The main causes of electric power outages are natural calamity and various technical challenges. Technical challenges include cyber issues. We have used a correlation analysis to explore relationships between 56 Norwegian grid operators’ cybersecurity levels and outages. We have collected technical risk scores through BlackKite’s technical cyber rating tool and management risk scores from a survey performed by the Norwegian Water Resources and Energy Directorate. Further, we collected outage data from the Norwegian Transmission System Operator. Our results show no clear relationship between grid operators’ cybersecurity level and outages. In an extension of our analysis, we found strong correlation between distribution substations and load disconnectors, and outages. Future work may therefore concentrate on cybersecurity specifically for these two grid component categories.
The introduction of smart metering systems is a paradigm shift for the power grid. New business cases such as virtual power plants and local flexibility markets are evolving. Security risks and the potential consequences of smart-grid-enabled business cases have been assessed by researchers. However, the research efforts have not ranked the business cases according to their potential disruptive consequences, which makes it difficult to prioritize risk reduction measures. This chapter describes the results of a survey of market players that sought to rank smart-grid-enabled business cases based on their perceptions of cyber attack consequences. As expected, the consequence perceptions of the market players vary considerably between the business cases. Consequence scenarios suggested by the market players are employed to explain the highest-ranked business cases, which include digital twins, remote access to smart meter circuit breakers, and grid flexibility and balance management. The survey results can support governments and market players in assessing power grid risk and prioritizing risk reduction measures.
The transformation of conventional power grids to smart grids over the past decade has led to increased exposure to cyber attacks. Understanding the impacts of cyber attacks is essential to selecting appropriate mitigation strategies. This research examines the evolution in the understanding of the consequences of cyber attacks on smart grids. It has explored the literature on consequence verification during risk assessments of smart grids from 2009 to 2023. A total of 839 articles were collected. After filtering duplicate and irrelevant articles, deep content analysis yielded 125 articles that assessed cyber risks to smart grids, with 67 of them also focusing on real consequence verification. Further study identified 23 smart-grid-enabled business areas impacted by cyber risks and six methods for verifying the real consequences of cyber attacks on smart grids. Real consequence verification is important because it helps identify the most critical smart grid vulnerabilities and prioritizes efforts for mitigating cyber attacks and their negative impacts.
This chapter discusses ongoing developments in cyber security regulations in the Norwegian energy sector through research and government-industry cooperation. The focus is on cyber security policies for Norwegian electric power supply entities at the strategic, tactical and operational levels. The chapter promotes the integration of regulatory requirements with traditional cyber security standards tailored to electric power supply entities and highlights how the integration contributes to effective cyber security governance and risk management.
Digital vulnerabilities and the risk of cyberattacks against the electric grid are a concern for both governments and businesses. There are several opportunities for authorities to impose security measures on grid operators to reduce risks. German legislation requires grid operators to certify their information security management system according to the ISO/IEC 27001 standard. Some researchers have tried to measure various effects of ISO/IEC 27001 certification, but nobody has so far assessed the effect of certification on technical security performance. This study hypothesizes that ISO/IEC 27001 certification will lead to increased technical security performance for Norwegian grid operators. A Quasi-Experimental methodology based on Difference in Differences logic is applied to test the hypothesis. 11.010 technical security scores from 400 entities were collected through BlackKite’s Technical Cyber Rating tool and Security Scorecard’s Security Rating tool. The effect of ISO/IEC 27001 certification was estimated by taking the difference in technical security performance between uncertified Norwegian grid operators and certified German grid operators, and subtracting the difference between a control group of Norwegian and German banks. The analysis predicts a significant positive effect for small Norwegian grid operators, it is inconclusive for medium-sized grid operators, and it indicates a negative effect for large grid operators. Since the research was limited to externally identifiable security mechanisms only, more research is necessary to fully understand the effect of ISO/IEC 27001 certification on technical security performance.
Advanced metering systems deployed in Europe are enablers of distributed power production where prosumers can feed surplus energy into the grid. Successfully managing complex energy systems requires real-time data access, flexible production and rapid demand response. The accompanying need for data storage capacity and processing power has rendered cloud services an attractive option. However, at this time, European cyber security legislation related to advanced metering systems does not reflect the broad usage of cloud technology. This chapter describes an advanced metering system reference model based on the cloud profiles of five distribution grid operators. It identifies cloud-related gaps in current European Union cyber security legislation applicable to advanced metering systems. The gaps are identified via a holistic mapping of security principles from prominent cloud security frameworks to existing European Union legislation. A novel, advanced metering system security policy framework that covers all the identified cloud security gaps is specified. The security policy framework is an important first step towards cloud-ready security legislation for advanced metering systems. Authorities overseeing cyber security and energy resources can employ the policy framework as a starting point for a broad debate among the various stakeholders to institute cloud-ready security policies for advanced metering systems.
Protecting industrial control systems against cyber threats has become more pressing in the last decades. An increasing number of released vulnerabilities specifically targeting industrial systems makes protecting them exceedingly challenging. Incident detection is essential in protecting industrial systems, and this paper examines the state of the art in this area. The focus is on the research aspect, and the paper investigates "How has the research on the detection of cyber threats in industrial control systems evolved over the years?" This survey has explored research covering incident detection in industrial control systems from 1950 until today and reviewed a total of 750 papers, most of them published after 2003. After screening, 239 papers were relevant for a deeper exploration. The study reveals an increasing trend of published papers addressing detection capabilities in industrial control systems, with a rise in published papers from 2011. 86% of these research papers address standard features characteristic of industrial control systems, and 58% of the papers suggest using data from physical processes. However, most studies have a low technology readiness level; only 38 papers cover testing in a live test environment, and none cover testing in a system in operation. The overall findings show that, given the development of the threat landscape, and the urgency of good detection capabilities, there is a need for further research on detecting cyber threats using combined data sources in a live testing environment.
Identity fraud is a serious problem which can be used to conduct crimes such as economic fraud, human trafficking and terrorism. Many organizations have pointed out challenges in performing identity control, and a more operable framework for identity proofing and verification is desired in many practical applications. Although there are several guidelines and international standardization activities available on identity proofing and verification routines, complexity and variation among these frameworks can make them complicated to interpret and understand and thus little operable, particularly for smaller organizations performing identity control. Against the increasing trend of identity fraud worldwide, this paper proposes an Evidence of Identity (EoI) evaluation system design aiming at operationalizing requirements to evidence of identities in ID proofing and verification processes. The suggested system is designed to be included in a computer application, allowing easy use by front-desk officers.