What is Cyber-Informed Engineering?
Cyber-Informed Engineering (CIE) is a design methodology in which engineers address cyber risk from the concept phase onwards, so that a digital attack on a physical installation cannot cause an unacceptable consequence such as an explosion, a flood or a prolonged outage. The methodology comes from Idaho National Laboratory (INL) and the US Department of Energy (DOE). Where conventional cybersecurity adds controls to a system after the fact, CIE tries to engineer out the risk: through process design, physics and mechanics rather than through firewalls and monitoring alone.
π°οΈ Where does Cyber-Informed Engineering come from?
CIE took shape at INL from the mid-2010s, building on the laboratoryβs long-running research into cyberattacks with physical effects, such as the Aurora generator test of 2007. The key milestones:
| Year | Milestone |
|---|---|
| 2015 | Robert Anderson and Joseph Price (INL) present CIE as a new, risk-informed design methodology |
| 2017 | INL report Cyber-Informed Engineering, prepared for the DOE Office of Nuclear Energy |
| 2019 | Section 5726 of the US National Defense Authorization Act for FY2020 directs DOE to develop a national CIE strategy |
| 2021 | The book Countering Cyber Sabotage by Andy Bochman and Sarah Freeman (INL) introduces CCE to a wide audience |
| June 2022 | DOE publishes the National Cyber-Informed Engineering Strategy, built on five pillars |
| August 2023 | INL publishes the CIE Implementation Guide, version 1.0 |
The five pillars of the strategy are awareness, education, development of the body of knowledge, current infrastructure and future infrastructure. Although the strategy was written for the energy sector, it is explicitly intended as a model for other critical infrastructure sectors. A CIE Community of Practice with more than 200 practitioners helped turn the principles into the Implementation Guide.
π§ What are the 12 principles of CIE?
The national strategy divides CIE into six design and operational principles and six organisational principles.
| # | Principle | OT example |
|---|---|---|
| 1 | Consequence-focused design | Start with functions where digital manipulation leads to disaster, such as chlorine dosing at a drinking water plant |
| 2 | Engineered controls | A mechanical overspeed trip on a turbine or a pressure relief valve on a reactor vessel |
| 3 | Secure information architecture | Let data flow only in the intended direction, for example through a data diode |
| 4 | Design simplification | Leave unused functions, web servers and remote access out of field devices |
| 5 | Resilient layered defenses | Defence in depth, redundancy and diversity, so that one failure cannot cascade |
| 6 | Active defense | Detection that isolates an intruder while the process keeps running |
| 7 | Interdependency evaluation | Process, safety and maintenance disciplines jointly reviewing digital dependencies |
| 8 | Digital asset awareness | An up-to-date inventory of hardware, firmware and software per installation |
| 9 | Cyber-secure supply chain controls | Security requirements in specifications and contracts for vendors and system integrators |
| 10 | Planned resilience with no assumed security | Manual operation and local control keep working when the network is compromised |
| 11 | Engineering information control | Protecting P&IDs, configurations and test reports against leakage |
| 12 | Cybersecurity culture | Making cybersecurity as natural as the safety culture already is |
The first principle is the foundation: CIE focuses scarce engineering effort on the handful of functions that genuinely matter.
π§ How does Consequence-driven Cyber-informed Engineering (CCE) work?
CCE is INLβs practical method for applying CIE to an existing organisation. It starts from three baseline assumptions: the adversary already has logical and physical access (including credentials, IP addresses and firewall access), understands the process and is well resourced. The question is therefore not whether the network will be penetrated, but what an attacker can do physically once inside. CCE has four phases:
- Consequence prioritisation β determine which events would be catastrophic for the organisation and prioritise them as High Consequence Events (HCEs), for example a chemical overdose in drinking water.
- System-of-systems analysis β map every system, person, process and supplier involved in each HCE and look for unverified trust: places where the design blindly relies on digital signals.
- Consequence-based targeting β think like the adversary: what knowledge, access and steps are needed to cause the HCE? The output is a fully developed attack scenario.
- Mitigations and protections β first remove the possibility of the physical effect through an engineering or process change (a protection). Where that is not feasible, use the attack scenarios for targeted detection and other mitigations, categorised using the functions of the NIST Cybersecurity Framework.
π How does CIE relate to process safety?
CIE deliberately builds on the culture of process safety. A HAZOP systematically examines deviations in a process; a LOPA determines how many independent protection layers are needed; a SIS designed to IEC 61511 intervenes when the process gets out of control. Those analyses, however, assume random failures and human error, not an intelligent adversary who can disable several layers at once.
The TRITON attack on a petrochemical plant in Saudi Arabia in 2017 showed that the safety system itself can be the target. CIE therefore asks of every protection layer: is it digital, and can the same attacker reach it? Non-digital layers such as a pressure relief valve, a bursting disc, a mechanical overspeed trip or a hardwired interlock cannot be hacked. They form the last, deterministic line of defence. In this way CIE extends functional safety with the question of which failure scenarios could be caused deliberately.
