Reading in standalone mode. Open this treatise in the complete 2-Column Sovereign Research Wiki Engine:Open Wiki Dashboard (117 Treatises) →
Grid ImpactGrid Stability and Cascading Failure

Cascading Failure Hypothesis: Non-Linear Energy Grid Instability

100% Complete & Untruncated 185 min read
Return to Research Tracks

J. McKenney

This paper sits within the WG-04-CF Grid Stability and Cascading Failure working group. It draws its central attack scenario directly from the Death Wobble frequency-instability analysis and its renewable-penetration and inverter-based-resource evidence directly from the ERCOT-WECC reliability study, both in this same working group, and its mitigation and incident-response material is carried forward into the companion Grid Incident Response Playbook.

Licence: CC BY 4.0. 17 September 2026.

Executive Abstract#

This assessment models cascading failure from a coordinated cyber-physical attack on RefDNSP-1.2M, a reference modeled New South Wales distribution network, drawing on the BESS Architecture Vulnerability Assessment and the DERMS Security Architecture Review.

The central finding is that a coordinated Death Wobble oscillation attack, documented in a companion paper and in the 2016 South Australia, 2019 UK, and 2025 Iberian Peninsula events, could drive the grid's rate of change of frequency past the protection relay trip threshold under reduced-inertia conditions. Relay cascades could carry a localized 8,000-customer outage into a regional blackout of 1.2 million customers within 120 minutes, with six interdependent systems, water, hospitals, telecommunications, transport, military, and financial services, amplifying the crisis. Direct customer cost of unserved energy runs from AUD 1.3 million at the localized tier to AUD 8.95 billion at system-wide collapse, an upper bound, not a determination.

The probability of an attack within a ten-year horizon is assessed at 15 to 30 percent, a MEDIUM rating resting on vulnerable DERMS architecture, inadequate industrial control system protocol security, reduced inertia from renewable penetration, and demonstrated nation-state capability. Physical safety consequences range from 5 to 25 fatalities and 40 to 120 serious injuries, from thermal runaway, traffic signal failures, medical infrastructure collapse, and delayed emergency services.

Abstract#

A coordinated Death Wobble oscillation attack, documented by McKenney (2024, 2025) across the South Australia 2016 blackout (456 MW disconnected in under seven seconds by a voltage-dip-count protection setting), the UK 2019 blackout (0.125 Hz/s RoCoF relay threshold), and the Iberian Peninsula 2025 event (inter-area oscillations), executed through the Retailer API supply chain, can induce rate of change of frequency above 1.0 Hz per second under reduced-inertia conditions. This triggers protection relay cascades propagating from a localized 8,000-customer outage to a regional blackout of 1.2 million customers within 120 minutes, while six interdependent critical infrastructure systems, water, hospitals, telecommunications, transport, military, and financial services, amplify the consequences. Direct customer cost of unserved energy runs from AUD 1.3 million at the localized tier to AUD 8.95 billion at system-wide collapse; the lower figure rests on the AER's determined Value of Customer Reliability, the upper extrapolates that 12-hour-bounded value across 72 hours and is an upper bound, not a determination (section 5). The attack's probability within a 10-year horizon is assessed at 15 to 30 percent (MEDIUM), based on vulnerable DERMS/API architecture, inadequate ICS protocol security, reduced grid inertia, and demonstrated nation-state capability. Physical safety consequences range from 5 to 25 fatalities and 40 to 120 serious injuries, arising from thermal runaway, traffic signal failures, medical infrastructure collapse, and delayed emergency services.


1. Background and Context#

1.1 Purpose and Scope#

This document establishes the cascading failure risk profile for RefDNSP-1.2M's DER infrastructure under coordinated cyber-physical attack conditions. It synthesizes vulnerability findings from EE-CTI-004 (BESS Architecture Vulnerability Assessment) and EE-CTI-005 (DERMS Security Architecture Review) into a comprehensive impact model spanning grid operations, interdependent infrastructure, economic consequences, and physical safety.

The scope encompasses the full RefDNSP-1.2M distribution network, including 54 community batteries (270 MW aggregate capacity), 278,622 controllable DER devices (1.07 GW), and the six critical infrastructure systems directly dependent on uninterrupted electricity supply within the service territory.

1.2 Threat Context#

The Australian Energy Market Operator (AEMO) identifies grid frequency stability as the primary operational risk during the transition to high-renewable-penetration generation portfolios. As synchronous generation retires, system inertia declines from a historical constant of 4-6 seconds to 2-3 seconds during high-renewable periods. This reduction doubles the grid's sensitivity to rapid power imbalances, creating conditions where cyber-physical attacks against battery energy storage systems can trigger cascading failures that were physically impossible under the legacy generation mix.

McKenney's (2024, 2025) research across Australian, UK, European, and US interconnections argues that this vulnerability is not theoretical. The argument rests on incidents that system operators investigated and published, so the figures supporting it belong to those operators rather than to this working group, and each is stated below with the date and the scope the operator gave it.

ERCOT's inverter-based resource capacity share is bracketed by 28.8 percent in November 2021 and 45.0 percent in August 2026 (sourced: ERCOT and WECC Renewable Integration Challenges, sections 1 and 6, from ERCOT's own monthly reporting). ERCOT's peak instantaneous renewable penetration is recorded at a single instant: 75.67 percent at 2:13 p.m. on 29 March 2024, 34,958 MW. That instant and the capacity share above are measured over different windows and coincide at no point, so each is stated with its own date. The Western Interconnection queue duration of roughly 5 years, up from under 2 years in 2008, is verbatim from Lawrence Berkeley National Laboratory's Queued Up 2024 edition, and it is a national United States figure, so this paper states it as a national figure.

The mechanism carries the argument rather than the arithmetic around it. NERC has documented inverter-based resources disconnecting during faults they were not required to disconnect for, across four disturbance reports covering ERCOT and southern California (sourced: ERCOT and WECC Renewable Integration Challenges, section 4). That is a specification and settings failure inside the resources themselves. It is independent of how much inertia the system happens to be carrying, and section 2.3 keeps the two mechanisms apart for that reason.

Concurrent vulnerability assessments have identified an attack surface score of 8.7/10 across the BESS infrastructure and a DERMS risk score of 21/25 (CATASTROPHIC). The Retailer API, which provides third-party control of DER assets through the mPrest DERMS platform, lacks behavioral analytics, oscillation detection, and physics-based command validation. These are the three specific controls that would prevent the "Death Wobble" attack scenario detailed in this document.

1.3 Regulatory Framework#

This assessment is conducted under the requirements of:

  • Security of Critical Infrastructure Act 2018 (SOCI Act): Mandatory risk management programs for critical infrastructure assets
  • Australian Energy Sector Cyber Security Framework (AESCSF): Security Profile 2 (SP2) compliance obligations
  • IEC 62443: Industrial automation and control systems security, zones and conduits model
  • NERC CIP: Critical Infrastructure Protection standards for bulk electric systems (international reference)

Current compliance status: AESCSF SP2 at 32 percent (target 80 percent), IEC 62443 at 38 percent (target 80 percent). These gaps directly enable the cascading failure scenarios modeled in this document.

1.4 Reference Network Specification: RefDNSP-1.2M#

This analysis is conducted against a specified synthetic distribution network, designated RefDNSP-1.2M. It is not a specific operator. Its parameters are drawn from published Australian network data so that every result in this paper can be reproduced or contested.

ParameterValueBasis
Customers served1.2 millionModeled, mid-size NEM distribution network
Critical substations185Modeled
Distributed BESS fleet54 units, 270 MW aggregateAEMO DER register scale [n]
Nominal frequency50.0 HzAEMO NEM operating standard [n]
Protection RoCoF threshold1.0 Hz/sAEMO frequency risk review [n]
DERMS platformVendor-neutral aggregation layerModeled
Control protocolsDNP3, IEC 61850, ICCPIEC standards
Regulatory regimeSOCI Act, AESCSF SP-2Australian Government [n]

Each [n] marks a citation whose index is assigned when this paper's bibliography is consolidated. Until then the marker signals that a source exists for the row and names where it will appear, not that the index is final.


2. Death Wobble Physics: Grid Frequency Dynamics#

2.1 Frequency Stability Fundamentals#

The Australian electricity grid operates at a nominal frequency of 50 Hz. Grid frequency is a direct, real-time measure of the balance between power generation and power consumption. When generation exceeds load, frequency rises; when load exceeds generation, frequency falls.

The governing equations for grid frequency response are:

Grid Frequency: f = f_0 +/- delta_f
  where f_0 = 50 Hz (nominal), delta_f = deviation from power imbalance

Power Imbalance: delta_P = P_generation - P_load

Frequency Response: delta_f = delta_P / (D x S_base)
  where D = Load damping constant (approx 1.5%/Hz for Australian grid)
        S_base = System base power (approx 10,000 MVA for NSW region)

Rate of Change of Frequency (RoCoF): RoCoF = (1 / 2H) x delta_P
  where H = System inertia constant (seconds)

[Based on McKenney (2024) Death Wobble analysis and AEMO grid parameters]

The critical parameter is the system inertia constant H, which McKenney (2024) defines mathematically as:

H = (J × ω²) / (2S)

Where:
- J = moment of inertia (kg·m²)
- ω = nominal rotational speed (rad/s)
- S = generator MVA rating
- H = time (seconds) a generator could supply rated power from stored kinetic energy

Under traditional synchronous generation, H ranges from 4-6 seconds, providing substantial resistance to frequency disturbances. Under high-renewable conditions (30 percent or more inverter-based generation), H drops to 2-3 seconds. This drop in inertia represents a 50 percent reduction that doubles the RoCoF for any given power imbalance. As McKenney notes: "In a low-inertia system, the same disturbance (e.g., a large power plant loss) causes the frequency to change much faster than in a high-inertia system. This rapid frequency change is the dangerous 'wobble.'" (McKenney, 2024).

The swing equation behind these relations, and the distinction between a protection setting and a measured value, are derived at length in Project Inertia. That paper works the RoCoF relation through to the thresholds actually in service and cites the operator document each one comes from. Read it before treating any Hz/s figure in this section as a measurement.

2.1.1 Grid Inertia Depletion Mechanics#

The transition from synchronous generation to inverter-based resources fundamentally alters the grid's physical response to disturbances. Traditional synchronous generators provide inertia through massive rotating turbines and generators. This rotational inertia is physical momentum that resists changes in rotational speed (and thus frequency). A 500 MW coal-fired generator with an H constant of 5.0 seconds stores approximately 2,500 MWh of kinetic energy in its rotating mass.

In contrast, inverter-based resources (solar PV, wind with full-power converters, battery energy storage systems) have zero inherent inertia. These devices use power electronics to convert DC power to AC, with no rotating mass coupled to the grid. While "synthetic inertia" or "virtual inertia" control algorithms can emulate inertial response through rapid power injection, this is fundamentally different from physical momentum:

Physical Inertia (Synchronous Generators):

  • Instantaneous and automatic response (no delay)
  • Governed by laws of physics (cannot be disabled by software)
  • Proportional to rotating mass and rotational speed
  • Provides bidirectional support (absorbs or releases energy)

Synthetic Inertia (Inverter-Based Resources):

  • Requires frequency measurement, signal processing, and control action (10-100 millisecond delay)
  • Dependent on software and control system availability (vulnerable to cyber manipulation)
  • Limited by available headroom (cannot exceed device power rating)
  • Can be disabled, misconfigured, or exploited through cyberattack

The implications for cascading failure risk are profound. McKenney's (2024) analysis of the South Australia 2016 blackout demonstrates how rapid inertia depletion creates cascading vulnerability:

South Australia September 28, 2016 - Inertia Timeline:

T-60 minutes: System inertia = 3,500 MWs (stable, 6 wind farms operational)
T-30 minutes: System inertia = 3,200 MWs (weather conditions deteriorating)
T-5 minutes:  System inertia = 2,800 MWs (multiple wind farm faults reducing output)
T-2 minutes:  Six voltage dips across the SA grid (tornado-damaged 275 kV transmission lines)
T-0 seconds:  456 MW sustained wind generation loss (8 of 9 wind farms respond to a voltage-dip-count protection setting, over less than seven seconds)

Frequency Response:
- Supply-demand imbalance: in the order of 1,000 MW, against 1,826 MW of regional demand
- Design assumption for protection relays: 3.0 Hz/s maximum

Outcome: a 1,000 MW deficit inside an islanded region, triggering:
- Heywood Interconnector special protection scheme trip, about 700 ms after the last wind farm reduced output
- Islanding of South Australia from Victoria
- Complete system black (state-wide blackout) 87 seconds after the first fault
- 850,000 customers without power

Two attributions attach to that block. The inertia trace above is McKenney's (2024) modeled reconstruction. The supply-demand imbalance, the regional demand, the Heywood special protection scheme trip and its 700 ms delay, the 87-second sequence and the 850,000 customers are AEMO's own figures from the final report of March 2017.

This historical precedent establishes that protection operating exactly as configured can strip a region of enough generation to black it out. Its evidentiary reach is that mechanism, established from AEMO's own figures for the sequence, the regional demand and the customer count.

The magnitude claim rests on Great Britain instead, where every number is in the system operator's own technical report. On 9 August 2019 approximately 350 MW of embedded generation disconnected on RoCoF protection set to trip at 0.125 Hz/s. Cumulative infeed loss reached 1,481 MW, frequency was arrested at 49.1 Hz and then fell to 48.8 Hz, and low frequency demand disconnection shed 931 MW across 1,152,878 customers. That is the harder finding for an operator to dismiss, because the cascade needed no extreme rate of change. It needed a rate of change above a relay setting of one eighth of a hertz per second, which is well inside what a coordinated oscillation can produce.

Protection relay manufacturers (ABB, Siemens, SEL) design under-frequency protection with assumed RoCoF limits of 1.0-3.0 Hz/s. When actual RoCoF runs above that design band, relays built for slower frequency decline can:

  1. Trip spuriously when frequency passes through their setpoint too quickly to allow proper time delay
  2. Measure frequency incorrectly due to zero-crossing detection errors at extreme RoCoF
  3. Operate in unintended sequences as multiple protection stages activate simultaneously

2.1.2 Oscillation Frequency and Grid Resonance#

Power systems exhibit mechanical and electrical resonance modes that can amplify oscillations under specific frequencies. These are distinct from electrical frequency (50 Hz) and represent slower inter-area oscillations between different parts of the grid.

Electromechanical Oscillation Modes:

The NSW grid exhibits three primary oscillation modes identified through modal analysis:

Mode TypeFrequency RangePhysical MechanismDamping Ratio
Local Mode0.8-2.0 HzSingle generator oscillating against rest of system5-10% (well-damped)
Inter-Area Mode0.3-0.8 HzGroups of generators oscillating against each other3-8% (lightly damped)
Control Mode0.1-0.3 HzInteraction between generator governors and load frequency control10-15% (moderately damped)

Critical Finding: The inter-area oscillation mode (0.3-0.8 Hz) has the lowest damping ratio and thus the highest susceptibility to resonant amplification. A coordinated BESS oscillation attack at 0.5 Hz frequency would align precisely with this natural resonance mode, producing cumulative amplitude growth through constructive interference.

The mathematical relationship for oscillation amplitude growth under resonant excitation is:

Amplitude Growth: A(t) = A_0 × e^(-ζωt) × sin(ω_d × t)

Where:
- A_0 = Initial disturbance amplitude (MW)
- ζ = Damping ratio (0.03-0.08 for inter-area modes)
- ω = Natural frequency (rad/s) = 2π × f_natural
- ω_d = Damped natural frequency ≈ ω × sqrt(1 - ζ²)
- t = Time since disturbance initiation (seconds)

For lightly damped systems (ζ < 0.1), amplitude growth can reach 5-10x initial disturbance

Attack Optimization:

An attacker with knowledge of grid resonance modes can optimize oscillation frequency to maximize amplitude growth. The optimal attack frequency is:

f_attack = f_natural × (1 + ε)

Where:
- f_natural = Inter-area mode natural frequency (0.5 Hz for NSW)
- ε = Small detuning factor (0.05-0.10) to prevent exact resonance deadband
- f_attack ≈ 0.5-0.55 Hz (one oscillation every 1.8-2.0 seconds)

This timing is well within the control bandwidth of BESS inverters, which can respond to charge/discharge commands in 50-200 milliseconds. The DERMS API command rate limiting (if present) is typically 1-5 seconds, allowing sustained oscillation at the target frequency.

2.2 Attack Mechanism: Coordinated BESS Oscillation#

The "Death Wobble" attack exploits this reduced inertia by inducing coordinated charge/discharge oscillations across the community battery fleet.

Attack Parameters:

ParameterValueBasis
Target Assets54 community batteriesFull fleet, 5 MW each
Total Controllable Capacity270 MW54 x 5 MW
Power Swing Magnitude+/- 540 MW270 MW charge to 270 MW discharge
Oscillation Frequency0.3-1.2 HzTuned to grid mechanical resonance
Attack Duration15-30 minutesTime to trigger protection cascade

2.2.1 BESS Synchronous Oscillation Attack Mechanics#

The coordinated oscillation attack requires precise synchronization across all 54 community batteries to create coherent power swings. Unlike random or uncoordinated fluctuations that would tend to cancel out statistically, synchronized oscillation produces cumulative grid stress.

Technical Implementation via Retailer API:

A DERMS Retailer API provides RESTful endpoints for third-party control of DER assets. A compromised retailer account with OAuth 2.0 credentials can issue mass dispatch commands:

json
POST /api/v1/dispatch/bulk
Authorization: Bearer <compromised_oauth_token>
Content-Type: application/json

{
  "command_id": "oscillation_001",
  "target_assets": [
    "BESS_Bawley_Point_001",
    "BESS_Central_Coast_002",
    ... (52 additional BESS identifiers)
  ],
  "mode": "DISCHARGE",
  "power_setpoint_MW": 5.0,
  "duration_seconds": 60,
  "synchronize": true,
  "execute_at_utc": "2026-02-15T13:00:00Z"
}

Current Control Gaps Enabling Attack:

According to the DERMS Security Architecture Review, the following controls are typically absent:

  1. No rate limiting on bulk dispatch commands: attacker can issue unlimited commands at maximum API bandwidth
  2. No behavioral analytics: no detection of unusual oscillation patterns or rapid charge/discharge cycling
  3. No physics-based validation: DERMS does not verify that commanded power changes are grid-safe based on current inertia and frequency conditions
  4. No dual authorization for large commands: single OAuth token sufficient to control entire 270 MW fleet
  5. No oscillation detection algorithm: no mathematical analysis of command frequency signatures

Oscillation Waveform Mathematics:

A simple attack waveform uses square-wave oscillation between full charge and full discharge:

Power Command Sequence (5 MW per BESS, 54 BESS total):

Cycle 1 (T+0 to T+60s):  All 54 BESS: CHARGE at 5 MW   → Grid sees +270 MW load
Cycle 2 (T+60 to T+120s): All 54 BESS: DISCHARGE at 5 MW → Grid sees -270 MW generation
Cycle 3 (T+120 to T+180s): All 54 BESS: CHARGE at 5 MW   → Grid sees +270 MW load
...
Cycle N: Continue until protection relay cascade triggers

Effective Frequency: 1 cycle / 120 seconds = 0.0083 Hz

However, this simple square wave is inefficient. A more sophisticated attack uses variable duty cycle to match grid resonance:

Optimized Attack Waveform (sinusoidal modulation):

P(t) = P_max × sin(2π × f_resonance × t)

Where:
- P_max = 270 MW (total BESS capacity)
- f_resonance = 0.5 Hz (inter-area mode natural frequency)
- t = time in seconds

Command Implementation:
- Sample waveform every 10 seconds
- Issue power setpoint commands matching sampled value
- Synchronize all 54 BESS to same phase angle

This produces smoother oscillation that is harder to detect through simple statistical methods and aligns more precisely with grid resonance modes for maximum amplification.

2.2.2 Geographic Clustering for Localized Impact#

While the full 54-battery fleet produces maximum power swing magnitude, geographic clustering allows targeted attack on specific transmission corridors or substations.

Scenario Analysis: Sydney Metropolitan Cluster:

18 community batteries are deployed within 25 km of Sydney CBD:

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

Localized Attack Impact:

An attacker targeting only the Sydney Metro cluster (18 BESS, 90 MW total) can create localized transmission corridor stress:

Sydney West Terminal Power Flow Analysis:

Normal Operation:
- Canterbury + Parramatta clusters: 55 MW injection during peak solar
- Transmission line thermal rating: 450 MVA @ 132 kV = 600 MW
- Power flow: 380 MW (63% of rating, stable)

During Attack (coordinated discharge):
- T+0 to T+60s:   All 18 BESS charging → 90 MW additional load
- Transmission flow: 380 + 90 = 470 MW (78% of rating)

- T+60 to T+120s: All 18 BESS discharging → 90 MW generation
- Transmission flow: 380 - 90 = 290 MW (48% of rating)

Power Swing: 180 MW every 2 minutes (0.5 Hz oscillation)

This 180 MW power swing, while smaller than the full 540 MW fleet capability, is concentrated on a single transmission corridor. After 10-15 oscillation cycles (20-30 minutes), cumulative stress can trigger:

  1. Transmission line thermal overload protection (even though peak flow is below rating, rapid cycling causes thermal stress)
  2. Transformer differential protection (rapid power swings appear as internal faults to differential relays)
  3. Under-frequency load shedding in adjacent zones (as Sydney West Terminal capacity is constrained)

RoCoF Threshold Analysis:

The AEMO standard for RoCoF tolerance is 1.0 Hz/s. Protection relays are configured to trip when RoCoF exceeds this threshold for more than 100 milliseconds. McKenney (2024) documents critical RoCoF thresholds based on international case studies:

RoCoF ValueSystem ResponseHistorical Precedent
< 0.1-0.2 Hz/sHistorically normal under high inertiaTraditional grid operations
0.125 Hz/sUK 2019 relay disconnection threshold (not a measured system RoCoF)UK August 9, 2019 blackout
> 1 Hz/s (500ms window)Protection system maloperation likelyENTSO-E warnings
6 Hz/sExtreme instabilitySouth Australia Sept 28, 2016 (design: 3 Hz/s)

McKenney explicitly warns: "Experts explicitly warn that RoCoF values above 1 Hz/s (measured over 500ms) may be unmanageable by current system protections, potentially leading to fast grid collapse" (McKenney, 2024).

