Search NASA⌕ Search

SEARCH · Search NASA

Results for “Cybersecurity Risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Cybersecurity Standards for Distributed Energy Resources: Gaps and Harmonization Strategy

This report examines cybersecurity standards for Distributed Energy Resources (DERs) in light of their rapid growth and increasing integration into energy systems. It identifies critical gaps in existing frameworks, including inadequate coverage of DER-specific challenges, complexities in implementing comprehensive standards, integration issues with legacy systems, adoption hurdles for newer standards, and a lack of harmonization across regulatory landscapes. The analysis highlights vulnerabilities such as data integrity risks, unauthorized device control, and denial-of-service attacks across various DER technologies like solar PV, wind turbines, energy storage systems, and hydrogen fuel cells. The report proposes a harmonization strategy to address these deficiencies by developing unified cybersecurity requirements, certification programs, and training resources while fostering collaboration among stakeholders such as government agencies, industry groups, DER operators, manufacturers, and research institutions. A phased roadmap is outlined to refine and implement these measures through pilot testing and widespread adoption. Ultimately, the report underscores the urgent need for coordinated efforts to enhance DER cybersecurity and ensure the reliable operation of future energy systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

CIE Curriculum Guide (V.2.0)

The Cyber-Informed Engineering (CIE) Curriculum Guide offers a comprehensive framework, guidance, and resources for integrating CIE into university-level engineering programs and related educational activities. The primary goal is to help educators adopt CIE principles into their teaching to produce future engineers and technicians who understand digital risks in modern engineered systems, thereby addressing the nation’s infrastructure resilience needs. This guide outlines practical integration examples, links to resources to accelerate CIE adoption, and shares insights from partner academic institutions on various implementation strategies. CIE is a framework for embedding engineered controls that mitigate the impact of cyber-attacks in any cyber-physical system used in critical energy infrastructure and other sectors. Developed by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), the National Cyber-Informed Engineering Strategy emphasizes embedding CIE into formal education, training, and credentialing. This guide supports this strategic objective by providing examples of integrating CIE concepts into engineering curricula, from class activities to new courses and certificate programs. The importance of educating cyber-informed engineers is underscored by the evolving cybersecurity threats facing engineered systems. As industrial control systems (ICS) increasingly incorporate digital technologies, the responsibility for security extends to both cyber professionals and engineers. CIE addresses critical gaps in designing and protecting physical systems with digital components against cyber risks, ensuring engineers consider digital risk throughout the engineering design lifecycle. Currently, engineering education does not routinely include cyber-informed principles, highlighting a gap in addressing modern engineering system risks. This guide advocates for updating engineering curricula to include digital risk management as a fundamental element. By doing so, future engineers will be equipped to design resilient systems that mitigate digital risks from the outset. Through this guide, engineering faculty can integrate CIE into their curricula, bridging the gap between digital risk and engineering. This approach prepares a cyber-informed workforce capable of safeguarding the cyber-physical systems crucial to national security and public welfare. By embedding CIE into education and training, institutions can produce engineers and technicians who can effectively mitigate cyber impacts throughout the engineering design lifecycle, resulting in more secure critical infrastructures.

42 - ENGINEERING↗

Clean Energy Cybersecurity Accelerator: Cohort 2 - runZero Public Report

The U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) sponsors the Clean Energy Cybersecurity Accelerator™ (CECA) to expedite the deployment of emerging security technologies that address the most urgent security concerns facing modern and future electric grids. CECA Cohort 2 assessed solutions focused on hidden risks due to incomplete system visibility and device security and configuration. Improving visibility can be achieved through operational technology (OT) asset identification solutions, including capabilities like automatic discovery, vulnerability reporting, and configuration monitoring. Solutions that monitor and identify assets in information technology (IT) networks in other domains are widely used; however, there is far less adoption of monitoring solutions for operational technology environments. Wider adoption may increase with increased confidence in the ability for these solutions to understand and respond to the specific requirements of OT environments. CECA Cohort 2 evaluated the active and passive asset discovery capabilities of market-ready solutions, documented and analyzed results, and identified gaps in functionality or capabilities. This report and describes how these results can help advance the adoption of these and similar solutions in the electric sector.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Evaluating Methods of Software Bill of Materials Generation to Enhance Nuclear Power Plant Cybersecurity

Instrumentation and control (I&C) systems in nuclear power plants (NPPs) are potential targets of cyberattacks and can prove deleterious for the safety of the NPPs. A Software Bill of Materials (SBOM) provides a detailed list of the various components and their dependencies in software, which helps in vulnerability and risk assessment for cyber hygiene and situational awareness. For an NPP, the process of generating an accurate SBOM report can be complex due to the legacy systems and firmware binaries involved. While most current SBOM tools are focused more on modern internet technology software, this research provides insights and guidelines for an NPP to generate an accurate and efficient SBOM. Here, the paper proposes a new methodology to help NPPs categorize software and use appropriate tools to generate SBOMs for their digital I&C systems.

