Search NASA⌕ Search

SEARCH · Search NASA

Results for “Cybersecurity Risk Reduction”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction, A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

01 COAL, LIGNITE, AND PEAT↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction: A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

20 FOSSIL-FUELED POWER PLANTS↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction: A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

20 FOSSIL-FUELED POWER PLANTS↗

Advanced Transmission Technologies – GETs and HPCs Session 2: Advanced Power Flow Control and Transmission Topology Optimization

The INL TADA GETs Cohort Session 2, held on November 7, 2025, conducted in collaboration with ScottMadden, focused on two core Advanced Transmission Technologies (ATTs): Advanced Power Flow Control (APFC) and Transmission Topology Optimization (TTO). These technologies are pivotal in enhancing grid flexibility, reliability, and cybersecurity resilience. APFC, particularly through modular FACTS devices like Modular Static Synchronous Series Compensators (M-SSSCs), enables dynamic voltage injection to reroute power flows. The session highlighted the deployment benefits of APFC, such as rapid installation, minimal civil works, and re-deployability. Regulatory drivers like FERC Order 2023 mandate the inclusion of Grid-Enhancing Technologies (GETs) in interconnection studies. Case studies from Central Hudson, CAISO, and National Grid (UK) demonstrated APFC’s effectiveness in congestion relief and cost savings. The session also addressed cybersecurity concerns, including firmware vulnerabilities, SCADA integration risks, and supply chain dependencies. Participants engaged in interactive exercises to rank cybersecurity and supply chain risks, emphasizing the need for robust digital assurance strategies. TTO involves software-based reconfiguration of transmission networks to optimize power flow without new infrastructure. The session showcased its operational value, with examples from SPP, PJM, and MISO showing significant congestion cost reductions. Cybersecurity vulnerabilities were discussed, particularly in API security and software supply chains, referencing incidents like SolarWinds and attacks on Danish utilities. Digital assurance exercises explored worst-case scenarios, attack paths, and mitigation responsibilities between vendors and utilities. Reliability challenges such as algorithm stability, vendor dependency, and operator trust were also examined. Cross-cutting themes emphasized the importance of digital assurance tools, including Software Bills of Materials (SBOMs) and hardware-in-loop testing. Human performance, training, and operational confidence were identified as critical enablers of technology adoption. The session concluded with a preview of Session 3, which will focus on High Performance Conductors (HPCs) and risk-based cybersecurity tools. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity concerns for the energy sector in the maritime domain

The world has seen a number of high-profile maritime disasters in recent months and years, and has felt the impact of them. At the same time, the world has also seen a number of high-profile cyberattacks. It has felt their impact, as well. And, likely no sector has been more affected by the maritime and cyber incidents than the energy sector, as fuel prices often spike or trough, and access to energy resources can become an instant source of concern, tension, or even conflict. As energy sectors—in all their forms—continue to rely on the maritime domain or even increase that reliance, they must be mindful that traditional maritime threats—like piracy, theft, and weather events—are not the only threats they face today. Maritime cybersecurity concerns are among the most potentially disruptive to energy-sector interests and, yet, are among the least understood and least addressed. This paper identifies nine areas in which the energy sector faces harmful cyber vulnerabilities in the maritime domain, to provide enough insight and examples to allow for action to be taken to reduce the risk of harm from these different vulnerabilities. The paper develops the example of offshore wind energy to model how to assess cyber considerations more fully. Ultimately, it concludes with a series of recommendations that offer policymakers, energy-sector actors, and security and law-enforcement professionals steps to minimize the exposure of the maritime energy sector to harmful cyberattacks.

99 GENERAL AND MISCELLANEOUS↗

Autonomous Tools for Attack Surface Reduction (Final Report)

The electric power grid is a complex critical infrastructure that forms the lifeline of modern society, and its secure and reliable operation is of paramount importance to national security and economic wellbeing. However, recent findings documented in authoritative sources indicate the threat of cyber-based attacks growing in numbers and sophistication. However, securing the grid against stealthy cyberattacks is a challenging task due to legacy nature of the infrastructure coupled with dynamic nature of threat landscape and ever-growing sophistication of the adversaries. Additionally, the grid’s attack surface continues to grow with the increased dependence on digital communications and control that now extends to each consumer through smart meters and distributed energy resources. Unfortunately, this expansive surface increases the grid’s vulnerability and further exposes critical control systems in both substations and control centers. To respond to this emerging need, we had successfully assembled an interdisciplinary team with academic- industry partnership to successfully conduct research, development, evaluation, demonstration, and commercialization of attack surface reduction tools, whose goal was to significantly reduce the cyber attack surface in the North American power grid. Our proposed project was a synergistic collaborative effort leveraging the synergistic expertise of the team members across power systems, cyber security and CPS security, testbeds, field deployments and demonstration, and successful commercialization. The following are the specific tasks that have been successfully completed two phases (2016-2020). Phase I: Task 1: Developed and implemented a robust Project Management and Data Management Plan, coupled with a well thought out Risk Mitigation Plan. Task 2.1: Developed a comprehensive framework that continually assesses and autonomously reduces the attack surface for the power grid control environment spanning across substations, control center and the SCADA network to significantly reduce the risks of cyber attacks. Task 2.2: Developed attack surface analysis techniques, metrics, and tools that assess the attack surface at multiple levels including the control center, substations, and the SCADA network. Task 2.3: Developed attack surface reduction techniques and tools that dynamically reduce attack surface and hence increase attacker’s cost without interfering in the critical functions of the system. Task 2.4: Prototyped, implemented, and quantitatively evaluated/validated the techniques and tools on a realistic industrial CPS security testbed environment by leveraging the unique resources of the team. Task 3: Developed Commercialization plan to transition the developed tools into power system industry stakeholders for a broader adoption by leveraging the expertise of our industrial members. Phase II: Task 4: Successfully completed field demonstration, verification, and evaluation of the effectiveness of the attack surface analysis and reduction techniques on a realistic utility testbed environment. This also involved the development of realistic scenarios, sound metrics, data sets, evaluation criteria, and documentation. Technology integration & Field demonstration: The project had significantly advanced the state-of-the-art research and practice in improving the cybersecurity of our nation’s power grid infrastructure against cyber threats. In particular, the proposed, designed, and deployed attack surface analysis and reduction algorithms and tools have contributed to significantly reducing the exposure and risk of the devices, substations, and the integrated SCADA/EMS/ DMS grid environment to cyber threat. Strong demonstration and evaluation techniques have verified the feasibility of the developed techniques on realistic cyber-physical testbeds and utility partner's real grid environment, and collaborative research and evaluation of attack surface reduction techniques (for wide-are monitoring and control) within a vendor (GE) EMS platform. The Attack Host Analyzer (AHA) tool that was developed through this project was made available through GitHub.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Connecting the Dots: An Assessment of Cyber-risks in Networked Building and Municipal Infrastructure Systems

