Testing Cyber Resilience of Operational Technology in the Energy Sector

CyTRICS partners across stakeholders to identify high priority operational technology (OT) components, perform expert testing, share information about vulnerabilities in the digital supply chain, and inform improvements in component design and manufacturing.

CyTRICS leverages best-in-class test facilities and analytic capabilities at four DOE National Laboratories and strategic partnerships with key stakeholders including technology developers, manufacturers, asset owners and operators, and interagency partners.

CyTRICS PROGRAM SUPPORTS:

  • Supply Chain Executive Orders
  • National Defense Authorization Act of 2020 (Sec. 5726 Pilot Program)
  • Multiple critical infrastructure sub-sectors, including electricity, oil & natural gas, wind and other renewables, hydroelectrics, and other federal partners
  • Expanding laboratories involved
  • Commercial partners for testing

Industrial Control Systems Announcements

https://www.energy.gov/ceser/articles/doe-announces-hitachi-abb-power-grids-participation-cytrics-program

DOE enhance

https://www.energy.gov/ceser/articles/doe-ceser-partners-schneider-electric-strengthen-energy-sector-cybersecurity-and

hitachi energy logo cytrics

Hitachi Energy and INL Testing of Relion® 670 Series’ RED670

Hitachi Energy and the DOE CESER CyTRICS program partnered to perform component enumeration and vulnerability testing of a Relion® 670 Series’ RED670. As a result of the testing, CyTRICS researchers noted significant improvements in the security posture of the Relion® 670 Series firmware over the past 10 years.  Researchers also observed that Hitachi Energy has avoided common security weakness that other industry stakeholders continue to struggle with and has invested in the security of the Relion® 670 Series’ RED670 product.

CyTRICS shared a number of vulnerabilities with Hitachi Energy which were rapidly addressed with the following mitigation alerts published by Hitachi Energy’s Product Security Incident Response Team (PSIRT):

The CyTRICS program team values our partnership with Hitachi Energy and we look forward to further testing opportunities.

Past Announcements

Industrial Control System Advisory (ICSA-21-075-02) - General Electric Universal Relay family

dhs cisa logo

Industrial Control System Advisory (ICSA-21-075-02) – General Electric Universal Relay family
This contains vulnerabilities reported to GE by the CyTRICS program, including high-impact vulnerability, CVSS 9.8

March 16, 2021

Director of National Intelligence Guidance for Energy Sector Supply Chain Assurance

Innovative Components

Prioritization Methodology
An approach to prioritizing OT components for testing that incorporates key factors including operational impact, prevalence, and national security interest. This approach provides a strategic, transparent rationale for testing components that optimizes security impact.

Standardized Testing Process
DOE has developed and refined a standardized approach to enumerating and vulnerability testing firmware and software subcomponents. Standardization ensures consistency, repeatability, and comparability of results, to scale up testing and automation across Labs and partners.

Standardized Reporting and Repository
CyTRICS captures testing results in a standard, bill of materials format that captures granular “digital ingredients” to the subcomponent level, to rapidly identify embedded high-risk components and subcomponents. The program features a central repository of testing results for comprehensive, sector-wide analysis of systemic risks and vulnerabilities.

Vendor Agreements
CyTRICS partners with top manufacturers and utilities in the sector to sign participation Agreements to frame mutual cooperation prior to conducting testing. The standard agreement establishes types of software and firmware testing to be performed, timely disclosure of vulnerabilities identified during testing, and coordinated disclosure of vulnerability information with impacted asset owners, federal agencies, and energy sector stakeholder.

Contact Info

INL NHS Media Contact

Ethan Huffman

Phone: 208-526-5015

Send a Message
  • This field is for validation purposes and should be left unchanged.

DOE Energy Cyber Programs

Virginia Wright

 

Send a Message
  • This field is for validation purposes and should be left unchanged.

Federal Sponsor

DOE logo

Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) addresses the emerging threats of tomorrow while protecting the reliable flow of energy to Americans today by improving energy infrastructure security and supporting the Department of Energy’s national security mission. CESER’s focus is preparedness and response activities to natural and man-made threats, while ensuring a stronger, more prosperous, and secure future for the nation. >> Read more on CyTRICS

Participating Laboratories

inl

oak ridge national laboratory

llnl logo

PNNL Centered Logo Color RGB

px Sandia National Laboratories logo

NREL