Research gap. The actual RoCoF tolerance of the RefDNSP-1.2M network is not known. Establishing it requires a dynamic stability study run with AEMO against the network's own topology, protection relay settings and interconnection to the transmission system. No cost anchor for a study of that kind was sourced for this paper, so no cost is stated. Until such a study exists, the analysis below uses the published AEMC and AEMO thresholds as a conservative baseline.

Under the reduced-inertia scenario:

Critical Power Imbalance = RoCoF_max x 2H x S_base / f0
  = 1.0 x 2 x 3 x 10,000 / 50 = 1,200 MW

Attack capability: 540 MW swing = 45% of critical threshold (single oscillation)

The swing equation is RoCoF = (dP x f0) / (2H x S_base), where dP is the power imbalance in MW, f0 the nominal frequency (50 Hz), H the inertia constant in seconds, and S_base the system base in MVA (Basakarad et al., 2020). Rearranged for the imbalance that produces the 1.0 Hz/s maximum design RoCoF, the critical figure is 1,200 MW. A single 540 MW fleet swing reaches 45 percent of that threshold in one oscillation. That is the sharp result in this analysis: one controllable command, issued through a compromised retailer API, moves the system almost halfway to the imbalance that drives RoCoF past the point where protection maloperates.

A single oscillation cycle does not by itself exceed the RoCoF threshold. Sustained oscillation at frequencies matching the grid's electromechanical resonance (0.3 to 1.2 Hz) is the mechanism that does. For a sinusoidal frequency deviation of amplitude A at oscillation frequency f, the peak rate of change is df/dt = A x 2 x pi x f. A deviation of +/- 0.15 Hz at the top of the resonance band, 1.2 Hz, gives a peak RoCoF of 0.15 x 2 x pi x 1.2 = 1.13 Hz/s. The same +/- 0.15 Hz at 1.0 Hz gives 0.94 Hz/s, and at 0.3 Hz gives 0.28 Hz/s. At the top of its own resonance range the attack crosses the 1.0 Hz/s threshold at which this analysis already places likely protection maloperation.

The detail that makes the attack work is where the frequency sits while that happens. A +/- 0.15 Hz deviation around 50 Hz stays between 49.85 and 50.15 Hz, which is exactly the AEMC normal operating band the system occupies almost all the time. Absolute-frequency protection, under-frequency load shedding, never sees it, because the frequency never falls to a shedding setpoint. Rate-of-change protection does see it, because df/dt reaches 1.13 Hz/s while the frequency itself never leaves the band an operator watches. The cascade is initiated by RoCoF relays tripping on rate of change, not by under-frequency relays tripping on an absolute setpoint. This is the same failure mode that disconnected roughly 350 MW of embedded generation in Great Britain on 9 August 2019, where RoCoF protection set to 0.125 Hz/s tripped generation the system needed. The earlier characterization, an oscillation growing until frequency reached 49.85 Hz and under-frequency relays tripped, described a setpoint no network service provider would install, because 49.85 Hz is the floor of the normal band and shedding there would fire during ordinary operation.

The diagram below traces the same attack through the two protection systems that could stop it. The left lane is what under-frequency protection watches, the absolute frequency, which never leaves the 49.85 to 50.15 Hz normal band. The right lane is what RoCoF protection watches, the rate of change, which climbs with oscillation frequency until it crosses the 1.0 Hz/s threshold. The attack passes the left lane untouched and trips the right lane, which is the whole point.

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

A single oscillation cycle reaches only 0.113 Hz/s and trips nothing. The values above are the sustained-oscillation peaks derived earlier in this section: df/dt of A x 2 x pi x f for a +/- 0.15 Hz deviation at each resonance frequency. Great Britain's 9 August 2019 relays were set even lower, at 0.125 Hz/s, and a cascade followed.

2.3 Why Reduced Inertia Creates Vulnerability#

McKenney (2024, 2025) identifies four pathways by which low inertia accelerates cascading failures:

  1. Amplified Initial Shock: Lower inertia = less kinetic energy buffering, resulting in faster, deeper frequency deviation from the same disturbance (mathematical relationship: ΔF ∝ 1/H)
  2. Protection System Errors: High RoCoF triggers spurious trips of healthy equipment. McKenney (2024) cites the UK 2019 event where approximately 350 MW of distributed generation tripped on RoCoF protection relays set to disconnect at 0.125 Hz/s (that setting is the relay's disconnection threshold, not a measured system-wide RoCoF), part of a cumulative infeed loss that reached 1,481 MW before frequency was arrested at 49.1 Hz, and notes that NERC data indicates approximately 70 percent of major disturbances involve protection system issues.
  3. Faster Escalation: Under-Frequency Load Shedding (UFLS) activates more quickly, generator self-protection trips accelerate, and control systems are outpaced by rapid frequency changes.
  4. Increased Complexity: Legacy systems + new inverter-based resource behaviors + novel load types create unexpected interactions. McKenney (2025) highlights the July 2024 Eastern Interconnection event where a 1,500 MW data center simultaneously disconnected, noting that "power systems have historically been planned and operated to withstand the loss of large generators, not the sudden, simultaneous loss of large loads."

The following table illustrates how the same 540 MW attack produces different consequences depending on the grid's inertia condition:

Grid ConditionInertia (H)RoCoF per 540 MW SwingCycles to Relay TripAttack Outcome
Traditional (90% synchronous)5 seconds0.0036 Hz/s>100 (impractical)No cascading failure
Transitional (60% synchronous)3.5 seconds0.0051 Hz/s45-60Marginal risk
High-Renewable (30% synchronous)2.5 seconds0.0072 Hz/s15-25Protection cascade likely
Minimum-Inertia Event2.0 seconds0.009 Hz/s8-12Cascade within 10 minutes

The grid does not need to be at minimum inertia for the attack to succeed. Any period where H falls below 3.0 seconds creates conditions where sustained oscillation can trigger the protection cascade within the 15-30 minute attack window. AEMO data indicates that H drops below 3.0 seconds during approximately 15 to 20 percent of operational hours in 2025-2026, primarily during midday solar peaks and overnight low-demand periods.

Operators publish inertia floors for exactly this reason, and those floors are the check on the table above. EirGrid holds a minimum synchronous area inertia of 23,000 MVA.s against a largest infeed of about 450 MW (EirGrid, Inertia Management on the Power Systems of Ireland and Northern Ireland, March 2024). ERCOT sets a critical inertia System Operating Limit of 100 GW.s, derived from a 2,750 MW contingency and a 0.416 second budget to reach the first stage of under-frequency load shedding (ERCOT, Inertia: Basic Concepts and Impacts on the ERCOT Grid, April 2018). Project Inertia works both figures against the RoCoF relation and projects the decay to 2030 and 2040. It is also where the 105 GW.s figure that circulates for ERCOT is separated from the 100 GW.s limit, which is the same setting-against-measurement error this paper corrects for South Australia and Great Britain.

International Precedents Supporting Death Wobble Risk:

McKenney's (2024, 2025) comprehensive analysis of three major blackouts demonstrates how declining inertia transforms grid vulnerability:

  1. South Australia (September 28, 2016): 48.36 percent inverter-based resource penetration, 456 MW sustained wind generation loss over less than seven seconds (8 of 9 wind farms tripping on a voltage-dip-count protection setting), a supply-demand imbalance in the order of 1,000 MW against 1,826 MW of regional demand, and loss of all supply to the region 87 seconds after the first fault. The Heywood Interconnector's special protection scheme tripped about 700 milliseconds after the last wind farm reduced its output, doing exactly what it was configured to do, and islanding South Australia against a 1,000 MW deficit blacked out the state. What South Australia establishes, from AEMO's final report, is that eight of nine wind farms disconnected on a voltage-dip-count protection setting rather than on the fault itself. That is a protection settings failure of the same class NERC found at Odessa, and it is the finding this paper carries forward. The ERCOT record is the reason the mechanism is read as a protection settings failure rather than as a consequence of low inertia: the larger of the two Odessa losses, 2,555 MW on 4 June 2022, occurred at 73.5 percent synchronous generation, while the smaller loss of 1,340 MW on 9 May 2021 occurred at 56 percent (sourced: ERCOT and WECC Renewable Integration Challenges, section 4.2, from the NERC and Texas RE Odessa disturbance reports). If low inertia were the operative cause the ordering would run the other way.
  2. UK Blackout (August 9, 2019): Lightning strikes near the Eaton Socon to Wymondley circuit triggered cascading generation losses: 641 MW from Little Barford gas plant, in three separate trips (a 244 MW steam turbine, then 210 MW and 187 MW gas turbines), plus 737 MW from Hornsea offshore wind. Approximately 350 MW of distributed generation tripped on RoCoF protection relays set to disconnect at 0.125 Hz/s (the relay's disconnection threshold; no measured RoCoF of 0.135 Hz/s appears anywhere in National Grid ESO's technical report). This result also confirms protection system maloperation even at moderate RoCoF. System inertia: 210 GVA·s (National Grid ESO technical report, Table 4); the report gives no wind-penetration figure for 9 August 2019.
  3. Iberian Peninsula (April 28, 2025): 60 million people affected (Spain + Portugal), up to 10 hours outage, 56 percent renewable penetration. Suspected inter-area oscillations between Iberia and Continental Europe due to weak interconnection (approximately 2,800 MW, only 6 percent of Spanish capacity). McKenney recorded two significant inter-area oscillations in the 30 minutes before the blackout. This paper carries the Iberian event as an oscillation precedent and as nothing more. No final report from the Spanish or Portuguese system operator sits in this working group's evidence base; the renewable-penetration and interconnection figures above come from contemporary reporting rather than from an incident investigation, and the causal attribution to inter-area oscillation is stated in the sources as suspected rather than established. A prediction and an outcome nobody has causally attributed are not a confirmation of each other, and this paper reads the Iberian event as a precedent for the oscillation mechanism rather than as confirmation of any warning given before it.

2.4 BESS Thermal Runaway Cascading Scenarios#

Battery thermal runaway represents a distinct attack vector with potential for physical cascading failure beyond electrical grid disruption. Unlike the Death Wobble oscillation attack (which targets grid frequency stability), thermal runaway attacks exploit battery management system (BMS) vulnerabilities to induce fires or explosions.

The same failure mode at campus scale, where a battery fleet sits behind one microgrid controller alongside inverter plant and, increasingly, small modular reactor auxiliaries, is worked through in Emerging Power Topologies. That paper carries the Arrhenius kinetics for the runaway, the convective heat removal collapse that precedes it, and the case for hardwired analog safety isolation: a temperature limit enforced in firmware is a limit an attacker with write access can move.

2.4.1 Lithium-Ion Thermal Runaway Physics#

Lithium-ion batteries store tremendous energy density (150-250 Wh/kg) in chemically reactive materials. When cell temperature exceeds safe limits, a self-sustaining exothermic reaction begins:

Thermal Runaway Progression:

Stage 1: Initial Heating (120-130°C)
- Solid Electrolyte Interphase (SEI) decomposition begins
- Heat generation: 100-200 J/g
- Timeline: 5-15 minutes from thermal abuse initiation

Stage 2: Separator Melting (130-150°C)
- Polyethylene or polypropylene separator melts
- Internal short circuit develops between anode and cathode
- Heat generation: 300-500 J/g
- Timeline: 2-5 minutes

Stage 3: Electrolyte Decomposition (150-180°C)
- Organic carbonate electrolytes decompose
- Flammable gas release (CO, CO₂, hydrocarbons)
- Heat generation: 800-1,200 J/g
- Timeline: 1-3 minutes

Stage 4: Cathode Material Decomposition (180-250°C)
- Metal oxide cathode releases oxygen (LiCoO₂, NMC chemistries)
- Self-sustaining combustion begins
- Heat generation: 1,500-2,500 J/g
- Timeline: <1 minute to full thermal runaway

Stage 5: Propagation (250-400°C)
- Thermal propagation to adjacent cells
- Cell-to-cell timeline: 30 seconds to 15 minutes (geometry dependent)
- Container-level fire: 4-12 hours total energy release

Attack Vector: Modbus Injection to BMS Controllers:

As detailed in EE-CTI-002 (Bawley Point Vulnerability Assessment) and EE-CTI-003 (Protocol-Level Threats), the BESS control architecture exhibits CRITICAL vulnerabilities:

Vulnerability IDDescriptionCVSSExploitation Method
V-001Modbus TCP Plaintext Communication9.1Man-in-the-middle command injection between SwitchDin Utility Server and Vendor RTU
V-004Unmanaged Vendor 4G/5G Connections8.8Direct internet access to BESS controllers bypassing all RefDNSP-1.2M security controls
FrostyGoopWeaponized Modbus Function Code 610.0Write Single Register command to thermal setpoint registers (demonstrated in Ukraine January 2024)

FrostyGoop Attack Adaptation for BESS:

The FrostyGoop malware (discovered by Dragos in April 2024, analyzed in EE-CTI-003) demonstrated the first Modbus-specific ICS attack causing physical damage. The Ukrainian heating system attack manipulated thermal setpoints via Modbus Function Code 6 (Write Single Register), causing 100,000 residents to lose heat for 48 hours.

An identical attack vector threatens RefDNSP-1.2M BESS infrastructure:

python
### FrostyGoop-style BESS thermal runaway attack (ANALYSIS ONLY)
### Based on Eigenia-OTCE-EAB-009 technical analysis

modbus_client = ModbusClient(target_ip="10.50.1.100", port=502)
modbus_client.connect()

### Phase 1: Disable overtemperature protection (Function Code 6)
modbus_client.write_register(
    address=0x1000,  # Cell temperature limit register
    value=0x00FF,    # 255°C (far exceeds safe limit of 60°C for lithium-ion)
    unit=1
)

### Phase 2: Force overcharge to exceed 4.5V/cell (Function Code 16)
modbus_client.write_multiple_registers(
    starting_address=0x2000,
    values=[0x46F5, 0x46F5, 0x46F5],  # 4.5V per cell (safe max: 3.65V)
    unit=1
)

### Phase 3: Disable cooling system (Function Code 5)
modbus_client.write_coil(
    coil_address=0x0001,  # HVAC cooling enable
    value=False,           # Disable
    unit=1
)

### Phase 4: Disable fire suppression pre-arming (Function Code 5)
modbus_client.write_coil(
    coil_address=0x0010,  # Fire suppression system enable
    value=False,           # Disable
    unit=1
)

### Timeline to thermal runaway:
### T+15 minutes: Cells reach 120°C (SEI decomposition)
### T+30 minutes: Cells reach 150°C (separator melting)
### T+45 minutes: Thermal runaway initiated
### T+60 minutes: Cell-to-cell propagation begins
### T+2-4 hours: Full container fire

2.4.2 Multi-Site Thermal Cascade Scenario#

Attack Scenario: Coordinated Thermal Runaway Across 54 BESS Sites

An attacker with access to the SwitchDin Utility Server (Zone 3) or compromised Retailer API credentials can issue simultaneous Modbus commands to all 54 community battery sites.

Cascading Timeline:

TimeEventCumulative Impact
T+0Attacker injects Modbus commands to all 54 BESS sites via compromised Retailer API54 sites receiving malicious thermal setpoint modifications
T+15 minFirst cells reach 120°C across all sites due to disabled cooling and overcharge54 sites in Stage 1 thermal runaway progression
T+30 minFirst cells reach 150°C, internal short circuits develop54 sites in Stage 2, evacuation alerts triggered
T+45 minFirst thermal runaway events (cathode decomposition)10-15 sites reach Stage 4 (statistical variation in battery age/condition)
T+60 minCell-to-cell propagation begins at affected sites15-25 sites with spreading thermal runaway
T+2 hoursMultiple container fires, fire brigades overwhelmed30-40 sites with active fires, regional fire emergency declared
T+4 hoursPeak fire intensity, toxic gas plumes over residential areas40-50 sites with fires, evacuation orders for 500m radius per site
T+12 hoursSelf-extinguishing phase begins (fuel exhaustion)Firefighting resources from across NSW deployed
T+24-48 hoursFires fully extinguished, damage assessment beginsTotal loss of 54 BESS assets, environmental contamination, potential fatalities

Energy Release Calculations:

Each 5 MWh BESS contains approximately:

Battery Specifications (typical community BESS):
- Capacity: 5 MWh = 5,000 kWh = 18,000 MJ
- Cell count: ~13,500 cells (280 Ah, 3.2V LFP or NMC chemistry)
- Cell mass: 0.5 kg each
- Total battery mass: 6,750 kg

Thermal Runaway Energy Release:
- Heat of reaction: 2,500 kJ/kg (exothermic decomposition)
- Total energy: 6,750 kg × 2,500 kJ/kg = 16,875,000 kJ = 16,875 MJ

TNT Equivalent:
- TNT energy density: 4.184 MJ/kg
- TNT equivalent: 16,875 MJ / 4.184 MJ/kg = 4,033 kg TNT per BESS

54 BESS sites: 4,033 kg × 54 = 217,782 kg TNT equivalent total energy

CRITICAL NOTE: This TNT equivalent represents total thermal energy released over 4-12 hours, not instantaneous detonation. Lithium-ion thermal runaway is a deflagration (subsonic burning) not a detonation (supersonic explosion). However, the energy release is still sufficient to:

  • Destroy the battery container and adjacent equipment
  • Create toxic gas plumes (HF, CO, particulates) requiring 500m evacuation radius
  • Ignite nearby structures and vegetation
  • Cause serious injury or fatality to nearby personnel

2.4.3 Fire Suppression Failure Analysis#

Community BESS installations typically use one of three fire suppression technologies:

Fire Suppression Technologies:

TechnologyMechanismEffectiveness Against Li-Ion FireLimitations
Water DelugeCooling through thermal mass60-70% (requires sustained application)Requires 50,000+ liters, runoff contamination, reignition risk
FM-200 / Novec 1230Oxygen displacement + cooling40-50% (ineffective once thermal runaway initiated)Cannot extinguish self-sustaining exothermic reaction
Aerosol (Condensed Aerosol)Free radical suppression30-40% (insufficient for severe thermal runaway)Limited mass, overwhelmed by large battery fires

Critical Finding: No fire suppression technology can reliably extinguish a lithium-ion battery fire once thermal runaway is established. The exothermic reaction is self-sustaining (cathode provides its own oxygen source), making traditional oxygen-displacement or cooling approaches ineffective.

Industry Precedents:

  • Arizona McMicken BESS Fire (April 2019): 2 MWh Tesla Powerpack, thermal runaway led to explosion injuring 4 firefighters, 5-hour fire suppression effort
  • Moss Landing BESS Fire (September 2022): 300 MWh facility, thermal runaway in single container, 30,000+ liters of water required, 5-hour suppression
  • Beijing BESS Fire (April 2021): 25 MWh facility, thermal runaway killed 2 firefighters, 8-hour suppression effort

Cascading Failure Through Firefighting Resource Exhaustion:

NSW Fire and Rescue has approximately:

  • 70 fire stations in RefDNSP-1.2M service territory
  • 120 pumper appliances (typical capacity: 3,000 liters)
  • 15 hazmat-rated teams capable of lithium-ion fire response

A simultaneous 54-site thermal runaway event would require:

Firefighting Resource Requirements:

Per-Site Requirements:
- 2-3 pumper appliances (50,000+ liters water over 4-8 hours)
- 1 hazmat team (toxic gas monitoring)
- 8-12 firefighters per site
- 4-8 hour continuous operation

54-Site Simultaneous Event:
- 108-162 pumper appliances required (actual available: 120)
- 54 hazmat teams required (actual available: 15)
- 432-648 firefighters required (total NSW F&R: ~7,000, but geographically dispersed)

Result: COMPLETE RESOURCE EXHAUSTION within first 10-15 sites

This creates a secondary cascading failure where fires at sites 16-54 burn uncontrolled for extended periods, increasing:

  • Structural damage and environmental contamination
  • Toxic gas exposure for nearby residents
  • Risk of fire spread to adjacent structures
  • Potential for fatalities among late-arriving firefighters entering high-toxicity environments

3. Cascade Propagation Modeling#

3.1 Four-Tier Cascade Model#

The cascading failure propagates through four tiers, each amplifying the affected customer base by an order of magnitude. This multi-tier cascade pattern is consistent with McKenney's (2024) analysis of European Network of Transmission System Operators for Electricity (ENTSO-E) system split risks: "ENTSO-E studies confirm that declining inertia significantly increases the risk of system splits leading to high RoCoF (>1 Hz/s) and potential widespread blackouts in future scenarios." McKenney documents that ENTSO-E "Project Inertia" studies for 2030-2040 scenarios identify an increasing number of "global severe splits" where both separated systems collapse due to uncontrollable RoCoF. This is precisely the multi-tier cascade failure pattern modeled in this assessment.

That attribution does not survive checking, and this paper flags it here rather than carrying it unqualified. Project Inertia records that no ENTSO-E document under the name "Project Inertia", and no ENTSO-E use of the phrase "global severe splits", appears in any primary source this working group holds. What it does hold in full is the ENTSO-E ICS Investigation Expert Panel final report on the Continental Europe separation of 8 January 2021, which is a post-event investigation and not a forward scenario study. Read the four-tier model below against that report. Eigenia's own forward projection of inertia decay is published in that same paper; it shares a name with an ENTSO-E workstream and nothing in it is an ENTSO-E finding.

The following diagram models the complete propagation chain from initial attack execution to system-wide collapse:

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

The node chain above shows what connects to what. It does not show the causal ordering in time, which is where the danger lives; each tier fires because the previous one did, and the intervals between them are short. The sequence diagram below carries the same tiers as a timeline, so the reader can see how little time separates a compromised token from a regional blackout. It is added rather than substituted because the two views answer different questions: the node chain shows the propagation topology, the sequence shows the order and the intervals.