The buildings and city streets we walk down are changing. Driven by various data-driven use cases, there is increased interest in networking and integrating lighting and other building systems (e.g., heating, ventilation, and air conditioning (HVAC), security, scheduling) that were previously not internet-facing, and equipping them with sensors that collect information about their environment and the people that inhabit it. These data-enabled systems can potentially deliver improved occupant and resident experiences and help meet the U.S. Department of Energy (DOE) national energy and carbon reduction goals. Deploying connected devices new to being networked, however, is not without its challenges. This paper explores tools available to system designers and integrators that facilitate a cybersecurity landscape assessment – or more specifically the identification of threats, vulnerabilities, and adversarial behaviors that could be used against these networked systems. These assessments can help stakeholders shift security prioritization proactively toward the beginning of the development process.

cyber-risk assesment, adversarial behavior, MITRE ↗

Distributed Optimization in Distribution Systems: Use Cases, Limitations, and Research Needs

We report electric distribution grid operations typically rely on both centralized optimization and local non-optimal control techniques. As an alternative, distribution system operational practices can consider distributed optimization techniques that leverage communications among various neighboring agents to achieve optimal operation. With the rapidly increasing integration of distributed energy resources (DERs), distributed optimization algorithms are growing in importance due to their potential advantages in scalability, flexibility, privacy, and robustness relative to centralized optimization. Implementation of distributed optimization offers multiple challenges and also opportunities. This paper provides a comprehensive review of the recent advancements in distributed optimization for electric distribution systems and classifications using key attributes. Problem formulations and distributed optimization algorithms are provided for example use cases, including volt/var control, market clearing process, loss minimization, and conservation voltage reduction. Finally, this paper also presents future research needs for the applicability of distributed optimization algorithms in the distribution system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Grid Energy Storage: Supply Chain Deep Dive Assessment

The report “America’s Strategy to Secure the Supply Chain for a Robust Clean Energy Transition” lays out the challenges and opportunities faced by the United States in the energy supply chain as well as the Federal Government plans to address these challenges and opportunities. It is accompanied by several issue-specific deep dive assessments, including this one, in response to Executive Order 14017 “America’s Supply Chains,” which directs the Secretary of Energy to submit a report on supply chains for the energy sector industrial base. The Executive Order is helping the Federal Government to build more secure and diverse U.S. supply chains, including energy supply chains. To combat the climate crisis and avoid the most severe impacts of climate change, the U.S. is committed to achieving a 50 to 52 percent reduction from 2005 levels in economy-wide net greenhouse gas pollution by 2030, creating a carbon pollution-free power sector by 2035, and achieving net zero emissions economy-wide by no later than 2050. The U.S. Department of Energy (DOE) recognizes that a secure, resilient supply chain will be critical in harnessing emissions outcomes and capturing the economic opportunity inherent in the energy sector transition. Potential vulnerabilities and risks to the energy sector industrial base must be addressed throughout every stage of this transition. The DOE energy supply chain strategy report summarizes the key elements of the energy supply chain as well as the strategies the U.S. Government is starting to employ to address them. Additionally, it describes recommendations for Congressional action. DOE has identified technologies and crosscutting topics for analysis in the one-year time frame set by the Executive Order. Along with the capstone policy report, DOE is releasing 11 deep dive assessment documents, including this one, covering the following technology sectors: carbon capture materials; electric grid including transformers and high voltage direct current (HVDC); energy storage; fuel cells and electrolyzers; hydropower including pumped storage hydropower (PSH); neodymium magnets; nuclear energy; platinum group metals and other catalysts; semiconductors; solar photovoltaics (PV); and wind. DOE is also releasing two deep dive assessments on the following crosscutting topics: Commercialization and competitiveness; and cybersecurity and digital components. More information can be found at www.energy.gov/policy/supplychains.

25 ENERGY STORAGE↗