Search NASA⌕ Search

SEARCH · Search NASA

Results for “Cybersecurity Risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

A Blockchain Case Study for Urban Air Mobility Operational Intent

To realize the potential of Urban Air Mobility (UAM), an assurance of cybersecurity is critical for public acceptance. UAM is a concept that proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical takeoff and landing (VTOL) aircraft to overcome increasing surface congestion. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. The intent of this work is to leverage a permissioned blockchain to simulate secure data exchange and storage for the UAM operational intent use case. In this case study, two vehicle operators are operating in the same airspace. Their intent is to fly vehicles that land at a shared vertiport, securely.

Urban Air Mobility↗

A Blockchain Case Study for Urban Air Mobility Operational Intent

To realize the potential of Urban Air Mobility (UAM), an assurance of cybersecurity is critical for public acceptance. UAM is a concept that proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical takeoff and landing (VTOL) aircraft to overcome increasing surface congestion. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. The intent of this work is to leverage a permissioned blockchain to simulate secure data exchange and storage for the UAM operational intent use case.

UAM↗

A Blockchain Case Study for Urban Air Mobility Operational Intent

To realize the potential of Urban Air Mobility (UAM), an assurance of cybersecurity is critical for public acceptance. UAM is a concept that proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical takeoff and landing (VTOL) aircraft to overcome increasing surface congestion. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. The intent of this work is to leverage a permissioned blockchain to simulate secure data exchange and storage for the UAM operational intent use case.

UAM↗

Integrating Cyber-Informed Engineering into Enterprise Risk Management

This document supports the application of Cyber-Informed Engineering (CIE) within the context of Enterprise Risk Management (ERM) to enhance cyber-resilience. It highlights that many critical infrastructure organizations use ERM to manage business risks and emphasizes the importance of evaluating critical systems and assets. The proposed approach can be adopted independently of formal ERM processes and offers a starting point for integrating CIE alongside existing or new ERM practices. Both CIE and ERM are iterative, and their alignment fosters continuous improvement and supports the engineering and operations cultures of an organization.

42 ENGINEERING↗

Immutable Secure Data Exchange and Storage for Urban Air Mobility Environments

Urban air mobility (UAM) is a concept that proposes to develop short-range aerial vehicles to overcome increasing surface congestion. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within the UAM environment. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. To address these challenges, this research focuses on the secure data exchange and storage of this decentralized UAM environment. The intent of this research is to leverage a permissioned blockchain approach to address cybersecurity threats that may impact a UAM environment.

Urban Air Mobility↗

Immutable Secure Data Exchange and Storage for Urban Air Mobility Environments

Urban air mobility (UAM) is a concept that proposes to develop short-range aerial vehicles to overcome increasing surface congestion. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within the UAM environment. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. To address these challenges, this research focuses on the secure data exchange and storage of this decentralized UAM environment. The intent of this research is to leverage a permissioned blockchain approach to address cybersecurity threats that may impact a UAM environment.

Urban Air Mobility↗

Advanced Transmission Technologies –GETs and HPCs Session 3: HPCs and Building Actions Plans to Digital Assurance Risks

The third session of the Idaho National Laboratory’s (INL) Technical Assistance for Digital Assurance (TADA) program, held on November 11, 2025, centered on High Performance Conductors (HPCs) and the formulation of action plans to address digital assurance risks associated with Grid-Enhancing Technologies (GETs). This session convened experts from utilities, vendors, and government agencies to examine the technical, operational, and cybersecurity aspects of HPC deployment. Discussions highlighted the benefits of HPCs, such as their ability to rapidly increase transmission capacity using existing corridors, improve grid resilience, reduce system losses, and align with FERC Orders 2023 and 1920. Participants evaluated supply chain and digital assurance risks, including reliance on imported materials, limited domestic manufacturing capacity, workforce shortages, and traceability issues. The session also emphasized the importance of digital trust, integration-layer cybersecurity, and unified risk frameworks, introducing tools like intrusion detection systems, encryption, zero trust networking, and firmware integrity. Recaps of earlier workshops on Dynamic Line Ratings (DLRs), Advanced Power Flow Control (APFC), and Transmission Topology Optimization (TTO) underscored institutional barriers and integration challenges. Action plans were proposed to mitigate issues such as inconsistent cybersecurity practices, SBOM usage, supply chain visibility, operator trust, and misaligned incentives. Additionally, INL presented its supply chain risk management tools and Cyber-Informed Engineering (CIE) principles to support secure procurement and system design. The session concluded with a commitment to share key takeaways, incorporate cohort feedback into future policy development, and continue collaborative engagement through upcoming pilot activities. Session 3 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Engineering Out Industry 4.0 Cyber Risk