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

3.2 Tier-by-Tier Impact Quantification#

Tier 1: Immediate Impact Zone (T+0 to T+15 minutes):

  • Geographic Area: 5 km radius around targeted substation cluster
  • Customers Affected: 8,000-12,000 residential, 200-400 commercial
  • Duration: 2-4 hours with priority restoration
  • Direct customer cost: AUD 1.3 million to AUD 4.0 million, computed in section 5.4 from the AER's 2024 residential NSW value of customer reliability [n]. Both bounds sit inside the 12-hour range for which that value was determined

Tier 2: Local Cascade Zone (T+15 to T+30 minutes):

  • Geographic Area: 3 adjacent substations, 15 km radius
  • Customers Affected: 80,000-120,000 residential, 2,000-3,500 commercial
  • Duration: 8-16 hours with sequential restoration
  • Direct customer cost: AUD 53 million at 8 hours, computed in section 5.4 [n], rising to AUD 159 million at 16 hours (modeled: VCR extrapolated past its 12-hour determination)

Tier 3: Regional Cascade Zone (T+30 to T+60 minutes):

  • Geographic Area: 8 additional substations, 40 km radius
  • Customers Affected: 400,000-600,000 residential, 8,000-15,000 commercial
  • Duration: 16-36 hours
  • Direct customer cost: AUD 530 million to AUD 1.79 billion, computed in section 5.4 (modeled: VCR extrapolated to 36 hours, three times its determined range)

Tier 4: System-Wide Collapse (T+60 to T+120 minutes, worst case):

  • Geographic Area: Full RefDNSP-1.2M network plus adjacent DNSPs
  • Customers Affected: 1.0-1.5 million residential, 25,000-40,000 commercial
  • Duration: 24-72 hours
  • Direct customer cost: AUD 1.99 billion to AUD 8.95 billion, computed in section 5.4 (modeled: VCR extrapolated to 72 hours, six times its determined range)

3.3 Attack Execution Timeline#

The following table details the minute-by-minute progression of the attack from initial API authentication through full cascade:

TimeAttacker ActionTechnical DetailGrid Response
T+0:00API authenticationCompromised retailer OAuth token establishes sessionNormal operation
T+0:05Asset enumerationQuery returns 54 controllable BESS unitsNormal operation
T+0:10Geographic clusteringIdentify 18 batteries within 5 km of target substationNormal operation
T+0:15First oscillation commandAll 18 batteries: "Charge 100%, duration 60s"Grid: +90 MW load
T+1:15Second oscillationAll 18 batteries: "Discharge 100%, duration 60s"Grid: -90 MW load (180 MW swing)
T+2:15Third oscillationRepeat charge cycle at 0.3 Hz effective frequencyFrequency: 50 Hz to 50.03 Hz
T+10:00Amplitude growth10 cycles completed, oscillation amplitude +/- 0.15 HzProtection relays detect instability
T+15:00Protection cascadeRoCoF relays trip on rate of change above 1.0 Hz/s while frequency stays inside the 49.85 to 50.15 Hz normal band (RefDNSP-1.2M scenario assumption, not a sourced AEMO relay setting)Load shedding initiated
T+18:00Regional expansionLoad shedding causes voltage sag across 3 substations100K customers offline
T+22:00Stabilization attemptAEMO Emergency Frequency Control System activatedBlackout contained
T+26:00Restoration beginsManual substation restoration commencesProgressive re-energization

3.4 Multi-Substation Coordinated Attack Integration#

The most severe cascading failure scenario integrates multiple attack vectors simultaneously: BESS oscillation, thermal runaway, and protocol exploitation of substation automation systems.

Sandworm Coordinated Attack Methodology:

As documented in EE-CTI-005 (Sandworm Energy Grid Campaign), the Russian GRU Unit 74455 has demonstrated coordinated multi-substation attack capability across three Ukrainian grid attacks (2015, 2016, 2022). Key characteristics:

  • implementation period required reconnaissance timeline to map substation architecture and identify critical nodes
  • IEC 61850 GOOSE injection to trigger protection relay cascades
  • DNP3 Direct Operate commands to open circuit breakers simultaneously
  • Modbus TCP exploitation (via FrostyGoop evolution) for physical damage
  • Wiper malware deployment (ORCSHRED, SOLOSHRED, CADDYWIPER) to destroy forensic evidence and delay recovery

RefDNSP-1.2M Attack Surface:

Infrastructure ComponentQuantityProtocol VulnerabilitySandworm Demonstrated Capability
Major Substations185IEC 61850 GOOSE (unencrypted, no authentication)Industroyer, deployed against Ukrainian transmission in 2016
Distribution RTUs32,000+DNP3 (unencrypted, optional authentication not deployed)BlackEnergy and Industroyer, deployed against Ukrainian distribution in 2015 and transmission in 2016
Community BESS54 (270 MW)Modbus TCP (plaintext, no authentication)FrostyGoop, deployed against a Ukrainian district heating utility in 2024
Protection IEDs10,000+IEC 61850 GOOSE peer-to-peerIndustroyer GOOSE injection module

Integrated Attack Scenario: "Coordinated Infrastructure Collapse"

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

185-Substation Synchronized Trip Scenario:

RefDNSP-1.2M operates 185 major substations classified as "critical" for grid stability. A coordinated DNP3 Direct Operate attack, modeled on the Industroyer malware framework, could simultaneously trip circuit breakers across these substations.

Attack Execution (Sandworm Methodology):

Reconnaissance Phase (Months -12 to -8):
1. Compromised engineering workstation provides access to SCADA network
2. Extract DNP3 outstation configuration files from SCADA master
3. Map circuit breaker DNP3 addresses (typical: Point Index 1-50 per substation)
4. Identify critical load transfer paths and interconnection points

Weaponization Phase (Months -8 to -2):
1. Develop custom DNP3 payload (Industroyer module adaptation)
2. Test against vendor-specific RTU firmware (Hitachi RTU560 known deployment)
3. Incorporate wiper malware (ORCSHRED, SOLOSHRED) for forensic destruction
4. Establish command-and-control channel via compromised 4G vendor modem

Pre-Positioning Phase (Months -2 to 0):
1. Deploy malware to compromised engineering workstation
2. Schedule timed execution via Windows Task Scheduler
3. Establish redundant C2 channels (primary: 4G modem, backup: VPN)

Execution Phase (T+0):
1. Malware activates, establishes 185 DNP3 sessions simultaneously
2. Send Direct Operate commands (Function Code 5: Operate - no select required)
3. Target: Circuit breaker control points (DNP3 Binary Output objects)
4. Command: TRIP (open circuit breaker, de-energize substation)

Timing: All 185 substations receive TRIP commands within 5-second window

DNP3 Direct Operate Command Structure:

DNP3 Application Layer Protocol Data Unit (APDU):

Function Code: 5 (Direct Operate - No ACK)
Object Group: 12 (Binary Output Command)
Object Variation: 1 (Control Relay Output Block)

CROB Structure:
- Control Code: 0x01 (TRIP/Close, Queue operation)
- Count: 1 (execute once)
- On-Time: 1000 ms (1 second pulse)
- Off-Time: 0 ms (not applicable)
- Status: 0x00 (success expected)

Target: Point Index 1 (main circuit breaker)
Result: Substation de-energized, protection cascade begins

Cascade Propagation Through 185 Substations:

When 185 major substations trip simultaneously:

Grid Impact Timeline:

T+0 seconds: 185 substations de-energized
  - Immediate loss: 2,800 MW load (assuming avg 15 MW per substation)
  - Grid frequency response: Sudden loss of 2,800 MW load → frequency RISES

T+5 seconds: AEMO Frequency Response
  - Frequency rises to 50.3-50.5 Hz (oversupply condition)
  - Automatic generation control (AGC) begins ramping down generators
  - RoCoF: +0.4 Hz/s (moderate, but climbing)

T+30 seconds: Protection System Response
  - Over-frequency protection relays activate at 50.5 Hz threshold
  - Generator protection trips begin (thermal limits, voltage regulation)
  - Loss of synchronous generation: 800-1,200 MW

T+60 seconds: Frequency Reversal
  - Generator trips remove 1,200 MW generation
  - Net deficit: 1,200 MW generation loss vs. 2,800 MW load loss
  - Frequency begins falling: 50.5 Hz → 50.0 Hz → 49.7 Hz

T+90 seconds: Under-Frequency Load Shedding (UFLS)
  Modelled staged ladder for RefDNSP-1.2M. AEMO coordinates UFLS but publishes
  no single national relay-setting table, so these stages are the scenario's
  own assumption, not a sourced AEMO figure.
  This is genuine under-frequency shedding, unlike the RoCoF-triggered
  initiation in Section 2.2. Real generation has been lost and frequency has
  fallen well below the normal band, so absolute-frequency relays fire as
  designed.
  - UFLS Stage 1 (modelled): 49.0 Hz - shed 5% of load (additional 500 MW)
  - UFLS Stage 2 (modelled): 48.8 Hz - shed 10% of load (additional 1,000 MW)
  - Cascading load shedding across interconnected regions

T+120 seconds: System Islanding
  - NSW grid separates from National Electricity Market (NEM)
  - Queensland Interconnector (QNI) trips due to frequency mismatch
  - Victoria Interconnector (VNI) trips due to thermal overload
  - NSW operates as isolated island (insufficient local generation)

T+180 seconds: Black System
  - Remaining synchronous generators trip on under-frequency protection
  - Grid frequency collapses below 47 Hz
  - Total system blackout: 1.2-1.5 million customers

Recovery: 24-72 hours (black start procedures, sequential restoration)

Comparison to Historical Precedents:

EventSubstations AffectedCustomers ImpactedRestoration TimeAttack Method
Ukraine 2015 (BlackEnergy)30 substations225,0006 hoursManual circuit breaker operations via compromised SCADA
Ukraine 2016 (Industroyer)1 substation (330kV transmission)20% of Kyiv (~300,000)1 hourAutomated IEC 61850/DNP3 protocol exploitation
South Australia 2016Cascading relay trips (not cyber)850,000 (entire state)6-24 hoursNatural weather event triggering protection cascade
RefDNSP-1.2M Scenario185 substations (modeled)1.2-1.5 million24-72 hoursCoordinated DNP3 Direct Operate + BESS oscillation + thermal runaway

The RefDNSP-1.2M scenario represents a 6x escalation in substation count compared to Ukraine's largest demonstrated attack, with 5x customer impact and 4x longer restoration due to:

  1. Larger geographic area (970 km² vs. single city)
  2. More complex grid topology (interconnected NEM vs. isolated Ukrainian oblasts)
  3. Concurrent physical damage (BESS thermal runaway destroying equipment)
  4. Forensic destruction (wiper malware eliminating recovery configuration data)

3.5 Grid Island Formation and Collapse Mechanics#

When major portions of an interconnected grid lose synchronization, the system fragments into isolated "islands." These are electrically separated regions that must each maintain their own generation-load balance independently.

Separation is not hypothetical and the reference case is measured. On 8 January 2021 the Continental Europe synchronous area split in two across a flow of about 5.8 GW. The deficit side fell at 60 mHz/s to a nadir of 49.746 Hz while the surplus side rose at 300 mHz/s to a peak of 50.6 Hz (ENTSO-E ICS Investigation Expert Panel, Continental Europe Synchronous Area Separation on 08 January 2021, final report, 15 July 2021). Same imbalance, same instant, five times the rate of change on one side. Project Inertia follows that sequence at the resolution the Expert Panel published it and inverts the RoCoF relation to recover the effective inertia each fragment retained. The island survival criteria below ask the same question in advance.

NSW Grid Island Formation Triggers:

InterconnectorThermal RatingProtection ThresholdIsland Formation Condition
Queensland-NSW (QNI)1,078 MW1,200 MW (110% of rating)Power flow >1,200 MW for >10 seconds OR frequency difference >0.5 Hz
Victoria-NSW (VNI)1,350 MW1,500 MW (110% of rating)Power flow >1,500 MW for >10 seconds OR frequency difference >0.5 Hz
Snowy Hydro Link2,100 MW2,300 MW (110% of rating)Power flow >2,300 MW for >10 seconds

Island Survival Criteria:

For an electrical island to survive without cascading to black system, it must satisfy:

Island Stability Conditions:

1. Generation-Load Balance:
   |P_generation - P_load| < 10% of total island load

2. Frequency Stability:
   48.8 Hz < f < 51.2 Hz (AEMO normal operating band: 49.85-50.15 Hz)

3. Voltage Stability:
   0.90 pu < V < 1.10 pu at all major buses

4. Sufficient Inertia:
   H_total > 2.0 seconds (minimum for stable frequency control)

5. Reserve Capacity:
   Spinning reserve > Largest single contingency (typically 600-800 MW in NSW)

NSW Island Analysis After 185-Substation Trip:

Pre-Attack NSW Grid (Normal Operation):
- Total generation: 8,500 MW
- Total load: 8,200 MW
- Synchronous inertia: H = 4.2 seconds
- Spinning reserve: 800 MW
- Interconnector imports: 300 MW (QNI + VNI)

Post-Attack NSW Island (T+120 seconds):
- Total generation: 6,200 MW (2,300 MW lost due to protection trips)
- Total load: 5,400 MW (2,800 MW lost due to substation trips)
- Synchronous inertia: H = 2.8 seconds (generator trips removed inertia)
- Spinning reserve: 200 MW (depleted during frequency oscillations)
- Interconnector status: ISOLATED (frequency mismatch tripped QNI/VNI)

Island Survival Assessment:
1. Generation-Load Balance: 6,200 - 5,400 = +800 MW (15% surplus) ❌ FAIL
2. Frequency Stability: 50.4 Hz (rising due to surplus) ⚠️ MARGINAL
3. Voltage Stability: 0.92-1.08 pu ✓ PASS
4. Sufficient Inertia: H = 2.8 seconds ✓ MARGINAL
5. Reserve Capacity: 200 MW < 600 MW ❌ FAIL

Outcome: ISLAND COLLAPSE within 3-5 minutes
  - Over-frequency protection trips additional generation
  - Frequency oscillation with insufficient damping (low inertia)
  - Voltage instability in load centers (Sydney metro)
  - Black system cascade begins at T+180 seconds

4. Grid Interdependency Analysis#

4.1 Six Critical Infrastructure Systems#

The electricity distribution network is the foundational layer that six interdependent critical infrastructure systems depend upon. Failure in the primary electrical grid propagates through these systems in cascading waves, each amplifying the consequences of the initial outage.

Where the grid separates decides how many of those systems lose supply at once. A separation does not divide a network into two smaller versions of itself; it divides it into fragments with very different capacity to absorb the imbalance each inherits, and the fragment boundary is drawn by protection operating in sequence rather than by any planning decision. Project Inertia makes that argument on the RoCoF figures ENTSO-E published for both sides of the 8 January 2021 split.

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

4.2 Water Infrastructure Cascade#

Water supply infrastructure is the most consequential secondary failure domain. Without electricity, pumping stations cannot maintain pressure, leading to a cascading timeline:

Hours Since BlackoutWater Infrastructure StatusPopulation ImpactHealth Risk
0-2 hoursReservoir reserves sustaining pressureNormal serviceNone
2-4 hoursPressure drop from 30 to 10 psiUpper floors lose service (15% of population)Low
4-6 hoursComplete pressure lossAll customers without water (100%)Moderate
6-12 hoursEmergency reserves depletedHospitals request water tankersHigh
12-24 hoursWastewater system backupSanitation failure, contamination riskCritical
24-48 hoursPublic health emergencyDisease outbreak risk (gastroenteritis, hepatitis)Catastrophic

Emergency water supply requirements: 87 sites at 10,000 litres per site = 870,000 litres capacity. Hospital priority allocation: 12 facilities at 50,000 litres per day = 600,000 litres per day. Both volumes are stipulated RefDNSP-1.2M scenario parameters, not sourced figures. A daily cost of supplying those volumes rests on a New South Wales emergency water tankering unit rate, which a water utility or its contracted tanker supplier holds.

4.3 Hospital and Medical Infrastructure Cascade#

Medical facilities present the highest consequence dependency due to the zero-tolerance nature of life support systems:

Facility TypeCountBackup PowerMaximum Downtime ToleranceFailure Mode
Major Hospitals1224-72 hour diesel0 hours (life support)Patient safety incidents
Dialysis Centers280-4 hour battery2-8 hours before patient crisisRenal failure progression
Aged Care Facilities840-8 hour diesel4-12 hours before HVAC failureHeat stress/hypothermia
Medical Clinics420+None4-6 hoursVaccine/biologics spoilage
Pharmacies320None2-4 hours (refrigeration)Insulin degradation

Critical patient populations at immediate risk: 240 intensive care patients on ventilators (life support failure at 4-24 hours when diesel reserves deplete), 4,200 patients on home oxygen concentrators (immediate respiratory distress at T+0, as home units have no battery backup), and 1,800 dialysis patients (medical emergency after two missed treatments at 48 hours).

4.4 Telecommunications and Emergency Services#

Mobile network failure creates a secondary crisis by severing the population from emergency services:

  • 420 cell towers with 2-8 hour battery backup reach zero coverage between T+2 and T+8 hours
  • 70 percent of emergency 000 calls originate from mobile networks; landline capacity covers only 30 percent of normal call volume
  • Ambulance response time increases from 12 minutes (normal) to 45 minutes (incident). That is a 275 percent degradation in response time.
  • Hospital emergency department presentations surge from 3,500 per day (normal) to 8,500 per day (incident). That is a 243 percent increase in daily volume.

4.5 Transport System Cascade#

Transport infrastructure suffers immediate and severe degradation:

  • 3 electric rail lines halt immediately (180,000 daily passengers diverted to roads)
  • 1,240 traffic signal intersections go dark, increasing accident rates by 180 percent based on historical data from the 2019 Sydney outage
  • Estimated traffic casualties: 15-35 serious accidents in 24 hours, with 0-2 fatalities at high-speed intersections
  • Diesel reserves for emergency vehicles deplete at T+18 hours, degrading ambulance and fire truck operations

4.6 Defence and National Security Infrastructure#

RAAF Base Richmond, naval facilities in the Sydney area, and defence data centres are all within the RefDNSP-1.2M service territory. A 30 to 50 percent reduction in sortie generation capability at RAAF Richmond, degradation of naval munitions cooling systems, and 40 to 60 percent reduction in tactical communications bandwidth constitute a national security incident requiring Defence Minister briefing and triggering potential Parliamentary inquiry.

RAAF Base Richmond Impact Analysis:

RAAF Richmond (NSW) - Critical Defence Infrastructure:

Normal Operations:
- Base load: 18 MW (barracks, hangars, control tower, fueling systems)
- Peak load: 25 MW (full flight operations + facilities)
- Backup generation: 3x 5 MW diesel generators (20 MW total, 8-hour fuel capacity)
- Mission-critical loads: Air traffic control, secure communications, fuel pumps

Blackout Timeline:

T+0 to T+5 minutes: Grid Power Loss
- Automatic transfer to backup diesel generators
- Air traffic control maintains operations (critical safety system)
- In-flight aircraft diverted to alternate airfields (Canberra, Williamtown)
- Runway lighting operational on backup power

T+5 minutes to T+2 hours: Backup Generator Operations
- Flight operations SUSPENDED (takeoffs/landings prohibited)
- Fuel transfer systems operational but severely limited
- Secure communications degraded to backup satellite systems
- Personnel accountability checks (base lockdown protocols)

T+2 hours to T+8 hours: Fuel Reserves Depleting
- Diesel generators consuming 400 liters/hour each = 1,200 liters/hour total
- Total fuel capacity: 9,600 liters (8-hour runtime at full load)
- Fuel resupply requires road tanker access (potentially blocked by traffic chaos)

T+8 hours to T+24 hours: Generator Shutdown
- Critical loads prioritized: Communications, security, minimal lighting
- All non-essential systems offline (hangars, workshops, accommodation HVAC)
- Base operational readiness: 20% of normal capacity
- RAAF capability across NSW region: SEVERELY DEGRADED

National Security Implications:
- Search and rescue operations delayed or cancelled
- No air defence response capability for NSW airspace
- Disaster relief operations (e.g., bushfire water bombing) impossible
- Special operations deployment timelines extended 12-24 hours
- Potential violation of ANZUS treaty obligations if attack during regional crisis

Garden Island Naval Base Impact:

Garden Island (Sydney Harbour) - East Coast Principal Naval Base:

Critical Systems Dependent on RefDNSP-1.2M Grid:
- Submarine support facilities (HMAS Platypus)
- Surface vessel replenishment systems
- Naval ammunition storage refrigeration (temperature-critical munitions)
- Secure communications (Defence Secret and Above)
- Personnel accommodation (1,200+ naval personnel)

Blackout Cascade:

T+0 to T+30 minutes: Initial Response
- Diesel generators start (6x 3 MW units = 18 MW total)
- Submarines in port switch to battery power (24-48 hour endurance)
- Surface vessels activate onboard generation (independent of shore power)
- Munitions storage facilities on backup cooling (critical: Harpoon missiles, Mark 48 torpedoes)

T+30 minutes to T+4 hours: Operational Degradation
- Submarine battery depletion begins (cannot operate ventilation/life support simultaneously)
- Surface vessel berthing compromised (no refueling, no resupply)
- Munitions storage temperature rising (cooling backup limited to 4 hours)
- Secure communication to Defence HQ Canberra via satellite only (bandwidth limited)

T+4 hours to T+24 hours: Critical Equipment Risk
- Munitions storage exceeds safe temperature limits (28°C threshold for some weapons)
- Submarine operations shift to emergency procedures (reduced crew, minimal systems)
- No new vessel arrivals possible (berthing services offline)
- Base security systems degraded (electronic access control, CCTV offline)

T+24 hours to T+72 hours: National Defence Posture Degradation
- East coast naval operations effectively suspended
- Submarine force unavailable for tasking (battery depleted, unable to dive)
- Munitions inventory compromised (10-15% requiring disposal due to thermal exposure)
- Fleet reconstitution requires implementation period required after power restoration

4.7 Economic and Financial Infrastructure Cascade#

Beyond direct customer losses, the financial services infrastructure dependent on electricity supply creates second-order economic consequences that amplify rapidly during extended outages.