SBOM↗

Clean Energy Cybersecurity Accelerator: Cohort 2 - Asimily Public Report

The U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) sponsors the Clean Energy Cybersecurity Accelerator (TM) (CECA) to expedite the deployment of emerging security technologies that address the most urgent security concerns facing modern and future electric grids. CECA Cohort 2 assessed solutions focused on hidden risks due to incomplete system visibility and device security and configuration. Improving visibility can be achieved through operational technology (OT) asset identification solutions, including capabilities like automatic discovery, vulnerability reporting, and configuration monitoring. Solutions that monitor and identify assets in information technology (IT) networks in other domains are widely used; however, there is far less adoption of monitoring solutions for operational technology environments. Wider adoption may increase with increased confidence in the ability for these solutions to understand and respond to the specific requirements of OT environments. CECA Cohort 2 evaluated the active and passive asset discovery capabilities of market-ready solutions, documented and analyzed results, and identified gaps in functionality or capabilities. This report and describes how these results can help advance the adoption of these and similar solutions in the electric sector.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Integrating a Microgrid Controller with a Local OpenADR Server

When military microgrids isolate themselves from the main electrical grid, they must locally balance electricity supply and demand. Since local generation may be limited, the current strategy is to shed all but the most critical loads by tripping smart circuit breakers, which must then be reset manually (e.g., ESTCP project EW-201350). This strategy is typically applied at the building level, meaning that entire buildings housing mission critical activities must be excluded from any load management, while those considered non-critical may lose service entirely. The remotely controlled switchgear needed to manage load in this way is very expensive ($\$30,000$-$\$50,000$ per building). While effective at shedding load, this strategy disrupts installation operation and risks damaging equipment during both disconnection and re-energization. With the goals of lowering costs, protecting equipment, and enhancing the agility of DoD microgrids, this report demonstrates the use of cybersecure automated demand response (ADR) technology to manage microgrid loads during grid-independent (a.k.a. "islanded") operation. This automated approach achieves load shedding and shifting through communication signals sent to equipment controllers rather than by cutting off the flow of electricity within the microgrid itself. Because it operates only on the base network, with no connection to external entities, this strategy avoids the main cybersecurity concern raised by past applications of ADR on military bases.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CIE Analysis Process for Engineered Systems

"CIE Analysis Process for Engineered Systems" outlines a comprehensive methodology for integrating Cyber-Informed Engineering (CIE) principles into both new and existing engineered systems. Sponsored by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER), the process aims to achieve cyber-informed decisions by producing functional security requirements for new systems and retrofitting existing systems to mitigate digital risks. The document details a step-by-step approach, including mission and function definition, digital asset awareness, consequence analysis, and mitigation analysis. It emphasizes the importance of documenting mechanical, electrical, programmable, and network components to protect system functions and provides examples and considerations for each step. The ultimate goal is to ensure that engineered systems remain resilient against cyber threats, maintaining safety, performance, and reliability.

42 - ENGINEERING↗

The Design and Evaluation of Zero Trust Architecture for Electric Vehicle Charging Infrastructure: EVs @ Scale Series on EV Charging Station Cybersecurity

