News

Idaho National Lab researchers publish book on cybersecurity for public utilities

Two cybersecurity researchers at Idaho National Laboratory (INL) have authored a book to help train employees at public utilities to recognize cybersecurity vulnerabilities and develop measures to defend their networks from cyberattacks.

The book — Countering Cyber Sabotage: Introducing Consequence-Driven, Cyber-Informed Engineering – was written by Andy Bochman and Sarah Freeman. It details INL’s innovative approach to secure critical infrastructure systems like the electric power grid, oil and natural gas refineries, and water treatment facilities.

The authors point out that much of the technology responsible for controlling operations at many public utilities is decades-old and lacks modern defense capabilities. This makes them vulnerable to cyberattacks ranging from ransomware threats to significant service disruptions.

INL developed an approach to cybersecurity called Consequence-driven Cyber-informed Engineering (CCE) to address this challenge. Instead of relying on traditional protection strategies like intrusion detection software or additional firewalls, INL’s cybersecurity approach uses engineering design principles to prevent cyberattackers from damaging or disrupting operations.

“Every day, millions of Americans depend on the seamless operation of our nation’s critical infrastructure systems. We take for granted how necessary energy, power, clean water, and communications are for our daily lives,” Bochman, a researcher at INL, said. “This book lays the groundwork for a new approach to cybersecurity that acknowledges the grim reality of targeted cyberattacks and teaches utilities how to engineer barriers that prevent nation-state hackers from completing their objectives.”

INL developed the CCE method over the last decade in consultation with leading government, industry, and academic researchers. In 2018, the Department of Energy Office of Cybersecurity, Energy Security and Emergency Response provided INL with $20 million to further develop the method. INL has used the funding to support hands-on security engagements with large utilities whose operations impact multiple states, millions of residents, or other critical operations.

In December 2020, INL licensed the CCE method to West Yost, a California company that provides engineering services and training to many of the nation’s 50,000 water utilities. West Yost plans to offer CCE training to their customers to increase cybersecurity awareness and preparedness in the water sector. INL is currently discussing other licensing opportunities.

The book is published by Taylor and Francis Group and can be purchased online and in select retail outlets.

Dave Kovaleski

Recent Posts

Analysts update report on Order 1000’s impact on project costs ahead of FERC’s transmission order

The Federal Energy Regulatory Commission’s (FERC) long-awaited transmission planning and cost-allocation proposal is being considered on May 13 in a…

1 day ago

DOE issues final rule on transmission permitting

The U.S. Department of Energy (DOE) issued a final rule on transmission permitting and announced a commitment for up to…

2 days ago

Con Edison updates clean energy progress in annual sustainability report

Con Edison released its annual sustainability report, in which it outlines its progress in developing the energy infrastructure to support…

2 days ago

Joint NASEO, NARUC report suggests nuclear options amid coal closures

As the U.S. energy industry moves further from coal as a resource, many options have arisen as replacements, but a…

2 days ago

Duke Energy reports carbon emissions down 48 percent since 2005

According to Duke Energy’s 2023 Impact Report, electric generation carbon emissions are down 48 percent since 2005 and the company…

2 days ago

EPA announces clean heavy-duty vehicle transition grants

On Wednesday, the U.S. Environmental Protection Agency announced it would provide nearly $1 billion in grants for zero-emission heavy-duty vehicles,…

2 days ago

This website uses cookies.