Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Incident response”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Washington State Cyber Incident Response Summit Event Report

On September 7 and 8, 2022, Pacific Northwest National Laboratory and Washington State Adjutant General Major General Bret Daugherty, with support from the Department of Homeland Security Cybersecurity and Infrastructure Security Agency, hosted the Washington State Cyber Incident Response Summit at Camp Murray in Washington State. The invite-only summit convened 40 key decision makers and stakeholders from across the state to discuss strategies and pilot a collaborative approach to improve cyber incident response readiness within Washington. In small working groups, participants shared incident response lessons learned, best practices, and opportunities for improvement within the water and transportation sectors. This report highlights the details of the workshop presentations and discussions.

97 MATHEMATICS AND COMPUTING↗

Cybersecurity Incident Response Guide for Wind

As wind energy systems become increasingly digitized and interconnected, they face a growing array of cyber threats that can disrupt operations, compromise safety, and trigger cascading impacts across the energy ecosystem. The Wind Incident Response Guide provides a structured, wind-specific framework for preparing for, detecting, responding to, and recovering from cyber incidents. Drawing on lessons from field demonstrations, cyber-physical testbeds, and stakeholder engagement across the wind sector, this guide integrates technical, operational, and regulatory considerations to support asset owners, operators, and responders. It outlines key roles and responsibilities, maps incident response phases to wind-specific scenarios, and highlights applicable laws, regulations, standards, and best practices. By tailoring general cybersecurity principles to the unique architectures and operational constraints of wind systems—including remote access, legacy components, and environmental interfaces—this guide aims to enhance resilience, reduce response time, and support coordinated action across public and private stakeholders. It is intended as a practical resource for utilities, developers, regulators, and emergency managers working to secure the future of wind energy.

17 - WIND ENERGY↗

AR4IR (Automated Reasoning for Incident Response) [SWR-24-103]

A basic formal methods tool with the ability to aid and/or automate a utilities’ incidence response and instills confidence that the proposed action satisfies the system’s physical constraints, the organization’s cyber policies, and will not cause violations of technical standards.

Etigowni, Sriharsha [National Renewable Energy Lab↗

Does practice make perfect? Lessons learned from full-scale power system incident response exercise

While threats to the energy sector occur daily, few utilities get the opportunity to fully test out their detection and response mechanisms to advanced threats in the real world. With the high demand for reliability, few grid operators would allow execution of simulated cyber-attacks on their live systems. The DOE-funded Liberty Eclipse project offers a unique opportunity for small and large utilities and coops to practice their combined IT/OT responses to a live red team executing attacks against an isolated power system on an island in New York. Both cyber teams and power operations teams must work together to detect and respond to attacks, even restoring the power system against extreme impacts. Lessons learned from these exercises reveal key takeaways for understanding what a real attack against the electric sector will look like, gaps in execution of the best-laid plans when the pressure of a real event is bearing down, and how organizations can better prepare for advanced attacks by optimizing participation in exercises. This presentation will discuss successes and opportunities for improvement both in how utilities can prepare for and respond to events, as well as how full-scale IT/OT exercises can be coordinated.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Ev Info And Incident Response Solutions

In post-crash situations, passengers, bystanders, and first responders are exposed to the immediate safety risks of stranded energy in electric vehicle (EV) batteries. A potentially damaged battery with an unknown state of safety might go into a thermal runaway without proper handling, leading to potential loss of life and property damage. Therefore, it is imperative to develop methods, guidelines and tools to handle the post-crash EVs appropriately and minimize safety risks from immediately after an EV accident to final disposal or re-entry to the road. This software tool: (1) provides quick access to EV specification, (2) estimate stranded energy left in an EV after a crash specific to EVs in a user-friendly way, (3) inform EV structure/disconnect for appropriate quick post-crash handling, (4) perform the calculation for the first responder to decide on onsite or offsite discharge, and (5) feature appropriate battery disposal and education/lessons learned. This software tool will directly help the emergency responders to handle EV post-crash situations effectively and safely.

Zhang, Bo [Idaho National Laboratory (INL), Idaho ↗

Wheelbyte Incident Response [Slides]

Wheelbyte faced some challenges regarding cyber attacks. The company reported possible exfiltration of company and customer data, along with the sudden death of an employee.

97 MATHEMATICS AND COMPUTING↗

Uncertainty Analysis of Inhalation Dose Coefficients for Nuclear Incident Response

This study addressed the need to characterize variability in inhalation dose coefficients due to uncertainties in respiratory tract deposition, systemic biokinetics, and physiological parameters. A Python-based implementation of the International Commission on Radiological Protection Publication 66 Human Respiratory Tract Model was developed called the Radiological Exposure Dose Calculator (REDCAL) to propagate parameter uncertainty.