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

42 - ENGINEERING↗

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session Two

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. A comprehensive exploration of BESS cybersecurity supply chain risks, systematic vendor risk assessment through the BESS Procurement Guide, and practical application of the INL SCRM Chatbot for enhanced supply chain resilience. This is Session 2 of 3. (Full Version)

25 - ENERGY STORAGE↗

Utility-Scale Operational Consequences for Solar Grid Services

This report delves into the critical aspects of grid services provided by solar inverter-based resources (IBRs), with an emphasis on the evolving landscape of microgrids, virtual power plants (VPPs), aggregators, and distributed energy resource management systems (DERMS). As the energy sector undergoes a transformative shift towards more decentralized and resilient grid architectures, understanding the multifaceted risks associated with these technologies becomes paramount. The report categorizes these risks into organizational, technical, and procedural domains, providing a thorough risk assessment framework that stakeholders can utilize to anticipate and mitigate potential issues. In addressing the increasing complexity of grid interconnections, the report highlights the importance of Cyber-Informed Engineering (CIE). By embedding engineering controls and cybersecurity measures into the early stages of system design, this approach aims to fortify grid infrastructure against emerging cyber threats. The analysis includes an exploration of best practices and strategies for integrating CIE principles to enhance grid security and resilience. To provide practical insights, the report conducts a detailed consequence analysis of various grid services and cyber mitigations that can be applied through the interconnection process. This analysis evaluates the potential impacts of different failure modes and vulnerabilities, offering a clear understanding of the consequences that could arise from disruptions within the energy grid. The findings are further enriched by a series of case studies that illustrate real-world scenarios and lessons learned from past incidents. Through this comprehensive examination of grid services and their criticality, the report aims to prepare industry professionals with the knowledge and tools necessary to navigate the complexities of modern energy systems. By providing a comprehensive approach that includes risk assessment, cybersecurity, and consequence analysis, solar stakeholders can more effectively guarantee the reliability, efficiency, and security of the energy grid.

14 SOLAR ENERGY↗

NASA Blue Team: Determining Operational Security Posture of Critical Systems and Networks

Emergence of Cybersecurity has increased the focus on security risks to Information Technology (IT) assets going beyond traditional Information Assurance (IA) concerns: More sophisticated threats have emerged from increasing sources as advanced hacker tools and techniques have emerged and proliferated to broaden the attack surface available across globally interconnected networks.

cybersecurity↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

ARCADE Technical Pathway and Industry Impact

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) simplifies the evaluation and assessment of robustness factor and cyber resilience that support secure-by-design for advanced reactor nuclear power plants. In this manner, ARCADE supports risk-informed performance based (RIPB) evaluations of cybersecurity through its integration of plant physics with high-fidelity emulations of control systems. This cross domain approach enables comprehensive analysis of control system sensitivities, cyber-attack scenarios, and their consequences. ARCADE has been custom developed to meet the demands identified in Tier 1 of the Tiered Cyber Analysis (TCA) as outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors.

