Interdependence and Security of Cyber-Physical Power System (CPPS)
This Technical Brochure examines the interdependence and security of Cyber-Physical Power Systems (CPPSs), where electric power infrastructure is increasingly integrated with communication, computation, control, and social systems. It explains how cyber and physical domains interact through facilities, topologies, and functions, and how these interactions can create new vulnerabilities under natural hazards, cyber threats and coupling failures. The Technical Brochure reviews integrated modelling methods, cybersecurity threats and countermeasures, resilience-oriented planning and operation, cross-domain simulation tools, and cyber-physical-social frameworks. It provides CIGRE members and industry stakeholders with a structured foundation for understanding, assessing, and strengthening secure and resilient CPPSs.
Members
Convenor (CN)
Q. Guo
Secretary (CN)
L. Xu
U. Adhikari (US), G. Azevedo (BR), Y. Chen (CH), J. Csatár (HU), J. Feijoo-Martínez (ES), G. Giraud (FR), J. Huang (CN), S. Li (CA), K. Manyapetsa (ZA), V. Meneguim (FR), F. Mohammadi (CA), W. Zhu (UK)
Corresponding Members
A. Louh (NL), S. Jia (CN), N. Tian (CN)
Modern power systems are under rapid digitalization and increasingly rely on digital monitoring, communication, automation and control systems. Electricity grids are no longer only physical infrastructures composed of generators, transmission lines, substations, distribution networks, and loads. They are increasingly becoming highly digitalized, interconnected, and intelligent systems, where physical electricity flows are continuously monitored, coordinated, and controlled through communication networks, computation platforms, sensing devices, control algorithms, and human decision-making processes. This transformation has given rise to Cyber-Physical Power Systems (CPPSs), which are now fundamental to the reliable and secure operation of modern electric power systems.
This Technical Brochure (TB), prepared by CIGRE Working Group D2.56, provides critical insights into the interdependence and security of CPPSs. It aims to help power system engineers, utilities, operators, planners, researchers, cybersecurity specialists, and decision-makers understand how cyber and physical infrastructures interact, how vulnerabilities emerge from this interaction, and how CPPSs can be modelled, assessed, protected, and strengthened.
CPPS interdependence is organized into three layers: facilities, topologies and functions. At the facility level, cyber and physical components are increasingly embedded in the same devices, such as sensors, actuators, intelligent electronic devices, smart meters, power electronic converters, and inverter-based resources. At the topology level, power networks and communication networks may share infrastructure or physical corridors, creating the possibility of common-cause failures. At the functional level, protection, control, energy management, dispatch, market operation, and demand response rely on continuous interaction between information flow and energy flow. This three-layer cyber-physical interdependence framework provides a useful foundation for understanding how local disruptions may propagate across domains.
To support CPPS analysis, we review integrated modelling approaches that can represent interactions between cyber and physical domains. These include control-signal embedded cyber-physical modules, hybrid automaton models, interdependent network models and information-energy flow models. Component-level models can describe how cyber signals affect physical devices. Hybrid models can represent interactions between discrete cyber events and continuous physical dynamics. Interdependent network models can reveal structural vulnerabilities and cascading failures across coupled infrastructures. Information-energy flow models can describe the chain from measurement, communication and computation to decision-making and control execution. These approaches help analysts trace how failures, delays or incorrect information may propagate through CPPSs.
The cybersecurity landscape of CPPSs is examined with emphasis on the evolving threat vectors that emerge from increasingly open and interconnected architectures. Cybersecurity is treated as a core CPPS issue because cyber incidents can directly affect physical grid operation. As power systems become more open, distributed and interactive, their attack surfaces expand. Distributed energy resources, electric vehicles, prosumers, aggregators, third-party service providers and digital platforms create new interfaces between the grid and external actors. This TB reviews major cyber threats to CPPSs, including false data injection attacks, denial-of-service attacks, malware, ransomware, man-in-the-middle attacks, social engineering and supply-chain vulnerabilities. It also discusses security measures such as secure architecture design, endpoint protection, network monitoring, backup and restoration, trust and reputation mechanisms, blockchain-based approaches and self-adaptive systems.