Cyber-Informed Engineering
Cyber-Informed Engineering (CIE) integrates engineering and cybersecurity practices to help manage cyber risk throughout the lifecycle of critical systems.
What is Cyber-Informed Engineering?
Cyber-Informed Engineering is an engineering approach that reduces the consequences of cyberattacks by designing systems so digital compromise cannot easily translate into physical harms.
This is achieved by identifying undesired system consequences and incorporating engineered controls and design features — such as manual overrides, analog redundancy, resilience mechanisms and functional isolation — that constrain or limit the harm an adversary can cause, even with full digital access.
CIE enables engineers to treat cyber risk as an element of engineering risk management and incorporate appropriate controls throughout the lifecycle of engineered systems.
CIE Knowledge Hub
Foundational guidance, tools and resources supporting the National Cyber-Informed Engineering Strategy.
CIE Resource Library
Implementation guides, publications and reference materials that help designers, manufacturers, vendors, asset owners and operators apply CIE principles.
Join the CIE Community of Practice
The Community of Practice connects engineers, operators, researchers and organizations advancing Cyber-Informed Engineering through collaboration, knowledge sharing and practical implementation.
Participation includes quarterly community meetings, focused working groups and opportunities to share implementation guidance, tools and practical experience.
Second Wednesday of January, April, July and October | 11am MT / 1pm ET
Multi-stakeholder team to aid the translation of CIE into technical requirements that can inform guidance, practices, and standards development.
Support integration of CIE into engineering and cybersecurity standards.
Develop curricula that integrate CIE principles into engineering degree programs.
Develop CIE implementation guidance and an open-source library of resources.
All monthly meetings held at 9am MT / 11am ET
Why Traditional Cybersecurity Isn't Enough
Traditional engineering and cybersecurity each address different types of risk. Traditional engineering focuses on preventing failures and human error, while cybersecurity focuses on protecting digital systems and information. Cyber-Informed Engineering builds on both by addressing what happens when digital compromise could create unacceptable physical consequences.
Traditional Engineering
- Designed to protect against failures or human error that affect safety, reliability and system performance.
- Does not address sophisticated adversaries who deliberately manipulate control logic, sensor inputs or system states via digital means.
Traditional Cybersecurity
- Focuses on protecting the confidentiality, integrity and availability of information within digital systems, making unauthorized access more difficult to achieve.
- Does not address how digital compromise can create unacceptable physical consequences.
Cyber-Informed Engineering
- Incorporates protection from digital risk into core engineering decisions.
- Extends protection beyond the digital domain and into engineered systems so cyber compromise cannot produce unacceptable physical outcomes.
CIE addresses the gap between traditional engineering and cybersecurity by incorporating protection from digital risk into core engineering decisions. It expands defenses from cyber risk beyond the digital domain and into engineered systems so cyber compromise cannot produce unacceptable physical outcomes.
Cyber-Informed Engineering Resources
Whether you’re implementing Cyber-Informed Engineering, developing curriculum or expanding your expertise, these materials support every stage of CIE adoption—from foundational guidance to practical application and ongoing professional development.
Implementation
Start with the key resources, reference materials and engineering tools that help organizations implement Cyber-Informed Engineering throughout the engineering lifecycle.
Foundational Resources
CIE Knowledge Hub
Foundational guidance, tools and resources developed to support the National CIE Strategy, strengthen energy sector resilience and advance Cyber-Informed Engineering adoption.
CIE Resource Library
Implementation guides, publications and reference materials that help designers, manufacturers, vendors, asset owners and operators apply CIE principles.
Implementation Guide
A comprehensive reference describing CIE principles and the engineering considerations teams should evaluate throughout each phase of a system’s lifecycle.
Engineering & Analysis Tools
Engineering Controls Database
Provides examples and guidance for defining, selecting and applying engineered controls within Cyber-Informed Engineering.
CIE Analysis Tool (CIEAT)
Supports the deployment and management of energy systems by incorporating Cyber-Informed Engineering principles into system planning and analysis.
Microgrid Analysis Tool (CIEMAT)
Supports microgrid planning and analysis by incorporating Cyber-Informed Engineering principles into microgrid and energy system design.
Battery Energy Storage Systems Analysis Tool (CIEBAT)
Supports battery energy storage system analysis as part of the CIEMAT ecosystem, helping evaluate cyber-informed engineering approaches for Battery Energy Storage Systems (BESS).
Gas Compressor Station Analysis Tool (CIEGAS)
Supports gas compressor station analysis by helping designers and operators identify critical functions and engineering mitigations that reduce the impacts of cyberattacks.
Education & Curriculum
Extend Cyber-Informed Engineering beyond implementation by supporting classroom instruction, curriculum development and workforce preparation.
CIE in Higher Education
More than 22 universities have incorporated Cyber-Informed Engineering into engineering courses and certificate programs, helping prepare the next generation of engineers to address cyber risk through engineering.
Explore curriculum resources, teaching materials and adoption guidance to support CIE implementation at your institution.
Professional Development
Stay current with evolving Cyber-Informed Engineering practices through recorded presentations, guided exercises and featured perspectives from across the CIE community.
On-Demand Webinars & Conference Recordings
Introduces the core concepts of Cyber-Informed Engineering and demonstrates how CIE principles are applied through a practical engineering case study.
A nine-part video series exploring the principles of CIE and the engineering mindset behind designing systems that reduce the physical consequences of cyberattacks.
CIE News & Insights
May 26th, 2026
Features testimony from Virginia Wright, INL CIE Program Manager, before the House Science, Space, and Technology Committee on strengthening the resilience of U.S. water systems through Cyber-Informed Engineering.
Idaho and INL Lead the Charge in Cyber-Informed Engineering to Protect Water Systems
Highlights how Idaho and INL are advancing CIE to improve the resilience of community water systems through engineering, education and funding initiatives.
Securing U.S. Critical Water Infrastructure in the Energy Sector
Senate testimony examining cyber threats to critical water infrastructure and the engineering approaches needed to improve resilience across the energy sector.
Strategy for Cyber-Physical Resilience: Fortifying Our Critical Infrastructure for a Digital World
National report outlining strategies to strengthen the resilience of critical infrastructure against cyber-physical threats through engineering, technology and policy.
CIE Training Workbooks
Uses a utility SCADA Volt/VAR scenario to apply Cyber-Informed Engineering principles through exercises focused on consequences, engineered controls, layered defenses, active defense and system interdependencies.
Guided exercises that apply Cyber-Informed Engineering principles to a municipal water utility, helping engineering teams identify critical functions, evaluate cyber risks and develop engineered protections.
Uses a community microgrid case study to apply the 12 Cyber-Informed Engineering principles through consequence analysis, engineered controls and system design exercises.
Explores how Cyber-Informed Engineering can strengthen substation design through guided exercises focused on critical functions, resilience and cyber-informed engineering decisions.
Examines the design of an Advanced Distribution Management Systems (ADMS) through guided exercises that identify critical consequences, evaluate digital assets and develop cyber-informed mitigations.
Connect with our Team
Questions about our research, capabilities or collaboration opportunities?
Our team is ready to connect you with the right experts and resources at INL.
Cyber-Informed Engineering (CIE)