<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Cybersecurity Assessment of Digital Twin in Smart Grids</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Mulualem Bitew Anley</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Otuekong Ekpo</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>T. Milinda H. Gedara</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>IMT School for Advanced Studies Lucca</institution>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Università degli Studi di Milano</institution>
          ,
          <addr-line>Milano</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Università degli Studi di Napoli</institution>
          ,
          <addr-line>Napoli</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Università degli Studi di Salerno</institution>
          ,
          <addr-line>Salerno</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The advent of the digital twin paradigm marks a technological revolution, particularly within smart grid systems enhanced by the Internet of Things (IoT). This study investigates the application of the PILAR tool for assessing the potential cyber risk in a smart grid, leveraging digital twins for improved data management and system performance. Our methodology, informed by standards such as ISO/IEC 27002:2022, the cybersecurity framework, and GDPR, evaluates the security measures necessary for protecting these infrastructures. The efectiveness of PILAR in risk and security control identification is underscored through a comparative analysis with current literature, establishing a proactive risk management approach vital for the cyber-resilience of a smart grid.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Cybersecurity</kwd>
        <kwd>Digital Twin</kwd>
        <kwd>Risk Assessment</kwd>
        <kwd>Smart Grid</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Smart grids are a key part of today’s energy systems. They bring together eficiency, sustainability,
smart management, and energy distribution. Central to this innovation is the integration of
CyberPhysical Systems (CPS) and the Internet of Things (IoT), with the Digital Twin (DT) concept significantly
enhancing the performance and operational intelligence of these systems. These virtual counterparts of
the physical grids play a crucial role in mirroring and managing the complexities of energy networks.
However, this advancement increases cybersecurity risks, as interconnected digital infrastructures
become more prevalent and critical in smart grids, making them targets for sophisticated cyber-attacks
with potentially wide-reaching implications [1].</p>
      <p>Cyber-attacks on smart energy grids are a serious worldwide issue, as these grids are vital for
powering our homes, businesses, and critical services. These advanced and connected grids are at risk
of cyber threats, which could lead to large-scale power cuts, financial damage, and threats to national
safety. For instance, the cyber-attacks in Ukraine during 2015 and 2016 [2], [3], [4]. These attacks
caused extensive blackouts, afecting hundreds of thousands of people and exposing the fragility of
national power systems [5]. These attacks disrupt the power supply, pose risks to data privacy, and
undermine public trust in safeguarding essential services. Moreover, they threaten personal and national
security by exposing sensitive information, diminishing confidence in energy providers [ 6]. The use
of DTs in smart grids is widespread because it allows the application and testing of new experiments
without afecting mission-critical physical systems with the aid of Industry 4.0 and IoT. Simulation and
emulation of physical system components play a vital role in DT of smart grid [7]. However, it also
adds additional cyber risk to the smart grids.</p>
      <p>In response to cyber risk, a detailed cybersecurity risk analysis of the DT of the smart grid needs to
be performed[8]. In the absence of such safeguards, cyber-criminals may compromise the integrity,
confidentiality, and availability of this system. It motivates the introduction of a comprehensive risk
assessment method specific to DT in smart grid using PILAR [ 9], a distinguished commercial tool
known for its adeptness in modeling complex grid infrastructures and evaluating various security risk
scenarios [10]. By enabling a proactive approach, PILAR allows grid operators to anticipate, prepare for,
and mitigate potential cyber threats efectively, thus reinforcing the security posture of smart grids.
The tool’s advanced algorithms are instrumental in assessing the likelihood and impact of diferent
cyber-attack types, aiding in prioritizing and implementing critical security measures. The analysis
highlights the vulnerabilities and potential threats looming over these sophisticated energy networks.
