Search NASA⌕ Search

SEARCH · Search NASA

Results for “supply chain cybersecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Data Center Cybersecurity, Supply Chain Risk Management, and Emerging Regulation Cohort Summary: Takeaways and Action Plans

This report summarizes the outcomes of the Data Center Cohort under the Department of Energy’s Technical Assistance for Digital Assurance (TADA) initiative, aimed at enhancing grid resilience through cybersecurity, supply chain risk management (SCRM), and Cyber-Informed Engineering (CIE). The cohort engaged 17 organizations across utilities, data center operators, vendors, and technology providers in three sessions combining presentations, discussions, and exercises. Key topics included AI-driven load behavior, cybersecurity vulnerabilities in UPS/BESS and cooling systems, governance gaps at utility–data center boundaries, and supply chain integrity. Five cross-cutting themes emerged: interconnection architecture vulnerabilities, fragmented governance, AI-driven stability risks, lack of regulatory frameworks, and long-term supply chain concerns. Actionable recommendations were developed, including implementing DMZ segmentation, formalizing vendor access agreements, designing AI workload limits, and advancing standards through NERC and state-level programs. These strategies aim to strengthen resilience, clarify responsibilities, and ensure secure integration of data centers into the grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Supply Chain Cybersecurity Recommendations for Solar Photovoltaics

Solar photovoltaic (PV) cybersecurity is a growing field of research. As deployments of solar PV has increased, cyber risk has also increased. However, utility solar PV installations are not required to comply with North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) unless they meet a minimum generation threshold of 75 Megawatts (MW). Individual residential scale solar PV deployments will not meet that generation threshold and are therefore excluded from NERC CIP requirements. With most solar installations below 75MW, solar PV has been deployed with minimal oversight and highly variable cybersecurity maturity. The resources that make up the digital supply chain can include software, code, data, as well as other digital components. However as clean energy technology advances, cybersecurity threats and vulnerabilities continue to evolve and grow in sophistication. Solar PV faces a unique challenge in which it can be deployed in residential buildings and purchased by a consumer directly. This makes the supply chain of PV a unique challenge, where responsible parties for cybersecurity vary widely depending on the type of solar PV being deployed. Supply chain cybersecurity for solar PV represents a critical area for ensuring safe operations as the U.S. moves towards a clean energy future.

14 SOLAR ENERGY↗

Cybersecurity Supply Chain Risk Management: Forge Institute Presentation

In this talk, INL will discuss how to develop a cyber supply chain risk management program, to include assessment of vendor risk and applying appropriate mitigations. INL will discuss key risk factors and the challenges of securing supply chain in complex and dynamic vendor environments. Finally, INL will share example language that can be adopted in RFPs and procurement contracts to promote supply chain security.

battery energy storage system↗

Data Centers and Digital Assurance Introduction to Supply Chain and Cybersecurity for Data Centers, Session 1

The first session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort Workshop, held on October 30, 2025, introduced foundational concepts of Digital Assurance in the context of data center and grid integration. Sponsored by the U.S. Department of Energy, the workshop brought together utilities, data center operators, developers, and vendors to address cybersecurity and supply chain vulnerabilities. The session emphasized the growing criticality of data centers within the electric grid and the need for secure, real-time, bidirectional communication. Participants explored the principles of Digital Assurance, including cybersecurity, cyber-informed engineering (CIE), and lifecycle security, and applied a threat-vulnerability-consequence framework to identify and mitigate risks at the data center–grid interface. Discussions covered a range of threats such as spoofed dispatch signals and insider threats, architectural vulnerabilities like SCADA interfaces and insecure protocols, and potential consequences including cascading grid failures. The session also raised strategic questions about business value, vendor assurance, and defining cyber boundaries and responsibilities. This foundational workshop set the stage for deeper technical analysis and the development of actionable frameworks in subsequent sessions. Session 1 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Grid Communications: Cybersecurity and Supply Chain Challenges and Emerging Regulation Session Three

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem. This is Session 3 of 3 (Full Version).

