Search NASA⌕ Search

SEARCH · Search NASA

Results for “Cybersecurity Risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Performing Numerical Analysis of Cybersecurity Options Using Dynamic Risk Analysis Tool EMRALD

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Considering a cyber threat should involve defense-in-depth methods and a quantitative or numerical evaluation of overall effectiveness against dynamic, time-dependent attacks to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related safety is a requirement set by North American Electric Reliability and the U.S. Nuclear Regulatory Commission. They are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks may focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want to know business reliability and recovery from those threats, and that requires modeling physical behavior of the targets. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with different tools having issues such as state-base explosion. Dynamic modeling enables time and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic numerical risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies. Keywords: cyber modeling; cyber-physical systems; numerical cyber modeling

97 - MATHEMATICS AND COMPUTING↗

Progress on the MARVEL Cybersecurity by Design Model-Based Systems Engineering Project

Formal model-based systems engineering (MBSE) combines a model, systems thinking, and systems engineering to visually depict the boundaries, context, and behavior of interconnected systems, facilitating effective design, development, and utilization of engineered systems throughout the systems engineering lifecycle. Although nuclear reactor vendors employ these tools to integrate functionality, performance, and safety, they are not yet addressing digital risk concerns introduced by use of operational technology, such as digital instrumentation and control systems. To accomplish this objective, the Microreactor Applications Research Validation and EvaLuation (MARVEL) microreactor was used as an MBSE case study. This real-world application provides a first-of-a-kind opportunity to demonstrate the benefits of integrating digital risk and cybersecurity into the MBSE design process of a nuclear reactor. This paper provides an update of the ongoing MARVEL Cyber MBSE project as it specifically relates to the integration of digital risk management and cybersecurity by design.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

FEMP Cybersecurity Arsenal

The FEMP Cyber Security Arsenal is a family of cyber security tools for the federal facility owners and operators. Using these tools, facility owners can evaluate their overall cybersecurity posture. These tools are web-based front-end tools. The tools are meant to help federal owners and operators to evaluate their overall cybersecurity posture. These tools are developed based on the NIST Cybersecurity framework, risk management framework, and DOE C2M2 architectures. Version 3 provides significant updates and features in ten areas

Ashley, Travis [Pacific Northwest National Laborat↗

Survey of Space Professionals’ Perception of Satellite Cybersecurity from 2012 to 2022: Decision-Makers’ Thoughts on Satellite Cybersecurity Evolving

Cyberattacks on space assets are often portrayed in vague terms of doubt and mystery. Several claims depict satellites being compromised or attacked, but little corroboration has been published or made publicly available. As the commercial space industry is growing, commercial satellite decision makers will need to analyze the unacknowledged risk of cyberattacks against satellites. This paper identifies and characterizes what a cybersecurity risk to a space asset could look like and why space professionals might not prioritize cybersecurity. Additional information was captured from a decadal survey of space professionals in 2012 and 2022. Comparing the decadal results shows a rise in the perceived risk of satellites to cybersecurity threats from a sample of space professionals. This growing notable shift of perspective is not fully defined or agreed upon.

97 MATHEMATICS AND COMPUTING↗

Digital risk analysis in nuclear engineering projects: Designing for safety, performance, reliability, and security

Cyber-informed engineering and security-by-design frameworks are important in promoting the need to identify cybersecurity concerns early in the systems engineering lifecycle so risks from adversarial cyber-attacks can be eliminated or reduced through engineering design practices. In addition to adversarial risk, risk in operational technology systems also includes non-adversarial and unintentional risk from other factors such as human performance errors, environmental conditions, design flaws, and device degradation or failure. This paper introduces a new concept for characterizing digital risk, both adversarial and non-adversarial, and provides the basis for initial research into a novel digital risk analysis approach focused on incorporating attack difficulty into a multi-attribute analysis technique using robust decision-making. This digital risk characterization is also used to frame a discussion on the challenges of competing objectives and competing stakeholder requirements in an integrated energy system project that incorporates a small modular reactor and industrial facility.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Securing Digital Energy Infrastructure: Procurement, Contracting, and Supply Chain Risk Management Guidance

Recognizing the scale of this industry challenge, the United States (U.S.) Department of Energy (DOE) Grid Deployment Office (GDO) and Cybersecurity Energy Security & Emergency Response office have launched a multi-year BESS supply chain security initiative to identify consequence-driven approaches to addressing BESS supply chain security and provide resources to support prioritization of supply chain security efforts associated with the procurement of BESS equipment and services. This guide is one element of the supporting resources to be provided and sets forth a framework and guidance for procurement bidding, selection, risk analysis, and agreements stakeholders can implement to mitigate cybersecurity risks across the entirety of battery system component ecosystem, including the interconnected software and hardware required for control and monitoring BESSs.