By leveraging the capabilities of DT in testing, monitoring, and standardizing security protocols within
smart grid environments, the study seeks to highlight the practical implications and challenges, thereby
emphasizing the imperative of fortifying the security framework of smart grids against the ever-evolving
landscape of cyber risks.</p>
      <p>This paper’s primary focus is to thoroughly examine the smart grid infrastructure digital twin, with
particular emphasis on identifying potential threats and vulnerabilities. Subsequently, the study aims
to provide a comprehensive set of recommendations aimed at strengthening the security posture of the
smart grid digital twin systems. This is achieved through a critical assessment of the assets, identifying
the potential cyber threats, vulnerabilities, and security controls actioned to safeguard these critical
infrastructures. The remainder of the paper is structured as follows: section 2 provides related studies on
risk assessment in the implementation of the smart grid digital twin; section 3 presents our methodology
for risk assessment using PILAR. Section 4 presents the results of our findings from the risk assessment
and strategic recommendations for strengthening the cyber resilience of the smart grids in the face of
sophisticated cyber threats. Finally, section 5 concludes the paper and outlines the possible directions
for future research.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related Works</title>
      <p>The current body of research on cybersecurity risk assessment in smart grids is presented in this
section. A range of approaches and tools have been proposed to investigate the threats in smart grid
infrastructure.</p>
      <p>In [11], the authors investigate the cyber-physical security aspects of a microgrid (the building block
of the smart grid) concerning their vulnerabilities and threat landscape. This is achieved through
a risk assessment exercise to evaluate the impact of risk on microgrid operations. In their findings,
they identify possible threats to the microgrid, which include physical attacks, eavesdropping and
interception attacks, and nefarious activities. Organizations, cyber criminals, insider threats, hacktivists,
nation-state actors, terrorists, and cyber-fighters were also identified as possible threat agents. However,
their study only ofers theoretical insights into the threat landscape of the microgrid.</p>
      <p>The authors in [12] address the challenges associated with the integration of ICT and its standards in
a smart grid. They ofer a risk management framework based on the CAN/CSA Q-634-91 standard to
address both security and health risks associated with smart meters in a smart grid. The framework
follows a nine-step process that includes: risk identification, risk analysis, risk planning, risk
prioritization, risk treatment, risk monitoring, risk evaluation, risk communication, and documentation.
They suggest that further studies are still required to eficiently guide resource allocations and optimize
practices at all levels of the smart grid platform to identify, measure, and minimize associated risks.
In another study, [13]carried out a cybersecurity risk assessment to methodically examine the impact
and likelihood of cyberattacks. They leverage the smart grid Information Security (SGIS) toolbox and
apply it to a voltage control and power flow optimization smart grid use case. To determine the security
level of an information asset, the toolbox uses a six-step procedure to arrive at its findings. In their
results, they assert that a smart grid’s operational behavior and related infrastructure may be afected by
compromising the integrity of information assets that are essential for voltage control. Also, they assert
that the impact of the availability of information assets is limited because grid protection measures
account for possible sensor failures. Importantly, they find that compromising the confidentiality of
essential assets, such as metering data, could have a significant impact on the Distribution System
Operator (DSO) under consideration, thereby impacting the population as a whole and resulting in
reputational damage for the operator. In [14], they investigate the applicability of tool-assisted threat
modeling to the smart grid. In their study, they employ the Microsoft Threat Modeling Tool (MTMT) to
present a template that enables tool support for threat modeling of cyber security in the smart grid.