Implementing a zero trust architecture can significantly bolster the security of electric vehicle (EV) charging infrastructure. EV charging infrastructure includes numerous networked interfaces, each of which can present potential vulnerabilities. When these vulnerabilities are exploited, they can compromise the entire system, leading to severe operational and security risks. Zero trust is a security model that operates on the principle of "never trust, always verify," which helps manage the attack surface and limit the scope of any potential compromises. Fundamentally, this model ensures that no entity, whether inside or outside the network, is trusted by default. The design principles of zero trust include continuous verification, strict deny-by-default access controls, and micro-segmentation. Continuous verification ensures that every request is thoroughly checked, regardless of its origin. Strict access controls enforce the principle of least privilege, allowing users and devices only the minimum necessary access to perform their functions. Micro-segmentation involves dividing the network into smaller, isolated segments to prevent lateral movement in case of a breach. In the context of EV charging infrastructure, zero trust can be implemented through various strategies. For example, multi-factor authentication (MFA) can be required for engineers to access the management interfaces and control systems of charging stations. Real-time monitoring and analysis of network traffic can help detect and respond to anomalies. Systems that do not need to communicate with each other can be micro-segmented to enhance security. All communications should adhere to predefined policies to be permitted. Additionally, encrypting communications can protect sensitive information exchanged between chargers and management systems. This paper presents a zero trust architecture specifically designed for EV charging infrastructure. Implementing zero trust not only mitigates risks but also builds a resilient infrastructure capable of withstanding and quickly recovering from cyber threats. The architecture addresses six defined security objectives. A comprehensive test plan is developed to assess the architecture against these objectives, and the results of the evaluation are reported. This approach is essential for maintaining the reliability and integrity of EV charging services in an increasingly interconnected and vulnerable digital landscape. This is the first in a planned series of papers exploring the implementation of zero trust in EV charging infrastructure. Each paper will delve into different aspects and applications of zero trust, highlighting how various work processes and requirements can lead to distinct architectural designs. These architectures will be tailored to address specific security challenges and operational needs within the EV charging ecosystem, ensuring a robust and adaptable security framework.

33 ADVANCED PROPULSION SYSTEMS↗

Grid Communications: Digital Assurance and Supply Chain Challenges and Emerging Regulation Session Two

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem. This is Session 2 of 3 (Full Version).

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Grid Communications: Cybersecurity and Supply Chain Challenges and Emerging Regulation Session Three

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem. This is Session 3 of 3 (Full Version).

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Grid Communications Supply Chain & Emerging Regulation Challenges Session 1

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem.

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

DER Cybersecurity Standards: Assessment and Gap Analysis

The purpose of this report is to share the comprehensive gap analysis of existing cybersecurity standards applicable to Distributed Energy Resources (DERs) within the electric power sector. This analysis aims to identify critical deficiencies in current standards, assess their alignment with industry needs, and provide actionable recommendations for enhancing cybersecurity measures. The scope encompasses various DER technologies, including solar, wind, energy storage, and hydrogen fuel cells, and emphasizes the significance of establishing robust cybersecurity frameworks and standards to safeguard these increasingly integrated systems. The report provides valuable insights for stakeholders in the DER ecosystem, including manufacturers, utilities, and regulators. It underscores the importance of continued development and refinement of cybersecurity standards to keep up with the technical advances in DERs and associated cybersecurity challenges. The analysis evaluated IEC, IEEE, ISA, ISO, and UL standards relevant to DER cybersecurity. Standards were assessed on their coverage of key requirements including data availability, integrity, confidentiality, access control, authentication, encryption, and system hardening. For each standard, the analysis assessed its alignment with current industry practices, regulatory compliance, effectiveness in addressing known risks, coverage of emerging risks, and how it promotes interoperability. The evaluation also considered potential integration challenges and barriers to adoption.

97 MATHEMATICS AND COMPUTING↗

Risks to the DOW Mission From Global Advanced Energy Adoption

Advanced energy technologies have the potential to enhance energy security and resilience; however, they can introduce new vulnerabilities even as they mitigate existing ones. This dichotomy highlights that both action and inaction carry strategic risks in a contested and logistically complex operating environment. Regardless of U.S. civilian or military adoption of such technologies, key allies and adversaries are on adoption paths that will impact the U.S. military at the tactical, operational, and strategic level. The global adoption of advanced energy technologies presents the potential for both positive and negative consequences for U.S. Department of Defense (DOD) missions in the next 10-20 years. Three categories of risk drivers are presented in this analysis: infrastructure-related, adoption-related, and response-related. Each risk type can generate consequences for DOD, including power disruptions, suboptimal DOD mission performance and operational effectiveness, higher costs and shortages for both legacy and advanced energy technologies, and loss of U.S. influence and strategic deterrent value. Specific impacts could include tactical impacts, operational impacts, and strategic impacts. Mitigation strategies could include energy resource and technology planning, cybersecurity, supply chain resilience, workforce development, exercises and simulations, investments in commercialized technology, operational testing and pilot programs, research into emerging technologies, partnerships and working groups, common standards, budget planning, and repurposing infrastructure.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Nine Canyon Long-Duration Energy Storage: A Feasibility Study