25 ENERGY STORAGE↗

Advanced Transmission Technologies – GETs and HPCs Session 2: Advanced Power Flow Control and Transmission Topology Optimization

The INL TADA GETs Cohort Session 2, held on November 7, 2025, conducted in collaboration with ScottMadden, focused on two core Advanced Transmission Technologies (ATTs): Advanced Power Flow Control (APFC) and Transmission Topology Optimization (TTO). These technologies are pivotal in enhancing grid flexibility, reliability, and cybersecurity resilience. APFC, particularly through modular FACTS devices like Modular Static Synchronous Series Compensators (M-SSSCs), enables dynamic voltage injection to reroute power flows. The session highlighted the deployment benefits of APFC, such as rapid installation, minimal civil works, and re-deployability. Regulatory drivers like FERC Order 2023 mandate the inclusion of Grid-Enhancing Technologies (GETs) in interconnection studies. Case studies from Central Hudson, CAISO, and National Grid (UK) demonstrated APFC’s effectiveness in congestion relief and cost savings. The session also addressed cybersecurity concerns, including firmware vulnerabilities, SCADA integration risks, and supply chain dependencies. Participants engaged in interactive exercises to rank cybersecurity and supply chain risks, emphasizing the need for robust digital assurance strategies. TTO involves software-based reconfiguration of transmission networks to optimize power flow without new infrastructure. The session showcased its operational value, with examples from SPP, PJM, and MISO showing significant congestion cost reductions. Cybersecurity vulnerabilities were discussed, particularly in API security and software supply chains, referencing incidents like SolarWinds and attacks on Danish utilities. Digital assurance exercises explored worst-case scenarios, attack paths, and mitigation responsibilities between vendors and utilities. Reliability challenges such as algorithm stability, vendor dependency, and operator trust were also examined. Cross-cutting themes emphasized the importance of digital assurance tools, including Software Bills of Materials (SBOMs) and hardware-in-loop testing. Human performance, training, and operational confidence were identified as critical enablers of technology adoption. The session concluded with a preview of Session 3, which will focus on High Performance Conductors (HPCs) and risk-based cybersecurity tools. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

On the Application of Cyber-Informed Engineering (CIE)

The 2023 National Cybersecurity Strategy has recommended a transition to secure-by-design methodologies in critical infrastructure. This paper presents the adoption of the National Cyber-Informed Engineering (CIE) Strategy as initiated by the U.S. DOE’s CESER office, advocating for the integration of cybersecurity at the earliest stages of system design. The strategy targets design engineers responsible for energy infrastructure to embed CIE principles within the engineering lifecycle, thus enhancing cyber resilience. This paper discusses the expansion of secure-by-design concepts to cyber-physical systems, moving beyond traditional IT security to include engineering considerations that can mitigate cyber risks through design choices. The paper introduces Digital Risk Management, balancing traditional cybersecurity with CIE to reduce both likelihood and impact of cyber threats. A set of CIE starter questions derived from 12 core principles is detailed, aiding engineers to consider cybersecurity in their designs and highlights the importance of CIE in anticipating and reducing the impacts of cyber attacks, suggesting that such integration is essential for national security and infrastructure resilience.

42 ENGINEERING↗

Talk Title: AI & Cybersecurity in ASEAN's Digital Future Venue: CyberForum: ASEAN Cyber Resilience Conference Hosted by: Indonesia Cyber Security Forum (ICSF) in coordination with US State Department's mission to ASEAN in Indonesia

The talk covers: * Quick orientation around AI * Quick review of relevant domains of Cybersecurity * The promise of AI in cybersecurity – applications * Discussion of the state of technology today, referencing Gartner Hype Cycle diagram * The peril of AI for cybersecurity – threats and risks * A roadmap for where to go from here, emphasizing a trained workforce, referencing published (ISC)^2 survey results

Benz, Zachary O.↗

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Engineering in Cyber Resilience with Cyber-Informed Engineering

Engineers have super powers to provide cybersecurity resilience with deterministic engineering solutions and to protect systems from the most catastrophic consequences that a cyber saboteur could cause. Come to this session to learn how to use engineering risk management skills to harden your engineered systems from cyberattacks. Objective 1 Identify what system functions could be digitally induced to cause undesired high-impact consequences. Objective 2 Analyze how loss or instability of digital controls in a subsystem could lead to high-impact consequences. Objective 3 Analyze how loss or instability in the digital connectivity between systems could lead to high-impact consequences. Objective 4 Identify engineering controls which could build resilience by eliminating digital loss or instability pathways or reduce the impact of digital loss or instability. This presentation will introduce Cyber-Informed Engineering, described below, and walk participants through specific engineering use cases to show how engineers can consider the potential for cyber sabotage in their existing system designs and enact deterministic engineering-based controls which eliminate pathways for attack or mitigate specific consequences. A wide variety of application use cases will be considered so that audience members can align the material with familiar engineering applications. CIE is an engineering approach that integrates cyber resilience into the conception, design, build, and operation of any physical system that has digital connectivity, sensors, monitoring, or control. CIE offers the opportunity to use engineering to eliminate or mitigate avenues for cyber attack—starting from the earliest stage of design and continuing throughout the system’s lifecycle. Today, engineers and industrial control system (ICS) technicians build engineered systems with specific goals for safety, reliability, and functionality. While systems engineering includes considerable safety and failure mode analysis, cybersecurity risks are often not specifically addressed—particularly the risks of intentional cyber compromise, exploitation, and misuse. Cyber-Informed Engineering pairs well with traditional cyber defenses and offers an extra designed-in protection to eliminate the most catastrophic consequences which can be realized by an adversary should traditional cyber defenses fail.

