Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cybersecurity Resilience”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Assessing Cybersecurity Resilience of Distributed Ledger Technology in Energy Sector Using the MITRE ATT&CK® ICS Framework

Digitization in the power industry enables wide connectivity among multiple new entrants such as DERs, prosumers, and P2P counterparts within or outside the Distributed Ledger Technology (DLT). The use of DLT to improve resilience in the power grid has growing support, but new technology provides new opportunities for adversaries to cause harm. This work completed by the Cybersecurity- focused task force of IEEE SA P2418.5 evaluates the potential risks by applying the MITRE ATT&CK® ICS matrix to the DLT Engineering and Cybersecurity Stack designed for power systems applications

Gourisetti, Sri Nikhil Gupta↗

Toward a Resilient Cybersecure Hydropower Fleet: Cybersecurity Landscape and Roadmap 2021

With this roadmap, Pacific Northwest National Laboratory (PNNL) hopes to assist the U.S. Department of Energy’s (DOE’s) Water Power Technologies Office (WPTO) in improving the cybersecurity of hydropower plants across the nation. This effort draws upon collected data from the dams sector, from industrial control system cybersecurity threat reports, from similar work focused on neighboring sectors, and from frank discussions with owners, operators, and vendors. While remaining tightly focused on the needs of hydropower projects, during this landscape study and development of the resulting roadmap, the research team sought to remain informed by the larger energy sector’s vision and direction so that the topics and milestones may fit within a larger vision common to the whole.

13 HYDRO ENERGY↗

Nuclear-Integrated Energy Units: Advancing Cybersecurity for Resilient Energy Systems

Rapidly increasing usage of nuclear-integrated energy units has created new challenges in terms of cybersecurity. This paper discusses the potential cyberthreat challenges and cyber risks associated with the widespread adoption of these units, and the role of artificial intelligence (AI) and machine learning (ML) techniques in enhancing the security and resilience of these systems.

20 FOSSIL-FUELED POWER PLANTS↗

Engineering in Cyber Resilience with Cyber-Informed Engineering

Engineers have super powers to provide cybersecurity resilience with deterministic engineering solutions and to protect systems from the most catastrophic consequences that a cyber saboteur could cause. Come to this session to learn how to use engineering risk management skills to harden your engineered systems from cyberattacks. Objective 1 Identify what system functions could be digitally induced to cause undesired high-impact consequences. Objective 2 Analyze how loss or instability of digital controls in a subsystem could lead to high-impact consequences. Objective 3 Analyze how loss or instability in the digital connectivity between systems could lead to high-impact consequences. Objective 4 Identify engineering controls which could build resilience by eliminating digital loss or instability pathways or reduce the impact of digital loss or instability. This presentation will introduce Cyber-Informed Engineering, described below, and walk participants through specific engineering use cases to show how engineers can consider the potential for cyber sabotage in their existing system designs and enact deterministic engineering-based controls which eliminate pathways for attack or mitigate specific consequences. A wide variety of application use cases will be considered so that audience members can align the material with familiar engineering applications. CIE is an engineering approach that integrates cyber resilience into the conception, design, build, and operation of any physical system that has digital connectivity, sensors, monitoring, or control. CIE offers the opportunity to use engineering to eliminate or mitigate avenues for cyber attack—starting from the earliest stage of design and continuing throughout the system’s lifecycle. Today, engineers and industrial control system (ICS) technicians build engineered systems with specific goals for safety, reliability, and functionality. While systems engineering includes considerable safety and failure mode analysis, cybersecurity risks are often not specifically addressed—particularly the risks of intentional cyber compromise, exploitation, and misuse. Cyber-Informed Engineering pairs well with traditional cyber defenses and offers an extra designed-in protection to eliminate the most catastrophic consequences which can be realized by an adversary should traditional cyber defenses fail.

42 ENGINEERING↗

Trade-off Analysis of Operational Technologies to Advance Cyber Resilience through Automated and Autonomous Response to Threats

The advancement of cyber resilience requires a preliminary stage of characterizing the trade-off space of mitigation options and how these might affect the stability and determinism of an operational technology (OT). This first step will set the stage for the proper cyber-secure and cyber-resilient design and confirm the affects that can be considered and approved by the OT and the security groups. To provide a baseline for this discussion, this paper provides a consideration of the cyberphysical interactions, possible mitigation steps against certain attacks and their corresponding affects that lend to the security design planning and evaluation process. As an integral part of the proposed scheme this work introduces the concept of systemwide fuzzer, i.e., a tool that manipulates the system state in an effort to determine mitigation response sequences that minimize detriments and maximize benefit in accordance with specified operational requirements.