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Securing Solar for the Grid (S2G) (Final Project Report) [Slides]

This is the final technical report for the SETO-funded project Securing Solar for the Grid (S2G) from FY22-24. The project scope included development and dissemination of standards' requirements, best practices, equipment testing procedures, assessment tools, as well as education and training materials for cyber defense, posture and maturity tailored to solar technologies. The outcomes for this work include: co-led the development of cybersecurity certification standard (UL2941), co-led the development of cybersecurity guide (IEEE1547.3), development of recommendations for supply chain cybersecurity, and development of cybersecurity risk profiles and recommendations for DERMS.

14 SOLAR ENERGY↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Risks to the DOW Mission From Global Advanced Energy Adoption

Advanced energy technologies have the potential to enhance energy security and resilience; however, they can introduce new vulnerabilities even as they mitigate existing ones. This dichotomy highlights that both action and inaction carry strategic risks in a contested and logistically complex operating environment. Regardless of U.S. civilian or military adoption of such technologies, key allies and adversaries are on adoption paths that will impact the U.S. military at the tactical, operational, and strategic level. The global adoption of advanced energy technologies presents the potential for both positive and negative consequences for U.S. Department of Defense (DOD) missions in the next 10-20 years. Three categories of risk drivers are presented in this analysis: infrastructure-related, adoption-related, and response-related. Each risk type can generate consequences for DOD, including power disruptions, suboptimal DOD mission performance and operational effectiveness, higher costs and shortages for both legacy and advanced energy technologies, and loss of U.S. influence and strategic deterrent value. Specific impacts could include tactical impacts, operational impacts, and strategic impacts. Mitigation strategies could include energy resource and technology planning, cybersecurity, supply chain resilience, workforce development, exercises and simulations, investments in commercialized technology, operational testing and pilot programs, research into emerging technologies, partnerships and working groups, common standards, budget planning, and repurposing infrastructure.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Hawaii Threat Brief

The Digital Energy Transformation is redefining how power systems operate, integrating physical infrastructure with digital technologies to enhance efficiency, visibility, and resilience. For islanded and digitally modernizing systems like Hawai‘i’s, this shift presents both new opportunities and evolving challenges in cybersecurity, supply chain assurance, and environmental resilience. This brief provides an overview of critical infrastructure dependencies and systemic risks associated with increasing digital integration. It summarizes recent energy-sector threat activity and case studies that illustrate adversary tactics and supply chain vulnerabilities, and identifies pathways to strengthen resilience.

25 - ENERGY STORAGE↗

Data Centers and Digital Assurance Workshop 2 – Prioritizing Digital Assurance Challenges, Session 2

The second session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 10, 2025, focused on prioritizing digital assurance challenges at the intersection of data centers and the electric grid. Building on the foundational concepts introduced in Workshop 1, this session deepened the application of the Threat–Vulnerability–Consequence (TVC) framework and emphasized the urgency of addressing cybersecurity, supply chain integrity, and operational reliability. Participants explored the growing convergence of digital and physical systems, the expanding attack surface due to global supply chain dependencies, and the implications of AI-driven load behavior. Real-world incidents—including the Volt Typhoon campaign and vulnerabilities in Solarman and Deye platforms—were analyzed to illustrate the risks of unpatched systems, insecure APIs, and inadequate vendor oversight. Key themes included architecture and interface weaknesses, governance gaps, and human and procedural shortcomings. The workshop also examined the evolving regulatory landscape, highlighting new federal mandates around Foreign Entity of Concern (FEOC) compliance and large-load reliability standards. Through interactive exercises, stakeholders ranked and mapped digital assurance risks from their respective perspectives—utilities, operators, and vendors—laying the groundwork for mitigation strategies and shared accountability models to be developed in Workshop 3. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session Two

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. A comprehensive exploration of BESS cybersecurity supply chain risks, systematic vendor risk assessment through the BESS Procurement Guide, and practical application of the INL SCRM Chatbot for enhanced supply chain resilience. This is Session 2 of 3. (Full Version)