This template is characterized by four threat properties which include priority, loss of power, dificulties
in implementing mitigation, and afected systems. The strength of their study lies in the possibility of
using the template to reduce the problem of threat explosion that is often encountered during threat
modeling.</p>
      <p>Similarly, [15] describes a framework for scenario-based risk assessment methodologies that employs a
multi-directed graph model to depict the asset-dependency model of smart grids. They achieve this by
ifrst categorizing the assets and then developing a web-based tool for visualizing a graph-based model
of the assets and their dependencies.</p>
      <p>A smart grid ontology with adversarial models and vulnerabilities is presented in [16]. They ofer an
automated method for integrating the ontology with relevant entries from the Common Vulnerabilities
and Exposures (CVE) database, which is the industry-standard vulnerability knowledge base. This
leads to a deeper understanding that informs the establishment of security policies and vulnerability
assessments for smart grid systems.</p>
      <p>Our work distinctively uses the PILAR risk assessment tool to assess the risk in a smart grid,
leveraging digital twins for improved data management and system performance. We follow a well-laid-out
methodology to examine risks across multiple dimensions, including confidentiality, integrity,
availability, authenticity, and traceability (accountability). Our approach is highly parameterizable, allowing
customization based on assets, asset dependencies, threat profiles, and security controls. It also
supports quantitative and qualitative analysis, impact analysis, and business continuity. This approach,
leveraging PILAR with specific capabilities, provides a general yet practical and domain-dependent
methodology, distinguishing our work from the existing literature in the field.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Proposed Methodology</title>
      <p>In this section, the step-by-step methodology followed in assessing the cyber risk of the smart grid using
PILAR software as a tool is presented. In state-of-the-art, the DT smart grid risk assessment is identified
as an interesting research area. As a use case scenario, the DT of Smart Microgrid Polygeneration (SPM)
in Savona Campus, Genoa [7, 17], has been selected to perform the risk assessment. However, the
study is conducted in a more general method covering the basic components of DT of the smart grid.
The proposed methodology consists of five steps, as shown in Fig 1 followed by the PILAR software.
Evaluation and identify critical areas of risk mitigation action needed. The following paragraph details
describe each step in the evaluation process.</p>
      <sec id="sec-3-1">
        <title>3.1. Identification of Assets and its Dependencies</title>
        <p>In this phase of the risk assessment, forty-four (44) key assets were identified of SMP in Savona
Campus [7]. These assets comprise physical components (solar panels, batteries, turbines, etc.), software
components (SCADA data systems and energy management applications, etc.), as well as people
(operators, administrators, and technical staf). We also categorized and identified the roles that these
assets play, especially those that are mission-critical. For example, the data generated from the SCADA
is considered critical for real-time monitoring and control, whereas storage equipment for energy
is considered pivotal in maintaining an energy balance. Other critical assets identified were remote
access control devices, the main controlling system, and various internal services and communication
protocols. Additionally, the interdependence of the assets was also identified. For instance, the SCADA
system functions through a reliance on various interconnected components like servers, firewalls,
and communication lines. This holistic approach puts forward the complex nature of the network of
dependencies that characterize a typical smart grid. This can range from advanced control systems to
human resources to software, each contributing to the overall eficiency of this critical infrastructure.</p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2. Risk Evaluation of the Assets</title>
        <p>In this phase, the dependencies of the assets were evaluated and earlier identified to evaluate them.
This valuation is necessary in providing an understanding of risk factors for each asset as well as that
of the entire system. Each asset is assessed based on five criteria: availability, integrity, confidentiality,
authenticity, and accountability as provided by the tool.</p>
        <p>
          Due to their interconnected nature, we observe that the evaluation of one asset can have an impact
on other assets that depend on it. We consider this a butterfly efect as a threat to one asset can have an
impact on others dependent on it or otherwise, it depends. Similarly, this evaluation also takes into
cognizance factors such as recovery time, compliance with legal and regulatory obligations, security
measures, protection of commercial interests, potential activity disruption, maintenance of public
order, alignment with operational missions, management considerations, preservation of goodwill,
and support in crime prosecution eforts. The severity of the risk impact on the assets is categorized
using a numerical range of one (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) to ten (10). A rating of 10 indicates the highest potential impact,
while a rating of 1 suggests a negligible impact. This allows for a structured approach to assessing risk,
minimizing bias, and achieving consistent evaluation across asset categories. The tool also provides
for automated categories of assets such as essential assets, internal services, equipment, subcontracted
services, facilities, and personnel which is useful in this phase.