97 MATHEMATICS AND COMPUTING↗

Cyber-Informed Engineering

Briefings provided to Duke Energy during their visit to INL on January 25, 2023. This is following the process to release the slides to Duke Energy.

42 ENGINEERING↗

Applying Cyber-Informed Engineering to Power System Operations

This presentation covers the interaction of the discipline of system operations with the growing body of knowledge around Cyber-Informed Engineering (CIE). First is discussion of a number of fundamental concepts for system operators - organizational division of responsibilities, human and machine cooperation, goals, and priorities. The next section covers the reasons why CIE was developed, what it is, and the key design and operational, and organizational principles of CIE. Finally, some thoughts on how CIE can be applied to power system operations are offered, along with some examples of how an organization can approach applying CIE principles in their particular circumstances.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Using Cyber-Informed Engineering for Cyber Defense Workbook

This workbook was prepared for a detailed workshop in Cyber-Informed Engineering. It is designed to provide an audience of electrical cooperative engineering staff with an opportunity to practice leveraging the principles of Cyber-Informed Engineering for a hypothetical system upgrade. This workbook contains material describing the fictional project, information about Cyber-Informed Engineering, hands-on exercises, and a copy of the slides presented during the workshop. It can stand alone as a CIE resource.

42 ENGINEERING↗

Application Guide for the Cyber-Resilient Design Framework for Hybrid Systems

As the energy landscape evolves, hybrid power plants—integrating multiple renewable energy sources (e.g., solar, wind, and battery storage) with the bulk power electric system—play a crucial role in meeting growing energy demands. However, with a hybrid power plant’s increased number of components, complex network connectivity and digitization of controls, these systems face growing cybersecurity risks. To help mitigate these risks, Idaho National Laboratory (INL) presents this application guide specifically designed for operators and systems engineers to evaluate the cybersecurity resilience of their hybrid power plant’s design.

14 SOLAR ENERGY↗

The Energy Transition: Advanced Nuclear Needed but Address Climate Vulnerabilities Now

The term “Energy Transition” is an attempt to capture an elaborate set of activities related to the modernization and decarbonization of energy grids. Performed concurrently and often in an ad hoc manner across local, state, regional and national boundaries, it is bringing chaos to what should arguably be one of the most conservatively managed of all critical infrastructure sectors. What’s more, with climate change producing an increasing tempo of extreme events, confidence in the intended resilient and redundant structure of the electric grids is likely to ebb. Even without these climate induced stressors, the nation’s electric grid was built for an earlier century. In addition to a drive towards greater efficiency via digitization and a continuing price decline in distributed energy resources (DERs), one could argue that climate change concerns are the primary driver of the energy transition. Non-CO2 emitting generation sources like wind and solar have become an important part of the overall generation fleet, albeit ones that cannot be counted upon to provide dispatchable power. Current projections indicate deployment of even larger percentages of DERs in coming years. Until far better storage capabilities arrive, the variability of wind and solar, inconsistent performance of traditional thermal generation plants, and energy delivery failures associated with natural gas pipelines will reinforce mounting reliability concerns. This pertains to both electric transmission and distribution. The recent shuttering of nuclear power plants in Germany, Japan, the US and elsewhere are also putting more downward pressure on dispatchable generation. Russia’s attack on Ukraine has roiled energy markets worldwide and forced some countries to return to coal as a primary fuel. In view circumstances such as these, it is essential that significant changes be made to policies and planning criteria, and to the standards and code on which they are based. Given the accelerating pace of extreme weather events, this needs to occur as soon as possible.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Advanced Transmission Technologies – GETs and HPCs Session 2: Advanced Power Flow Control and Transmission Topology Optimization

The INL TADA GETs Cohort Session 2, held on November 7, 2025, conducted in collaboration with ScottMadden, focused on two core Advanced Transmission Technologies (ATTs): Advanced Power Flow Control (APFC) and Transmission Topology Optimization (TTO). These technologies are pivotal in enhancing grid flexibility, reliability, and cybersecurity resilience. APFC, particularly through modular FACTS devices like Modular Static Synchronous Series Compensators (M-SSSCs), enables dynamic voltage injection to reroute power flows. The session highlighted the deployment benefits of APFC, such as rapid installation, minimal civil works, and re-deployability. Regulatory drivers like FERC Order 2023 mandate the inclusion of Grid-Enhancing Technologies (GETs) in interconnection studies. Case studies from Central Hudson, CAISO, and National Grid (UK) demonstrated APFC’s effectiveness in congestion relief and cost savings. The session also addressed cybersecurity concerns, including firmware vulnerabilities, SCADA integration risks, and supply chain dependencies. Participants engaged in interactive exercises to rank cybersecurity and supply chain risks, emphasizing the need for robust digital assurance strategies. TTO involves software-based reconfiguration of transmission networks to optimize power flow without new infrastructure. The session showcased its operational value, with examples from SPP, PJM, and MISO showing significant congestion cost reductions. Cybersecurity vulnerabilities were discussed, particularly in API security and software supply chains, referencing incidents like SolarWinds and attacks on Danish utilities. Digital assurance exercises explored worst-case scenarios, attack paths, and mitigation responsibilities between vendors and utilities. Reliability challenges such as algorithm stability, vendor dependency, and operator trust were also examined. Cross-cutting themes emphasized the importance of digital assurance tools, including Software Bills of Materials (SBOMs) and hardware-in-loop testing. Human performance, training, and operational confidence were identified as critical enablers of technology adoption. The session concluded with a preview of Session 3, which will focus on High Performance Conductors (HPCs) and risk-based cybersecurity tools. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

