
Provides society information that may include news, reviews or technical notes that should be of interest to practitioners and researchers.
Modern power grids are evolving into highly interconnected cyber-physical systems (CPSs), enabling advanced monitoring, automation, and control. While these innovations improve efficiency and reliability, they also introduce new vulnerabilities. A well-devised single cyberattack can cascade across the grid, disrupting essential services to the society and economy. This has been demonstrated in major critical infrastructure attacks, such as the Ukraine power grid hack (2015), and Colonial pipeline attack (2021). Traditional cybersecurity measures alone fall short as threats grow more sophisticated. Artificial intelligence (AI) offers a transformative approach to safeguarding smart distribution systems by enabling proactive detection and self-healing capabilities before the anomalies escalate into major disruptions. By leveraging AI’s ability to learn patterns, anticipate adversarial behavior, and coordinate defense across distributed assets, utilities can enhance resilience against evolving cyber threats. This article explores how AI-driven strategies can become a shield for the future grid security. It highlights their potential to enhance operational resilience and outlines a vision for integrating intelligent defense into the infrastructure of modern electric power distribution systems.
It is the quiet stretch of the night, before the predictable morning load ramp, and control room operators watch a familiar rhythm of telemetry across their displays. Loads are steady, voltages remain within bounds, and system frequency is tightly regulated. Nothing appears out of place. However, deep within the operational environment, an intruder may already be present, quietly mapping communication paths, probing devices, and learning how the system is organized. No breaker has opened, and no alarm has been triggered, yet the most consequential phase of a cyberattack, reconnaissance, may already be complete.
Power grids are currently facing novel and incumbent cybersecurity challenges posed by advanced persistent threats (APTs). They are perpetrated by advanced, often state-sponsored adversaries targeting transmission and distribution system operators. APTs and emerging well-resourced cyberattacks on control centers, digital substations, renewables, and storage technologies can cause distributed contingencies across the power system leading to N-k components being suddenly disconnected from the power grid. Cyberattacks may instigate multiple, unprecedented excitation modes and lead to protection schemes disconnecting other generators and power lines, which result in a fast domino effect called cascading failures. The impact of a cyberattack on power system dynamics can be fundamentally different from the consequences of physical faults or contingencies. APTs can speed up the cascading failure mechanisms, leading to an accelerated point of no return in the cascading failures sequence and potentially cause a blackout much faster than historical blackouts initiated by physical disturbances. This leaves insufficient time for reactive measures to contain the spread of disruptions and may result in an unprecedented large-scale, continental blackout.
The NERC CIP standards have been mandatory for more than fifteen years and are widely regarded as a baseline for securing the bulk power system, yet little is known about how the people who implement, audit, and write them experience the regulatory lifecycle in practice. Drawing on interviews with twenty two auditors, utility implementers, and standard drafters, this article synthesizes firsthand accounts of where compliance succeeds and where it creates friction. We find that prescriptiveness can hinder flexibility and encourage a check the box mentality, that the burden of proving compliance increasingly competes with substantive security work, and that workforce shortages and a persistent gap between information technology auditors and operational technology environments compound these difficulties across the lifecycle. Because the ultimate purpose of the standards is to prevent cyber events from producing physical harm, we connect these findings to the power engineering literature on cyber-physical risk in substations and argue for a shift from compliance-driven practice toward engineering-based methods that use system modeling, risk quantification, and analysis of cascading effects. We close with a roadmap for modernization built on risk-based auditing, flexible standards, specialized auditor training, and automation, with the goal of moving beyond mere compliance toward measurable operational resilience.
This article explores the role of AI in securing IEC61850-based communication protocols within digital substations, emphasizing the potential and challenges of applying AI in this context. It highlights various AI techniques used for cybersecurity of IEC61850 communication, such as machine learning and deep learning, and discusses their strengths and limitations. It highlights both the promise and the limitations of rule-based and current AI approaches. While many machine learning (ML) models achieve impressive results in controlled settings, challenges related to data scarcity, class imbalance, real-time constraints, and explainability need focused efforts to build operators’ confidence for wider deployments. By articulating these challenges and distilling practical lessons from live deployment and comparative benchmarking, this article aims to provide a roadmap for utilities, vendors, and researchers seeking to deploy AI responsibly in safety-critical grid environments.