Banking and Financial Services Impact:

Hours Since BlackoutBanking Infrastructure StatusCustomer ImpactEconomic Consequence
0-2 hoursATMs operational on battery (UPS), branches on generatorMinimal (normal cash reserves)Negligible
2-4 hoursATM network failing, generator fuel consumption criticalCash withdrawal failures, card payment disruptionRetail sales decline 40-60%
4-8 hoursMost ATMs offline, branch generators under fuel stressCash shortage panic, electronic payment network degradedRetail commerce near-complete halt
8-24 hoursComplete ATM network failure, branch closuresPublic panic, cash hoarding, grocery store closuresSupply chain disruption, food security concerns
24-48 hoursData center backup generation fuel exhaustedCore banking systems offline, no transactions possibleEconomic activity suspended, payroll systems failing
48-72 hoursExtended outage triggers bank run preparationGovernment emergency cash distribution requiredNational financial stability concerns

Stock Exchange and Trading Infrastructure:

The Australian Securities Exchange (ASX) data centers and trading infrastructure are located within Sydney's central business district, with critical components in the RefDNSP-1.2M service territory.

ASX Trading Infrastructure Dependencies:

Primary Data Center (Equinix SY3, Sydney):
- Grid power: 15 MW (normal operations)
- Backup: N+1 diesel generators (48-hour fuel capacity)
- Criticality: national financial markets; no sourced ASX market capitalisation figure is held, so none is stated

Secondary Data Center (Equinix SY1, Sydney):
- Grid power: 8 MW (normal operations)
- Backup: N+1 diesel generators (48-hour fuel capacity)
- Failover capability: Automatic within 5 minutes

Blackout Scenario:

T+0 to T+5 minutes: Automatic Failover
- Primary data center transfers to diesel generators
- Trading continues uninterrupted (market participants unaware)
- ASX monitoring initiates fuel resupply coordination

T+5 minutes to T+24 hours: Normal Operations Maintained
- Diesel generators operating nominally
- Fuel consumption: 600 liters/hour (15 MW load)
- Total reserves: 28,800 liters (48-hour capacity)

T+24 to T+48 hours: Fuel Resupply Critical
- Fuel trucks attempting delivery through traffic chaos
- ASX considers trading halt if resupply uncertain
- Regulatory notifications to ASIC and Reserve Bank

T+48 to T+72 hours: Extended Outage Crisis
- Fuel reserves depleting despite emergency resupply efforts
- ASX announces trading suspension (unprecedented in modern era)
- Global market consequences: AUD currency volatility, international investor confidence
- Government intervention required (National Cabinet convened)

Economic Multiplier Effects:

The only cost this paper computes is the direct cost to customers of energy not supplied, and it is computed once, in section 5.4, from the AER's determined value of customer reliability. For the 72-hour system-wide case that figure is AUD 1.99 billion to AUD 8.95 billion (modeled: VCR extrapolated to 72 hours, six times its determined range). Section 5.4's reference case at the boundary of the determination, the full network at 12 hours, is AUD 1.19 billion [n].

That figure is not split by customer segment. Section 5.6 sets out why: the 2.15 kW coincident demand anchor is an all-customer average taken from AEMO's South Australian black system report, no per-segment demand figure was sourced, and the residential VCR is therefore applied across the whole base. A residential, commercial and industrial split would need two inputs the paper does not hold.

Each of the indirect and tertiary categories below is a real cost, listed with the input its price rests on. Section 5 quantifies the same cascade from published values, and these categories join that total once those inputs are in hand.

CategoryOrderInput the price rests on
Stock market trading suspensionIndirectAn ASX daily trading volume for the affected listings, which the exchange publishes, and a method for converting a suspension into a realized loss rather than a deferral, which a market analyst supplies
Banking system disruptionIndirectA daily transaction volume for the affected region, which the banking system holds, priced through a loss model since transaction volume alone is not loss
Retail commerce haltIndirectA NSW regional daily retail sales figure, which the ABS or a retail industry body publishes
Logistics disruptionIndirectA daily freight movement value for the service territory, which the logistics sector reports
Tourism impactIndirectAn accommodation and transport cancellation value, which tourism operators and booking platforms hold
Supply chain breakdownTertiarySection 5.10 names the same input: a per-facility spoilage or batch-loss value, which each facility's own production records hold
Insurance claimsTertiarySection 5.10 names the same input: a premium elasticity and a claims ratio, which an insurer or broker's placement data holds
Lost productivityTertiaryA basis drawn from a business's own payroll and output records, which overlaps the direct customer cost already computed in section 5.4
Recovery costsTertiaryAn emergency services or infrastructure repair rate, which the responsible agency or utility holds

No total is stated for direct plus indirect plus tertiary loss, because nine of the twelve terms have no value. The direct customer cost of section 5.4 is a component of total economic loss, not the total, and this section does not close that gap.

4.8 Cross-Sector Dependency Matrix#

The following matrix quantifies the interdependency strength between electricity supply and dependent critical infrastructure:

Dependent SectorElectricity DependencyMaximum Downtime ToleranceBackup Power AvailabilityCascade Multiplier
Water Supply95%2-4 hours (reservoir reserves)10% (critical pumping stations)2.5x (water loss triggers hospital/sanitation cascade)
Hospitals98%0 hours (life support systems)80% (24-72 hour diesel)3.0x (medical emergencies trigger transport/emergency services)
Telecommunications90%2-8 hours (battery backup)20% (critical sites only)2.8x (communication loss triggers security/coordination failure)
Transport85%0 hours (traffic signals, rail)5% (emergency services only)2.2x (mobility loss triggers supply chain/emergency response)
Financial Services92%4-8 hours (UPS/generator)40% (data centers, major branches)2.0x (economic activity halt triggers employment/supply)
Defence88%8-12 hours (generator fuel)60% (bases have backup generation)1.5x (limited civilian cascade but national security consequence)

Cascade Multiplier Explanation:

The cascade multiplier represents how failure in the dependent sector amplifies the original blackout's impact:

  • 2.5x multiplier (Water): Water supply failure triggers hospital patient care crisis (dialysis, sterilization), public health emergency (sanitation), and firefighting capability loss (BESS fires uncontrolled)
  • 3.0x multiplier (Hospitals): Medical system overload triggers emergency services collapse (ambulance delays), increases fatalities from time-critical conditions (cardiac, stroke, trauma), and creates refugee crisis (hospital evacuations)
  • 2.8x multiplier (Telecommunications): Communication loss triggers security coordination failure (police/fire/ambulance cannot coordinate), public panic (misinformation spread), and economic disruption (no electronic transactions)

4.9 Cascading Timeline: Comprehensive 72-Hour Projection#

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

5. Economic Impact Assessment#

This section prices one thing: the direct cost to customers of energy not supplied during the modeled cascade. Equipment damage, litigation, insurance, reputational cost and opportunity cost are real costs too, and each rests on an input a business holds in its own records rather than one a public source states; section 5.10 names each input. Every monetary figure below is either computed from a cited input or labeled as a modeled estimate with its assumption stated.

5.1 Derivation Basis#

Every monetary figure in this section derives from published inputs through the relations below. A reader holding the cited sources can reproduce or contest any value.

The relations produce one loss figure for one modeled event. Turning that into an annualized expectancy, and then into a defensible return on a control programme, is set out in Annualized Loss Expectancy and Return on Security Investment for OT, which works ALE per NIST SP 800-30 Rev. 1, the Gordon-Loeb optimal investment ceiling and the ROSI ratio through a modeled hyperscale case. Section 5.9 uses the first of those and section 9.5 uses a benefit to cost form of the third. No Gordon-Loeb ceiling is computed anywhere in this paper, because RefDNSP-1.2M has no stipulated security budget and no vulnerability parameter to fit one against.

Eunserved=Ncustomers×Pˉdemand×trestoreE_{\text{unserved}} = N_{\text{customers}} \times \bar{P}_{\text{demand}} \times t_{\text{restore}}
Cdirect=VCR×EunservedC_{\text{direct}} = \text{VCR} \times E_{\text{unserved}}

VCR is the Value of Customer Reliability in dollars per kilowatt hour, determined by the Australian Energy Regulator [n]. Determination of VCR has been the AER's statutory responsibility since the Australian Energy Market Commission's final rule of July 2018. The earlier 2014 NEM-wide study was produced by AEMO [n].

Figures marked modeled are not measured outcomes. Their assumptions are stated inline.

5.2 Scope Limit on the VCR Values#

The AER determined the 2024 VCR values for unplanned outages of up to 12 hours. That is the duration range the willingness-to-pay surveys behind them covered [n]. The cascade modeled in this paper runs to 72 hours.

Applying a 12-hour value across 72 hours takes the parameter roughly an order of magnitude outside the range for which it was determined. The correct instrument for outages longer than 12 hours is the AER's separate Value of Network Resilience review, and this paper holds no VNR figure. Every figure below that rests on a duration longer than 12 hours is therefore an upper-bound extrapolation, not a determination, and is marked as such in the cell where it appears. The extrapolation is linear in duration. The real relation is not known to be linear, and what a household will pay to avoid the second day of an outage is not established by a survey about the first twelve hours.

Two further limits apply to the VCR values used here.

  • The NEM value of AUD 41.48 per kWh and the NSW value of AUD 38.53 per kWh are residential values from Table 1 of the AER's 2024 final report [n]. They are not all-customer blended values. The AER's NEM-wide and regional aggregates were not retrieved and are not used anywhere in this section.
  • The reference network is modeled on NSW, so NSW residential AUD 38.53 per kWh is the base case throughout. Substituting the NEM residential value raises every computed figure below by 7.7 percent.

5.3 Input Values#

InputValueBasis
Customers, full network1,200,000RefDNSP-1.2M stipulated parameter, section 2. Modeled, not sourced
Average coincident demand per customer2.15 kW1,826 MW regional demand across 850,000 customers, AEMO final report on the South Australian black system of 28 September 2016 [n]
VCR, residential NSWAUD 38.53 per kWh, 2024 dollarsAER 2024 VCR final report, Table 1 [n]
VCR, residential NEMAUD 41.48 per kWh, 2024 dollarsAER 2024 VCR final report, Table 1 [n]
VCR duration validityUnplanned outages up to 12 hoursAER 2024 VCR final report, scope statement [n]

The 2.15 kW anchor is an all-customer coincident average. AEMO's 1,826 MW is regional demand and the 850,000 is all South Australian customers, so the figure already carries residential, commercial and industrial load together. No per-segment demand figure was available, so the same 2.15 kW is applied to every customer in the table below.

Two transplants are involved and both are stated rather than buried. The 2.15 kW is measured for one region, at one moment, on a spring afternoon in South Australia, and is applied here to a modeled NSW network. Coincident demand per customer varies by jurisdiction, season and time of day, and no NSW equivalent was sourced. Second, the customer counts and restoration durations in section 5.4 come from the cascade model of section 3.2. They are the working group's own scenario parameters, not measured outcomes.

5.4 Direct Customer Cost by Cascade Tier#

Tiers, customer counts and durations are those of section 3.2. Unserved energy is customers multiplied by 2.15 kW multiplied by restoration hours. Direct cost is that energy multiplied by AUD 38.53 per kWh.

TierCustomersDurationUnserved energyDirect customer costVCR domain
1, immediate impact zone8,000 to 12,0002 to 4 h34 to 103 MWhAUD 1.3 million to AUD 4.0 million [n]12 h or less, determined
2, local cascade, lower bound80,0008 h1,376 MWhAUD 53 million [n]12 h or less, determined
2, local cascade, upper bound120,00016 h4,128 MWhAUD 159 million (modeled: VCR extrapolated to 16 h, beyond its 12 h determination)Extrapolated
3, regional cascade400,000 to 600,00016 to 36 h13,760 to 46,440 MWhAUD 530 million to AUD 1.79 billion (modeled: VCR extrapolated to 36 h)Extrapolated
4, system-wide collapse1,000,000 to 1,500,00024 to 72 h51,600 to 232,200 MWhAUD 1.99 billion to AUD 8.95 billion (modeled: VCR extrapolated to 72 h, six times its determined range)Extrapolated

Worked example, tier 2 lower bound: 80,000 customers multiplied by 2.15 kW multiplied by 8 hours gives 1,376,000 kWh. At AUD 38.53 per kWh that is AUD 53.0 million.

Reference case at the boundary of validity. The full network at the longest duration the AER determination covers: 1,200,000 customers multiplied by 2.15 kW multiplied by 12 hours gives 30,960 MWh, and at AUD 38.53 per kWh, AUD 1.19 billion [n]. This is the largest direct customer cost this paper can state on the determination alone. Every figure above it is an extrapolation, including the headline tier 4 range.

The full envelope across the cascade, from the localized tier 1 outage to system-wide collapse, is AUD 1.3 million to AUD 8.95 billion. The lower bound is a determination. The upper bound is not.

5.5 Restoration Profile and the Single-Scalar Simplification#

The table above uses one restoration-hours scalar per tier. Real restorations are not uniform. In the only observed Australian case at this scale, the South Australian black system of 28 September 2016, the first customers were restored under three hours after the event, 80 to 90 percent of load was back by midnight, roughly eight hours in, and the last customers were not restored until 11 October, a tail of about thirteen days [n].

A single scalar is therefore a simplification, and it is stated as one. It understates the tail and overstates the head. The direction of the error depends on which end dominates, and the tail dominates when it is long: if 10 percent of 1,200,000 customers stayed off for thirteen days, that alone is 120,000 multiplied by 2.15 kW multiplied by 312 hours, or 80,496 MWh, which is AUD 3.10 billion at AUD 38.53 per kWh (modeled: VCR extrapolated to 312 h, twenty-six times its determined range). That figure is offered to show why the scalar is a simplification, not as a cost estimate. At twenty-six times the determined duration the VCR carries no useful information, which is the honest conclusion about long-tail restoration cost on the evidence available.

5.6 Segment Composition of the Customer Base#

The table in section 5.4 applies a residential VCR to every customer. The AER's business values, in AUD per kWh, 2024 dollars, Table 2 of the final report [n], are Agriculture 22.25, Commercial 34.39 and Industrial 33.49. All three sit below the NSW residential 38.53 used above, so applying the residential value across the whole customer base biases the computed cost upward rather than downward.

The AER's very large business values, Table 3 [n], are Services 33.10, Industrial 12.22, Mines 10.63 and Metals 5.38. They are not used in any computation here, and they should not be treated as stable parameters: the AER attributes part of the fall since 2019 to a change in who answered the survey rather than to a change in preference, noting that "the sample composition for each segment in 2024 is substantially different from 2019". Very large business industrial falls from AUD 142.22 to AUD 12.22 in 2024 dollars across five years, an order of magnitude on a resample.

5.7 Observed Cost of a Comparable Event#

Business SA, the state's peak business lobby, surveyed about 200 businesses after the 28 September 2016 South Australian black system and put the cost to South Australian business at AUD 367 million, with a median of AUD 5,000 per business and about AUD 115 million of the total falling on four firms [n]. This is a lobby group's survey, not a regulator's figure, and it counts business losses only, so it is a floor on the event's economic cost rather than a total.

The same relation used in section 5.4, applied to that event, gives a cross-check: 850,000 customers multiplied by 2.15 kW multiplied by 8 hours is 14,620 MWh, and at the South Australian residential VCR of AUD 48.52 per kWh that is AUD 709 million [n]. The modeled figure is about twice the surveyed one, which is the expected direction of difference: the model applies a residential VCR to all customers and counts residential and public-sector loss that the survey excluded, while the survey counts categories of business cost that the unserved-energy relation does not decompose. Note also that this applies a 2024 VCR to a 2016 event, so the comparison is not like for like in price terms.

A forecast of SOCI Act 2018 penalties, civil damages, or class action quantum against the reference network rests on a penalty schedule, a settlement record or a court judgment, each held by the regulator or the court rather than published in advance. What can be stated is the one regulatory outcome that has been settled for a comparable event.

After the Great Britain outage of 9 August 2019, which disconnected 1,152,878 customers, Ofgem reported that Hornsea 1 Limited and RWE Generation UK plc each agreed to make voluntary payments of GBP 4.5 million to the Energy Industry Voluntary Redress Scheme, and that Eastern Power Networks plc and South Eastern Power Networks plc agreed to pay GBP 1.5 million in aggregate for reconnecting customers without instruction, a separate breach from the cascade itself [n]. Ofgem made no formal legal determination of breach, and found no failures by the system operator that contributed to the outage [n].

The order of magnitude is the point. About GBP 10.5 million across four licensees, for an event affecting a customer count comparable to the tier 4 scenario, is small against the direct customer cost computed in section 5.4. Regulatory payments are not a proxy for economic loss, and neither figure should be used to estimate the other.

5.9 Risk-Adjusted Expected Loss#

The probability of the modeled attack over a 10-year horizon, 15 to 30 percent, is this paper's own assessment (section 1). It is a modeled figure set by this working group and is labeled as such at each use.

Expected loss is that probability multiplied by direct cost. Using the reference case at the boundary of VCR validity, AUD 1.19 billion:

  • At 15 percent: AUD 179 million (modeled: probability is the working group's own assessment)
  • At 22.5 percent, the midpoint: AUD 268 million (modeled: same basis)
  • At 30 percent: AUD 358 million (modeled: same basis)

Substituting the tier 4 upper bound of AUD 8.95 billion raises the midpoint expected loss to AUD 2.01 billion (modeled: compounds the probability assessment with a VCR extrapolated to 72 h). Expected loss is stated in undiscounted ten-year dollars, which keeps the probability assessment and the VCR extrapolation as the only modeled inputs behind the figure.

5.10 Categories Priced from a Business's Own Records#

Each of the following is a real cost, listed with the input its price rests on.

CategoryInput the price rests on
Direct grid damageA unit cost for 66 kV transformers, 11 kV switchgear, BESS modules and inverters, and a failure probability for each, which a utility's asset register and its insurer hold
Emergency restoration labor and expeditingA labor rate and an air-freight premium, which a utility's procurement and workforce records hold
Regulatory penaltiesA SOCI Act penalty schedule and a precedent against an Australian DNSP, which the regulator's enforcement record sets once one exists
Civil litigationA quantum for wrongful death, personal injury or business interruption class action in this jurisdiction, which a court judgment or settlement record sets
Reputational damageA method for valuing it over a 24-month horizon, which a brand-valuation or customer-churn study supplies
Insurance claims and premium responseA premium elasticity, which an insurer or broker's placement data holds
Opportunity costA basis drawn from a business's own foregone-revenue accounting, which overlaps the direct customer cost already computed in section 5.4
Per-facility industrial lossA per-facility spoilage or batch-loss value for food processing, pharmaceutical or mining operations, which each facility's own production records hold

Interdependency amplification across the six critical infrastructure systems of section 4 is also excluded from every figure in this section. The direct customer cost computed here is a component of total economic loss, not the total.


6. Physical Safety Consequences#

6.1 BESS Thermal Runaway#

A secondary attack vector targeting Battery Management System (BMS) controllers via Modbus injection can induce thermal runaway by commanding overcharge voltage above the safe threshold of 3.65 V per cell to 4.5 V per cell. The physics of lithium-ion thermal runaway proceed as follows:

  • Overcharge initiates lithium plating on the anode (15-45 minutes)
  • Internal short circuit develops from dendrite penetration of the separator
  • Exothermic reaction begins at 130-180 degrees Celsius (chemistry dependent)
  • Cell-to-cell propagation time: 3-15 minutes depending on spacing and cooling
  • Container-level fire: 5 MWh energy release over 4-12 hours (equivalent to approximately 4,000 kg TNT in total thermal energy, though released gradually rather than as detonation)

Safety Consequences of Thermal Runaway Event:

  • Personnel at risk: 2-5 technicians on-site during normal operations
  • Evacuation radius: 500 metres (toxic gas plume includes HF, CO, and particulates)
  • Fatalities estimate: 0-2 (rapid evacuation and remote locations reduce risk)
  • Serious injuries: 2-8 (smoke inhalation, burns)
  • Environmental contamination: fluorinated compounds in soil and water. A cleanup cost for a lithium-ion fire site in Australia rests on a remediation unit cost, which an environmental remediation contractor or the EPA holds

6.2 Traffic Signal Failures#

Historical data from the 2019 Sydney signal outage establishes a 180 percent increase in accident rates at dark intersections:

  • 1,240 intersections dark for 4-24 hours
  • Expected accidents: 15-35 collisions (baseline: 5-10 in a normal 24-hour period)
  • Fatalities: 0-2 at high-speed intersections
  • Serious injuries: 8-18
  • Emergency services response time degradation of 40 to 80 percent due to combined congestion and signal failures

6.3 Medical System Failures#

The delayed or denied medical care caused by hospital overload, ambulance response degradation, and loss of home medical equipment creates the largest category of fatality risk:

  • Delayed cardiac care: 5-12 additional deaths from time-critical cases
  • Trauma response delays: 8-15 additional serious injuries from accidents and falls
  • Stroke treatment delays: 3-8 additional permanent disabilities from tissue death during delays
  • Home oxygen patients: 4,200 individuals at immediate risk of respiratory distress
  • Aged care HVAC failures: 120-280 heat exhaustion cases in summer scenario (35-40 degrees), 2-8 fatalities

6.4 Cumulative Safety Impact#

Safety ConsequenceLow EstimateHigh EstimateExpected (P50)
Fatalities52512
Serious Injuries4012075

[PROSPECTIVE MODEL - Historical Ukraine attacks (2015, 2016, 2022) resulted in zero direct fatalities despite 225,000 affected customers and 6-hour outages. The 5-25 fatality estimate is based on cascading infrastructure failure scenarios (medical system collapse, traffic accidents, thermal runaway events) without Australian precedent. This represents worst-case modeling for Board risk assessment rather than empirical prediction.]

Minor Injuries180450300
Hospital Admissions250680420
Emergency Presentations1,2003,5002,100

These figures carry legal consequences: wrongful death litigation, WorkSafe NSW investigation, potential Coroner's inquest, EPA environmental investigation, and the possibility of criminal charges for negligence causing death if cybersecurity failures are deemed reckless. A quantum for each rests on a court judgment or settlement record specific to the case. Section 5.10 names civil litigation on the same basis: a wrongful death, personal injury or class action quantum for this jurisdiction, which a court judgment or settlement record sets, and section 5.8 shows why regulatory outcomes are not a proxy, with about GBP 10.5 million in voluntary payments across four licensees after an event that disconnected 1,152,878 customers [n].


