intended to be relevant across various technologies and threat landscapes. We welcome institutions and vendors to identify new or different framework alignments and mappings as we collectively work towards a safer and more reliable digital landscape.

97 MATHEMATICS AND COMPUTING

Requirements Framework for Cyber-Informed Engineering

The existing requirements frameworks or models cater to the existing practices. However, they fall short in directly using them for Cyber informed engineering. Therefore, this paper develops and presents a comprehensive framework that can be used for Cyber informed Engineering during the requirements phase. We describe the existing requirements process and models, then develop a requirements framework for cyber informed engineering.

97 MATHEMATICS AND COMPUTING

Cyber-Informed Engineering Workbook: SCADA (VoltVAR)

This case study workbook provides a hypothetical project to support discussion and application of Cyber-Informed Engineering principles. Participants in the workshop are encouraged to use the workbook to capture insights and lessons learned.

42 - ENGINEERING

Cyber-Informed Engineering Requirements Framework Use Cases

The requirement analysis use case effort leverages the Cyber-Informed Engineering (CIE) requirements framework to examine two real-world scenarios: Battery Energy Storage System (BESS) installation at the Flatirons Campus, NLR; SCADA improvement program. This work evaluates the existing requirements for each use case, applies the CIE requirements framework, and assesses the benefits and enhancements gained compared to the current requirements. The results will advance CIE from concept to practical application by identifying key opportunities for integrating CIE principles into established engineering workflows during the requirements phase.

97 MATHEMATICS AND COMPUTING

Integrating Cyber-Informed Engineering into Process Automation

As organizations increasingly automate their core missions and essential functions to address business risks and enhance efficiency, process automation becomes pivotal. This shift, involving minimal or no manual intervention, significantly impacts an organization's cyber-risk landscape. While automation drives efficiencies, it also introduces new cyber risks if not properly managed. Cyber-Informed Engineering (CIE) provides a proactive framework for managing these digital risks, enhancing cyber-resilience in process automation. This document supports organizations in applying CIE principles to mitigate the cyber risks associated with automation. The outlined approach can be independently implemented to improve any organization’s cyber-resilience, ensuring that the advantages of automation do not result in unaddressed or unmanaged digital risks. It serves as a starting point, offering considerations for integrating CIE principles and practices into organizational processes. CIE is presented as an iterative process, fostering continuous improvement and reinforcing the engineering and operational cultures to manage digital risks effectively. The document is structured as follows: Section 1 provides background on CIE and process automation, and their integration. Section 2 explores the twelve CIE principles in the context of process automation, highlighting key questions, engineering considerations, and implications for digital risk management. Section 3 synthesizes the findings and offers recommendations to advance resilience by design.

42 - ENGINEERING

IEEE PES GM Poster - Cyber-Informed Engineering Approach to Mitigating BESS Supply Chain Concerns

Battery energy storage systems (BESS) are increasingly important to meet the needs of grid resilience and reliability. BESS provide critical grid services, maintaining stability of the grid with increased variable conditions. However, there are significant geopolitical and security concerns regarding their operation in critical infrastructure, due to lack of a domestic supply chain and prevalence of foreign entity of concern (FEOC) components in BESS and associated inverter-based resources. The supply chain challenge is dually exacerbated by a lack of alternative suppliers who can meet the economic targets for energy delivery and a potentially adversarial supply chain. Solutions are needed to secure components, addressing mixed layers of risk and engineering controls. This paper presents a specific application of Cyber-Informed Engineering (CIE) principles for BESS and recommends an alternative strategy to blocking the supply chain, ensuring that grid modernization targets can be met despite lack of a validated or secure supply chain. This study focuses on the United State (U.S.) use case, but the process can be applied globally to address supply chain security challenges. CIE practices represent the next step in functional assurance and risk mitigation, ensuring optimal resource allocation and enhancing security measures to safeguard the future of energy in the U.S. and beyond.

25 - ENERGY STORAGE

Cyber-Informed Engineering (CIE) Workbook: End-of-Train (EoT) / Head-of-Train (HoT) Communications

This workbook presents a vulnerability (CVE-2025-1727 ) found in train applications and guides a digital risk assessment and mitigation analysis and application of Cyber-Informed Engineering principles to mitigate the potential consequences and ultimately the hazard through the engineering discipline because of exploiting this vulnerability. Workshop participants are encouraged to use the workbook to capture insights and lessons learned. The workbook guides the participant to: • Understand the HE communication vulnerability • Map digital threats to physical consequences • Use bowtie analysis to illustrate both “security” and “engineering” barriers • Apply CIE principles to ensure that even if communications are compromised, the physical engineered system still behaves safely. • Produce an actionable set of engineered and infosec controls for implementation

42 - ENGINEERING

Cyber-Informed Engineering Power Generation Guide [Slides]

The CIE for Power Generation: Insights and Case Studies guide is being developed to assist engineers at utilities, asset owner-operators developers, and cybersecurity teams to build in robustness and cyber resiliency into their designs using cyber-informed engineering practices. This guide will break out these topics including use cases by chapters for areas such as Nuclear, IBRs, Geothermal, natural gas, etc.

97 MATHEMATICS AND COMPUTING

Application of Cyber-Informed Engineering for Protecting BESS

This white paper synthesizes an array of crucial grid services provided by BESS technology, assesses its architecture and communications, and presents a case study for analysis against the principles introduced by Cyber-Informed Engineering (CIE). Furthermore, in walking through the analysis, this paper presents a framework to evaluate risks and solutions when considering BESS components. Asset owners and buyers could perform this analysis to assess their BESS product implementations, alternative inverter-based resources (IBR), and energy management systems (EMS). Battery systems fulfill various roles contingent on the unique market demands and the specific challenges presented by regional grid infrastructures. These roles also vary due to the differing utility models for ownership and operation, which are adapted to meet regional and local capabilities and requirements. Concerns have been raised regarding the potential for adversaries to exploit knowledge of battery operational patterns to orchestrate decisive attacks. However, the security of operational data for these systems may not be the primary vulnerability, as much of this information is already well-understood within the community. Applying a modest degree of subject matter expertise can often yield valuable predictions regarding how a battery will respond under certain conditions, such as grid emergencies, high or low-temperature days, Public Safety Power Shutoff (PSPS) events, and outages. The operational characteristics of batteries are well-documented, and their capabilities, including the risks associated with misoperation and the resulting consequences, are published and understood within the industry. CIE practices represent the next step in gaining functional assurance and providing an acceptable level of risk, regardless of whether a battery vendor can support a trusted and validated supply chain. While this issue has exacerbated supply chain challenges, it is not an isolated condition. This foreign supply route is the primary source of BESS for the U.S. market. Significant efforts are underway through the Bipartisan Infrastructure Law (BIL) to change that. Still, strategic short-term operational mitigations are needed to ensure the security of our operational technology (OT) systems, which are enhanced by instilling trust and are separate from vendors implementing CIE principles.

25 ENERGY STORAGE