Power systems are large scale cyber-physical critical infrastructure systems whose electrical reliability and resilience is made possible by numerous interrelated operation and control subsystems that span diverse timescales from subcycle protecton and control to multi-year long-term planning. Threats to power systems are multifold and include myraid sources ranging from weather, to accidental failures, to intentional adversaries. In defending the resilient operation of these systems against such threats, it is crucial to take a holistic resilience-oriented approach: operating through failure. Operating through failure is defined as continuing to sustain the critical functions of the system, to ensuringe the reliable delivery of power to consumers during a disturbance, specifically especially whenduring events that may cause or require the degradation of some systems or non-ideal operation. This includes both cyber-resilience, partially achieved though network segmentation, as well as physical operational reliability, achieved though engineering in planning and operations[1]. Here, we would like to expand upon a particular element of that type of resilience-preserving response of defense: network defense. In particular, since power system communication and control networks are a crucial part of the infrastructure that underpins the resilient monitoring and operation of power systems, we focus in this article on the segmentation of these networks, including the design and deployment of proper firewall rules that enforce who can talk to whom on a network. Firewalls are a crucial element of network defense in these power systems, used to segment informational and operational technology networks, ensuring that only authorized users can remotely access/operate systems. Firewalls are configured with rules to block unwanted traffic, and there may be thousands of rules in a firewall. This type of defense is often referred to as perimeter defense because a firewall traditionally functions like a gatekeeper that decides what traffic to allow. However, recent years have seen a revolution in artificial intelligence (AI) technology, with systems transforming from passive, prompt-driven assistants to agentic AI, which provide capabilities as autonomous systems that can formulate plans, make decisions, and execute actions to achieve a goal. The electric power industry is now at a crucial inflection point, where it must address how these ever-evolving agentic AI capabilities and supporting infrastructures can potentially transform its resilience and defense capabilities. The cyber-physical power system defense ecosystem is a key area of interest, where a crucial element for the safe deployment of these technologies involves carefully assessing and evaluating their limitations, vulnerabilities, and risks. In this article, we explore the question: “How can machine learning help us with network defense?” We consider how network segmentation plays a role, and we offer possibilities for how these technologies can come together to enable more cyber-resilient power system operations.
The electric power grid is undergoing a fundamental transformation driven by the widespread deployment of distributed energy resources (DERs), digital substations, advanced metering infrastructure (AMI), and Industrial Internet of Things (IIoT) devices. Cloud platforms and edge computing are increasingly used to support advanced analytics, asset management, and real-time control. While these technologies improve flexibility and efficiency, they also expand the cyber-physical attack surface by increasing connectivity across field devices, substations, DER fleets, control centers, enterprise systems, and third-party services. As a result, cybersecurity incidents and physical consequences are now tightly coupled, elevating the potential impact on grid reliability and safety. Recent cybersecurity campaigns against electric utilities energy infrastructure, such as Colonial Pipeline ransomware (2021) and Volt Typhoon (2021), show a shift in attacker behavior. The goal is often stealthy access and long-term presence, rather than immediate disruption. This trend challenges perimeter-focused defenses and reactive security practices. Utilities are expanding monitoring across information technology (IT) and operational technology (OT) environments. Regulatory requirements, including the North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP-015) standards, are also encouraging broader visibility. Still, many security models were designed for enterprise IT systems. They do not translate easily to power system environments, where signature-based detection, log-centric analytics, and external indicators of compromise may be less effective. When cybersecurity activity blends seamlessly into normal grid operations, how can operators distinguish it before it affects reliability? These limits point to the need for a next-generation grid-focused Security Operations Center (SOC). Such a SOC should connect visibility across IT, OT, cloud, and edge environments. It should also reflect a deep understanding of grid operations. Artificial intelligence (AI)-driven analytics can support future grid SOCs through scalable anomaly detection, cross-domain correlation, and operationally meaningful insights. This article examines how an AI-enabled SOC can bridge the gap between cybersecurity and physical domains by providing intelligent, grid-aware monitoring and analytics to enhance the resilience, reliability, and security of modern power systems.