42 ENGINEERING↗

Securing The Future: 2026 Manufacturing & Critical Infrastructure Threat Landscape

This report outlines the current state of manufacturing weaknesses introduced by the complexities of modern environments, including cloud services and Internet of Things (IoT) devices, with particular attention paid to the unique vulnerabilities encountered by SMMs. It also highlights CyManII’s strategic initiatives and collaborative solutions to mitigate these risks and strengthen the cybersecurity posture of the manufacturing ecosystem. Utilizing data from 2025 to inform forward-looking mitigation strategies, this report provides manufacturers with a clear understanding of both current and emerging cybersecurity threats, as well as practical opportunities to strengthen their cyber ecosystems. The following sections detail key vulnerabilities and threat vectors, along with actionable mitigation strategies, many of which have been developed or piloted through CyManII-led efforts. A thorough understanding of these risks and mitigation strategies is essential for manufacturers seeking to strengthen the security and resilience of their manufacturing operations.

3D Printing↗

Renewable Energy and Storage Cybersecurity Research (RESCue) Pilot Final Report

The Renewable Energy and Storage Cybersecurity Research (RESCue) project is a collaborative effort aimed at securing the rapidly growing deployment of distributed energy resources (DERs) and transmission-connected hybrid renewable energy systems against escalating cyber threats. This project brings together major original equipment manufacturers (OEMs) of wind, solar, and energy storage, along with major asset owners and DOE National Laboratories, to collectively identify cyber threats, assess risks, and develop robust cybersecurity strategies and solutions. This publication the final report for the first year of the project.

24 POWER TRANSMISSION AND DISTRIBUTION↗

RESCue Model (RESCue Experiment and Model) [SWR-24-84]

The Renewable Energy and Storage Cybersecurity Research (RESCue) project is a collaborative effort aimed at securing the rapidly growing deployment of transmission-connected hybrid renewable energy systems, consisting of a combination of wind, solar, and/or energy storage equipment, against escalating cyber threats. This project brings together major original equipment manufacturers (OEMs) of wind, solar, and energy storage, along with major asset owners and DOE National Laboratories, to collectively identify cyber threats, assess risks, and develop robust cybersecurity strategies and solutions. The development of hybrid reference architectures has provided comprehensive blueprints for the secure design and integration of hybrid renewable energy systems, accounting for their unique characteristics and interdependencies. Additionally, NREL has created a cyber-resilient design framework that integrates cybersecurity considerations from the start of the system lifecycle, ensuring security is "baked in" from the initial design phase. The research thrusts for the project included (i) development of hybrid reference architectures and (ii) a cyber-resilient design framework for hybrid energy systems. The reference architectures has provided comprehensive blueprints for the secure design and integration of hybrid renewable energy systems, accounting for their unique characteristics and interdependencies. Additionally, NREL has created a cyber-resilient design framework that integrates cybersecurity considerations from the start of the system lifecycle, ensuring security is "baked in" from the initial design phase. A demonstration experiment was developed for one of the architectures using NREL's Cyber Range resources. This experiment configuration, deployable using open-source tools, is provided here in this repository. Additional models were developed for the wind and solar architectures as well, however the configurations for only the Energy Storage scenario are provided here: https://www.nrel.gov/docs/fy24osti/89921.pdf

Hasandka, Adarsh↗

SDN-Based Smart Cyber Switching (SCS) for Cyber Restoration of a Digital Substation

In recent years, critical infrastructure and power grids have increasingly been targets of cyber-attacks, causing widespread and extended blackouts. Digital substations are particularly vulnerable to such cyber incursions, jeopardizing grid stability. This paper addresses these risks by proposing a cybersecurity framework that leverages software-defined networking (SDN) to bolster the resilience of substations based on the IEC- 61850 standard. The research introduces a strategy involving smart cyber switching (SCS) for mitigation and concurrent intelligent electronic device (CIED) for restoration, ensuring ongoing operational integrity and cybersecurity within a substation. The SCS framework improves the physical network’s behavior (i.e., leveraging commercial SDN capabilities) by incorporating an adaptive port controller (APC) module for dynamic port management and an intrusion detection system (IDS) to detect and counteract malicious IEC-61850-based sampled value (SV) and generic object-oriented system event (GOOSE) messages within the substation’s communication network. The framework’s effectiveness is validated through comprehensive simulations and a hardware-in-the-loop (HIL) testbed, demonstrating its ability to sustain substation operations during cyber-attacks and significantly improve the overall resilience of the power grid.

Liu, Chen-Ching (ORCID:0000000289417958)↗

Electric Vehicle Supply Equipment Cybersecurity Through Emulation

As the grid evolves, it is paramount to understand the risks that cyberattacks pose before assets are deployed. Leveraging the ARIES Cyber Range, NREL has created a platform to conduct analysis of EV charging protocol cybersecurity to understand the risks and impacts that cyberattacks may pose to critical infrastructure.

bug bounty prize↗