Search NASA⌕ Search

SEARCH · Search NASA

Results for “Vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Integration of equitable resilience metrics into climate-informed electric utility planning processes: phase one

Working together, Sandia National Laboratories, Southern California Edison (SCE) - an Investor-Owned Utility (IOU) - and the California Public Utilities Commission (CPUC) are studying how electric utilities can use equity and resilience metrics to help inform the prioritization and sequencing of resilience-driven infrastructure investments. To this end, this project evaluated “Social Burden,” an equitable resilience metric which measures the potential impact of disruptions in access to non-electric critical services on people and estimates community resilience to these disruptions. The Social Burden was expanded to incorporate SCE’s existing equity metric and applied to evaluate the potential impacts from a range of climate-informed hypothetical outage scenarios developed under SCE’s 2022 Climate Adaptation Vulnerability Assessment. One baseline (“blue-sky”) state and eight different outage scenarios were evaluated to measure the potential impacts of the outages on non-electric infrastructure, critical services, and people. Key findings include: 1) the Social Burden framework is flexible enough to adapt to and build upon existing utility equity and/or resilience metrics, 2) Social Burden results highlight the high degree of non-electric service redundancy within the SCE service area with most (6/8) hypothetical outage scenarios predicted to increase people’s Social Burden by less than 10%; however, 3) access to critical services and people’s ability to obtain them is unequal and spatially clustered, meaning that there are some hypothetical outage scenarios (2/8) that will exert a higher toll on communities directly experiencing the outage as well as some nearby communities with pre-existing vulnerabilities. The report concludes with recommendations for potential use cases of the expanded Social Burden metric and identifies priority follow-on work. Potential use cases may include incorporating equity into IOU’s prioritization of climate resilience investments. Additionally, Social Burden analysis may provide additional data and insights to augment grid planning, potentially by identifying additional needs and/or prioritizing previously identified needs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Assessing Historical Extreme Weather Event Impacts

Resilience planning, particularly energy and water resilience planning, has been a key priority for the federal government for many years, leading federal agencies to develop processes for identifying and addressing critical resilience gaps at their facilities and sites. Furthermore, recent federal policy is driving agencies to prioritize climate change impacts as a more central component of their resilience planning efforts. To achieve this, federal sites must understand their vulnerability to climate change, which involves identifying climate hazards projected to impact the site (known as exposure), as well as understanding the sensitivity (the degree to which a site, including its people and the things they value, could be harmed by that exposure), and adaptive capacity of the site (the degree to which the site could lessen bathe potential for harm by taking action to reduce exposure and sensitivity). To assess and understand sensitivity and adaptive capacity, it is important to first obtain a baseline and understand how a site has been impacted by past events, in addition to considering the potential for unprecedented impacts based on climate projections. This information paper highlights current limitations for developing event history assessments and suggests a framework for more consistently capturing key data points. The purpose of this paper is to help inform how organizations could begin structuring a comprehensive process for recording the impacts of extreme weather events in order to facilitate climate vulnerability assessments, and thus, resilience planning.

54 ENVIRONMENTAL SCIENCES↗

The Essence of Cryptol: A Denotational Cryptol Interpreter in Coq for Foundational Assurances for Quantum Resistant Cryptosystems

Systems of the utmost consequence need a means to establish authenticity of software and data. Cryptosystems implement authentication, but can be vulnerable to cryptographic and implementation attacks. With the threat of quantum cryptographic attacks, “post-quantum” cryptosystems (PQCs) must be henceforth used in these systems. However, the new cryptography needs new ways to, rigorously and machine-checkably, prove systems free of vulnerabilities. We propose a retargetable capability to rapidly instantiate proven correct postquantum cryptosystems through novel proof-carrying synthesis and proof-automation technique, extending those proven successful on existing systems. This capability is crucial to meeting the cryptographic requirements for future high-consequence systems. Since specifications for high consequence cryptography are presently captured in a domain specific language known as Cryptol. While this can enable convenient fully automated reasoning about Cryptol specificaitons and implementations via the Software Analysis Workbench (SAW), Cryptol has expressivity gaps, so that cryptosystems with probabilistic programming features like Falcon cannot be fully expressed in the language. Moreover, SAW’s automation fails for programs and specificaitons with inductive and recursive structure, as in the Sphincs+ PQC. Finally, Cryptol and SAW together represent some 200,000 lines of unverified Haskell, so that the any guarantees about high consequence cryptography are presently contingent on a large, unverified, yet trusted computing base. The first step of the larger project of agile, assured crpytography is therefore to provide a formal, mechanized semantics for Cryptol, so that the specifications expressed by cryptographers in Cryptol can be reasoned about and compiled into performant implementations with a foundational, machine checkable certificate of correctness. This report describes our work on this first step, culminating in the design of a certified denotational interpreter, in Coq, for core Cryptol.