The Nine Canyon Long Duration Energy Storage (LDES) Feasibility Study explores the technical and economic viability of deploying advanced energy storage technologies at Energy Northwest's (EN) Nine Canyon (9C) Wind Project site in Benton County, Washington. Supported by the Washington State Department of Commerce and the U.S. Department of Energy’s Office of Electricity under its LDES Voucher Program, the study represents a collaborative effort between EN, Pacific Northwest National Laboratory (PNNL), and ARES North America. At the core of this effort is the development of a generalized techno-economic modeling framework and evaluation tool designed to assess the value proposition of LDES projects across a variety of contexts. The modeling tool is technology-agnostic and accommodates user-defined parameters such as rated power, energy duration, round-trip efficiency, capital and operational costs, and dispatch constraints. It also integrates economic inputs, including market prices, energy revenue structures, and financing parameters to evaluate performance through key metrics. The tool provides utilities with a transparent, adaptable platform to support decision-making, investment prioritization, and portfolio planning for various storage technologies. To guide scenario design and interpretation, the study first surveyed the LDES technology landscape, including lithium-ion batteries, flow batteries, non-hydro gravity storage, and thermo-mechanical systems, comparing cost trajectories, technical performance, safety and hazards, materials sourcing and recyclability, and spatial/siting considerations. This literature-grounded review highlights technology trade-offs and reinforces the need to align technology choice with site characteristics, use cases, and project objectives. A companion chapter examines ownership structures (EN ownership, third-party ownership, shared models) and offtake options (energy marketing, capacity/energy PPAs, time-of-use PPAs, block-delivery PPAs, and tolling), where PPAs (power purchase agreements) represent contractual arrangements for buying and selling electricity. The chapter also highlights implications for risk allocation, capital access, operational control, and revenue certainty. The study also evaluates supervisory control and data acquisition (SCADA) and transmission interconnection pathways, options include upgrading the existing SCADA or deploying a dedicated LDES controller, with attention to protection schemes, data telemetry, cybersecurity, and regulatory coordination with BPA. In addition, an ARES-specific geotechnical and hydrology assessment presented in the appendix screens multiple corridors for slope stability, bearing capacity, cut-and-fill magnitude, and stormwater behavior.

25 ENERGY STORAGE↗

Reference Architecture Discussion [Slides]

NREL is developing reference architectures - industry-validated and verified models - to provide a common operational view and emulation environment for analyzing risk to the energy sector. In this presentation, we overview our work in developing these architectures.

97 MATHEMATICS AND COMPUTING↗

Engineering Out Industry 4.0 Cyber Risk Presentation for EnCyCriS

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

99 GENERAL AND MISCELLANEOUS↗

Digital Assurance Checklist for Homeowners and Installers

This document provides a comprehensive Digital Assurance Checklist for securing behind-the-meter energy assets, focusing on both installers and homeowners. As distributed energy resources (DERs) such as solar PV and battery storage become integral to residential energy systems, cybersecurity emerges as a critical component of reliability and safety. The guide outlines actionable steps for installers during pre-installation, commissioning, and post-installation phases, emphasizing practices like network segmentation, credential management, firmware validation, and homeowner education. For homeowners, the document introduces a tiered approach to cyber hygiene—from essential measures like strong Wi-Fi credentials and automatic updates to advanced strategies such as network segmentation, DNS filtering, and intrusion detection. By adopting these practices, stakeholders can mitigate cyber risks, safeguard energy infrastructure, and ensure resilient, secure operation of DER systems. Additional resources and references to industry standards are included to support implementation.

99 - GENERAL AND MISCELLANEOUS↗

Digital Assurance Checklist for Homeowners and Installers

This document provides a comprehensive Digital Assurance Checklist for securing behind-the-meter energy assets, focusing on both installers and homeowners. As distributed energy resources (DERs) such as solar PV and battery storage become integral to residential energy systems, cybersecurity emerges as a critical component of reliability and safety. The guide outlines actionable steps for installers during pre-installation, commissioning, and post-installation phases, emphasizing practices like network segmentation, credential management, firmware validation, and homeowner education. For homeowners, the document introduces a tiered approach to cyber hygiene—from essential measures like strong Wi-Fi credentials and automatic updates to advanced strategies such as network segmentation, DNS filtering, and intrusion detection. By adopting these practices, stakeholders can mitigate cyber risks, safeguard energy infrastructure, and ensure resilient, secure operation of DER systems. Additional resources and references to industry standards are included to support implementation.

99 - GENERAL AND MISCELLANEOUS↗