        </p>
      </sec>
      <sec id="sec-3-3">
        <title>3.3. Threats Identification</title>
        <p>After identifying potential risks, the threats posed to the system were evaluated by using the PILAR
tool to identify security threats with a particular focus on privacy, errors, unintentional failures, and
industrial risks which are typical of such systems. The threats identified are rated on a scale of zero (0)
to ten (10) as performed during the risk evaluation phase. Here, a rating of 10 represents a catastrophic
system failure, while 0 indicates the absence of a threat. This rating is however adjustable, allowing for
modification based on the evaluator’s insights.</p>
        <p>In the study, the focus is on cybersecurity risk which results in the exclusion of potential threats
due to natural phenomena (such as earthquakes and volcanoes, etc.) The PILAR tool is invaluable in
providing insights into the likelihood (frequency) of each threat and its impact on the security objectives
of each asset. The security objectives include availability, integrity, confidentiality, privacy, user and
information authenticity, and accountability of service and data.</p>
        <p>In this phase, threats have been identified which include, for instance, threats to the SCADA Data,
Such as software failure, hardware failure, malware difusion, data misuse, and external attacks, each
with its frequency of occurrence. These threats significantly afect aspects like asset accessibility and
accountability. From the digital twin point of view, we identified threats related to remote access control.
These threats include unauthorized access, identity masquerading, and abuse of access privileges, each
afecting integrity and availability to varying degrees.</p>
        <p>Other risks, like system failures due to resource exhaustion or administrative errors, and the
deliberate or accidental alteration of information, are also noted for their high frequency and impact.
By systematically evaluating these threats and their potential impacts, the PILAR tool facilitates an
extensive understanding of the risks associated with diferent assets. This understanding is crucial for
making informed decisions and developing efective mitigation strategies.</p>
      </sec>
      <sec id="sec-3-4">
        <title>3.4. Risk Assessment</title>
        <p>
          In this phase, the risk was assessed by using the PILAR tool to again categorize the risk into ten distinct
levels (
          <xref ref-type="bibr" rid="ref1 ref2">0 - 9</xref>
          ). It is also used to automatically generate other potential risks to the system, which can
be manually refined and adjusted based on the accumulated knowledge and prior evaluations. This
target level is informed by the ISO/IEC 27002:2022 Information Security Controls and Cybersecurity
framework/ The security risk of the system, an essential step following the comprehensive threat
analysis. Pilar plays a pivotal role in this phase by categorizing risks into ten distinct levels. These levels
range from 0, indicating negligible risk, to 9, denoting catastrophic failure. PILAR’s role extends beyond
mere risk categorization; it automatically generates potential risks, which can be manually refined and
adjusted based on accumulated knowledge and prior evaluations. This target level is informed by the
ISO/IEC 27002:2022 Information Security Controls and cybersecurity framework.
        </p>
      </sec>
      <sec id="sec-3-5">
        <title>3.5. Risk Mitigation</title>
        <p>Following the evaluation of risks associated with the digital twin, it is evident that most critical points
require targeted mitigation actions. To efectively address these, we adhere to the guidelines set forth by
ISO/IEC 27002:2022, the Cybersecurity Framework, and GDPR. These standards are crucial in guiding
our approach to cyber risk mitigation and mainly focus on a proactive approach to cybersecurity
risk management and protecting critical information from unauthorized access and loss instead of a
common standard for process control systems ISO/IEC 27019:2017. In this process, the PILAR tool plays
a significant role, providing essential recommendations for establishing a robust and resilient security
framework. These measures, as advised by PILAR, are not just suggestions but form the backbone of
our strategy to reinforce the security of the digital twin’s critical components.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Findings from the Risk Assessment</title>
      <p>In this section, we present the results of the risk assessment methodology followed in using the PILAR
tool. We acknowledge the subjectivity of most risk assessment eforts which we recognize is mostly
dependent on the experience and knowledge of the analyst. However, in our experience, we are a group
of five (5) security specialists (evaluators) actively involved in this kind of exercise, therefore, biases are
reduced to the barest minimum.</p>
      <sec id="sec-4-1">
        <title>4.1. Evaluating our Approach</title>
        <p>All evaluators concur on the identification of 44 essential assets that constitute a comprehensive
representation of the smart grid’s digital twin. These assets span from physical components such
as solar panels, sensors, and turbines—represented in the digital environment through simulations.
