Cyber Security Primer for DER Vendors, Aggregators, and Grid Operators
This report provides an introduction to cyber security for distributed energy resources (DER)?such as photovoltaic (PV) inverters and energy storage systems (ESS). This material is motivated by the need to assist DER vendors, aggregators, grid operators, and broader PV industry with cyber security resilience and describe the state-of-the-art for securing DER communications. The report outlines basic principles of cyber security, encryption, communication protocols, DER cyber security recommendations and requirements, and device-, aggregator-, and utility-level security best practices to ensure data confidentiality, integrity, and availability. Example cyber security attacks, including eavesdropping, masquerading, man-in-the-middle, replay attacks, and denial-of-service are also described. A survey of communication protocols and cyber security recommendations used by the DER and power system industry are included to elucidate the cyber security standards landscape. Lastly, a roadmap is presented to harden end-to-end communications for DER with research and industry engagement.
Citation Formats
TY - DATA
AB - This report provides an introduction to cyber security for distributed energy resources (DER)—such as photovoltaic (PV) inverters and energy storage systems (ESS). This material is motivated by the need to assist DER vendors, aggregators, grid operators, and broader PV industry with cyber security resilience and describe the state-of-the-art for securing DER communications. The report outlines basic principles of cyber security, encryption, communication protocols, DER cyber security recommendations and requirements, and device-, aggregator-, and utility-level security best practices to ensure data confidentiality, integrity, and availability. Example cyber security attacks, including eavesdropping, masquerading, man-in-the-middle, replay attacks, and denial-of-service are also described. A survey of communication protocols and cyber security recommendations used by the DER and power system industry are included to elucidate the cyber security standards landscape. Lastly, a roadmap is presented to harden end-to-end communications for DER with research and industry engagement.
AU - Carter, Cedric
A2 - Lai, Christine
A3 - Jacobs, Nicholas
A4 - Hossain-McKenzie, Shamina
A5 - Cordeiro, Patricia
A6 - Onunkwo, Lfeoma
A7 - Johnson, Jay
DB - C-MIX - Community Microgrid Information Exchange
DP - Open EI | National Laboratory of the Rockies
DO -
KW - Solar
KW - Photovoltaics
KW - PV
KW - Power electronics and inverters
KW - Power electronics
KW - Inverters
KW - Diesel generators
KW - Other liquid-fuel generators
KW - Resilience
KW - Extreme weather
KW - Cybersecurity
KW - Power plant controls
KW - SCADA
KW - Standards
KW - Interconnection
KW - Protection
LA - English
DA - 2017/08/01
PY - 2017
PB - Sandia National Laboratories
T1 - Cyber Security Primer for DER Vendors, Aggregators, and Grid Operators
UR - https://cmix.openei.org/submissions/148
ER -
Carter, Cedric, et al. Cyber Security Primer for DER Vendors, Aggregators, and Grid Operators. Sandia National Laboratories, 1 August, 2017, C-MIX - Community Microgrid Information Exchange. https://cmix.openei.org/submissions/148.
Carter, C., Lai, C., Jacobs, N., Hossain-McKenzie, S., Cordeiro, P., Onunkwo, L., & Johnson, J. (2017). Cyber Security Primer for DER Vendors, Aggregators, and Grid Operators. [Data set]. C-MIX - Community Microgrid Information Exchange. Sandia National Laboratories. https://cmix.openei.org/submissions/148
Carter, Cedric, Christine Lai, Nicholas Jacobs, Shamina Hossain-McKenzie, Patricia Cordeiro, Lfeoma Onunkwo, and Jay Johnson. Cyber Security Primer for DER Vendors, Aggregators, and Grid Operators. Sandia National Laboratories, August, 1, 2017. Distributed by C-MIX - Community Microgrid Information Exchange. https://cmix.openei.org/submissions/148
@misc{CMIX_Dataset_148,
title = {Cyber Security Primer for DER Vendors, Aggregators, and Grid Operators},
author = {Carter, Cedric and Lai, Christine and Jacobs, Nicholas and Hossain-McKenzie, Shamina and Cordeiro, Patricia and Onunkwo, Lfeoma and Johnson, Jay},
abstractNote = {This report provides an introduction to cyber security for distributed energy resources (DER)?such as photovoltaic (PV) inverters and energy storage systems (ESS). This material is motivated by the need to assist DER vendors, aggregators, grid operators, and broader PV industry with cyber security resilience and describe the state-of-the-art for securing DER communications. The report outlines basic principles of cyber security, encryption, communication protocols, DER cyber security recommendations and requirements, and device-, aggregator-, and utility-level security best practices to ensure data confidentiality, integrity, and availability. Example cyber security attacks, including eavesdropping, masquerading, man-in-the-middle, replay attacks, and denial-of-service are also described. A survey of communication protocols and cyber security recommendations used by the DER and power system industry are included to elucidate the cyber security standards landscape. Lastly, a roadmap is presented to harden end-to-end communications for DER with research and industry engagement.},
url = {https://cmix.openei.org/submissions/148},
year = {2017},
howpublished = {C-MIX - Community Microgrid Information Exchange, Sandia National Laboratories, https://cmix.openei.org/submissions/148},
note = {Accessed: 2026-08-06}
}
Details
Data from Aug 1, 2017
Last updated Mar 30, 2026
Submitted Jun 2, 2026
Organization
Sandia National Laboratories
Contact
Jay Johnson

