Dive Brief:
The National Renewable Energy Laboratory (NREL) recently released two reports introducing cybersecurity tools designed to enhance utility asset management, risk evaluation, and visibility into industrial control systems (ICS) integrated with the U.S. electric grid.
One of these tools, the Cyber100 Compass application, is available for utilities to pilot. This application models cyber risks associated with energy system upgrades. Another report, focusing on the runZero cyber asset attack surface management (CAASM) system, found that its scanning methods can uncover hidden risks within a utility system without impacting the performance of ICS assets.
As the power grid becomes more decentralized and reliant on renewable energy, uncertainty about the risks associated with this transition is prevalent. Maurice Martin, a senior cybersecurity researcher at NREL, noted that utilities face challenges in understanding their risk exposure, which can hinder progress.
Dive Insight:
NREL’s Cyber100 Compass offers a novel approach to managing cyber risk for utilities. It combines expert data with user-provided information to conduct a probabilistic risk assessment, estimating potential financial losses from cyber attacks, including those that might cause power outages.
The application requires utilities to input details about their current energy systems and future plans, providing insights into how these upgrades could affect their cybersecurity stance and risk levels. Although still a proof of concept, Cyber100 Compass represents a significant step towards providing guidance for system planners on potential cybersecurity risks as they incorporate more renewable energy.
NREL encourages utilities to request access to Cyber100 Compass in exchange for feedback on its interface, usability, and results. Utilities must supply data on their risk tolerance and the value they place on avoiding specific types of cyber attack-induced physical events, such as power losses and equipment damage.
Maurice Martin emphasized that Cyber100 Compass aims to leverage expert knowledge in a reusable format applicable to various utilities, offering a monetary expression of risk to aid decision-makers in planning upgrades.
In a separate report, NREL’s Clean Energy Cybersecurity Accelerator (CECA) evaluated the effectiveness of runZero’s CAASM system. The assessment showed that runZero’s platform successfully identified all internet-protocol-addressable assets in the test environment, gathering detailed information about each device and its open ports without adversely affecting ICS assets or ongoing supervisory control and data acquisition processes.
Active scanning, as opposed to passive scanning, involves sending data to assets and analyzing their responses. While traditionally considered unsafe in operational technology (OT) environments due to bespoke assets, legacy firmware, or proprietary protocols, runZero’s platform demonstrated that active scanning can be conducted safely.
Rob King, runZero’s director of security research, highlighted the importance of this collaboration with CECA in proving the safety and efficacy of active scanning for OT/ICS infrastructure. Nick Blair, CECA’s technical team lead, noted that the successful use of active scanning in OT systems could pave the way for wider acceptance of this method.