97 MATHEMATICS AND COMPUTING↗

Advanced Research on Integrated Energy Systems (ARIES) Cyber Range Overview and Threat-to-Consequence Demonstration

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. The threat-to-consequence demonstration showcases NREL's capability to model, simulate, test, and evaluate cyberattacks targeting energy systems that coincide with natural hazards, as well as the ramifications for the energy grid as a whole.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Risk Analysis for Remote Operation of Microreactors

Microreactors are a subset of advanced nuclear reactors that can be factory fabricated, transportable, and self-regulating. They have the potential to be used in microgrids, rural and remote areas, or emergency response applications, replacing fossil fuel sources like diesel generators and enabling sustainable energy generation. In order to make microreactor operation cost-effective, it is likely that remote communications will be needed to reduce the number of personnel required to be on site. While remote operation of energy generation and other industrial control systems is common in other industries, it is not yet adopted in the nuclear community and has many perceived and actual risks. In this paper, the severity of the risks introduced by remote operations for microreactors are explored. The primary changes in the operations involve the addition of a remote communications network and a certification system for data and controls. These changes lend themselves to considerations of cyber risks, whether unintentional or adversarial, but the assessment considers not just cyber risks introduced, but also how physical and human factors-based risks will impact the remote operations system and change the overall risk profile. This initial assessment indicates that there are standard cyber and mitigation measures that can be put in place so the risk of doing remote operations does not dramatically increase compared to local operations. This evaluation is a critical step in the process of evaluating if remote operations of microreactors is a suitable solution to meet future sustainable grid needs

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Reverse Engineering of Medical Devices for Innovation and Advancement in Healthcare

Medical cybersecurity research addresses the critical intersection of healthcare and digital security. As medical devices expand and become increasingly interconnected, the healthcare sector is poised to become a primary target for cyber warfare. This project aims to mitigate the risks associated with a field that often underestimates the importance of cybersecurity.

Baldwin, David↗

Residential Vehicle-to-Home Backup Power Capabilities: Key Findings from a ComEd Beneficial Electrification R&D Pilot

This report summarizes key findings from a collaborative technical study of residential, non-grid-tied vehicle-to-home (V2H) backup power systems in Commonwealth Edison’s (ComEd’s) service territory. The work integrates (1) a feeder-level technoeconomic analysis (TEA) using historical outage-event data and simulated electric-vehicle (EV) driving/charging profiles to estimate potential reliability and customer interruption-cost impacts under V2H and vehicle-to-grid (V2G) adoption scenarios; (2) controlled laboratory performance testing of a representative V2H backup ecosystem to characterize transfer-to-backup behavior, sustained power delivery, efficiency trends, and repeatable reliability limitations; and (3) a cybersecurity assessment aligned with NIST Cybersecurity Framework (CSF) 2.0 and ISO/SAE 21434 to evaluate interface-level risk drivers and identify program-relevant mitigations. Results indicate that V2H can provide measurable resilience value, but outcomes are strongly context dependent on outage patterns and the share of events that are “V2H-applicable.” Typical transfer-to-backup behavior clustered on the order of minutes, but rare long-delay edge cases were observed (including an event approaching 30 minutes) and should be treated as a reliability risk. High-power testing showed that peak-rated output is not necessarily continuously deliverable; stable operation may require operation below nameplate ratings and attention to thermal and installation constraints. The cybersecurity assessment highlights a broad attack surface spanning commissioning, home networks, embedded services, and cloud/OTA pathways, motivating minimum controls for secure onboarding, signed updates, patch cadence, and coordinated vulnerability response for any scaled deployment.

24 POWER TRANSMISSION AND DISTRIBUTION↗

V-INT: Automated Vulnerability Intelligence and Risk Assessment

The project team, including the University of Arkansas (UA) as the lead, the University of Arkansas at Little Rock (UALR), Network Perception (NP), and Bastazo, has successfully researched, developed, and demonstrated the V-INT toolset, and also integrated it into the commercial products of NP (i.e., NP-View) and Bastazo (i.e., Spartan). The end product is a cybersecurity software tool for energy utilities that can automatically assess the risks of software vulnerabilities in an organization’s assets considering the organization’s firewall policies. It allows security operators to identify the small portion of vulnerabilities that poses true threats to their system (i.e., those that are not protected by firewall policies) and prioritize the mitigation of these vulnerabilities to minimize risks. It also allows security operators to identify the vulnerability-induced attack paths under their organization’s firewall policy, providing effective decision supports for mitigating potential attacks.

97 MATHEMATICS AND COMPUTING↗