Search NASA⌕ Search

SEARCH · Search NASA

Results for “Incident response”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Cloud forensics and incident response platform

A system, method, and device for cloud forensics and incident response is provided. In an embodiment, a computer-implemented method for performing cloud forensics and incident response includes intercepting, by a cloud incident response module (CIRM), communication between a virtual machine (VM) and a hypervisor. The method also includes extracting, by the CIRM, data from the communication between the VM and the hypervisor according to a forensic policy. Intercepting and extracting the data are transparent to the VM and to the hypervisor. Intercepting and extracting the data are independent of the VM and the hypervisor.

Urias, Vincent↗

Washington State Cyber Incident Response Summit Event Report

On September 7 and 8, 2022, Pacific Northwest National Laboratory and Washington State Adjutant General Major General Bret Daugherty, with support from the Department of Homeland Security Cybersecurity and Infrastructure Security Agency, hosted the Washington State Cyber Incident Response Summit at Camp Murray in Washington State. The invite-only summit convened 40 key decision makers and stakeholders from across the state to discuss strategies and pilot a collaborative approach to improve cyber incident response readiness within Washington. In small working groups, participants shared incident response lessons learned, best practices, and opportunities for improvement within the water and transportation sectors. This report highlights the details of the workshop presentations and discussions.

97 MATHEMATICS AND COMPUTING↗

Cybersecurity Incident Response Guide for Wind

As wind energy systems become increasingly digitized and interconnected, they face a growing array of cyber threats that can disrupt operations, compromise safety, and trigger cascading impacts across the energy ecosystem. The Wind Incident Response Guide provides a structured, wind-specific framework for preparing for, detecting, responding to, and recovering from cyber incidents. Drawing on lessons from field demonstrations, cyber-physical testbeds, and stakeholder engagement across the wind sector, this guide integrates technical, operational, and regulatory considerations to support asset owners, operators, and responders. It outlines key roles and responsibilities, maps incident response phases to wind-specific scenarios, and highlights applicable laws, regulations, standards, and best practices. By tailoring general cybersecurity principles to the unique architectures and operational constraints of wind systems—including remote access, legacy components, and environmental interfaces—this guide aims to enhance resilience, reduce response time, and support coordinated action across public and private stakeholders. It is intended as a practical resource for utilities, developers, regulators, and emergency managers working to secure the future of wind energy.

17 - WIND ENERGY↗

AR4IR (Automated Reasoning for Incident Response) [SWR-24-103]

A basic formal methods tool with the ability to aid and/or automate a utilities’ incidence response and instills confidence that the proposed action satisfies the system’s physical constraints, the organization’s cyber policies, and will not cause violations of technical standards.

Etigowni, Sriharsha [National Renewable Energy Lab↗

Does practice make perfect? Lessons learned from full-scale power system incident response exercise

While threats to the energy sector occur daily, few utilities get the opportunity to fully test out their detection and response mechanisms to advanced threats in the real world. With the high demand for reliability, few grid operators would allow execution of simulated cyber-attacks on their live systems. The DOE-funded Liberty Eclipse project offers a unique opportunity for small and large utilities and coops to practice their combined IT/OT responses to a live red team executing attacks against an isolated power system on an island in New York. Both cyber teams and power operations teams must work together to detect and respond to attacks, even restoring the power system against extreme impacts. Lessons learned from these exercises reveal key takeaways for understanding what a real attack against the electric sector will look like, gaps in execution of the best-laid plans when the pressure of a real event is bearing down, and how organizations can better prepare for advanced attacks by optimizing participation in exercises. This presentation will discuss successes and opportunities for improvement both in how utilities can prepare for and respond to events, as well as how full-scale IT/OT exercises can be coordinated.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Ev Info And Incident Response Solutions

In post-crash situations, passengers, bystanders, and first responders are exposed to the immediate safety risks of stranded energy in electric vehicle (EV) batteries. A potentially damaged battery with an unknown state of safety might go into a thermal runaway without proper handling, leading to potential loss of life and property damage. Therefore, it is imperative to develop methods, guidelines and tools to handle the post-crash EVs appropriately and minimize safety risks from immediately after an EV accident to final disposal or re-entry to the road. This software tool: (1) provides quick access to EV specification, (2) estimate stranded energy left in an EV after a crash specific to EVs in a user-friendly way, (3) inform EV structure/disconnect for appropriate quick post-crash handling, (4) perform the calculation for the first responder to decide on onsite or offsite discharge, and (5) feature appropriate battery disposal and education/lessons learned. This software tool will directly help the emergency responders to handle EV post-crash situations effectively and safely.

Zhang, Bo [Idaho National Laboratory (INL), Idaho ↗

Wheelbyte Incident Response [Slides]

Wheelbyte faced some challenges regarding cyber attacks. The company reported possible exfiltration of company and customer data, along with the sudden death of an employee.