The goal of this special issue is to publish the state-of-the-art cybersecurity challenges and emerging trends, research and industry practices that leverage AI-enabled solutions for grid’s security and resiliency. While the adversaries increasingly leverage AI for developing attacks, the system defenders have a huge responsibility and opportunity to adopt AI models, algorithms, and agentic frameworks for developing robust cyber defense solutions and countermeasures for the entire cybersecurity lifecycle—attack deterrence, attack prevention, anomaly detection, attack mitigation, system resilience, attack attribution and forensics. While the current R&D efforts and industry tools focused on AI-driven solutions for anomaly detection and mitigation, utilizing AI for other aspects of cybersecurity lifecycle are yet to be fully explored. Moreover, the dynamic nature of data security and privacy requirements necessitate advanced AI models, such as reinforcement learning and federated learning, to realize privacy-preserving data sharing and distributed decision making among utilities and system operators. It is to be noted that the AI-based solutions must be inherently secure themselves against adversarial attacks and should not result in any negative consequences to grid operations, such as violation of latency or operational constraints, or leakage of sensitive data. The cybersecurity solutions must continuously adapt and evolve to deal with the growing threat landscape and to leverage the fast-paced innovations in AI. The cyber defenses could be deployed at multiple layers of the grid infrastructure, namely, within the substation, at the Supervisory Control and Data Acquisition (SCADA) network, at the control center, and at the grid edges (e.g., microgrid controllers) ensuring their feasibility, efficacy, interoperability, and scalability. This special issue includes seven papers, contributed by reputed academic researchers and industry experts, that cover a broad range of cybersecurity challenges facing the grid in the AI era and discuss several practical solutions to address them.
When considering threats to the grid, Artificial Intelligence (AI) offers the promise of reducing the burden on staff, leveraging their time and allowing them to focus where a hands-on response is required. While concerns over the loss of jobs and malignment of the AI currently exist, there is substantial opportunity offered to inform an improved response to threats that historically were not possible. While I will briefly address the mentioned concerns, my view will focus on the overlooked opportunity. That is, while some look exclusively at AI as saving money, I suggest the pathway to Interdisciplinary response to threats, and perhaps transdisciplinary, is paved by AI.
As electrification accelerates and distributed energy resources (DERs) become more prevalent, utility-scale dc microgrids (MGs) are emerging as a technically viable and forward-looking solution for modernizing grid infrastructure. These systems enable higher operational efficiency, streamlined integration of renewable energy and energy storage systems, and advanced control functionality. Their inherent characteristics make them particularly well suited to enhance grid resilience and operational flexibility. This article provides insights into the design, implementation, and operational experiences of utility-scale dc MGs, with a focus on their role in enhancing grid reliability and resilience. It reviews a range of electrical architectures currently deployed or proposed for such systems, analyzing their technical characteristics and implementation considerations. The article also explores hierarchical control strategies, utility interconnection methods, grounding and protection schemes, and the interoperability of dc systems with existing ac infrastructure in the context of a real-world utility dc MG. Contributions from utility operators, developers, and consultants offer a multistakeholder perspective on integration challenges, technology readiness, and long-term serviceability. A key highlight is the operational experience of Tampa Electric Company (TECO) in integrating a dc MG into its distribution system, providing valuable real-world insights into deployment practices. Finally, the article discusses future trends, including emerging applications such as data centers and meshed dc MG networks. By addressing both technical approaches and practical challenges, this work supports the broader adoption of utility-scale dc MGs as a key enabler of resilient, flexible, and decarbonized energy systems.
Historically, distribution alternating current (AC) networks were designed to operate in a predictable manner, making monitoring, protection, and control relatively straightforward. Radial AC feeders, a dominant source at the substation, and healthy/nominal fault currents gave protection engineers a solid starting point for protection settings and coordination. Time-current curves, fuse-recloser coordination, and a few well-placed directional elements were usually enough to ensure selective, secure, and reliable protection. That world is disappearing. Across the globe, distribution grids are being rewired with power-electronics-based components, including direct current (DC) links, electric vehicle (EV) fast chargers, data centers, and rooftop photovoltaic (PV) and battery systems, all competing for space on networks that were never designed for them. Hybrid AC-DC distribution networks play a key role in this transformation. DC feeders now support EV charging and building microgrids, while low-voltage DC (LVDC) schemes enhance efficiency. Medium-voltage DC (MVDC) branches provide power for large industrial and information and communication technology loads. These DC components are increasingly connected to existing AC networks via a dense layer of converters. These converters change the nature of fault current distribution, waveforms, and magnitudes. Short-circuit currents can be tightly limited; can last only a few milliseconds; and may not appear "large" compared with the normal load, i.e., the nominal current. Power can flow in multiple directions at once. An event on a DC branch can ripple back into the AC system via complex converter controls. Under these conditions, relying on traditional overcurrent-based protection coordination and fuse-recloser philosophies becomes dangerously optimistic. This article examines what protection coordination entails when the distribution network transitions to a hybrid AC-DC system and how this change impacts the principles that have guided protection engineers for generations. We first review the fundamentals of protection coordination in classical AC distribution networks, then explore the impact of hybrid architectures on selectivity requirements. Building on this, we present emerging concepts for zone- and time-based coordination across AC and DC segments, emphasize the crucial role of interface protection at converters, and illustrate these ideas with a stylized urban feeder example. Our goal is to demonstrate how the existing practices must be adapted: from a world where fault current alone determined where to trip, to one where coordination must be deliberately designed across new timescales, understanding how fault currents behave and how new technology can support protection coordination of future distribution networks.