97 MATHEMATICS AND COMPUTING↗

Bridging the Gap on Data, Metrics, and Analyses for Grid Resilience to Weather Events: Information that utilities can provide regulators, state energy offices, and other stakeholders

A growing number of states require regulated utilities to file resilience plans to improve the electric grid’s ability to anticipate, withstand, adapt to and recover from increasingly severe weather events. This report aims to help state regulators identify and request data, metrics, and analyses from utilities and use it in decisions on utility resilience plans and investments. The report reviews state requirements and utility plans focused on overall grid resilience, climate change resilience and vulnerabilities, infrastructure modernization, storm protection, and wildfire mitigation. It details types of data, metrics, and analyses across five categories--and provides examples of each from the utility plans. The first category is vulnerability assessments, or evaluations of the susceptibility of systems, communities, or assets to potential harm from identified hazards. The second is data on hazards and the exposure of utility assets and customers to these hazards. The third is attribute metrics, or system characteristics that contribute to or describe the resilience of a system. The fourth is performance metrics, which are impacts of resilience investments on system performance--typically a reduction of negative impacts from hazard events. Finally, evaluation and prioritization are analyses that utilities conduct to estimate impacts from resilience measures (evaluation) and prioritize measures based on costs and estimated impacts (prioritization). The report concludes with examples of key trends and emerging best practices for states and utilities, and identifies areas for further research.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Unraveling the Noise: An Investigation Plan for Signal Interference in Hearing Aids

Bluetooth Low Energy (BLE) has revolutionized the performance of hearing aids with functionalities like seamless audio streaming and enhanced auditory functions. However, BLE operates within the highly congested 2.4 GHz frequency band, making it susceptible to signal interference that can degrade performance, reduce audio quality, and impact user experience. This paper documents interference patterns in BLE communication and introduces practical mitigation techniques aimed at improving the reliability of hearing aids. Attack vectors associated with Bluetooth enabled hearing aids include communication jamming, the interception of data between target devices, and GATT handle exploitation. Attackers could also use the vulnerabilities to block communications or intercept sensitive audio streams, posing significant security and privacy risks. These threats compromise two critical components of the CIA triad: (1) availability, by causing persistent connectivity issues, and (2) integrity, by enabling unauthorized data modifications. It is necessary to deal with these problems to ensure hearing aids work well and safely. This study investigates the impact of BLE signal interference on hearing aids, using tools such as HackRF [1], a Python tool to simulate interference scenarios, and Ubertooth [2] to sniff Bluetooth traffic between hearing aids and the device with the application. This paper investigates testing of BLE traffic in search of specific interference patterns that would impact the functionality of hearing aids, including jamming and flooding. This research focuses on developing robust mitigation techniques with the aim of securing BLE-enabled hearing aids against those vulnerabilities.

Baldwin, David [Savannah River National Laboratory↗

An assessment of the global cooling supply chain and implications for critical minerals

The global room air conditioner (AC) industry has undergone rapid growth, and the U.S. and India now face new supply chain risks due to China’s dominant role in manufacturing and driving demand. As India’s room AC market and related electricity consumption increases with continued economic development, it faces dual challenges of supply chain vulnerabilities and power grid blackouts from higher peak loads. To mitigate supply chain vulnerabilities for high-efficiency cooling equipment and critical mineral inputs to AC components, there is an increasing need to diversify the supply chain and address energy security and peak load risks to both the U.S. and India. This report assesses the potential for diversifying supply chains and scaling up manufacturing of highly efficient cooling equipment technologies and related critical mineral inputs in the U.S. and India. Successful cooperation on these technologies will enable the U.S., India, and their Quadrilateral Security Dialogue (Quad) partners to diversify AC supply chains while meeting India’s large and growing demand for efficient cooling. In the similarly concentrated supply chain for critical minerals, the U.S. and India can work with Japan and Australia to leverage each country’s strengths in diversifying mining, processing, and refining while pursuing alternatives to materials with high supply chain risks and supporting increased recycling and circular economy approaches.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