Software elements like SCADA data systems and energy management applications, are emulated within
the digital twin framework. Additionally, ’pass-through’ assets that encompass the human element,
including operators, administrators, and technical staf, were considered crucial to the operation. A
pivotal part of this analysis was the categorization and assessment of each asset’s significance and role
within the system. For instance, SCADA data is critical for real-time monitoring and control, while
storage energy plays a pivotal role in energy balance. Other significant assets included remote access
control and the main controlling system, along with various internal services and communication
protocols. The analysis also highlighted 62 interdependencies among these assets, with the SCADA
system’s functionality being particularly dependent on interconnected components such as servers,
ifrewalls, and communication lines.</p>
        <p>Given the subjective nature of risk evaluation, especially concerning human factors, the assessments
were quantified based on each evaluator’s viewpoint. The consensus was that the SCADA system data
is critically vital, warranting the highest criticality rating and priority in the evaluation. Conversely,
the data associated with the turbine on and of functions were assigned the lowest values, as depicted
in Table 1. This critical asset evaluation is an essential part of the overall risk assessment, spotlighting
the data as highly vulnerable to attacks and instrumental in the operation of the digital twin of the
smart grid. This structured and professional approach to risk assessment ensures a balanced and
comprehensive evaluation, crucial for the strategic management and protection of the digital twin’s
key assets.</p>
        <sec id="sec-4-1-1">
          <title>Asset</title>
          <p>SCADA data
Storage energy
Remote access control
Main controlling system
Data about power Usage
Storage discharge
Turbine start
Turbine stop
[C] [I] [A] [Auth]
5 9 9 9
3 5 7 4
6 5 7 6
9 7 9 7
6 5 7 5
3 5 7 7
4 7 7 3
4 7 7 3</p>
          <p>After evaluating potential risks, threats to each asset are evaluated in the next stage. However,
here, we only consider cyber security threats and their frequency of occurrence. Table 2 shows the
most critical threat identified and the probable frequent attacks or threats that can occur. Table
2 presents the most significant threats, with masquerading of identity (52%), unauthorized access
(51%), and deliberate alteration of information (52%) ranking as the most frequently occurring. Other
considerable threats include abuse of access privileges (40%), manipulation of configuration files (31%),
and denial of service attacks (20%). Conversely, malware difusion, software manipulation, defects in
software maintenance/updating, resource exhaustion-induced system failure, equipment loss or damage,
hardware failure, and third-party software information leaks are deemed to pose a less significant risk,
each with less than 15% likelihood of occurrence.</p>
        </sec>
        <sec id="sec-4-1-2">
          <title>Threat</title>
          <p>Unauthorized access
Masquerading of identity
Abuse of access privileges
Denial of service
Deliberate alteration of information
Manipulation of the configuration files
Defects in software maintenance/updating
Malware difusion</p>
          <p>Based on the potential threat to each asset, the risk estimation is calculated as described in the
methodology. The systematic risk evaluation is done on each asset, as shown in Fig 2: the radar
chart. The outer layer represents each asset, which is a total of 53, and each level of the inner layer
represents the critical levels, indicating each asset’s risk level. The critical level description is shown in
Fig2(a), which varies from catastrophic level(9) to negligible level(0). Moreover, the chart delineates
four distinct levels: the potential risk inherent to each asset, the current actual risk level, the target risk
level as determined by evaluators, and the recommended risk level as suggested by the PILAR tool. Our
assessment’s alignment with PILAR’s guidelines underscores the accuracy of our evaluation, aligning
closely with the standardized levels established by the tool’s framework.</p>
        </sec>
      </sec>
      <sec id="sec-4-2">
        <title>4.2. Security Controls for Risk Mitigation</title>
        <p>In the experimental findings of the study on the PILAR tool’s capabilities in mitigating information
security risks, several critical areas of focus are identified, aligning with established standards such as
ISO/IEC 27002:2022, the Cybersecurity Framework, and the General Data Protection Regulation (GDPR)
2016.</p>
        <p>1. Access control: The first critical area identified is access control. The experiments show that
efective risk mitigation involves comprehensive management of identities and credentials for all
authorized entities, including devices, users, and processes. Implementing principles such as least
privilege and separation of duties in access permissions management is emphasized. Additionally,
the authentication processes for users, devices, and assets are tailored to match the associated
risk levels.