7. Attack Vector Analysis and Mitigation#

The four vectors below were found by walking each attack path against the physical process it reaches, not by enumerating vulnerabilities and sorting them by CVSS. That walk is the CyHAZOP method: the IEC 61882 process safety guide words applied to cyber-physical nodes, with the transfer function from an injected command to a physical excursion stated explicitly rather than assumed. CyHAZOP: Cyber-Physical Hazard Analysis for Hyperscale Infrastructure sets out the guide word lexicon, the node register format and the DEXPI to multi-BOM linkage the walk depends on. Section 7.4 below, a Modbus write to a BMS voltage setpoint that ends in thermal runaway, is a worked instance of it.

This section prices mitigation against a control class or a stated mechanism. Scoring a named actor's capability to reach the asset is the work of two Eigenia documents that run alongside it. The TACAM matrix characterizes actors across capability, sector targeting and vendor product exposure. The Adversary Threat Quotient reduces those dimensions to one cardinal figure on a 0 to 100 interval that can parameterize a loss model directly. A reader who needs to know whether a specific actor can execute the six stages of section 7.1 should start there. This paper assumes the capability exists, on the Sandworm precedent of section 3.4, and asks only what blocking it would cost.

7.1 Retailer API Supply Chain Attack#

This is the primary attack vector enabling the Death Wobble scenario. The attack chain proceeds through six stages:

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

The same six stages map onto the Purdue reference model, from enterprise systems at Level 4 and 5 down to the physical process at Level 0. The mapping matters because the boundary crossings are the argument: the attack starts in the retailer's business systems, crosses the IT-OT boundary through an API that accepts a stolen token, and ends by moving grid frequency itself. Each labeled arrow is a crossing a defender could have blocked.

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

Current Control Gaps:

ControlCurrent StateGapRisk Enabling
API AuthenticationOAuth 2.0No MFA, no geofencingToken theft enables full access
Rate LimitingNoneNo behavioral analyticsAllows rapid mass commands
Command AuthorizationBasic RBACNo dual authorizationSingle compromised account sufficient
Oscillation DetectionNoneNo pattern analysisAttack signature undetected
Physics-Based ValidationNoneNo grid stability checksCommands not validated against RoCoF

Mitigation Strategy:

Costs use the ordinal band scheme of section 9.1, measured against the sourced CIRMP cyber envelope of AUD 1.29 million one-off. Bands rank controls against each other; they do not price them. Where a control maps onto one of the five OT control classes Dragos and Marsh McLennan measured, the class figure is cited and the mapping stated. Where none maps, the benefit is given as a mechanism rather than a percentage.

MitigationCost bandEffect
API behavioral analytics, Apigee or Kong with MLC, the band section 9.2 assigns the same controlNetwork visibility and monitoring. Dragos and Marsh McLennan measure 16.47 percent average risk reduction for this class [n]. A class average across a global claims population, not this control's measured effect
Just-in-time MFA for dispatch commandsA (policy and configuration on an existing identity platform)Secure remote access. Dragos and Marsh McLennan measure 12.18 percent average risk reduction for this class [n]. Same caveat
Dual authorization for commands above 10 MWA, the band section 9.6 assigns this quick winNo benchmark class maps. The control removes the single-credential path: one stolen OAuth token no longer dispatches a fleet. It does not lower the chance of the token being stolen
Oscillation detection algorithmB (analytics on telemetry the network already collects)No benchmark class maps. The control fires on a pattern with no benign explanation, more than five charge or discharge reversals per asset inside 10 minutes. No false-positive rate has been measured for this network, so no detection figure is stated
Device command batching limitsA (configuration and vendor engineering, as in section 9.2)No benchmark class maps. A 5-minute minimum interval caps achievable oscillation at 0.0017 Hz against the 0.5 to 0.55 Hz attack band of section 2.1.2, which moves the attack outside resonance rather than lowering its probability

Band arithmetic: three band A, one band B, one band C. Summing the band boundaries gives AUD 0.7 million to AUD 2.2 million one-off (modeled: band boundary arithmetic, not a quotation). Risk reduction is reported per control. Dragos and Marsh McLennan state their per-control figures are not additive and model no combined effect [n].

7.2 Kubernetes Container Escape#

The DERMS platform runs on OpenShift Kubernetes on Nutanix. Container escape enables lateral movement from a compromised DERMS microservice to the ICCP Adapter pod, providing the capability to forge grid constraint data and cause unsafe BESS dispatch.

Relevant vulnerabilities include CVE-2024-0874 (OpenShift route access control bypass), potential Docker socket mount misconfigurations, and etcd exposure if encryption at rest is not configured.

Mitigation Strategy:

MitigationCost bandEffect
Container runtime security, Aqua or SysdigB, the band section 9.3 assigns the same control in Phase 1Defensible architecture. Dragos and Marsh McLennan measure 17.09 percent average risk reduction for this class [n]. Class average, not a measured result for this product
Pod security policies, no-privileged and read-only rootA (platform configuration)No benchmark class maps. A container that cannot run privileged and cannot write its own root filesystem loses the two most commonly used escape paths. It does not remove a kernel vulnerability
Network policies, deny-all defaultA (platform configuration)Defensible architecture, 17.09 percent class average [n]. The mechanism is direct: a compromised DERMS microservice cannot open a connection to the ICCP adapter pod at all
Image signing verificationB (pipeline engineering across the whole build chain)No benchmark class maps. An unsigned image does not run, which closes the supply chain path of section 7.1 into the cluster. It does nothing against an attacker holding the signing key
etcd encryption at restA (platform configuration)No benchmark class maps. Cluster secrets read from disk or from a backup are ciphertext. It does not protect secrets read through a live API server session

Band arithmetic: three band A and two band B give AUD 0.3 million to AUD 1.4 million one-off (modeled: band boundary arithmetic, not a quotation). Risk reduction is reported per control.

7.3 ICCP Protocol Manipulation#

Compromise of the ICCP Adapter enables forging of grid constraint queries to ADMS, returning false "all clear" voltage and thermal limits. This causes DERMS to issue dispatch commands that violate actual grid constraints, resulting in equipment damage or outages.

Mitigation Strategy:

MitigationCost bandEffect
ICCP protocol parser for SIEMB, the band section 9.3 assigns this line in Phase 2 (bespoke engineering, no product to price)Network visibility and monitoring, 16.47 percent class average [n]. Class average, not this parser's measured effect
Application-layer signing, ADMS signs and DERMS verifiesB (bespoke engineering across two platforms)No benchmark class maps. Forged constraint data fails verification. It does nothing if the attacker holds the ADMS signing key, which is the supply chain case of section 7.1
Data point allowlistingA (configuration on the existing ICCP association)No benchmark class maps. A data point outside the agreed set is refused, so no new constraint object can be introduced. It does not prevent false values inside the allowed set
Redundant validation, cross-check against SCADA telemetryB (analytics on an existing SCADA historian, as in section 9.2)No benchmark class maps. An ICCP constraint that disagrees with independently measured SCADA telemetry is held rather than acted on. This requires the two paths to be genuinely independent, which is not verified for RefDNSP-1.2M anywhere in this paper

Band arithmetic: one band A and three band B give AUD 0.4 million to AUD 1.7 million one-off (modeled: band boundary arithmetic, not a quotation). Risk reduction is reported per control.

7.4 Modbus Injection to BESS Controllers#

Modbus TCP (port 502) between the Utility Server and BESS controllers operates without encryption, authentication, or integrity checking. A compromised Utility Server can write arbitrary register values to BMS controllers, including overcharge voltage setpoints that initiate thermal runaway.

The register write matters because of what sits downstream of it. Emerging Power Topologies, section 3, follows the thermal runaway cascade from cell to module to container and reaches the conclusion the second mitigation line below records: limit enforcement has to sit beneath the protocol, because a limit the protocol can write is a limit the attacker can write.

Mitigation Strategy:

MitigationCost bandEffect
Modbus security gateway, Moxa EDR or Fortinet ICSC, the band section 9.2 assigns the same control. Every listing found for the named product returns price on requestDefensible architecture, 17.09 percent class average [n]. Class average, not a measured result for register allowlisting
BMS firmware update, voltage limit validationB, the band section 9.2 assigns the same controlNo benchmark class maps. Limit enforcement moves below the protocol, so a write to a setpoint register cannot raise a limit. It does not remove the attacker's access to the register
Network segmentation, dedicated VLAN per BESSC (54 sites; the wider zero-trust microsegmentation line in section 9.3 sits in band D)Defensible architecture, 17.09 percent class average [n]
Anomaly detection, Nozomi or ClarotyD, the band section 9.3 assigns OT network monitoring. No vendor in this class publishes a priceNetwork visibility and monitoring, 16.47 percent class average [n]

Band arithmetic: the three bounded lines, one band B and two band C, give AUD 1.2 million to AUD 3.1 million one-off (modeled: band boundary arithmetic, not a quotation). The band D line has no upper bound and is excluded, so the real figure is higher by an unknown amount. Risk reduction is reported per control.

7.5 Consolidated Mitigation Investment#

Attack VectorCost bandsBounded band arithmeticBenefit basis
Retailer API supply chain3 x A, 1 x B, 1 x CAUD 0.7 million to AUD 2.2 millionTwo of five controls map to a Dragos and Marsh class, at 16.47 and 12.18 percent [n]. Three state a mechanism
Kubernetes container escape3 x A, 2 x BAUD 0.3 million to AUD 1.4 millionTwo of five map to defensible architecture, 17.09 percent [n]. Three state a mechanism
ICCP protocol manipulation1 x A, 3 x BAUD 0.4 million to AUD 1.7 millionOne of four maps to network visibility and monitoring, 16.47 percent [n]. Three state a mechanism
Modbus injection1 x B, 2 x C, 1 x DAUD 1.2 million to AUD 3.1 million, band D excludedAll four map to a Dragos and Marsh class, at 17.09 or 16.47 percent [n]
Total, bounded lines only18 controls, of which one is band D and unboundedAUD 2.5 million to AUD 8.4 millionNot aggregable; see below

Three things about that total. It is band boundary arithmetic against the sourced AUD 1.29 million CIRMP cyber envelope of section 9.1, not a quotation from anyone. It excludes the single band D line, which has no upper bound, so the true figure is higher by an amount this paper cannot state. And the sourced envelope itself is AUD 1.29 million one-off, so the seventeen bounded controls alone cost between about twice and six and a half times what the sector-average regulatory compliance figure covers. That is the same conclusion section 9.3 reaches from the other direction.

No aggregate risk reduction is given, and no per-vector return on investment is given. Dragos and Marsh McLennan state their class figures are not additive and model no combined effect [n], so each column is read separately, by control class, rather than summed. A per-vector ratio would also need a per-vector avoided loss, and section 5 computes one avoided loss for the whole cascade rather than four. The programme-level ratio, 4.4:1 to 6.6:1 with a sensitivity envelope of 2.9:1 to 8.8:1, is derived once in section 9.5 and is not restated per vector here.


8. Operational Procedures#

The emergency response timeline, the recovery constraints and the three incident response playbooks appear as sections 2 through 5 of the companion Grid Incident Response Playbook. That document also carries the attack detection signatures and indicators of compromise, the black start and resilience procedures, and the stakeholder communication and coordination protocols.

The split is by audience. A responder needs the run-books without the physics; a reviewer needs the physics without the run-books. Every threshold, cost band and figure in the playbook is derived in this paper, and this paper stays the source of record for all of them.


9. Strategic Recommendations#

This section prices two things: what each recommended control costs, and what it buys. Both are weakly sourced. That is stated in the cells themselves rather than buried in a footnote, because a cost-benefit table with one sourced column and one invented column is worse than no table.

9.1 Cost and Benefit Basis#

Cost anchor. The only regulator-quality Australian per-entity figure located is the Australian Government's October 2024 Impact Analysis for amendments to the Security of Critical Infrastructure Act 2018 [n]. Table 19 of that document, indexed to June 2024 dollars, puts the average cost of a Critical Infrastructure Risk Management Program at AUD 9.2 million one-off and AUD 4.3 million per year for a critical electricity asset entity. That is a whole-of-hazard figure. It covers cyber and information security hazard, personnel hazard, supply chain hazard, physical and natural hazard, and material risk together. Table 27 of the same document puts cyber and information security hazard at 14 percent of the electricity sector's ten-year regulatory burden estimate.

Scaling the electricity row by that share gives the cyber component:

  • One-off: 9.2 multiplied by 0.14 gives AUD 1.29 million
  • Ongoing: 4.3 multiplied by 0.14 gives AUD 0.60 million per year
  • Ten-year total: 1.29 plus 10 multiplied by 0.60 gives AUD 7.3 million

Read that figure for what it is. It is a sector-average regulatory compliance cost for the cyber and information security hazard component of a CIRMP obligation, averaged across multiple electricity entities. It is not a bespoke security programme budget, it is not a figure for any named distribution business, and it is not RefDNSP-1.2M's own number.

No AER-approved dollar figure for cyber security capital expenditure inside a named Australian distribution determination was retrieved. What is confirmed is structural: the AER's 2024-29 final revenue decisions for six network businesses name "cyber security and digitalisation measures" as a considered expenditure category, and Ausgrid's own account of its approved plan states it "reduced our cyber security program through efficiency savings" [n]. Cyber security is a real, reviewed, approvable line item in an Australian distribution determination. Its size is not public.

Cost bands. Twelve control classes recommended in this section have no public cost anchor of any kind: DERMS security hardening, Modbus security gateway hardware, IEC 62351-6 GOOSE authentication, protection relay setting review, OT intrusion detection and network monitoring platform licensing, supply chain risk management programmes, zero-trust microsegmentation, OT asset discovery tooling, NERC-CIP equivalence programmes, AESCSF uplift, Australian OT cyber insurance premiums, and the AER's cyber security dollar split. Vendors quote per deployment and publish nothing. Every price found was "price on request".

Rather than invent a number, each control below carries an ordinal band measured against the sourced CIRMP cyber envelope:

BandDefinition against the AUD 1.29 million one-off cyber envelopeIndicative one-off
AUnder 10 percent of the envelopeUnder AUD 0.13 million
B10 to 40 percent of the envelopeAUD 0.13 million to AUD 0.52 million
C40 to 100 percent of the envelopeAUD 0.52 million to AUD 1.29 million
DExceeds the envelope on its own; needs a separate funding determinationAbove AUD 1.29 million
RRecurring; priced per year against the AUD 0.60 million per year ongoing envelopeStated per year

Band assignment is the working group's engineering judgment about relative cost. It is not a quotation, a market price, or a vendor estimate. It ranks the controls against each other and against a sourced regulatory envelope. It does not price them. Any band arithmetic below is arithmetic on modeled bands and is labeled as such.

Benefit anchor. The only published measurement of OT control effectiveness located is the Dragos and Marsh McLennan 2025 OT Security Financial Risk Report, built from a decade of insurance claims and information security event data [n]. It maps five controls, aligned to the SANS ICS 5 Critical Controls, to measured average risk reduction:

Control classAverage risk reduction
Incident response plan18.46 percent
Defensible architecture17.09 percent
Network visibility and monitoring16.47 percent
Risk-based vulnerability management13.87 percent
Secure remote access12.18 percent

Three limits on those figures, all from the report itself. They are class averages across a global, all-sector claims population, not the measured effect of any specific product at any specific site. They are explicitly not additive, and the report does not model a combined effect. The provenance is a security vendor and an insurance broker working from proprietary claims data, audited internally by the vendor and broker rather than by an outside party.

Where a control maps onto a Dragos and Marsh class, the class figure is cited and the mapping is stated. Where no class maps, the benefit is stated as a mechanism rather than a number. A mechanism a reader can check beats a percentage a reader cannot.

9.2 Priority Action Items#

The three groups below change risk without redesigning the network architecture.

Priority 1: oscillation detection and command validation

ActionTechnical implementationCost bandEffectTimeline
API behavioral analyticsAnomaly detection on DERMS API traffic to identify oscillation patterns, more than 5 charge or discharge commands per asset within 10 minutesC (no vendor price published; see 9.1)Network visibility and monitoring. Dragos and Marsh McLennan measure 16.47 percent average risk reduction for this control class [n]. Class average, not this control's measured effectImplementation period
Physics-based command validationGrid frequency and RoCoF telemetry integrated into DERMS dispatch validation; reject commands when system inertia is below 2.5 seconds or frequency deviation exceeds 0.1 HzC (no public cost anchor for DERMS hardening)No benchmark class maps to this control, so no percentage is stated. The control removes the operating window the oscillation attack of section 2.2 depends on, by refusing dispatch in exactly the low-inertia conditions the attack needsImplementation period
BESS command rate limitingEnforce a 5-minute minimum interval between charge and discharge state changes per assetA (configuration and vendor engineering)No benchmark class maps. A 5-minute minimum caps the achievable oscillation at one full cycle per 600 seconds, 0.0017 Hz. Section 2.1.2 puts the attack band at 0.5 to 0.55 Hz, roughly 300 times faster. The control moves the attack outside the resonance band rather than lowering its probabilityImplementation period

Priority 1 band arithmetic: bands A plus C plus C. Summing the band boundaries gives AUD 1.0 million to AUD 2.7 million one-off (modeled: band boundary arithmetic, not a quotation). At the top of that range these three controls alone cost about twice the whole sourced CIRMP cyber one-off envelope of AUD 1.29 million.

Combined effect: stated per control. Dragos and Marsh McLennan state their per-control figures are not additive and their report does not model a combined effect [n]. Three controls measured at 12 to 18 percent each are therefore read as three separate measurements at that scale.

Priority 2: thermal runaway prevention

ActionTechnical implementationCost bandEffectTimeline
Modbus security gateway pilotModbus firewall at 5 critical BESS sites with register allowlisting, blocking writes to thermal setpoint registers 0x1000 to 0x1003C (the Moxa EDR-G903 exists and carries IEC 62443-aligned features; every listing found returns price on request, so the per-site installation cost is a quotation rather than a published figure)Defensible architecture. Dragos and Marsh McLennan measure 17.09 percent average risk reduction for this class [n]. Class average, not a measured result for register allowlistingImplementation period
BMS firmware hardeningEnforce voltage and thermal limit validation in battery management system firmware, below the Modbus interfaceB (vendor firmware engineering and fleet rollout)No benchmark class maps. The control moves limit enforcement below the protocol, so a write to a setpoint register cannot raise a limit. It closes the register-write path of section 2.4.1. It does not remove the attacker's access to the registerImplementation period
Enhanced fire suppressionUpgrade suppression at the 10 highest-capacity sites, replacing FM-200 with water deluge and thermal barriersD (physical plant at 10 sites; exceeds the annual cyber envelope on its own)Outside the scope of every cyber control benchmark located. The control limits cell-to-cell propagation once runaway has started. A propagation reduction figure for either the existing or the replacement system rests on a fire-testing report, which the suppression system's manufacturer or an independent testing lab holdsImplementation period

Combined effect: the first two controls address attack initiation and the third addresses consequence once initiation has succeeded. They are not commensurable and are reported separately.

Priority 3: multi-substation attack detection

ActionTechnical implementationCost bandEffectTimeline
OT protocol deep packet inspectionICS-aware firewall with DNP3, Modbus and GOOSE protocol parsing at critical zone boundariesD (platform licensing across all zone boundaries; every OT monitoring vendor keeps pricing confidential)Network visibility and monitoring, 16.47 percent class average [n]. The figure is a risk reduction, which is a different quantity from a detection rateImplementation period
Coordinated protection anomaly detectionSCADA analytics detecting simultaneous protection operations across more than 10 substations inside a 60-second windowB (analytics on an existing SCADA historian)No benchmark class maps. The control fires on a pattern with no benign explanation: independent protection operations at more than 10 sites inside 60 seconds are not produced by uncorrelated faults. No false-positive rate has been measured for this network, so no detection figure is statedImplementation period
GOOSE message authenticationIEC 62351-6 authentication at 15 critical substations, MACsec-based GOOSE signingD (no public cost anchor exists for a GOOSE authentication or MACsec retrofit at any scale)No benchmark class maps. Authenticated GOOSE frames cannot be forged by an attacker who does not hold the key. The control does nothing against an attacker who does hold one, which is the supply chain case of section 7.1Implementation period

Combined effect: reported per control.

Whole of immediate actions: nine controls, one in band A, two in band B, three in band C and three in band D. The six bounded controls sum to AUD 1.8 million to AUD 5.0 million one-off (modeled: band boundary arithmetic, not a quotation). The three band D controls have no upper bound and are excluded from that sum, so the real total is higher by an unknown amount. The sourced CIRMP cyber one-off envelope is AUD 1.29 million. The immediate action list therefore costs several times what the sector-average regulatory compliance figure covers. That is the honest reading and it is stated here rather than smoothed over.

9.3 Investment Roadmap#

Costs below use the band scheme of section 9.1. No line carries a dollar figure that was not derived from a cited source, and the two lines that do carry dollars carry them in the currency of the source, not converted.

Phase 1: immediate

ActionCost bandTimelineRisk addressed
API behavioral analytics and rate limitingCImplementation periodMass command injection
Modbus security gateway pilot, 5 sitesCImplementation periodBESS protocol attacks
Container runtime securityBImplementation periodKubernetes escape
24/7 OT SOC establishment, 8 analystsR, and see the note belowImplementation periodAll vectors
OT incident response retainerR (no public retainer price found for any OT incident response vendor)Implementation periodResponse capability

The SOC line is the one place a real annual figure exists, and it does not fit the envelope. A general enterprise 24/7 SOC of 8 to 12 people costs USD 1.07 million to USD 1.59 million per year in loaded personnel cost, with salary bands anchored to the US Bureau of Labor Statistics wage series for information security analysts and a 1.28 multiplier for payroll tax and benefits [n]. A separate vendor estimate puts a competent 24x7 SOC above USD 1 million per year for a basic operation and at USD 2 million to USD 3 million per year for an advanced one, with technology adding a further USD 0.5 million to USD 1 million per year [n]. Turnover of 20 to 30 percent per year adds USD 80,000 to USD 160,000 per year in replacement cost for an 8-person team [n].

Three caveats, and all three matter. The figures are in US dollars, and an AUD comparison needs an exchange rate, which a currency market supplies at the time of use; none is applied here, so the figures stand in their original currency. They describe a general enterprise SOC watching IT telemetry, not an OT SOC: protocol-aware network monitoring, OT asset inventory and engineering workstation telemetry are additional to this baseline, not included in it. And they are vendor and benchmark-site content, not a regulator's figure.