97 MATHEMATICS AND COMPUTING↗

Uncertainty Analysis of Inhalation Dose Coefficients for Nuclear Incident Response

This study addressed the need to characterize variability in inhalation dose coefficients due to uncertainties in respiratory tract deposition, systemic biokinetics, and physiological parameters. A Python-based implementation of the International Commission on Radiological Protection Publication 66 Human Respiratory Tract Model was developed called the Radiological Exposure Dose Calculator (REDCAL) to propagate parameter uncertainty.

61 RADIATION PROTECTION AND DOSIMETRY↗

NFPA Distributed Energy Resources Safety Training (DERST) For Emergency Responders

The National Fire Protection Association, with support from the Department of Energy, executed a multi-year initiative to develop, enhance, and disseminate Distributed Energy Resources Safety Training (DERST) tools for U.S. emergency responders. As Distributed Energy Resources (DER)—such as solar photovoltaics, battery energy storage systems (ESS), electric vehicles (EVs), and associated infrastructure—become increasingly prevalent, the NFPA identified a critical need for up-to-date standardized, accessible, and effective safety training tailored for the fire service and related public safety professionals. The project delivered a comprehensive suite of educational resources to improve responders’ abilities to safely manage DER-related incidents. This included: • Revised Modular Training Courses: Updated classroom-based DER safety courses, now modular and accessible nationwide through fire academies and the North American Fire Training Directors (NAFTD) network. • Live Burn Testing & Research: A full-scale controlled burn of a DER-equipped residential structure provided real-world data and insights, forming the basis for updated best practices. • A Gamified Simulation Tool – Firefighters Incident Response Simulation Tool (FIRST): A first-of-its-kind, multiplayer, scenario-based simulation using the Unreal Engine 5.0 to train responders in a realistic virtual, multi-DER incident environment. • Field Familiarization Software Tools & Prop Guide: Digital DER field familiarization evolutions software guide and a prop development manual to support field-based DER training exercises, enhancing responders' hands-on familiarity with DER infrastructure and collaboration on virtual incident responses. • National Dissemination Strategy: Strategic partnerships with NAFTD, Vector Solutions, and others enabled wide-scale distribution, with over 5,000 departments accessing resources and 1,100+ departments adopting the simulator in the first seven months. Also provided a web portal for easy access to all training and simulation programs developed under this grant for the U.S. responder community. Key findings from the project—particularly from the burn test—led to paradigm shifts in fire response tactics. For example, traditional approaches to garage fires may be hazardous if DERs are present, due to explosive off gassing and thermal runaway risks. The new training emphasizes scene assessment, stand-off approaches, thermal imaging verification, and careful post-incident cooling of DER components to prevent reignition. This initiative has had a significant national impact, raising awareness, enhancing preparedness, and supporting safer DER incident response practices. Significant engagement from the media, public safety organizations, and PBS coverage has further amplified the reach and adoption of NFPA’s DER safety training, tools, and simulations.

14 SOLAR ENERGY↗

Intern Deliverable Poster 2025

An Incident Response Plan (IRP) is a document that is created and maintained by an organization that provides guidance in the event of a cyber incident. The primary objectives of an IRP are to aid in the detection, response, and recovery from incidents, as well as to enhance preparation and preventative measures. An IRP should outline specific procedures at each stage of an incident, with the goal of minimizing asset damage, data leakage, and operational impact. By investing in a well-defined IRP, organizations can better manage and mitigate risks associated with cyber threats, ensuring business continuity and resilience. This poster summarizes incident response guidelines for wind energy, which faces unique cybersecurity and physical challenges.

17 - WIND ENERGY↗

Understanding How Organizations Handle Cybersecurity

If there is anything we can learn from the media, it is the frequency and severity of cyber-attacks is increasing and there are not enough qualified people to combat the risk organizations are facing. Current estimates say there are 3.5 million available cybersecurity related jobs globally and there has been a 350% growth in cybersecurity jobs since 2013 (Group, 2020). The Idaho Cyber Research Project (ICRP) is focused on finding an implementing solution to the problems in the workforce development pipeline. Our team consists of Cohort 2 of the ICRP, we are tasked with solving issues faced by organizations hiring new cyber personnel. To provide solutions to these issues we focused our research on four components of workforce availability and competency: resume and transcript analysis, apprenticeships, cyber incident response plan development, and adversarial mindset training. From this research we have produced the following focus areas and subsequent steps for each component of workforce capability: transcript and knowledge skills abilities (KSA) focused analysis, cybersecurity apprenticeships programs, the value of an adversarial mindset, and a guide to setting up cyber incident response plans for underprepared organizations. These solutions can be further developed and implemented to reduce the gap in workforce demand and talent.

97 MATHEMATICS AND COMPUTING↗