A Real-Time Testbed for Smart Inverter Cyber Security Studies

Distributed energy resources (DER) have become a popular solution to modern-day issues surrounding the efficiency and reliability of power generation, as well as climate change concerns. Energy centers are shifting towards incorporating smart inverters with embedded functionalities such as high voltage ride through (HVRT), low voltage ride through (LVRT), active and reactive power compensation. However, the integration of smart inverters leave DER systems highly vulnerable to cybersecurity threats. The distributed network protocol 3 (DNP3) is a common method of communication between grid-tied hardware. Despite its popularity, the level of security leaves all hardware connected to the grid at risk of severe cyber-attacks. Thus, it is important to study any potential cybersecurity threats towards grid-tied smart inverters to mitigate cybersecurity vulnerabilities and refine existing cyber-security protections. This report describes the proposed testbed design to study cybersecurity threats to smart inverters. The testbed utilizes a real-time simulation case in RSCAD that includes a grid-tied wind turbine (WT) topology featuring two back-to-back two-level voltage source converters (BTB,2L-VSCs) and a permanent magnet synchronous machine (PMSM). The simulated case runs within the NovaCor real time digital simulator (RTDS). This report focuses on the design and implementation of a single module of the GTNETx2 card as a distributed network protocol and the configuration of an IEEE 1518 DNP database file that includes input and output variables mapped to different connection points in the grid that transmit and receive discrete, analog, and binary signals on command. This allows realistic emulation of the communication between the smart inverter and the grid for cybersecurity studies.

97 MATHEMATICS AND COMPUTING↗

How Quantum Sensing Will Help Solve GPS Denial in Warfare

The U.S. military’s ability to posture, deter, and prevail in future conflicts may rest on the quantum sensing position, navigation, and timing (PNT) capabilities that are currently being developed. Heavy reliance on GPS signals for PNT has become a critical vulnerability for the U.S. military. Meanwhile, the conflict in Ukraine has demonstrated that GPS denial and electronic warfare (EW) is now a key component of modern combat and satellite-guided munitions are reportedly being rendered ineffective. The Department of Defense (DOD) is focusing on upgrading GPS to use stronger, military-specific signals, which will still be vulnerable to EW and anti-satellite capabilities. A more diverse and resilient alternate-PNT strategy is needed to ensure mission success.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Reverse Engineering of Medical Devices for Innovation and Advancement in Healthcare

• Medical technology is rapidly evolving and introducing new functionality and methodologies that suggest a higher risk for common vulnerability exposures (CVE) • Introduction of functionalities like Wi-Fi, Bluetooth, and internet connectivity require devices to be rigorously evaluated for vulnerabilities • Subsequently like many other fields cell-phone interconnectivity suggests a significantly higher level of risk to critical infrastructure and data security

Baldwin, David [Savannah River National Laboratory↗

Deploying Adversarial Attacks in Super-Resolution Models

Reliable super-resolution methods are crucial for applications like remote sensing, grid resilience and disaster impact analysis, and standoff biometrics. These methods infuse additional high-frequency information into reconstructions, allowing for better contextualization and image intelligence. However, super-resolution models can also introduce hallucinations or other unseen vulnerabilities that could be exploited by an adversary. This is further compounded by the prominence of deep learning in these models, as models are often blindly applied on out-of-distribution images. In this work, we implement adversarial attacks in common open-source super-resolution models and examine their impact on reconstructions and downstream classification tasks. We find that an adversarially trained super-resolution model can produce high-quality reconstructions that degrade downstream classifications. Moreover, these attacks do not require access to low-resolution imagery or class labels at inference time. These results demonstrate the vulnerability of super-resolution methods to malicious actors and motivates the development of a detector for super-resolution adversarial attacks. Further exploration of adversarial attacks in this domain is required to ensure trustworthiness and robustness of super-resolution models for national security applications.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Enhancing Power Resilience for Remote Communities: A Comprehensive Renewable Energy Solution for Itbayat Island