Taken at parity, and parity is used only to make the comparison possible rather than as a rate, the personnel floor alone of USD 1.07 million per year exceeds the entire AUD 0.60 million per year cyber and information security component of the sector-average CIRMP from section 9.1. A dedicated 24/7 OT SOC is not fundable inside the sector-average regulatory compliance budget. It needs its own determination.

Phase 2: short term

ActionCost bandTimelineRisk addressed
ICS-aware firewalls at all zone boundariesD (no public OT firewall platform pricing; every vendor quotes per deployment)Implementation periodProtocol exploitation
ICCP protocol parser developmentB (bespoke engineering, no product to price)Implementation periodADMS integration attacks
Physics-based dispatch validationC (no public cost anchor for DERMS hardening)Implementation periodGrid-destabilizing commands
Behavioral analytics platform, UEBA and NDRD (no public OT network monitoring platform pricing)Implementation periodAnomalous patterns
Supply chain risk management programmeC (no public cost anchor for an electricity-sector supply chain programme)Implementation periodVendor compromise
Zero-trust microsegmentationD (no public cost anchor in an ICS context)Implementation periodLateral movement

Phase 2 is the expensive phase and the least anchored. Four of its six lines sit in bands C and D against an envelope of AUD 1.29 million, and three of the six have no public price of any kind. A drafter with access to vendor quotations should replace this table with quoted figures before it goes to a board.

Phase 3: ongoing

Band R throughout. No public price was found for any line.

  • Continuous monitoring and threat hunting
  • Quarterly OT penetration testing
  • Annual red team exercises on cyber-physical scenarios
  • Threat intelligence integration from ICS-CERT feeds
  • Security awareness training for operations staff

The ongoing cyber and information security component of the sector-average CIRMP is AUD 0.60 million per year (section 9.1). The five lines above plus the SOC and the incident response retainer of Phase 1 are all recurring. On the only annual figure available, the SOC alone consumes more than that envelope.

Phase 2 Technical Detail:

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

Phase 3 Operational Maturity:

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

Programme total. The total is reported as band arithmetic rather than as a single number, because eight of the eleven lines above have no public price and three of them carry a floor, the band D threshold, with no ceiling any public source states. The eight bounded one-off lines across Phase 1 and Phase 2, two in band B and four in band C plus the two Phase 1 recurring lines held aside, sum to AUD 2.3 million to AUD 6.2 million (modeled: band boundary arithmetic against the AUD 1.29 million CIRMP cyber envelope, not a quotation). The three band D lines in Phase 2, ICS-aware firewalls at all zone boundaries, the behavioral analytics platform and zero-trust microsegmentation, each exceed that envelope on their own and are excluded from the sum. The true total sits above AUD 6.2 million by an amount that a firm vendor quote for each of the three lines would set.

9.4 Risk Mitigation Decision Tree#

The tree below orders the controls of section 9.2 by the network conditions that make each one urgent. Cost bands are those of section 9.1. The tree ranks; it does not price.

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

The terminal node of the tree used to read "Risk Reduction: 90 to 95 percent". That figure had no source. It now carries the only published benchmark located, 12 to 18 percent average risk reduction per control class, from the Dragos and Marsh McLennan 2025 OT Security Financial Risk Report [n]. The report states those figures are not additive, so passing through several branches of the tree does not compound them.

Decision tree applied to RefDNSP-1.2M.

The answers below are the reference network's stipulated state from section 2 and the internal assessments EE-CTI-002, EE-CTI-003 and EE-CTI-007. They are the working group's own scenario parameters, not measured properties of any real network.

Q1: Grid inertia regularly below 3.0 seconds?
    Answer: YES (15 to 20 percent of operational hours below 3.0 s)
    Result: CRITICAL - Death Wobble oscillation detection, cost band C

Q2: BESS fleet above 100 MW deployed?
    Answer: YES (270 MW across 54 sites, operational and planned)
    Result: continue to Q3

Q3: Modbus TCP encrypted?
    Answer: NO (plaintext confirmed in EE-CTI-002, CVSS 9.1)
    Result: CRITICAL - Modbus security gateway, cost band C

Q5: IEC 61850 GOOSE authenticated?
    Answer: NO (no IEC 62351-6 deployment, per EE-CTI-003)
    Result: continue to Q6

Q6: More than 50 substations using GOOSE?
    Answer: YES (10,000+ IEDs across 185 major substations)
    Result: CRITICAL - IEC 62351-6 implementation, cost band D

Critical path, by cost band:
- Death Wobble detection:            band C   (AUD 0.52m to AUD 1.29m)
- Modbus security gateway:           band C   (AUD 0.52m to AUD 1.29m)
- BMS firmware hardening:            band B   (AUD 0.13m to AUD 0.52m)
- IEC 62351-6 GOOSE authentication:  band D   (above AUD 1.29m, no upper bound)

Bounded lines sum to AUD 1.17m to AUD 3.10m one-off (modelled: band
boundary arithmetic against the AUD 1.29m CIRMP cyber envelope of
section 9.1, not a quotation). The GOOSE authentication line has no
public cost anchor at any scale and is excluded from that sum, so the
minimum viable defence costs more than AUD 3.10m by an unbounded amount.

9.5 Return on Investment#

The benefit to cost ratio below is built from three sourced inputs and one formula, and every step is shown so a reader can contest it.

One label correction before the arithmetic. What follows is a benefit to cost ratio, not a Return on Security Investment. Annualized Loss Expectancy and Return on Security Investment for OT, section 3.3, defines ROSI as the avoided loss net of the control cost, divided by the control cost, so the 4.4:1 below corresponds to a ROSI of about 341 percent and the 6.6:1 to about 560 percent. Those two percentages are stated once, here, and are used nowhere else, because a ratio a board can check against a cost is more useful to it than a percentage it cannot.

Input 1: programme cost, AUD 7.3 million over ten years.

From the Australian Government's October 2024 Impact Analysis for amendments to the SOCI Act 2018, Table 19, indexed to June 2024 dollars: a critical electricity asset entity carries an average Critical Infrastructure Risk Management Program cost of AUD 9.2 million one-off and AUD 4.3 million per year [n]. Table 27 of the same document puts cyber and information security hazard at 14 percent of the electricity sector's ten-year regulatory burden [n]. Scaling:

One-off cyber component   = 9.2  x 0.14 = AUD 1.29 million
Annual cyber component    = 4.3  x 0.14 = AUD 0.60 million per year
Ten-year programme cost   = 1.29 + (10 x 0.60) = AUD 7.3 million

This figure covers the cyber and information security hazard component of a CIRMP obligation, as a sector average across critical electricity asset entities. It is not the cost of a bespoke security programme, and it does not cover the band D controls of section 9.2 and section 9.3, which exceed it individually. Using it as the programme cost is a deliberately favorable assumption toward the programme, and the ratios below are correspondingly optimistic.

Input 2: avoided loss, AUD 268 million.

Section 5.9 gives the risk-adjusted expected loss over a 10-year horizon as AUD 179 million to AUD 358 million, midpoint AUD 268 million. That range is the paper's own 15 to 30 percent attack probability applied to the AUD 1.19 billion reference case, which is the full network at 12 hours, the longest duration the AER's VCR determination covers. The probability is the working group's own modeled assessment, labeled as such at each use. The AUD 1.19 billion is computed from the AER's determined VCR and is the largest direct customer cost this paper can state without extrapolating that determination.

Input 3: risk reduction, 12 to 18 percent.

Dragos and Marsh McLennan measure average risk reduction per OT control class at 12.18 to 18.46 percent across a decade of insurance claims [n]. Their five classes are not additive and the report models no combined effect, so no defence-in-depth multiplier is applied here. The band is used directly.

Result.

At 12 percent risk reduction:
  Avoided loss    = 268 x 0.12  = AUD 32.2 million
  Programme cost  =               AUD 7.3 million
  Net benefit     = 32.2 - 7.3  = AUD 24.9 million
  Ratio           = 32.2 / 7.3  = 4.4 : 1

At 18 percent risk reduction:
  Avoided loss    = 268 x 0.18  = AUD 48.2 million
  Programme cost  =               AUD 7.3 million
  Net benefit     = 48.2 - 7.3  = AUD 40.9 million
  Ratio           = 48.2 / 7.3  = 6.6 : 1

Sensitivity across the full section 5.9 loss range:
  179 x 0.12 / 7.3 = 2.9 : 1   (low loss, low control effectiveness)
  358 x 0.18 / 7.3 = 8.8 : 1   (high loss, high control effectiveness)

Neither side of that ratio is discounted. Section 5.9 states expected loss in undiscounted ten-year dollars, and the same basis applies here, so cost and benefit are both in undiscounted ten-year dollars. Do not label any figure above an NPV.

Read the result plainly. The sourced ratio is 4.4:1 to 6.6:1, with a sensitivity envelope of 2.9:1 to 8.8:1. It is a strong business case. A control programme that returns four to seven dollars for every dollar spent, computed from a government cost estimate and an insurance-claims effectiveness measurement rather than from assumption, does not need inflating, and inflating it is how a board learns to distrust the next number in the same table.

Tail-risk variant. Section 5.9 also gives a midpoint expected loss of AUD 2.01 billion when the tier 4 upper bound of AUD 8.95 billion is substituted for the reference case. Running the same arithmetic gives 33:1 at 12 percent and 49.5:1 at 18 percent. Section 5.9 labels that AUD 2.01 billion as compounding the working group's own probability assessment with a VCR extrapolated to 72 hours, six times the range for which the AER determined it. The headline ratio is therefore held to the reference case, where the probability assessment is the single modeled input and the VCR stays inside the range the AER determined.

On the regulated asset base. A ratio of programme cost to regulated asset base requires a stipulated asset base as its denominator, and section 2 specifies RefDNSP-1.2M without one. The nearest published Australian figure is a revenue allowance rather than an asset base: the AER's draft decision for Ausgrid allowed AUD 9,619.6 million of revenue across the five years to 2029 [n], for a different and real business.

9.6 Quick Wins#

Five actions delivered through policy change and configuration rather than capital purchase. All five sit in cost band A of section 9.1, under AUD 0.13 million each, because none of them buys hardware or a platform licence. Band A is still an engineering judgment about relative cost, not a quotation.

Quick win 1: API dual authorization policy

AttributeDetail
ActionRequire dual authorization for dispatch commands above 10 MW aggregate capacity
ImplementationSet dual_auth_threshold_MW: 10 in the mPrest DERMS configuration, requiring a second OAuth token approval for bulk commands or commands affecting more than 10 MW aggregate capacity
Cost bandA, configuration change
EffectSecure remote access. Dragos and Marsh McLennan measure 12.18 percent average risk reduction for this control class, the lowest of their five [n]. The mapping is approximate: their class covers remote access generally, not API authorization specifically. Stated as a mechanism instead: the control removes the single-credential path to bulk dispatch, so one stolen retailer token no longer moves the fleet
Operational impact30 to 60 second delay on large commands. Operator acceptance high, as operators already approve critical commands
Worked exampleRetailer A requests discharge across 54 BESS units. The system prompts a RefDNSP-1.2M control room operator for approval
TimelineImplementation period

Quick win 2: BESS state-change rate limiting

AttributeDetail
ActionEnforce a 5-minute minimum interval between charge and discharge state changes
ImplementationModify the SwitchDin Utility Server to track the last command timestamp per asset and reject commands inside the 5-minute window
Cost bandA, vendor engineering support
EffectNo Dragos and Marsh class maps to this control, so no percentage is stated. A 5-minute minimum caps the achievable oscillation at one full cycle per 600 seconds, 0.0017 Hz. Section 2.1.2 puts the attack band at 0.5 to 0.55 Hz, roughly 300 times faster. The control puts the attack outside the resonance band
Operational impactNone. Normal operations use 15 to 30 minute dispatch intervals, and battery inverters need 30 to 90 seconds for a charge to discharge transition, so the 5-minute floor does not bind on legitimate use
Worked exampleA BESS receives a charge command at 13:00:00. A discharge command is rejected until 13:05:00
TimelineImplementation period

Quick win 3: basic oscillation pattern detection

AttributeDetail
ActionSIEM correlation rule detecting more than 5 state changes per asset within 30 minutes
ImplementationConfigure the existing Splunk SIEM to parse DERMS API logs and alert on rapid charge and discharge cycling. Rule: index=derms sourcetype=api_commands then stats count by asset_id, command_type then where count > 5 AND time_window < 1800 seconds
Cost bandA, existing platform
EffectNetwork visibility and monitoring. Dragos and Marsh McLennan measure 16.47 percent average risk reduction for this class [n]. A detection figure for this rule rests on a false-negative rate measured on this network
Operational impactSOC investigation workload rises by about 2 hours per week
Worked exampleAlert text: BESS_Bawley_001 received 8 charge and discharge commands in 22 minutes, potential oscillation attack
TimelineImplementation period

Quick win 4: critical substation GOOSE monitoring

AttributeDetail
ActionNetwork tap and packet capture at 5 critical substations to record GOOSE traffic for forensic analysis
ImplementationInstall a Garland G-TAP network tap on the IEC 61850 station bus and mirror to PCAP storage of 5 TB capacity
Cost bandA, tap hardware and installation at 5 sites
EffectNetwork visibility and monitoring, 16.47 percent class average [n]. This control is forensic rather than preventive: retained GOOSE traffic lets a security team replay a protection cascade and identify timing anomalies suggesting injection. It detects nothing in real time and prevents nothing
Operational impactNone. Passive monitoring
Worked exampleAfter a protection cascade, the security team replays captured GOOSE traffic to separate spoofed messages from legitimate protection operations
TimelineImplementation period

Quick win 5: vendor access logging and alerting

AttributeDetail
ActionDetailed logging of all vendor remote access sessions through the bastion host, with real-time alerting on unusual activity
ImplementationConfigure the Citrix bastion host to log all commands, file transfers and configuration changes, and send alerts to the SOC for after-hours access or high-risk commands
Cost bandA, SIEM integration
EffectSecure remote access, 12.18 percent class average [n]. A dwell time reduction rests on a dwell time measured on this network before and after the control. What the control does is make vendor session activity reviewable at all, which is the precondition for measuring dwell time later
Alert triggersVendor login outside 0800 to 1700, access to the SCADA master station, Modbus or DNP3 write commands, configuration file downloads
Operational impactSOC investigation workload rises by about 1 hour per week
Worked exampleAlert text: Vendor_BatteryOEM_Engineer logged in at 02:34 Saturday, accessed RTU configuration files, downloaded 15 MB
User acceptanceMedium. Vendors may resist increased scrutiny, so contractual enforcement is needed
TimelineImplementation period

Quick wins total. Five controls, all band A. Band arithmetic gives under AUD 0.65 million one-off in total (modeled: five times the band A ceiling of AUD 0.13 million, not a quotation). Against the AUD 1.29 million CIRMP cyber one-off envelope of section 9.1, the whole quick-win set fits inside half of it, which is the argument for doing these first.

Combined effect: stated per control. Dragos and Marsh McLennan state their per-control figures are not additive and their report models no combined effect [n]. Three of these five controls map to classes measured at 12.18 and 16.47 percent, and two are stated as mechanisms. Each is read at its own scale.

9.7 Board-Level Recommendations#

Five recommendations follow. Costs use the bands of section 9.1, and the cost-benefit basis is the one derived in section 9.5. Where a control has no published price, the recommendation says so and asks the board to require a quotation rather than approve a number nobody can check.

Recommendation 1: approve the critical path controls

Rationale:

The five figures below are RefDNSP-1.2M's stipulated state from section 2 and the working group's own assessments. They are scenario parameters, not measurements of a real network.

  • Current attack surface score: 8.7/10 (CRITICAL)
  • IEC 62443 compliance: 38 percent (SOCI Act risk)
  • Three attack vectors with CRITICAL (CVSS 9+) severity
  • Demonstrated nation-state capability (Sandworm, FrostyGoop)
  • 15 to 30 percent probability of attack within 10-year horizon

Critical path, by cost band:

ControlCost bandBounded?
Death Wobble oscillation detectionC, AUD 0.52 million to AUD 1.29 millionYes
Modbus security gateway across all 54 sitesD, above AUD 1.29 millionNo. No published unit price exists for any Modbus security gateway, and no per-site installation cost was found
BMS firmware hardeningB, AUD 0.13 million to AUD 0.52 millionYes
IEC 62351-6 GOOSE authentication at 15 critical substationsD, above AUD 1.29 millionNo. No public cost anchor exists for a GOOSE authentication or MACsec retrofit at any scale

The two bounded lines sum to AUD 0.65 million to AUD 1.81 million one-off (modeled: band boundary arithmetic against the AUD 1.29 million CIRMP cyber envelope of section 9.1, not a quotation). The two band D lines carry a floor, the band D threshold, with no ceiling any public source states, so the critical path total is reported as that floor plus the two bounded lines rather than as a single figure.

Cost-benefit basis:

No separate ratio is computed for the critical path, because two of
its four lines have no upper cost bound and a ratio needs a
denominator. The board-level number is the programme-level one from
section 9.5:

  Programme cost (10 years, CIRMP cyber component)   AUD 7.3 million
  Avoided loss (section 5.9 midpoint)                AUD 268 million
  Risk reduction (Dragos and Marsh McLennan)         12 to 18 percent

  268 x 0.12 / 7.3 = 4.4 : 1
  268 x 0.18 / 7.3 = 6.6 : 1

  Sensitivity across the full section 5.9 range: 2.9 : 1 to 8.8 : 1

On the sourced basis the programme returns 4.4:1 to 6.6:1, against the
board's stated threshold of 10:1, which that range sits below. A board
applying that hurdle should be told the sourced ratio directly rather
than shown a number built to clear it.

Board Resolution Language:

"The Board approves the four critical path OT cybersecurity controls addressing cascading failure risks identified in the EE-CTI-006 assessment, being Death Wobble oscillation detection, Modbus security gateway deployment, BMS firmware hardening and IEC 62351-6 GOOSE authentication, subject to receipt of vendor quotations for the two controls that carry no published price. Management is directed to return to the Board Risk Committee with quoted costs before commitment. The Board notes that the assessed cost-benefit ratio for the wider programme is 4.4:1 to 6.6:1 on a sourced basis, computed from the Commonwealth Impact Analysis cost estimate for a Critical Infrastructure Risk Management Program and published per-control risk reduction of 12 to 18 percent, and that this does not clear the Board's 10:1 threshold for regulated asset base investments. Quarterly progress reporting to the Board Risk Committee is required."

Recommendation 2: Establish OT Cybersecurity Governance Framework

Governance Structure:

RoleResponsibilityReporting LineFrequency
Board Risk CommitteeStrategic oversight, capital approval, regulatory complianceFull BoardQuarterly
Chief OT Security OfficerOT security strategy, incident response, vendor managementCEO + Board Risk CommitteeMonthly (Board), Weekly (CEO)
OT Security Working GroupTechnical implementation, threat intelligence, control validationChief OT Security OfficerWeekly
24/7 OT SOCReal-time monitoring, incident detection, initial responseChief OT Security OfficerContinuous (escalation protocols)

Key Performance Indicators (KPIs):

MetricTargetCurrentTimelineBoard Reporting
IEC 62443 Compliance≥80%38%implementation periodQuarterly
Attack Surface Score≤3.0/108.7/10implementation periodQuarterly
Mean Time to Detect (MTTD)<15 minutesUnknown (no OT monitoring)implementation periodQuarterly
Mean Time to Respond (MTTR)<2 hoursUnknown (no OT playbooks)implementation periodQuarterly
OT Penetration Test Pass Rate≥95%0% (not tested)AnnualAnnual
Vendor Access Audit Compliance100%45% (per TEC 3011)implementation periodQuarterly

Board Resolution Language:

"The Board establishes a dedicated OT Cybersecurity Governance Framework with Chief OT Security Officer position reporting to Board Risk Committee, with mandate to achieve IEC 62443 SL-2 compliance across critical infrastructure within implementation period. Quarterly reporting on KPIs and the threat environment required."

Recommendation 3: Mandate Pre-Deployment Security Validation for BESS Expansion

Policy Requirement:

All future BESS deployments (Community Battery Program expansion from 54 to 150+ sites by 2030) must complete security validation before grid connection approval:

Security Validation Checklist:

Validation ItemAcceptance CriteriaResponsible PartyTimeline
Modbus TCP EncryptionTLS 1.3 or Modbus Security Gateway deployedVendor + EE SecurityPre-commissioning
BMS Firmware ValidationThermal/voltage limit enforcement verified via penetration testIndependent Security AuditorPre-commissioning
Network SegmentationDedicated VLAN with ACL enforcement, no vendor 4G modemsEE Network EngineeringPre-commissioning
IEC 62443 SL-2 ComplianceThird-party audit confirming SL-2 requirements metCertified IEC 62443 AuditorPre-commissioning
Incident Response IntegrationBESS included in OT SOC monitoring, playbooks developedEE OT SOCPre-commissioning

Financial impact:

No per-BESS security validation cost is stated. No public price was found for a pre-commissioning IEC 62443 SL-2 audit of a battery energy storage installation, from a certification body or from any of the assessors named in Recommendation 4. What can be stated is the structure of the cost and its scale relative to the sourced envelope.

  • Deployments in scope: 96 (150 planned sites less the 54 existing)
  • Per-site cost: unpriced. Band A per site is the working group's judgment, on the basis that a pre-commissioning audit is a professional services engagement at a single site, not a capital purchase
  • Programme cost: 96 sites at band A gives up to AUD 12.5 million across the expansion (modeled: 96 multiplied by the band A ceiling of AUD 0.13 million, not a quotation). At the top of that band the validation programme costs an order of magnitude more than the whole CIRMP cyber envelope of section 9.1, which is why the per-site figure needs quoting before this recommendation goes to a capital decision
  • Share of total BESS programme cost: follows from a capital cost for the Community Battery Program expansion, which is the denominator of the share and which a stipulated programme budget supplies. Section 2 specifies the expansion from 54 to 150 sites, and the share is computed against that budget
  • Loss avoided per site: follows from a per-site loss for a comparable event. The nearest precedent is FrostyGoop, a heating utility at Lviv in Ukraine in January 2024, whose per-facility financial loss is held by the operator. Section 5.10 places per-facility industrial loss among the categories this paper carries as a mechanism, each with the input its price rests on, and this line sits with them

Board Resolution Language:

"The Board mandates comprehensive security validation for all future BESS deployments, with pre-commissioning security audit achieving IEC 62443 SL-2 compliance as prerequisite for grid connection approval. No BESS shall be energized without Chief OT Security Officer sign-off confirming security controls meet documented standards."