2. Data and information security: The study highlights the importance of implementing robust
protections against data leaks in the realm of data security. This finding underscores the necessity
of safeguarding sensitive data from unauthorized access and potential breaches. The study also
points out the significance of information security, suggesting that organizations should formulate
and regularly review comprehensive information security policies. Efective management of
information security roles and responsibilities in the internal organization is deemed essential.
Moreover, segregating duties and properly handling information security incidents are crucial
elements.
3. Remote access and online services: For security control measures in remote access and
online services, the findings stressed adherence to business requirements for access control and
provisioning. The management of privileged access rights and the secure handling of secret
authentication information are highlighted. Secure log-on procedures and controlled access to
program source code are also recommended.
4. Cryptography: In the field of cryptography, the implementation of cryptographic controls and
efective key management emerged as a key finding. This approach is essential for ensuring the
confidentiality and integrity of sensitive data.
5. Operational security: The Operations Security section of the study reveals the necessity
for well-documented operational procedures, encompassing change management and capacity
management. Additionally, protection against malware, backup strategies, and information
logging and monitoring are pivotal elements.
6. Communication security: Communications security is another crucial area, with the study
emphasizing network security management and ensuring network services’ security. Policies
and procedures for information transfer and electronic messaging are also considered essential.</p>
        <p>The communication protocol needs to always be encrypted.
7. System acquisition, development and maintenance of digital twins: Lastly, in system
acquisition, development, and maintenance, ensuring security requirements in information
systems and secure development policies are vital. Policies include adhering to secure system
engineering principles and conducting thorough system security testing. By integrating these
comprehensive security control measures and adhering to the guidelines provided, organizations
can significantly enhance their information security posture. This approach efectively mitigates
risks and ensures a robust security framework in compliance with recognized industry standards
and regulations.</p>
      </sec>
      <sec id="sec-4-3">
        <title>4.3. Comparison with the State of the Art</title>
        <p>Proposed Method
Access Control
Data Security
Information Security
Remote Access and Online
Services
Cryptography
Operations Security
Communications Security
System Acquisition,
Development, and Maintenance</p>
        <p>Rekik et.al [11]
Physical threats
Unintentional data
damage
Unintentional data
damage
Interception,
Hijacking
Nefarious Activities</p>
        <p>Lars et. al [14]
Spoofing
Tampering
Repudiation
Information
Disclosure
Denial of Service
Elevation of
Privilege</p>
        <p>Tefek et.al [16]
Malicious command
injection
Malicious firmware or
configuration
False data injection
Remote Attack via VPN
Attacks via User
Interface</p>
        <p>Our findings not only show an intersection with some findings in the existing literature but also
expand upon it as given in Table 3. To the best of our knowledge, while studies into the cyber risk
assessment of the smart grid, leveraging digital twins for improved data management and system
performance was lacking in the literature, our work has now filled this gap by eliciting more
domaindependent threats as well security controls to mitigate them. We provide a detailed comparative analysis
below.</p>
        <p>Access control is universally acknowledged, with the literature citing physical threats, spoofing, and
malicious command injection as risks. The proposed approach more clearly details identified
vulnerabilities and intensely emphasizes managing identities and credentials, along with robust authentication