The island of Itbayat, Philippines, faces significant challenges in maintaining a reliable and resilient power supply due to its current reliance on a vulnerable power distribution system managed by a local electric cooperative. The existing infrastructure, which includes diesel generators and a radial network configuration with some above-ground lines, is highly susceptible to frequent typhoons and adverse weather conditions. These factors, combined with inadequate staffing and high operational costs, result in frequent power outages that disrupt daily life and hinder economic development. This white paper proposes a comprehensive solution to enhance the resilience and reliability of Itbayat's power system by integrating renewable energy sources, specifically solar photovoltaic (PV) systems, battery storage, and a microgrid controller. The proposed solution aims to reduce dependency on diesel fuel, optimize energy use, and provide a sustainable and robust power supply for the island. Key components of the solution include: 1. Solar PV Installation: Deploying solar PV panels to harness abundant solar energy, reducing reliance on diesel fuel. 2. Battery Storage Systems: Installing battery storage to store excess solar energy and ensure a continuous power supply during low solar generation periods. 3. Microgrid Controller: Implementing a microgrid controller to manage and optimize the integration of solar PV, battery storage, and existing diesel generators. The proposed solution addresses several critical issues, including system vulnerability, generator dependency, and operational inefficiencies. By adopting this innovative approach, Itbayat Island can achieve a more resilient, efficient, and sustainable energy infrastructure, ensuring a stable power supply for its residents and enhancing overall energy security.

14 SOLAR ENERGY↗

Strategic Energy Plan: City of Key West, Florida

This Strategic Energy Plan for the city of Key West, Florida—developed through the U.S. Department of Energy’s Energy Technology Innovation Partnership Project (ETIPP)—outlines a comprehensive strategy to advance the city’s energy vision: to improve energy efficiency and independence using local energy resources to foster long-term resilience. To guide this effort, the plan is structured around four focus areas: • Energy efficiency: Reduce overall energy consumption and utility costs across municipal, residential, and commercial buildings. • Local energy generation: Increase the share of energy produced from local sources to enhance energy independence. • Resilience: Strengthen critical infrastructure and community preparedness for flooding, hurricanes, and other natural weather hazards. • Electric transportation: Support the addition of new electric vehicles (EVs) and develop reliable charging infrastructure to reduce reliance on imported fuels. ETIPP provides strategic energy planning, technical assistance, and direct funding to U.S. coastal, remote, and island communities to improve energy resilience. Key West was part of ETIPP’s fourth cohort. As a low-lying island community vulnerable to infrastructure damage due to natural weather hazards, Key West seeks to reduce its dependence on external energy and build long-term sustainability. The Strategic Energy Plan identifies specific challenges, sets clear goals, and proposes actionable opportunities with implementation timelines and key stakeholders. A baseline assessment reveals significant energy consumption in both city-owned and residential/commercial buildings, limited local energy generation, and an early-stage EV market with vulnerable charging infrastructure. The proposed solutions emphasize a multifaceted approach, leveraging both established and innovative technologies, while addressing financial, technical, and community engagement challenges. The baseline assessment provided a snapshot of current energy conditions in Key West, evidencing key challenges and opportunities across the city’s energy priorities. Building on the baseline assessment and extensive input from city staff, local stakeholders, and community partners, a set of targeted opportunities was identified to address Key West’s energy goals. Each was evaluated in terms of its potential benefits, key implementation steps, associated challenges and mitigation strategies, and the city departments and stakeholders best positioned to lead or support progress.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

TASTI-GRID: a holistic view of Florida's grid resilience opportunities

In December of 2025, the American Society of Civil Engineers updated Florida’s infrastructure grade to a ”C+” – reflecting overall investments in recent years. With the recommendation to further strengthen the electric grid and establish consistent building standards, extreme weather, aging infrastructure, and population in-migration are still compounding Florida’s grid vulnerabilities. Key challenges related to hurricane and other tropical & marine weather events are not unique to Florida. However, the state’s topography, location, demographics, and variation among rural and urban centers for tourism and industry, demonstrate the need for unique approaches to advancing critical infrastructure resilience, particularly for large concentrations of elderly residents or in areas of historic underinvestment. Florida’s grid asset advancements are credited with a reduction in average power outage durations. Yet, improvements since 2021 have set the stage for future resilience activities – as modernization efforts have greatly improved data collection – enabling better understanding of vulnerabilities and trends across counties and localities (particularly in Central Florida).