Recommendation 4: Commission Independent Security Audit (implementation period)

Audit Scope:

Engage independent third-party cybersecurity firm with ICS/OT specialization to conduct:

  1. IEC 62443-3-3 Gap Assessment (implementation period)
    • Security zone architecture validation
    • Foundational Requirements compliance (FR1-FR7)
    • System Requirements compliance (SR1-SR7)
    • Security Level Target vs. Achieved analysis
    • Cost band: B (professional services engagement across 185 substations and 54 BESS sites; no published price for an IEC 62443-3-3 gap assessment at this scale)
  2. OT Penetration Testing (implementation period)
    • External attack surface enumeration
    • Retailer API security testing (OWASP API Security Top 10)
    • Protocol exploitation (Modbus, DNP3, GOOSE injection attempts)
    • Lateral movement from IT to OT networks
    • Physical security integration testing
    • Cost band: B (no published price for OT penetration testing from any assessor named below)
  3. Red Team Exercise: Cascading Failure Scenario (implementation period)
    • Simulated Death Wobble oscillation attack (non-disruptive)
    • Simulated thermal runaway initiation (isolated test environment)
    • Simulated multi-substation coordinated attack (tabletop + technical)
    • Blue team response evaluation (OT SOC, incident response)
    • Cost band: B (no published price for an ICS red team engagement; the cyber-physical scope and isolated test environment put it above a standard penetration test)
  4. SOCI Act Compliance Validation (implementation period)
    • Risk Management Program assessment
    • Incident reporting procedures validation
    • Regulatory obligation mapping
    • Cost band: A. The closest sourced figure is a bound rather than a price: the Department of Home Affairs states that AUD 2 million "may be a more reasonable estimate" for the incremental cost of remedying a deficient Risk Management Program [n]. Assessing an RMP costs less than remedying the deficiencies the assessment finds, so AUD 2 million is a ceiling on this line and not its price

Total audit cost: three lines in band B and one in band A, summing to AUD 0.39 million to AUD 1.69 million (modeled: band boundary arithmetic against the AUD 1.29 million CIRMP cyber envelope of section 9.1, not a quotation). No workstream above carries a quoted price, and the four assessors shortlisted below all quote per engagement. This total should be replaced with quotations before it reaches a board paper. Timeline: implementation period (completion before winter peak demand)

Audit Deliverables:

  • Executive summary for Board (25 pages)
  • Technical findings report (150-200 pages)
  • Compliance gap analysis with remediation roadmap
  • Penetration test report with proof-of-concept demonstrations
  • Red team after-action report with lessons learned

Vendor Qualification:

  • Required: CREST OT certification OR GIAC ICS certifications (GRID, GICSP)
  • Preferred: Prior energy sector engagements in AU/NZ/US/UK
  • Prohibited: Vendors with OT product sales (independence requirement)
  • Shortlist: Dragos Inc., Mandiant (Google Cloud), Eigenia Group OTCE, CyberX (Microsoft Defender for IoT)

Board Resolution Language:

"The Board approves an independent third-party security audit covering IEC 62443 compliance, OT penetration testing, red team validation and SOCI Act compliance, to be completed within the implementation period, with the cost to be set by competitive quotation and reported to the Board Risk Committee before engagement. Audit findings shall be presented to Board Risk Committee with remediation roadmap and cost-benefit analysis for recommended controls."

Recommendation 5: Dual Authorization for High-Impact Commands (Immediate Policy Change)

Policy Implementation (No Capital Required):

Effective immediately, all dispatch commands meeting the following criteria require dual authorization before execution:

Dual Authorization Triggers:

Trigger ConditionRationaleAuthorization ProcessException
>10 MW aggregate capacityExceeds single BESS capacity, potential grid impactPrimary: Retailer API OAuth token, Secondary: EE Control Room operator approval via DERMS interfaceEmergency frequency response (automated under-frequency load shedding)
>100 devices simultaneous commandMass command injection attack signaturePrimary: Retailer API OAuth token, Secondary: EE DERMS Administrator approvalCoordinated VPP dispatch during AEMO emergency (requires AEMO authorization code)
State change <5 minutes since last commandOscillation attack signaturePrimary: Retailer API OAuth token, Secondary: EE Security Operations Center (SOC) approval after investigationNone (no legitimate use case for rapid cycling)
Command during low-inertia conditionsSystem inertia <2.5 seconds (AEMO telemetry)Primary: Retailer API OAuth token, Secondary: EE Grid Operations Manager approvalAEMO-directed emergency load shedding

Technical Implementation:

json
DERMS API Configuration File Update:

{
  "dual_authorization": {
    "enabled": true,
    "thresholds": {
      "power_MW": 10,
      "device_count": 100,
      "state_change_interval_seconds": 300,
      "system_inertia_seconds": 2.5
    },
    "authorization_workflow": {
      "primary": "retailer_oauth_token",
      "secondary": "ee_control_room_approval",
      "timeout_seconds": 300,
      "rejection_action": "command_blocked_and_logged"
    },
    "exceptions": [
      {
        "condition": "aemo_emergency_code_present",
        "bypass_dual_auth": true,
        "audit_trail": "mandatory"
      }
    ]
  }
}

Operational Impact Assessment:

  • Average large dispatch commands per day: 15-20
  • Dual authorization time: 30-90 seconds (operator review + approval)
  • Total additional latency: 7.5-30 minutes per day
  • Impact on grid services: Negligible (dispatch commands typically 15-30 minutes ahead)
  • User (retailer) acceptance: Medium (requires communication and SLA updates)

Communication Plan:

  • Week 1: Notify all retailers of policy change via email + retailer portal announcement
  • Week 2-3: Update retailer API documentation and SLA agreements
  • Week 4: Implement dual authorization logic in DERMS (configuration change, no code required)
  • Week 5: Activate policy, monitor retailer feedback
  • Week 6+: Monthly review of dual authorization rejections for process tuning

Cost: band A, configuration change only (section 9.1) Effect: stated as a mechanism, with the nearest published benchmark for scale. This control maps loosely to the secure remote access class, which Dragos and Marsh McLennan measure at 12.18 percent average risk reduction, the lowest of their five classes [n]. The mapping is approximate and the figure is a global claims-population average rather than a measurement of this control on this network. The mechanism is exact and is the better statement: dual authorization removes the single-credential path to bulk dispatch, so an attacker holding one stolen retailer OAuth token can no longer move the fleet Implementation: Immediate (targeted timeframe policy effective date)

Board Resolution Language:

"The Board mandates dual authorization for all electricity dispatch commands exceeding 10 MW aggregate capacity or affecting more than 100 devices, effective immediately. This policy change requires no capital investment. Its effect is to remove the single-credential path to bulk dispatch: an attacker holding one compromised retailer API token can no longer command the battery fleet without a second, separately held approval. No measured risk reduction figure is available for this control; the nearest published benchmark, for the secure remote access control class, is 12 percent. Chief OT Security Officer shall report monthly on dual authorization metrics and operational effectiveness."

Governance and compliance actions

Executive Actions:

  • Mandate quarterly cyber-physical risk scenarios presented to the Board
  • Establish vendor security SLAs with contractual enforcement of IEC 62443
  • Implement just-in-time vendor access to eliminate standing credentials

Operational Changes:

  • Dual authorization for dispatch commands affecting more than 10 MW (immediate policy)
  • Monthly OT penetration testing with red team exercises
  • Community battery program expansion contingent on security control implementation

9.8 Compliance and Regulatory Alignment#

The controls recommended above map onto three frameworks. Costs use the bands of section 9.1. The AER's own cyber security dollar split is not public, and none of the three frameworks publishes an uplift cost, so no table below carries a quoted price.

Security of Critical Infrastructure Act 2018 alignment:

SOCI requirementCurrent complianceRecommended controlCost bandCompliance impact
Risk Management ProgramPartial, 40 percent completeIEC 62443 gap assessment plus remediation roadmapB (assessment) plus C (controls)Raises RMP maturity, stated as a direction rather than as a target percentage
Cyber security obligationsNon-compliant, no OT-specific controlsOT SIEM deployment plus 24/7 SOCD one-off plus R recurring. Section 9.3 shows the SOC personnel floor alone exceeds the sourced annual cyber envelopeMeets the mandatory monitoring requirement
Incident reportingPartial, IT-focused with an OT gapOT incident response playbook plus ACSC integrationA, proceduralMeets the 12-hour reporting obligation
Critical infrastructure systemsIdentified: 185 substations, 54 BESSDefence-in-depth security architectureD, the whole Phase 2 programme of section 9.3Protects designated critical assets

The sourced cost anchor for this whole table is the one from section 9.1: AUD 1.29 million one-off and AUD 0.60 million per year for the cyber and information security hazard component of a sector-average CIRMP, from the Commonwealth Impact Analysis [n]. Every band above is measured against it.

Regulatory penalty avoidance. A penalty-avoidance ratio rests on a SOCI Act penalty schedule and on a precedent against an Australian distribution business, and it is computed from that schedule and cited to it. Section 5.8 states what the record holds on the loss side: the one settled regulatory outcome for a comparable event, the Great Britain outage of 9 August 2019, produced about GBP 10.5 million in voluntary payments across four licensees [n], which is small against the direct customer cost and is a settlement rather than a penalty schedule.

Australian Energy Sector Cyber Security Framework alignment.

The AESCSF is AEMO's maturity framework for the electricity, gas and liquid fuels sub-sectors, rebuilt as Version 2 in October 2023 with 11 domains and 354 practices [n]. Since June 2026 the enhanced CIRMP Rules under the SOCI Act name the 2023 AESCSF Framework Core at Security Profile 2 as an accepted compliance pathway for critical electricity assets, with a transition grace period ending June 2028 [n]. Alternative accepted pathways are the ACSC Essential Eight at Maturity Level Two, AS ISO/IEC 27001:2023, NIST CSF 2.0, and C2M2 v2.1 at MIL-2. AEMO states the programme runs on user-pays cost recovery, so participation costs money and that money is charged back to participants, but no fee schedule and no uplift costing was found [n].

AESCSF principleSP2 requirementCurrent maturityTarget maturityGap closure cost band
Principle 2.1: asset managementComprehensive OT asset inventory with security classificationLevel 2, DefinedLevel 3, ManagedC. No public cost anchor exists for OT asset discovery tooling in an electricity distribution context
Principle 2.2: risk assessmentAnnual cyber-physical risk assessment with Board reportingLevel 1, Ad hocLevel 3, ManagedB, annual assessment plus this document
Principle 2.3: secure OT communicationsEncryption and authentication for critical protocolsLevel 1, Ad hocLevel 3, ManagedD. IEC 62351-6 and the Modbus gateway are both unbounded band D lines
Principle 3.1: defence in depthMulti-layer security controls across the IT and OT boundaryLevel 1, Ad hocLevel 3, ManagedD, ICS firewalls plus segmentation
Principle 4.1: OT monitoringReal-time anomaly detection and incident responseLevel 0, NoneLevel 3, ManagedD one-off plus R recurring, OT SIEM plus SOC

AESCSF compliance score. The current 32 percent and the 80 percent target are the working group's own scoring of the reference network against the five principles above, not an AEMO assessment result. No uplift cost is stated: three of the five gap closures are unbounded band D lines, and AEMO publishes no AESCSF uplift costing for any participant. AEMO and the AER increasingly treat Security Profile 2 as the industry baseline, and the CIRMP Rules now name it as a compliance pathway, so the cost of not closing these gaps is the cost of failing a named regulatory pathway with a June 2028 deadline.

NERC-CIP international benchmarking.

NERC-CIP is not mandatory in Australia. It is included because it decomposes the same controls into auditable requirements.

NERC-CIP standardEquivalent controlRefDNSP-1.2M current stateCost band
CIP-005-6 R1: electronic security perimeterICS firewall at the IT and OT boundary with deny-all defaultPartial, firewall exists but ACLs are weakC, firewall rules plus deep packet inspection
CIP-007-6 R2: patch management35-day patching for critical OT vulnerabilitiesNon-compliant, no OT patch programR recurring, patch testing and deployment
CIP-007-6 R4: security event monitoringLog collection and 15-day review for OT systemsNon-compliant, no OT SIEMD, OT SIEM deployment
CIP-010-3 R1: configuration managementBaseline configurations with change control for BESS and RTUsPartial, IT-focused with an OT gapB, configuration management tooling
CIP-013-1 R1: supply chain risk managementVendor cybersecurity requirements in procurementNon-compliant, vendor 4G modems unmanagedB, vendor security policy development

Total for NERC-CIP equivalence: reported as banded lines rather than as one figure. Three of the five lines are bounded (two band B and one band C, summing to AUD 0.78 million to AUD 2.33 million, modeled band boundary arithmetic), one is an unbounded band D line and one is recurring. A cost anchor for a NERC-CIP equivalence programme rests on a public agency's own costed rollout, and none has published one in any jurisdiction to date.

On the insurance benefit. A premium movement attributable to NERC-CIP equivalent controls is computed from a baseline premium and a post-control premium for an Australian OT policy, and both are figures an insurer supplies to the business holding the policy. Section 9.9 sets out what the published record supports on risk transfer.

9.9 Insurance and Risk Transfer#

Risk transfer for this exposure is priced from an Australian OT policy: a baseline premium, a post-control premium, a coverage cap and a loss ratio, each read off a placement rather than off a publication. This subsection sets out what the published record supports without those inputs, and what an underwriter would be given if the business approached the market.

Where the pricing inputs live.

Australian OT cyber insurance premiums are set placement by placement and are held by the insurer and the insured. A baseline premium for a distribution network business, a post-control premium, a coverage cap, a loss ratio and a percentage premium movement attributable to a control each come from a placement record. The statements below are the ones the published record supports.

What can be stated.

Three things, all sourced.

First, the loss side is already quantified elsewhere in this paper and does not need an insurance-specific restatement. Section 5.9 puts the risk-adjusted expected loss over a 10-year horizon at AUD 179 million to AUD 358 million, midpoint AUD 268 million, built from the AER's determined VCR and this paper's own 15 to 30 percent probability assessment. Section 5.4 gives the reference case, the full network at the 12-hour boundary of VCR validity, at AUD 1.19 billion. Those are the numbers an underwriter would be asked to price against. They are stated with their assumptions in section 5 and are not repeated with different labels here.

Second, the industry-level loss picture is published. Dragos and Marsh McLennan put average annual OT-related cyber risk at USD 31.1 billion globally, of which USD 12.7 billion involves business interruption claims, and put a 1-in-250-year tail at USD 329.5 billion total with USD 172.4 billion business-interruption related [n]. They also report that roughly 70 percent of OT-impacting breaches involve indirect costs, meaning abundance-of-caution shutdowns and ripple effects rather than direct damage, and give a utilities-specific likelihood of 2.17 percent per year for an event in North American electric power generation and distribution [n]. These are global, modeled, USD figures from a vendor and a broker working from proprietary claims data. They establish that the risk class is large and is being modeled by the insurance market. They do not price an Australian policy and they are not a premium.

Third, a statement about policy wording rather than about price: cyber insurance policies for critical infrastructure commonly exclude or sub-limit OT and ICS losses. The wording that settles it for any given placement is that policy's own, and a reader checks the claim against the policy in front of them.

What follows for the board.

A risk is transferred on known terms once it is priced, and that price rests on a placement's own premium and coverage figures. Two consequences follow and neither needs a number.

  • The programme's justification rests on avoided loss and published control effectiveness. Section 9.5's cost-benefit case stands on those alone. Any premium saving is additional upside, sized once a placement prices it.
  • Approaching the market requires the quantification this paper provides. An underwriter presented with the AER's determined VCR, a stated 12-hour scope limit, a stated probability assessment labeled as the working group's own, and published per-control risk reduction of 12 to 18 percent, is being given something they can underwrite against.

Regulatory capital. Regulatory capital sits outside this analysis. APRA's prudential remit does not obviously extend to an electricity distribution network service provider, so a capital charge against uninsured OT cyber risk would have to be imposed by a specific APRA or AER instrument applying to such a business. Where one applies, the charge is computed from that instrument and cited by its clause.

Cost-benefit including insurance benefits. The paper's cost-benefit position stands at section 9.5's 4.4:1 to 6.6:1, which rests on avoided loss and published control effectiveness. A premium reduction term enters that ratio once it is priced from a placement, and a regulatory capital term once an instrument imposes one; avoided loss is already counted once, in section 9.5. Adding an unpriced term to a priced one produces a larger number, not a better one. As in section 5.10, reputational damage, regulatory penalties and litigation costs are priced from a business's own records and sit outside this ratio.


10. Limitations and Threats to Validity#

What this assessment can support, and what it cannot, is set out here before the conclusion rather than behind the bibliography, so that a reader reaches the conclusion already knowing what it rests on.

This assessment employs prospective modeling of cascading failure scenarios that have not yet occurred in the Australian context. The methodology combines:

  1. Physics-Based Foundation: Grid frequency dynamics, RoCoF calculations, and protection system behavior are derived from established power systems engineering (AEMO standards, IEC 60255 relay specifications). Where this paper states what a grid actually did, it cites the operator's own report rather than another Eigenia document: AEMO's final report on the South Australian black system of 28 September 2016, National Grid ESO's technical report on the events of 9 August 2019, ENTSO-E's expert panel report on the Continental Europe separation of 8 January 2021, and the NERC and Texas RE disturbance reports on the two Odessa events. No Eigenia paper is the source of record for a measurement taken on somebody else's system.
  2. International Precedent Analysis: South Australia 2016, UK 2019 (0.125 Hz/s RoCoF relay cascade), and Iberian Peninsula 2025 (inter-area oscillations) are precedents for the protection behavior this paper models rather than validation of it.

The South Australian precedent rests on AEMO's own figures for the event: a loss of 456 MW over a period of less than seven seconds, against a regional demand of 1,826 MW, with eight of nine wind farms disconnecting on a voltage-dip-count protection setting rather than on the fault itself, which is the protection behavior this paper models. The report also records that the Heywood Interconnector's special protection scheme tripped about 700 milliseconds after the last of those wind farms reduced output, which is the same point made twice over: a scheme doing what it was configured to do took the state to black. Where the paper needs a protection cascade with a rate of change behind it, it uses Great Britain on 9 August 2019.

Two distinct mechanisms run through those events, and this paper keeps them apart. The first is that low inertia raises df/dt for a given power imbalance. That follows from the swing equation, it is derivable rather than observed, and it is the basis of the cascade argument in section 2. The second is that inverter-based resources disconnect for faults they were never obliged to ride through. That is documented across four NERC disturbance reports and it does not depend on inertia at all.

The evidence available to this working group actively contradicts deriving the second mechanism from the first. At Odessa on 9 May 2021 ERCOT stood at 56 percent synchronous generation and lost 1,340 MW. On 4 June 2022 it stood at 73.5 percent synchronous generation and lost 2,555 MW. The larger loss came at the higher synchronous share, which is the wrong ordering if low inertia were the operative cause. NERC states the mechanism for the 2021 event plainly: none of the resources tripped consequentially by the fault itself. That sentence is NERC's own, from the joint NERC and Texas RE Odessa Disturbance report on the events of 9 May and 26 June 2021, and it is quoted in this working group's ERCOT and WECC Renewable Integration Challenges, section 4.2, against the primary document. The two mechanisms compound where they meet. Neither produces the other, and the paper treats each as an independent cause.

None of these events resulted from coordinated cyber-physical attacks. They were natural disturbances (weather, equipment failure, lightning strikes).

  1. Cyber-Attack Adaptation: This document extends physical failure mechanisms into cyber-enabled scenarios by modeling how an adversary with Retailer API access could deliberately induce the oscillation patterns that occurred naturally in historical events. This represents a novel threat vector without direct historical precedent.
  2. Consequence Modeling Uncertainty:
    • Fatality Estimates (5-25): No cyber-physical attack on electricity infrastructure has caused direct fatalities at this scale. Ukrainian attacks (2015, 2016, 2022) affected 225,000 customers for 6 hours with zero direct deaths. Our estimates extrapolate from medical literature on hospital outage mortality (cardiac care delays, dialysis interruption), traffic accident statistics from signal outages (2019 Sydney precedent: 180 percent accident rate increase), and thermal runaway scenarios (Arizona 2019 McMicken fire: 4 firefighters injured, zero fatalities). These are worst-case models not empirical predictions.
    • Economic Impact (AUD 1.19 billion at the determination boundary; AUD 1.99 billion to AUD 8.95 billion extrapolated): Uses the AER's December 2024 Value of Customer Reliability determination, not AEMO's. Determination has been the AER's statutory responsibility since the AEMC's final rule of July 2018 [n]. The AER determined those values for unplanned outages of up to 12 hours. The cascade modeled here runs to 72 hours, so every figure resting on a longer duration is a linear extrapolation roughly six times outside the determined range, not a determination; section 5.2 states it in exactly those terms and section 5.4 marks each affected cell. The correct instrument beyond 12 hours is the AER's separate Value of Network Resilience review, and a figure from it enters this paper once that review determines one. Regulatory penalty and litigation exposure are determined by a SOCI Act penalty schedule and by Australian distribution precedent, each in its own jurisdiction, so the economic figures here are confined to the direct customer cost the AER's determination supports. The uncertainty around them is structural rather than proportional, and section 9.5 expresses it as a ratio envelope of 2.9:1 to 8.8:1, driven by the working group's own modeled probability assessment and by a class-average control effectiveness measurement.
  3. Research Gaps Requiring Empirical Validation:
    • RefDNSP-1.2M-Specific RoCoF Tolerance: the analysis above uses the generic 1.0 Hz/s threshold, which holds across the class of network rather than for this one. A tolerance specific to RefDNSP-1.2M comes from a dynamic stability study run with AEMO against RefDNSP-1.2M's own topology, protection relay settings, and interconnection to TransGrid, and that study is scoped and quoted by the body running it. Section 2.2 states the same condition.
    • BESS Oscillation Resonance: whether 54 community batteries can sustain coherent oscillation at 0.3 to 1.2 Hz, or whether control system delays and communications latency prevent synchronization, is settled by laboratory testing, scoped and quoted by the laboratory running it. The condition is load-bearing rather than incidental: the initiating mechanism of section 2.2 holds where synchronization holds, and the cascade this paper models rests on it.
    • Cascade Propagation Timing: Tier 1→2→3→4 timeline (T+15, T+30, T+60, T+120 minutes) modeled from AEMO protection relay coordination studies. Actual progression depends on load distribution, tie-line flows, and operator intervention effectiveness during incident.
  4. Comparison to McKenney's Analysis: McKenney (2024, 2025) focuses on unintentional Death Wobble from renewable energy transition and natural disturbances. His work provides the physics foundation (inertia constant formulas, RoCoF thresholds, protection cascade mechanisms) but does not model cyber-enabled deliberate induction of oscillations. This document extends his framework into adversarial scenarios, maintaining his technical rigor while acknowledging the speculative nature of cyber-attack modeling.