procedures, which directly mitigates these threats by preventing unauthorized physical and digital
access.</p>
        <p>Data and information security are also covered and identified by other studies as a concern due
to unintentional data damage, tampering, and the potential for malicious firmware or configuration
changes. The study’s recommendation for robust data leak protections corresponds with the need for
preventative measures against such tampering and unauthorized modifications.</p>
        <p>Remote access and online services risks, such as interception, hijacking, and remote attacks via VPN,
are met with the study’s control measures that include adherence to strict access control standards
and management of authentication information, thereby safeguarding against such interceptions and
unauthorized access. Communications security partially addresses issues such as eavesdropping in the
literature.</p>
        <p>Even though other studies did not identify cryptography, our studies have now proposed this as
a direct response to nefarious activities, with the implementation of cryptographic controls and key
management providing a robust defense against threats to confidentiality and integrity. Also, our
ifndings on operations security ofer an in-depth approach to mitigating the risk posed by malicious
actors. Documented procedures and malware protection are essential to safeguarding the integrity of
operational systems.</p>
        <p>Finally, our findings on system acquisition, development, and maintenance provide a thorough
defense against the information disclosure, denial of service, and elevation of privilege risks identified
in the literature. Secure development policies and system security testing are crucial to prevent such
vulnerabilities. In summary, the study supports and extends the existing literature by ofering specific
control measures to address the identified risks in smart grid systems. By implementing these control
measures, organizations can efectively mitigate the risks highlighted in this study.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusion and Future Work</title>
      <p>In this paper, we have systematically analyzed the security risk mitigation strategies proposed by the
PILAR tool within the context of digital twin smart grids, comparing our findings against existing
ifndings in the literature. Our findings reveal a significant correlation between the proposed methods and
the literature, with additional depth provided by PILAR’s adherence to updated international standards.
Moving forward, the focus for future work lies in addressing the emerging security risks associated
with digital twins, including the incorporation of predictive analytics and artificial intelligence to
anticipate and counteract potential cyber threats. This proactive stance is imperative as the complexity
and sophistication of digital twin systems evolve, demanding equally dynamic and resilient security
measures.</p>
    </sec>
    <sec id="sec-6">
      <title>Acknowledgments</title>
      <p>We extend our heartfelt gratitude to Prof. Paolo Prinetto, Prof. Stefania Tomasiello, and Prof. Pierangela
Samarati for their expert guidance and unwavering support throughout this study. We are also grateful
to the CINI Cybersecurity National Lab of Italy for providing essential information, and to the National
Ph.D. program in Cybersecurity at the IMT School for Advanced Studies Lucca for the opportunity to
undertake this research. Their collective expertise and encouragement have been instrumental to our
work.
[3] A. Bindra, Securing the Power Grid: Protecting Smart Grids and Connected Power Systems from</p>
      <p>Cyberattacks, IEEE Power Electronics Magazine 4 (2017) 20–27.
[4] D. E. Whitehead, K. Owens, D. Gammel, J. Smith, Ukraine cyber-induced power outage: Analysis
and practical mitigation strategies, in: 2017 70th Annual Conference for Protective Relay Engineers
(CPRE), IEEE, 2017.
[5] M. Lehto, Cyber-attacks against critical infrastructure, in: Cyber Security: Critical Infrastructure</p>
      <p>Protection, Springer, 2022, pp. 3–42.
[6] L. S. Gajanan, M. Kirar, M. Raju, Cyber-Attacks on Smart Grid System: A Review, in: 2022 IEEE
10th Power India International Conference (PIICON), IEEE, 2022.