61 RADIATION PROTECTION AND DOSIMETRY↗

NFPA Distributed Energy Resources Safety Training (DERST) For Emergency Responders

The National Fire Protection Association, with support from the Department of Energy, executed a multi-year initiative to develop, enhance, and disseminate Distributed Energy Resources Safety Training (DERST) tools for U.S. emergency responders. As Distributed Energy Resources (DER)—such as solar photovoltaics, battery energy storage systems (ESS), electric vehicles (EVs), and associated infrastructure—become increasingly prevalent, the NFPA identified a critical need for up-to-date standardized, accessible, and effective safety training tailored for the fire service and related public safety professionals. The project delivered a comprehensive suite of educational resources to improve responders’ abilities to safely manage DER-related incidents. This included: • Revised Modular Training Courses: Updated classroom-based DER safety courses, now modular and accessible nationwide through fire academies and the North American Fire Training Directors (NAFTD) network. • Live Burn Testing & Research: A full-scale controlled burn of a DER-equipped residential structure provided real-world data and insights, forming the basis for updated best practices. • A Gamified Simulation Tool – Firefighters Incident Response Simulation Tool (FIRST): A first-of-its-kind, multiplayer, scenario-based simulation using the Unreal Engine 5.0 to train responders in a realistic virtual, multi-DER incident environment. • Field Familiarization Software Tools & Prop Guide: Digital DER field familiarization evolutions software guide and a prop development manual to support field-based DER training exercises, enhancing responders' hands-on familiarity with DER infrastructure and collaboration on virtual incident responses. • National Dissemination Strategy: Strategic partnerships with NAFTD, Vector Solutions, and others enabled wide-scale distribution, with over 5,000 departments accessing resources and 1,100+ departments adopting the simulator in the first seven months. Also provided a web portal for easy access to all training and simulation programs developed under this grant for the U.S. responder community. Key findings from the project—particularly from the burn test—led to paradigm shifts in fire response tactics. For example, traditional approaches to garage fires may be hazardous if DERs are present, due to explosive off gassing and thermal runaway risks. The new training emphasizes scene assessment, stand-off approaches, thermal imaging verification, and careful post-incident cooling of DER components to prevent reignition. This initiative has had a significant national impact, raising awareness, enhancing preparedness, and supporting safer DER incident response practices. Significant engagement from the media, public safety organizations, and PBS coverage has further amplified the reach and adoption of NFPA’s DER safety training, tools, and simulations.

14 SOLAR ENERGY↗

Intern Deliverable Poster 2025

An Incident Response Plan (IRP) is a document that is created and maintained by an organization that provides guidance in the event of a cyber incident. The primary objectives of an IRP are to aid in the detection, response, and recovery from incidents, as well as to enhance preparation and preventative measures. An IRP should outline specific procedures at each stage of an incident, with the goal of minimizing asset damage, data leakage, and operational impact. By investing in a well-defined IRP, organizations can better manage and mitigate risks associated with cyber threats, ensuring business continuity and resilience. This poster summarizes incident response guidelines for wind energy, which faces unique cybersecurity and physical challenges.

17 - WIND ENERGY↗

On-the-fly response function generation method for composite coarse mesh

The hybrid stochastic deterministic transport code COMET, based on the incident response expansion theory, is used to model reactor cores with high fidelity and formidable computational speed. COMET models a reactor core using a library of incident flux response expansion coefficients that are pre computed for all the unique lattice cells (e.g., fuel assemblies, reflector blocks, etc.) in the core. In order to further improve its computational efficiency in pre-calculating the response library a new response function generation method is developed to compute the response functions for the composite coarse meshes made of a smaller set of unique lattices on the fly within the COMET's deterministic transport core sweep. The efficiency is achieved by eliminating a number of unique lattices that can be made up from the reduced set of unique meshes on the fly. The numerical process consists of the following steps. First, the boundary condition on composite coarse mesh boundaries is projected onto the expansion basis to compute the incident flux moments on external surfaces of all the basic (reduced set of unique) coarse meshes. Secondly, the deterministic sweeping solver in COMET is used to converge on the outgoing/incoming flux expansion moments crossing interfaces between the basic coarse meshes. Thirdly, the response functions for the composite coarse meshes are constructed as a superposition on the fly. The new response function generation method was tested on 88 composite coarse meshes consisting of CANDU fuel bundles and moderator blocks. It was found that response functions generated by the new method agree very well with those generated by direct Monte Carlo calculations. The average and maximum relative differences in the surface-to-surface response coefficients computed by the two methods are 0.10% and 0.20%, respectively. Similarly, the average and maximum relative differences in the response fission densities are 0.13% and 0.43%, respectively. These discrepancies are within one standard deviation of the stochastic uncertainties. The new method is five times faster than the original direct Monte Carlo method. The size of the response function library for the new method is five times smaller than that for the original method, leading to significantly less requirement for the computer hard drive space and memory. (authors)

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

NLIT 2022 Axonius Presentation

Axonius, a cybersecurity asset management tool used at INL, provides visibility into users, devices, software, and hardware in use at the lab. This visibility, provided by aggregating data on lab entities from many tools' perspectives, makes incident response, configuration management, and IT operations more capable.

42 ENGINEERING↗

WPTO Navigator

Protecting hydroelectric plants from incidents that adversely impact their cyber-physical systems presents unique challenges due to the plants’ widely dispersed geographic locations and varied configurations as well as the relative nascent nature of the cyberattacks targeting these facilities. To help hydroelectric plants better respond to and mitigate cybersecurity incidents, this Department of Energy Water Power Technologies Office Navigator aligns the processes within the National Institute of Standards 800-61r2 Computer Security Incident Handling Guide with the emergency actions within the FEMA 64 Emergency Action Plan Framework. This work is to be used at a hydroelectric plant to quickly understand how the plant responds to a cyber incident in relationship to the actions involved in an emergency action plan involving a hydroelectric plant. In addition to this product, there are three other products meant to be distributed to a hydroelectric plant to assist in their cyber incident response and recovery. The first, a report on the processes of building a R&R flip book based on a large set of existing guidance. The second, a handy flip book meant to be distributed to hydroelectric plants to assist them during a cybersecurity incident occurring on a hydroelectic plant. And the third is a comprehensive set of resources to assist an operator in locating appropriate guidance during the recovery process.

13 HYDRO ENERGY↗