The main objective is to develop a fully responsive cyber risk impact awareness tool, Cyber RIAST, that proactively scans the status of the cyber-physical energy system, providing a detailed picture of threat risk metrics and performing impact analysis on the physical energy system resilience. The purpose of this solution is to intervene cyber-attacks from their infancy and avoid the impact of cascading the cyber threats.
The key outcomes are:
- The development of a cyber-physical system risk impact awareness tool through the holistic approach.
- The development of a cyber intelligent system using sophisticated modelling, Machine Learning and Artificial Intelligence methodologies.
- The determination of cyber-physical system risk impact assessment criteria under various risk impact scenarios through both offline and hardware in loop testing.
Benefits
Cyber-RIAST proactively identifies potential vulnerabilities early in the design and operational phase, avoiding cyber-attacks. The impact of cybercrime is difficult to quantify but is estimated to cost the UK roughly £27bn per year.
Learnings
Outcomes
The project has delivered several key outcomes to date, aligned with its staged development approach.
A principal outcome is the development of a prototype Cyber‑Physical Risk Analysis System, capable of integrating physical network simulation outputs with cybersecurity vulnerability assessments. The system enables the calculation of physical resilience indices, cyber resilience indices, and an integrated risk impact index, which provides a holistic view of system vulnerability.
The data interface developed under the project represents a significant achievement, enabling real‑time synchronisation of system parameters such as voltage, current, and power flows with cyber‑physical risk models. This capability supports dynamic risk assessment and enhanced visualisation of system status.
Initial demonstrations using benchmark systems have validated the ability of the platform to compute resilience indices and present results in an accessible format. Quantitative outputs include load shedding levels, voltage profiles, and derived resilience indices under simulated disturbance scenarios.
Whilst the full integration of all modules (including cyber intelligent systems and real‑time lab validation) is ongoing, the project has progressed the method from conceptual development towards an early prototype stage (TRL 3–4). Planned laboratory validation and system integration activities are expected to further increase the TRL during subsequent phases.
The project has also identified opportunities for future work, including extension to larger networks, integration with real‑time operational systems, and enhancement of predictive analytics capabilities through advanced machine learning techniques.
Lessons Learnt
The project has generated several important lessons relevant to future cyber‑physical innovation initiatives within the energy sector.
Firstly, the integration of cyber and physical system models is inherently complex and benefits from a modular development approach. Separating the development of physical resilience models, cyber vulnerability models, and intelligent analytics has enabled parallel progress across work packages, whilst maintaining clear interfaces for later integration.
Secondly, the development of representative cyber vulnerability models requires close collaboration with network operators to ensure alignment with operational practices and cybersecurity frameworks. The use of fragility curves has proven to be an effective method for translating qualitative cybersecurity controls into quantitative risk metrics, although further refinement and validation will be required to enhance accuracy and applicability.
Thirdly, the project has highlighted the importance of scalable data architecture. The implementation of a data interface capable of handling real‑time system parameters and cyber data streams is critical for achieving meaningful situational awareness. Future projects should consider early investment in robust data engineering and integration frameworks.
In terms of technical challenges, limitations associated with simulation environments and hardware resources have constrained the scale of test systems during early development phases. This reinforces the need for access to advanced laboratory facilities, such as real‑time simulators, at earlier stages of development.
Looking ahead, further trialling will be required to advance the method to a higher TRL. This includes large‑scale validation in real‑time simulation environments, integration with operational SCADA systems, and demonstration under realistic cyber‑attack scenarios.
The likelihood of large‑scale deployment is considered promising, given the increasing importance of cyber resilience in power systems and the absence of integrated tools that simultaneously assess cyber and physical impacts. The research and development undertaken to date have been effective in establishing a PoC and demonstrating the feasibility of the approach.