[7] E. Russo, G. Costa, G. Longo, A. Armando, A. Merlo, Lidite: a full-fledged and featherweight
digital twin framework, IEEE Transactions on Dependable and Secure Computing (2023) 1–14.
doi:10.1109/TDSC.2023.3236798.
[8] T. Krause, R. Ernst, B. Klaer, I. Hacker, M. Henze, Cybersecurity in power grids: Challenges and
opportunities, Sensors 21 (2021) 6225.
[9] S. N. S. Agency, Ear/pilar- environment for the analysis of risk, 2004. URL: https://www.pilar-tools.</p>
      <p>com/en/.
[10] H. Mokalled, C. Pragliola, D. Debertol, E. Meda, R. Zunino, A Comprehensive Framework
for the Security Risk Management of Cyber-Physical Systems, Springer International
Publishing, Cham, 2019, pp. 49–68. URL: https://doi.org/10.1007/978-3-319-95597-1_3. doi:10.1007/
978-3-319-95597-1_3.
[11] M. Rekik, Z. Chtourou, C. Gransart, A. Atieh, A cyber-physical threat analysis for microgrids, in:
2018 15th International Multi-Conference on Systems, Signals &amp; Devices (SSD), IEEE, 2018, pp.
731–737.
[12] R. W. Habash, V. Groza, D. Krewski, G. Paoli, A risk assessment framework for the smart grid, in:
2013 IEEE Electrical Power &amp; Energy Conference, IEEE, 2013, pp. 1–6.
[13] L. Langer, P. Smith, M. Hutle, Smart grid cybersecurity risk assessment, in: 2015 International
Symposium on Smart Electric Distribution Systems and Technologies (EDST), IEEE, 2015, pp.
475–482.
[14] L. H. Flå, R. Borgaonkar, I. A. Tøndel, M. G. Jaatun, Tool-assisted threat modeling for smart grid
cyber security, in: 2021 International Conference on Cyber Situational Awareness, Data Analytics
and Assessment (CyberSA), IEEE, 2021, pp. 1–8.
[15] A. Priyanka, A. Monti, Towards risk assessment of smart grids with heterogeneous assets, in:
2022 IEEE PES Innovative Smart Grid Technologies Conference Europe (ISGT-Europe), IEEE, 2022,
pp. 1–6.
[16] U. Tefek, E. Esiner, C. Cheh, D. Mashima, A smart grid ontology: Vulnerabilities, attacks, and
security policies, in: 2023 IEEE Conference on Communications and Network Security (CNS),
IEEE, 2023, pp. 1–6.
[17] S. Bracco, M. Brignone, F. Delfino, R. Procopio, An energy management system for the savona
campus smart polygeneration microgrid, IEEE Systems Journal 11 (2017) 1799–1809. doi:10.1109/
JSYST.2015.2419273.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>N.</given-names>
            <surname>Tzanis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Andriopoulos</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Magklaras</surname>
          </string-name>
          , E. Mylonas,
          <string-name>
            <given-names>M.</given-names>
            <surname>Birbas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Birbas</surname>
          </string-name>
          ,
          <article-title>A hybrid cyber physical digital twin approach for smart grid fault prediction</article-title>
          ,
          <source>in: 2020 IEEE conference on industrial cyberphysical systems (ICPS)</source>
          , volume
          <volume>1</volume>
          , IEEE,
          <year>2020</year>
          , pp.
          <fpage>393</fpage>
          -
          <lpage>397</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>J. E.</given-names>
            <surname>Sullivan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Kamensky</surname>
          </string-name>
          ,
          <article-title>How cyber-attacks in Ukraine show the vulnerability of the U.S. power grid</article-title>
          ,
          <source>The Electricity Journal</source>
          <volume>30</volume>
          (
          <year>2017</year>
          )
          <fpage>30</fpage>
          -
          <lpage>35</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>