24 POWER TRANSMISSION AND DISTRIBUTION↗

Advanced Reactor Designs Security Analysis, Risk, and Recommendations: Risks, Consequences, and Possible by-Design Mitigation Approaches Associated with Select Advanced Reactors

Next-generation advanced reactors (ARs) incorporate enhanced safety systems, have smaller source terms, and feature compact modular designs, which should lessen their collective risk profiles. However, to fully evaluate risk, security needs to be a part of the equation. Without taking security into consideration, safety systems and components in the new ARs may be vulnerable to sabotage. These base attributes, coupled with enhanced security features specific to AR design through sound engineering and security-by-design (SeBD), should provide developers and operators with lower inherent security risk profiles. Building security early into the AR design may remove or passively secure potential critical targets from an adversary’s reach , thereby increasing overall safety and security. An integrated approach and diverse design team that includes engineering, operations, and security experts are fundamental to building security into the design without sacrificing fundamental operational efficiencies and principles. The objective of this project was to evaluate the security and safety interfaces for five classes of reactors, identify potential security vulnerabilities of structures, systems, and components (SSC), and underscore the need to consider security alongside safety in the design o f these concepts. The five reactor classes evaluated in this project and presented in this report are molten-salt reactors (MSR), high temperature gas reactors (HTGR), sodium-fast reactors (SFR), advanced light-water reactors (ALWR), and microreactors. These designs were selected because they reflect the concepts that are closest to market deployment and have received significant resource investments from the public and private sector. This project assesses the inherent security risks posed by common classes of ARs, provides a methodology and framework to assess security along with safety, and offers an analysis of potential mitigation strategies that could be incorporated. For each AR technology, the SSCs that relate to radionuclide source safety functions are discussed to understand the SSC contribution to safety and relative importance in the protective strategy for the design. The assumptions that went into evaluating each reactor concept originated from generic publicly available nonproprietary information and should not directly be used to qualify an absolute risk profile nor to rank specific AR designs. Instead, the purpose of the analysis is to understand and compare the generic inherent security risks of different AR technologies.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Securing the Modern Grid: Federal Investments, Digitization, and Supply Chain Strategy

Across the United States (U.S.) grid expansion and modernization is underway, paving the way for accelerated load growth and intelligent resource management. Digitization of the grid is supported by several state and federal programs, providing support for utilities installing advanced metering infrastructure (AMI), AI-powered analytics systems, battery energy storage systems (BESS), and distributed energy resource management systems (DERMS) to transform the grid from a one-way power delivery system into an intelligent, responsive network that will enable faster load growth and power expansion of data centers for advanced artificial intelligence (AI) applications. The digital transformation of America's grid presents opportunity for increased efficiency and resiliency but also introduces new digital risks that require careful management. Digital equipment often contains several vulnerabilities such as unencrypted communication protocols, and persistent remote access capabilities that could be exploited to manipulate device settings, coordinate service disruptions, or inject false data into grid operations. These digital risks become particularly important as the grid must rapidly scale to support AI-driven data centers, which the administration has identified as essential for maintaining U.S. technological leadership and economic competitiveness. These vulnerabilities are compounded by supply chain realities: Chinese manufacturers currently produce 70-90% of essential grid components including inverters, batteries, and control systems, with the U.S. lacking domestic manufacturing capacity for critical assets like extra-high voltage transformers. Recent federal legislation has established Foreign Entity of Concern (FEOC) restrictions to address these risks, requiring projects to achieve escalating thresholds of non-FEOC content to receive tax credits while utilities work to expand sourcing channels for their supply chains and strengthen security measures. These restrictions arrive precisely when utilities face unprecedented electricity demand growth driven by the rapid growth in data centers, creating a considerable challenge: rapidly expanding infrastructure while navigating complex compliance requirements while lacking viable alternatives for many critical components. Idaho National Laboratory (INL) and its partners have developed practical approaches to help utilities navigate these intersecting challenges as they leverage federal investment to strengthen and grow the grid. These solutions include Cyber-Informed Engineering (CIE) principles that build resilience directly into systems, the Cirrus tool for secure cloud migration, and enhanced procurement guidance that embeds security requirements throughout equipment lifecycles. Federal initiatives, such as the Technical Assistance for Digital Assurance (TADA) project, provide direct support to utilities implementing these approaches while facilitating knowledge sharing across the industry. While these tools and frameworks cannot eliminate all risks inherent in foreign supply chain dependencies, they offer pragmatic pathways for strengthening security posture without sacrificing the deployment momentum essential to meeting surging electricity demand. Ultimately, securing America's digital energy infrastructure demands dedicated coordination across multiple fronts: building domestic supply chains, implementing robust digital assurance practices, and maintaining the aggressive modernization timeline necessary for reliability, resilience, and energy independence.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Utilizing Time Reversal Ultrasonics to Detect the Removal of Nuclear Materials from Geological Repositories (FY26 Mid-Year)