With the rapid growth of renewable resources, the steady increase in electricity demand, including large-scale data centers and artificial intelligence training facilities, and the heightened occurrence of extreme weather events, today’s power systems are operating under conditions far more volatile than those of previous decades. Under such circumstances, state estimation has become critically important for ensuring the stable and secure operation of power systems.
As DC power sources and DC loads are connected to the power system on a large scale, the conventional AC distribution systems are reaching their limitations. In response, medium-voltage DC (MVDC) distribution systems are emerging as an alternative for the next-generation distribution system. In the Republic of Korea, the goal is to operate a hybrid AC/DC distribution system by 2030, and partially replacing existing AC distribution systems with DC distribution systems is being considered. This article investigates the issue of nearby transformer saturation that may occur when an MVDC distribution system replaces an existing AC distribution system and introduces countermeasures to prevent transformer saturation.
As medium-voltage (MV) dc networks gain traction in response to the rapid growth of distributed energy resources (DERs), data centers, and electric vehicles, MV hybrid ac/dc distribution networks—enabled by modular multilevel converters (MMCs)—are emerging as a key architecture for next-generation power systems. These hybrid systems integrate MVdc subsystems into existing ac infrastructures, creating new challenges in protection system design due to fundamentally different fault behaviors in dc networks and the lack of standardized fault analysis methods. Moreover, the interaction caused by ac/dc inverter alters fault characteristics of ac distribution system also. This article presents a comprehensive approach to fault current analysis in MMC-based hybrid ac/dc distribution networks. It introduces an equivalent circuit model-based fault current calculation methodology and highlights a dedicated fault calculation tool developed through a national research project in South Korea. The accuracy of this tool is verified against detailed electromagnetic transient simulations in PSCAD, demonstrating its practical applicability for protection studies in emerging hybrid grid environments.
Modern electrical distribution systems are transitioning toward hybrid AC/DC architectures to efficiently integrate renewable energy and DC-native technologies. This article provides an overview of the structural components and computational challenges inherent in these complex networks, focusing on the critical role of load flow analysis. It examines various modeling methodologies, such as sequential and unified frameworks, while addressing the unique impacts of active power electronic converters. Ultimately, these robust analytical tools serve as the foundation for essential applications including system planning, hosting capacity studies, and real-time grid optimization.
As the energy sector transitions toward increased renewable integration and bidirectional grid operation, the complexity and frequency of disturbance events rise, necessitating advanced situational awareness. Robust expert systems are needed that leverage a multilayered wide area monitoring, protection, and control (WAMPAC) architecture, integrating device-level detection, data aggregation, and an adaptive event classification and validation framework facilitated by dynamic incremental learning (DIL). These expert systems address challenges such as concept drift, catastrophic forgetting, and the need for human-in-the-loop oversight, enabling rapid and accurate identification of both known and novel disturbance events that can be expected in the future.
Transformer research is a specialized area of electrical engineering that requires a high level of investment in laboratory infrastructure. Many high-voltage (HV) and insulation research facilities have closed at numerous universities over the last three decades. However, due to the increasing proliferation of renewable energy sources, the need for power transformers has increased; concurrently, there has been a global shortage in the supply of new transformers. These issues therefore support the need for innovative research into power transformer design, particularly the use of transformer operation in a renewable-dominated power grid, as well as the use of sustainable materials for transformer construction, e.g., natural ester oil replacing mineral oil. The training of future engineers and the upskilling of the current workforce with specialist knowledge in transformer design and operation is becoming more important than ever. To this end, several global research-intensive universities have formed a virtual alliance, the University Transformer Research Alliance (UTRA), to share research and training expertise in power transformers. This article introduces power transformer research and training activities in eight universities across Asia, the Pacific, Europe, and North America.