New tool to assess cybersecurity risks at hydro plants

9 November 2021


A new tool is being developed to allow hydropower operators to assess their risks and make informed investments for enhanced cybersecurity.

Supported by the US Department of Energy Water Power Technologies Office, the National Renewable Energy Laboratory (NREL) and Argonne National Laboratory (ANL) tool named the Cybersecurity Value-at-Risk Framework (CVF) provides hydropower operators complete and customized assessments of their cybersecurity risks and demonstrates how different investments will help improve overall resilience.

“This is a much-needed framework for future security and resilience,” said Anuj Sanghvi, an NREL cybersecurity researcher who is helping develop the CVF. “Operators are eager to understand the right resilience investments for their systems, as well as the actual risks themselves. CVF can provide deep insight around how system-specific investments relate to cybersecurity and resilience.”

The CVF is designed to be easy and accessible for a facility manager to use. As an online tool, CVF guides users through a detailed analysis of the plant’s operations. Users answer a series of questions, and their responses are then compared against multidimensional criteria for environmental, operational, and economic impact. Results and data from the CVF include specific risk probabilities and scores that are indicative of financial value and that require cybersecurity improvements to withstand future threats.

The CVF leverages lessons from the NREL-developed Distributed Energy Resource Cybersecurity Framework (DER-CF), a successful tool originating from the federal government to secure its facilities, but with wide applicability to sites of many sizes and functions. The CVF borrows the DER-CF’s standardized cyber evaluation method and extends the scope to perform risk, impact, and likelihood scoring all within the valuation platform, angling the assessment to hydro-specific applications. Both frameworks follow National Institute of Standards and Technology guidance for criteria like data handling, risk scores, and environmental footprint, which also aligns facilities with relevant federal regulation.

The CVF is currently being validated on an initial case study at Delta Montrose Electric Association’s hydropower facilities. Other utilities and federal agencies are also implementing the CVF and advising on its design. As feedback comes in, NREL and ANL will continue to develop the framework for web release sometime in 2023.



Privacy Policy
We have updated our privacy policy. In the latest update it explains what cookies are and how we use them on our site. To learn more about cookies and their benefits, please view our privacy policy. Please be aware that parts of this site will not function correctly if you disable cookies. By continuing to use this site, you consent to our use of cookies in accordance with our privacy policy unless you have disabled them.