25 - ENERGY STORAGE↗

DER Digital Supply Chain Gap Analysis

Solar photovoltaic (PV) cybersecurity is a growing field of research. As deployments of solar PV have increased, cyber risk has also increased. Utility solar PV installations, however, are not required to comply with the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) plan unless they meet a minimum generation threshold of 75 MW. Individual residential-scale solar PV deployments will not meet that generation threshold and are therefore excluded from the NERC CIP requirements. With most solar installations less than 75 MW, solar PV has been deployed with minimal oversight and highly variable cybersecurity maturity. The resources that comprise the digital supply chain can include software, code, data, and other digital components. But as clean energy technologies advance, cybersecurity threats and vulnerabilities continue to evolve and grow in sophistication. Supply chain cybersecurity represents a critical area for ensuring safe operations as the U.S. moves toward a clean energy future.

cybersecurity↗

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session One - Abridged

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. This is Session 1 of 3.

25 - ENERGY STORAGE↗

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session One

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. This is Session 1 of 3. (Full Version)

25 - ENERGY STORAGE↗

The Benefits of a Software Bill of Materials Program at Nuclear Facilities

Software supply chain attacks are becoming increasingly more prevalent in both information communications technology and operational technology environments. Often, a supplier or other entity discloses vulnerability information about software components and subcomponents used in a digital asset, but an asset owner is unable to quickly ascertain if the vulnerable component is installed in their facility. The generation and use of a software bill of materials (SBOM) for installed digital assets can enable an asset owner to quickly identify if and where a component is used, allowing them to evaluate the risk and determine necessary risk treatments. The integration of an SBOM program into a nuclear facility not only improves vulnerability management and risk management processes, it also benefits asset and configuration management, cybersecurity, and supply chain programs. This paper reviews the U.S. Department of Energy Office of Nuclear Energy Cybersecurity Crosscutting Technology Development program’s work on integrating an SBOM program into a nuclear facility. It also provides a discussion on the benefits of such a program.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

BESSIE: Battery & Energy Storage Supply Chain Analysis, Mitigation Deployment, and Tools

Battery energy storage systems (BESS) and their associated power electronic interfaces are key components to delivering clean and more resilient energy, providing much-needed fast-ramping, emergency discharge, generation, and operations support to the electric grid. These services have grown to be invaluable over the past ten years and will soon be an irreplaceable element of energy delivery. The Idaho National Laboratory (INL) strives to address these challenges through a strategic approach to supply chain risk assessment and mitigation for BESS and related digital energy equipment through the BESSIE project under the Center for Securing Digital Energy Technology. Recognizing that decreasing dependence on a foreign supply chain will take significant time and investment, BESSIE’s focus is strategically addressing battery supply chain risks by pairing short-term steps to operate securely through today’s risks with long-term steps to shape the supply chain over the coming years.

25 ENERGY STORAGE↗

Developing a Supply Chain Security Program

Amid growing concerns over foreign manufacturing for components and devices deployed in critical energy infrastructure, this research from the national labs will highlight best practices for developing and maintaining a supply chain security program. Tools for asset inventory, tips for developing and maintaining software- and hardware-bills-of-materials (SBOMs and HBOMs), recommended contractual language for vendor agreements, and identification of responsibilities will be shared. We discuss the one-time requirements to enable a successful supply chain security program and the best ways to operationalize this program for maximum impact, including development of robust practices for vulnerability tracking, patch management, and workarounds, with understanding of the reliability and uptime requirements for utilities. The recommendations shared are based on a cyber-informed engineering approach to identification of high-consequence impacts and the engineering controls related to supply chain management that can best mitigate these impacts. This approach allows for prioritization of resources. Additionally, we highlight relative up-front and ongoing costs associated with recommended controls. Viewers will leave with an understanding what a supply chain security program is, and what steps, prioritized for resource-constrained organizations, can build a robust program.

14 SOLAR ENERGY↗