π§± How does CIE differ from IT security and IEC 62443?
CIE does not replace IEC 62443; it shifts the focus from the network to the physical process. The Implementation Guide explicitly aligns with the risk assessment approach of IEC 62443-3-2.
| Aspect | Traditional IT security | IEC 62443 risk assessment | CIE / CCE |
|---|---|---|---|
| Starting point | Information and systems | Zones, conduits and the system under consideration | Physical consequences and critical functions |
| Who does it | Security team | Asset owner, integrator and supplier | Process engineers together with security specialists |
| Point in lifecycle | Often after handover | Design and operation | From the concept phase |
| Typical control | Patching, endpoint protection, MFA | Security levels, segmentation, component requirements | Process design, physical safeguards, simplification |
| Assumption about attacker | Keep them out | Target security level per zone (SL-T 1β4), matched to attacker capability | Attacker is already inside and knowledgeable |
| Outcome | Lower likelihood of an incident | Demonstrably secured architecture | Unacceptable consequences are no longer achievable |
CIE is also the physical counterpart of security by design. Secure-by-design for software is about removing design flaws in code; CIE carries that idea through to pipes, valves, motors and control loops, long before software and security controls are added.
π How do you apply CIE in a European project?
Take the construction of a new treatment step at a Dutch drinking water company, or an extension to a chemical plant covered by the Seveso III Directive (see Seveso and Cybersecurity). A practical approach:
- Define the unacceptable consequences β for example an overdose of sodium hypochlorite, a supply area running dry or a toxic release. Use existing HAZOP and quantitative risk assessment scenarios as a starting point.
- Map the digital paths β which PLCs, SCADA screens, remote connections and suppliers can influence each scenario?
- Design physical limits β size the dosing pump so that its maximum capacity physically stays below the hazardous dose, and add a pressure relief valve and a hardwired high-level trip that bypasses the PLC.
- Simplify and segment β disable unused functions and separate the SIS from the basic process control system.
- Write it into the tender and contract β include IEC 62443 requirements and CIE principles in the procurement documents.
- Safeguard manual operation β rehearse running the process with the control network switched off.
- Repeat for every change β add cyber consequences to the management of change process.
This approach supports the risk management duty of care under NIS2 and its national transpositions, and the product requirements of the Cyber Resilience Act. The attacks by groups such as Sandworm on the Ukrainian power grid in 2015 and 2016 show why physical fallback options are so valuable: operators restored power by switching substations manually.
β Frequently asked questions
What is the difference between CIE and CCE?
Cyber-Informed Engineering (CIE) is the broad framework of twelve principles for addressing cyber risk across the whole lifecycle of an installation. Consequence-driven Cyber-informed Engineering (CCE) is a specific four-phase method for applying those principles to the most critical functions of an existing organisation. CCE is therefore a focused application within CIE.
Is Cyber-Informed Engineering a standard?
Cyber-Informed Engineering is not a formal standard with certification but a methodology from the US Department of Energy and Idaho National Laboratory. The CIE Implementation Guide of 2023 translates the principles into questions for each lifecycle phase. For certifiable requirements, you combine CIE with standards such as IEC 62443 and IEC 61511.
Can I apply CIE to an existing plant?
Yes, Cyber-Informed Engineering is most effective in new builds, but existing installations benefit too. The CCE method was in fact developed for existing infrastructure: you identify the worst consequences and then look for targeted changes, such as an additional mechanical safeguard or the removal of an unnecessary connection.
Why are mechanical safeguards so important in CIE?
Mechanical and hardwired safeguards, such as pressure relief valves and overspeed trips, contain no software and therefore cannot be manipulated remotely. Within Cyber-Informed Engineering they form the last deterministic protection layer, one that still works when every digital system has been compromised.
Who carries out Cyber-Informed Engineering?
Cyber-Informed Engineering is carried out by process engineers, designers and technicians working together with OT security specialists. The engineers understand the physical process and its failure modes; the security specialists understand attack techniques. That multidisciplinary collaboration is the core of CIE.
Is CIE only intended for the energy sector?
The 2022 National CIE Strategy was written for the US energy sector, but its principles apply to any installation with digital control. Cyber-Informed Engineering is also used in drinking water, wastewater, chemicals and manufacturing, and fits well with European legislation such as NIS2.
π In summary
Cyber-Informed Engineering engineers cyber risk out of an installation by assuming the attacker is already inside and choosing a design in which an unacceptable physical consequence is no longer achievable. With twelve principles, the four-phase CCE method and non-digital protection layers, CIE complements IEC 62443 and process safety at the point where controls are cheapest and strongest: in the design.