The evolution of the Human Systems and Simulation Laboratory in nuclear power research

The events at Three Mile Island in the United States brought about fundamental changes in the ways that simulation would be used in nuclear operations. The need for research simulators was identified to scientifically study human-centered risk and make recommendations for process control system designs. This paper documents the human factors research conducted at the Human Systems and Simulation Laboratory (HSSL) since its inception in 2010 at Idaho National Laboratory. The facility’s primary purposes are to provide support to utilities for system upgrades and to validate modernized control room concepts. In the last decade, however, as nuclear industry needs have evolved, so too have the purposes of the HSSL. Thus, beyond control room modernization, human factors researchers have evaluated the security of nuclear infrastructure from cyber adversaries and evaluated human-in-the-loop simulations for joint operations with an integrated hydrogen generation plant. Lastly, our review presents research using human reliability analysis techniques with data collected from HSSL-based studies and concludes with potential future directions for the HSSL, including severe accident management and advanced control room technologies.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Oakland University Cybersecurity Center (Final Scientific/Technical Report)

This report summarizes the outcomes of Award DE-CR0000023, “Oakland University Cybersecurity Center,” a 31-month project funded by the U.S. Department of Energy Office of Cybersecurity, Energy Security, and Emergency Response (CESER). The project addressed cybersecurity risks facing small and medium-sized manufacturers (SMMs) transitioning to Industry 4.0. The project integrated customer discovery, applied research, and cybersecurity training development. A total of 51 cybersecurity assessments identified significant gaps in baseline practices, incident response, and workforce capability. Research efforts produced a scalable mitigation framework tailored to SMM environments, and workforce analysis identified persistent talent gaps. Eight cybersecurity training modules were developed and deployed via Oakland University’s Professional and Continuing Education (PACE) platform. All objectives were completed, with 98.93% federal budget utilization and cost share exceeding requirements. The project establishes a scalable model for strengthening cybersecurity resilience and workforce capacity across U.S. manufacturing supply chains.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Distributed Energy Resource Visual Emulator: Phase 1

To help federal energy managers assess, monitor, and manage cybersecurity while achieving decarbonization, the National Renewable Energy Laboratory's Distributed Energy Resource Cybersecurity Framework (DER-CF) offers a comprehensive, web-based assessment tool focusing on cyber governance or policies, technical management, and physical security. The DER-CF currently presents users with a series of pertinent cybersecurity questions, which are used to generate a site-specific report and recommendations. This paper outlines a technical approach to integrate the DER-CF with another key asset—NREL's Advanced Research on Integrated Energy Systems (ARIES) Cyber Range—to visualize cybersecurity resilience and compliance and to enhance the usability and accessibility of the DER-CF. The result is a new tool called the Distributed Energy Resource Visual Emulator (DER-VE). Its development will include regular conversations with stakeholders to assess the effectiveness of these efforts, refine the visualization capability, and ensure its value to our partners. Phase 0 of the integration project was concluded in 2021. Phase 1, completed in 2022, has two components: The first is developing a working visualization of system compliance using the DER-CF, and the second is planning the design of a server application that takes input data from the DER-CF and creates a personal emulated environment of the user's system or a selected reference architect. Major components that were addressed in this phase are the DER-CF output, compliance visualization, data model, and compliance server design.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Critical Energy Infrastructure Cybersecurity: Enhanced Cyber Resilience for Federal Energy Systems

This presentation is an overview of FEMP Resilient and Secure Infrastructure and Facilities. An educational and interactive workshop centered on resilient and secure federal infrastructure and facilities, with a focus on inverter-based resources at Federal sites, building automation systems, and Federal supply chains. This workshop will illustrate an all-hazards scenario and discuss how Federal agencies can be positioned to resist these real-world scenarios.

97 MATHEMATICS AND COMPUTING↗