Detecting unauthorized nuclear material removal from storage environments, such as geological repositories, is a critical safeguards task essential to ensuring the integrity and non-diversion of nuclear materials. However, this process is fraught with significant technical challenges. Storage configurations often involve tightly packed nuclear material containers or obstructed environments, making detection of removal events exceedingly difficult. Optical surveillance cameras, which are commonly used for monitoring, suffer from substantial limitations, including restricted coverage, reliance on line-of-sight measurements, and vulnerability to environmental conditions in certain storage scenarios. As the global inventory of monitored nuclear materials increases and storage configurations become more complex— such as deep geological repositories, inaccessible storage vaults, and tightly packed containers—there is an urgent need for innovative detection technologies that can reliably identify unauthorized diversion events in these challenging environments. The challenge of detecting nuclear material removal in complex storage environments is both significant and urgent. Preventing unauthorized access, diversion, or tampering with nuclear materials is a cornerstone of global nuclear safeguards and nonproliferation efforts. Current detection methods are increasingly inadequate as storage configurations become more intricate and inaccessible. The limitations of existing technologies—such as their inability to detect changes behind obstructions, reliance on costly and labor-intensive processes, and vulnerability to environmental conditions—pose risks to the effectiveness of safeguards systems. Addressing this challenge is critical to maintaining international trust in nuclear safeguards frameworks and ensuring compliance with nonproliferation agreements. Our project builds on the proven concept of TRU technology that can address this unmet need. TRU has demonstrated exceptional spatial sensitivity and change detection capabilities in complex non-line-ofsight environments, making it uniquely suited for detecting unauthorized nuclear material removal in challenging storage configurations. Unlike optical methods, TRU is not limited by line-of-sight constraints or environmental conditions, enabling reliable detection of subtle alterations even behind obstructions. By leveraging TRU’s ability to identify removal or tampering events, we aim to develop a robust detection system that enhances safeguards in geological repositories, storage vaults, and other complex environments.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Advanced Reactor Safeguards & Security Program: Cybersecurity Scenarios

The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Data Center Cybersecurity, Supply Chain Risk Management, and Emerging Regulation Cohort Summary: Takeaways and Action Plans

This report summarizes the outcomes of the Data Center Cohort under the Department of Energy’s Technical Assistance for Digital Assurance (TADA) initiative, aimed at enhancing grid resilience through cybersecurity, supply chain risk management (SCRM), and Cyber-Informed Engineering (CIE). The cohort engaged 17 organizations across utilities, data center operators, vendors, and technology providers in three sessions combining presentations, discussions, and exercises. Key topics included AI-driven load behavior, cybersecurity vulnerabilities in UPS/BESS and cooling systems, governance gaps at utility–data center boundaries, and supply chain integrity. Five cross-cutting themes emerged: interconnection architecture vulnerabilities, fragmented governance, AI-driven stability risks, lack of regulatory frameworks, and long-term supply chain concerns. Actionable recommendations were developed, including implementing DMZ segmentation, formalizing vendor access agreements, designing AI workload limits, and advancing standards through NERC and state-level programs. These strategies aim to strengthen resilience, clarify responsibilities, and ensure secure integration of data centers into the grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