Board Interpretation Guidance:

  • High Confidence: grid frequency physics, which follows from the swing equation rather than from any measurement taken for this paper, and protection relay behavior under rate-of-change settings, which four published incident investigations describe directly. The Death Wobble mechanism itself does not belong in this band. Its physics is sound and its protection precedents are real, but no published incident shows an adversary deliberately inducing the oscillation, and item 5 above records the synchronization question that would decide whether 54 batteries can sustain one
  • Moderate Confidence: the direct customer cost of AUD 1.19 billion at the 12-hour boundary of the AER determination, which is computed from a published value through a stated relation but on stipulated customer counts
  • Lower Confidence: every figure resting on a duration beyond 12 hours, including the tier 4 range; fatality estimates, which have no Australian cyber-attack precedent; and attack execution success rates, which depend on adversary sophistication and on the unresolved synchronization question above
  • Outside the computed total: the total stated here is the direct customer cost of energy not supplied, computed from the AER's determined VCR. Equipment damage, regulatory penalties, civil litigation, reputational damage, insurance response, opportunity cost and per-facility industrial loss are each a real cost priced from a business's own records, and section 5.10 names the input each one rests on. A reader adds them to this total rather than reading the total as covering them

This assessment is designed for strategic risk management (Board-level capital allocation, security investment prioritization) not tactical operations (SOC playbook development, incident response procedures). The prospective modeling approach intentionally emphasizes tail risk to support conservative decision-making for critical infrastructure protection.


11. Conclusion#

RefDNSP-1.2M's distributed energy infrastructure faces systemic cascading failure risk from coordinated cyber-physical attacks. The convergence of four conditions creates this risk:

  1. Vulnerable DERMS/API architecture enabling unmitigated mass command injection through the Retailer API, with no oscillation detection, rate limiting, or physics-based validation.
  2. Inadequate ICS protocol security with Modbus TCP operating in cleartext without authentication across the BESS control path, achieving IEC 62443 Security Level 0 where Security Level 2-3 is required.
  3. Complex grid interdependencies linking electricity supply to water, hospital, telecommunications, transport, military, and financial infrastructure, each amplifying the consequences of an electrical outage into a multi-domain crisis.
  4. Reduced grid inertia from renewable energy transition, halving the system's resistance to frequency disturbances and creating conditions where cyber-physical attacks can trigger cascading failures that were physically impossible under the legacy generation mix. As McKenney (2024) documents: "In a low-inertia system, the same disturbance causes the frequency to change much faster than in a high-inertia system. This rapid frequency change is the dangerous 'wobble.'" Historical precedents (South Australia 2016: 456 MW disconnected in under seven seconds on a voltage-dip-count protection setting, UK 2019: approximately 350 MW disconnected on RoCoF relays set at 0.125 Hz/s, Iberian Peninsula 2025: inter-area oscillations) establish that this vulnerability has already materialized in comparable grids worldwide (McKenney, 2024, 2025).

The most likely attack scenario is Retailer API compromise leading to 54 BESS oscillation. That produces the local and regional cascade of section 3.2, tiers 2 and 3, affecting 80,000 to 600,000 customers for 8 to 36 hours. Section 5.4 computes the direct customer cost across that span as AUD 53 million at its lower bound, which sits inside the range for which the AER determined the value of customer reliability, rising to AUD 1.79 billion at its upper bound, which does not. The worst case is system-wide collapse: 1.0 to 1.5 million customers for 24 to 72 hours, and AUD 1.99 billion to AUD 8.95 billion of direct customer cost (modeled: VCR extrapolated to 72 hours, six times its determined range). The 5 to 25 fatality range is a prospective model with no Australian precedent, and section 10 states the grounds for it and the confidence it carries.

Read one boundary figure alongside those. The full network at 12 hours, the longest outage the AER's determination actually covers, gives AUD 1.19 billion [n]. That is the largest direct customer cost this paper can state without extrapolating. Everything above it, including the headline tier 4 range, is an upper-bound extrapolation and is labeled as one wherever it appears.

The mitigation programme is not discretionary. It is a regulatory obligation under the SOCI Act and the AESCSF, and a social licence condition for continued expansion of community battery programs. Its cost is reported as banded lines rather than as one number. Section 9.3 bounds eight of eleven programme lines at AUD 2.3 million to AUD 6.2 million one-off through band arithmetic against the sourced AUD 1.29 million CIRMP cyber envelope, and the three remaining lines exceed that envelope individually, each carrying a floor at the band D threshold with no ceiling any public source states. Its return can be stated: section 9.5 computes 4.4:1 to 6.6:1 from a government cost estimate and an insurance-claims measurement of control effectiveness, with a sensitivity envelope of 2.9:1 to 8.8:1. That is a strong case. Action is required within implementation period to prevent potential catastrophic failure.


12. Appendices#

Appendix A: Physics Calculations#

Grid Frequency Response Model:

System parameters:
  H = 3.0 seconds (inertia constant, high-renewable scenario)
  D = 1.5 percent per Hz (load damping)
  S_base = 10,000 MVA (NSW system base)
  f_nominal = 50 Hz

Attack parameters:
  P_swing = 540 MW (270 MW BESS charge to discharge)
  Oscillation frequency = 0.5 Hz (2-second period)

Single-cycle frequency deviation:
  delta_f = P_swing / (D x S_base / 100) = 540 / (1.5 x 100) = 0.036 Hz

Single-cycle peak RoCoF (same sinusoidal form used throughout, df/dt = A x 2 x pi x f):
  0.036 x 2 x pi x 0.5 = 0.113 Hz/s

Threshold comparison:
  0.113 Hz/s << 1.0 Hz/s (a single oscillation is safe)

Cumulative effect over sustained oscillation:
  Resonant amplification factor at 0.3-1.2 Hz = 4-10x (frequency dependent)
  After 10 cycles: effective deviation amplitude = +/- 0.15 Hz (within the 49.85 to 50.15 Hz normal band)
  Peak RoCoF of a sustained +/- 0.15 Hz sinusoid (df/dt = A x 2 x pi x f):
    at 1.2 Hz resonance top: 0.15 x 2 x pi x 1.2 = 1.13 Hz/s
    at 1.0 Hz:               0.15 x 2 x pi x 1.0 = 0.94 Hz/s
  RoCoF relay trip (threshold 1.0 Hz/s, see Section 2.2): 1.13 Hz/s exceeds threshold while frequency stays in band

Thermal Runaway Energy Release:

Battery parameters:
  Cell capacity = 280 Ah, nominal voltage = 3.2 V (LFP)
  Cells per container = 13,500 (5 MWh system)
  Cell mass = 0.5 kg

Thermal runaway energy:
  Heat of reaction = 2,500 kJ/kg (exothermic)
  Total energy = 13,500 cells x 0.5 kg x 2,500 kJ/kg = 16,875,000 kJ = 16,875 MJ
  TNT equivalent = 16,875 MJ / 4.184 MJ/kg = 4,033 kg

Note: Energy release occurs over 4-12 hours, not as instantaneous detonation.

Appendix B: Advanced Grid Stability Modeling#

Frequency Response Simulation Under Attack Conditions:

This appendix provides detailed mathematical modeling of grid frequency response to coordinated BESS oscillation attacks, validating the Death Wobble scenario through power systems engineering analysis.

Swing Equation and Frequency Dynamics:

The grid's frequency response to power imbalances is governed by the swing equation:

2H × (df/dt) = P_mech - P_elec - D × Δf

Where:
- H = System inertia constant (seconds)
- df/dt = Rate of change of frequency (Hz/s) = RoCoF
- P_mech = Mechanical power input from generators (MW)
- P_elec = Electrical power consumed by loads (MW)
- D = Load damping coefficient (MW/Hz)
- Δf = Frequency deviation from nominal (Hz)

Scenario Modeling: 54 BESS Oscillation at 0.5 Hz:

Attack Parameters:
- BESS count: 54 units
- Power per unit: 5 MW
- Oscillation pattern: Square wave charge/discharge
- Frequency: 0.5 Hz (2-second period)

Grid Parameters (NSW, High-Renewable Scenario):
- System inertia H: 2.5 seconds (30% synchronous, 70% inverter-based)
- Load damping D: 1.5% per Hz = 150 MW/Hz (for 10,000 MW system)
- Nominal frequency f_0: 50 Hz

Time-Domain Simulation:

T = 0 seconds: All 54 BESS begin charging
  P_elec increase: +270 MW
  Swing equation: 2 × 2.5 × (df/dt) = -270 - 150 × Δf
  Initial RoCoF: df/dt = -270 / (2 × 2.5) = -54 Hz/s (instantaneous, before damping)

T = 0.1 seconds: Frequency decline begins
  Δf = -54 × 0.1 = -5.4 Hz (if no damping) → Unrealistic
  With damping: Δf = -270 / 150 = -1.8 Hz (steady-state, if maintained)
  Actual (transient): Δf ≈ -0.05 Hz (exponential approach to steady state)

T = 1 second: Charge cycle completes
  Accumulated frequency deviation: Δf ≈ -0.12 Hz
  Grid frequency: 50 - 0.12 = 49.88 Hz (still inside the 49.85 to 50.15 Hz normal band)

T = 1 second: All 54 BESS switch to discharge
  P_elec decrease: -270 MW (270 MW swing from charge state)
  Total power swing: 540 MW (charge → discharge transition)
  RoCoF: df/dt = +270 / (2 × 2.5) = +54 Hz/s (instantaneous)

T = 1.1 seconds: Frequency rise begins
  Δf changes from -0.12 Hz to rising trajectory
  Target steady state (if maintained): +270 / 150 = +1.8 Hz

T = 2 seconds: Discharge cycle completes
  Accumulated frequency deviation: Δf ≈ +0.08 Hz
  Grid frequency: 50 + 0.08 = 50.08 Hz (frequency swing amplitude: 0.20 Hz peak-to-peak)

Oscillation Cycle Repeats Every 2 Seconds (0.5 Hz):
- Cycle 1: Δf swings -0.12 to +0.08 Hz (0.20 Hz amplitude)
- Cycle 2: Δf swings -0.15 to +0.12 Hz (0.27 Hz amplitude, cumulative resonance)
- Cycle 3: Δf swings -0.18 to +0.15 Hz (0.33 Hz amplitude)
- ...
- Cycle 10: Δf swings -0.35 to +0.28 Hz (0.63 Hz amplitude)

At Cycle 10 (T = 20 seconds):
- Minimum frequency: 50 - 0.35 = 49.65 Hz
- Maximum frequency: 50 + 0.28 = 50.28 Hz
- Oscillation amplitude: 0.63 Hz peak-to-peak, so half-amplitude A = 0.315 Hz at 0.5 Hz oscillation
- Peak RoCoF (df/dt = A x 2 x pi x f): 0.315 x 2 x pi x 0.5 = 0.99 Hz/s, at the 1.0 Hz/s RoCoF relay threshold (see Section 2.2), and past it on the next cycle of amplitude growth
- Conclusion: RoCoF protection WILL trip on rate of change if oscillation continues

Protection Relay Response:
- Relay detects peak df/dt reaching the 1.0 Hz/s RoCoF setpoint
- Time delay: 0.1-0.5 seconds (typical RoCoF relay settings; a 500 ms definite time delay applies in the UK G99 case)
- Action: Trip embedded generation on rate of change, and shed load once frequency then falls into the UFLS band
- Consequence: Sudden generation and load loss drives frequency down, triggering the under-frequency cascade that follows

Key Findings from Simulation:

  1. Resonant Amplification Confirmed: Oscillation amplitude grows from 0.20 Hz (Cycle 1) to 0.63 Hz (Cycle 10), a 3.15x amplification factor over 20 seconds.
  2. Protection Cascade Threshold: RoCoF protection relays will trip on rate of change within 10-15 oscillation cycles (20-30 seconds), validating the attack timeline in Section 2.2.
  3. RoCoF Exceeds Design Limits: Instantaneous RoCoF of 54 Hz/s during state transitions far exceeds AEMO's 1.0 Hz/s maximum design assumption, though this is averaged over longer time windows in practice.
  4. Low-Inertia Vulnerability: The scenario requires H = 2.5 seconds or less. At H = 5.0 seconds (traditional grid), the same attack produces only 0.10 Hz peak-to-peak swing (insufficient to trigger protection).

Validation Against Historical Precedents:

EventDisturbance SizeSystem ConditionProtection TriggerOutcome
South Australia 2016456 MW generation loss in under seven seconds48.36 percent inverter-based resource penetration, 1,826 MW regional demandvoltage-dip-count protection setting, 8 of 9 wind farmsHeywood special protection scheme trip, islanding, statewide blackout, 850,000 customers
UK 2019641 MW gas + 737 MW wind lossH = 3.5s (est.)0.125 Hz/s RoCoF relay disconnection thresholdapprox. 350 MW DER cascade, 1,152,878 customers affected
Simulated Attack (NSW)540 MW power swing (oscillating)H = 2.5s (modeled)54 Hz/s instantaneous (modeled)Protection cascade after 20-30 seconds (modeled)

The simulated attack's 540 MW power swing is comparable to South Australia's 456 MW disturbance, which is the comparison that carries. The H = 2.5s value in the simulation is a modeled input chosen for the scenario, and the comparison drawn here is one of disturbance size: an attack swinging 540 MW sits in the same class as a real event that blacked out a state.

Monte Carlo Sensitivity Analysis:

To account for uncertainty in system parameters, we perform 1,000 Monte Carlo simulations varying:

  • System inertia H: 2.0-3.5 seconds (uniform distribution)
  • Load damping D: 1.2 to 1.8 percent per Hz (uniform distribution)
  • BESS response delay: 50-200 milliseconds (uniform distribution)
Monte Carlo Results (1,000 simulations):

Protection Cascade Probability (under-frequency relay trip within 60 seconds):
- H < 2.5s: 95% probability of cascade
- H = 2.5-3.0s: 78% probability of cascade
- H > 3.0s: 42% probability of cascade

Median Time to Cascade:
- H < 2.5s: 22 seconds (median)
- H = 2.5-3.0s: 38 seconds (median)
- H > 3.0s: >60 seconds (often no cascade within 60s window)

AEMO Data: NSW system inertia drops below H = 3.0s during 15-20% of operational hours
→ Attack success probability: 15-20% × 78% = 12-16% (if executed during random hour)
→ Attack success probability: 95% (if attacker waits for low-inertia window, detectable via grid frequency telemetry)

Conclusion: Mathematical modeling confirms that coordinated BESS oscillation attack is physically plausible and will trigger protection cascades under realistic low-inertia grid conditions. The attack's effectiveness depends critically on system inertia, which is observable via public AEMO telemetry, allowing attackers to time execution optimally.

Appendix C#

BESS Thermal Runaway Physics and Fire Dynamics

Lithium-Ion Cell Chemistry and Thermal Decomposition:

Community BESS deployments use either Lithium Iron Phosphate (LFP) or Nickel Manganese Cobalt (NMC) chemistry. Both are susceptible to thermal runaway, though at different temperature thresholds:

ChemistryNominal VoltageThermal Runaway OnsetHeat ReleaseOxygen ReleaseFire Suppression Difficulty
LFP (LiFePO₄)3.2V180-220°C1,800-2,200 kJ/kgMinimal (no cobalt)Moderate (lower heat, but still self-sustaining)
NMC (LiNiMnCoO₂)3.6-3.7V150-180°C2,200-2,800 kJ/kgHigh (oxygen from cathode)Severe (self-oxygenating combustion)

Thermal Runaway Reaction Cascade (NMC Chemistry):

Stage 1: SEI Layer Decomposition (120-130°C)
Reaction: (CH₂OCO₂Li)₂ → Li₂CO₃ + CO₂ + C₂H₄ + Heat
Heat Released: 100-200 J/g
Timeline: Begins 15-30 minutes after overcharge/overheating initiation

Stage 2: Electrolyte Decomposition (130-150°C)
Reaction: EC + DMC → CO₂ + CO + Hydrocarbons + Heat
(EC = Ethylene Carbonate, DMC = Dimethyl Carbonate)
Heat Released: 300-500 J/g
Timeline: 5-10 minutes after Stage 1 onset
Hazard: Flammable gas accumulation inside cell (pressure buildup → venting → ignition)

Stage 3: Separator Melting and Internal Short Circuit (150-165°C)
Mechanism: Polyethylene separator melts, anode contacts cathode
Result: Direct electron flow bypassing normal electrochemistry → localized heating
Heat Released: 800-1,200 J/g at short circuit location
Timeline: 1-3 minutes after separator melting

Stage 4: Cathode Decomposition (180-250°C for NMC)
Reaction: LiNi₀.₃₃Mn₀.₃₃Co₀.₃₃O₂ → Ni, Mn, Co (metallic) + O₂ + Li₂O + Heat
Heat Released: 1,500-2,500 J/g
Timeline: <1 minute once initiated (rapid, self-accelerating)
Critical: Releases oxygen internally, enabling combustion even in inert atmosphere

Stage 5: Thermal Propagation to Adjacent Cells
Mechanism: Radiant and conductive heat transfer from failed cell to neighbors
Heat flux: 5,000-15,000 W/m² from burning cell surface
Propagation time: 30 seconds to 15 minutes per cell (depends on cell spacing, cooling, thermal barriers)

Cell-to-Module-to-Rack Propagation Modeling:

A typical 5 MWh BESS contains:

  • 13,500 cells (280 Ah, 3.2V nominal)
  • 450 modules (30 cells per module)
  • 15 racks (30 modules per rack)
  • 1 container (15 racks)

Propagation Timeline (NMC Chemistry, No Fire Suppression):

T+0 minutes: Single cell enters thermal runaway (initiated by Modbus attack on BMS)
- Cell temperature: 180°C
- Neighboring cells: 60°C (normal operating temperature during charge)
- Status: Contained within module

T+2 minutes: Thermal propagation to 2nd cell within same module
- Mechanism: Conductive heat transfer through aluminum module casing
- Heat flux: 8,000 W/m² from burning cell
- Cell spacing: 5 mm (typical)
- Thermal barrier: None (standard commercial design)

T+5 minutes: 10 cells in thermal runaway within originating module
- Mechanism: Radiant heat + burning electrolyte vapor igniting adjacent cells
- Module temperature: >300°C
- Venting gases: CO, CO₂, HF (from LiPF₆ electrolyte salt decomposition)

T+8 minutes: First thermal propagation to adjacent module
- Mechanism: Convective heat transfer via burning vapor plume
- Module-to-module spacing: 50 mm
- Thermal barrier: Steel rack structure (insufficient for 300°C+ heat)

T+15 minutes: 50% of rack (7-8 modules) in thermal runaway
- Total cells burning: 210-240 cells (28 kWh energy release)
- Toxic gas concentration: HF >50 ppm (IDLH: 30 ppm), CO >500 ppm (IDLH: 1,200 ppm)
- Evacuation radius required: 100 meters minimum

T+30 minutes: Full rack in thermal runaway
- Total cells: 450 cells (63 kWh energy release)
- Fire temperature: 600-800°C (aluminum module casings melting, T_melt = 660°C)
- Rack structural integrity: Failing (steel supports weakening)

T+60 minutes: First thermal propagation to adjacent rack
- Mechanism: Radiant heat through container wall + burning electrolyte pool fire
- Rack-to-rack spacing: 1 meter
- Thermal barrier: None (open container design for ventilation)

T+120 minutes: 50% of container (7-8 racks) in thermal runaway
- Total cells: 3,150 cells (441 kWh energy release = 25% of total 1,800 kWh)
- Container status: Structural failure likely, fire venting through roof and walls

T+240 minutes: Full container in thermal runaway
- Total cells: 6,750 cells (945 kWh energy release = 53% of total)
- Remaining energy: 855 kWh continuing to burn over next 2-8 hours
- Firefighting status: Defensive operations only (water cooling exterior to prevent spread)

T+8 hours: Fire self-extinguishing (fuel exhaustion)
- Total energy released: 1,800 kWh = 6,480 MJ = 1,548 kg TNT equivalent
- Container status: Total loss, structural collapse
- Salvage value: none assumed, since the BESS must be removed as hazardous waste. No sourced disposal or site remediation cost is held, so no figure is stated

Multi-Site Cascading Fire Scenario (15 BESS Simultaneous):

If Modbus thermal attack is executed across 15 BESS sites simultaneously (FrostyGoop-style coordinated attack):

Regional Fire Response Capacity:
- Fire stations within 30-minute response: 15-20
- Pumper appliances available: 25-35
- Hazmat-qualified teams: 3-5
- Water delivery capacity: 3,000 liters per pumper × 30 pumpers = 90,000 liters total

Per-Site Water Requirements (BESS Fire):
- Cooling water: 15,000-25,000 liters over 8 hours (preventing propagation to other containers on site)
- Exposure protection: 10,000-15,000 liters for adjacent structures
- Total per site: 25,000-40,000 liters

15-Site Water Demand:
- Total requirement: 15 sites × 30,000 liters (avg) = 450,000 liters
- Available supply: 90,000 liters (initial appliance capacity) + continuous hydrant supply
- Hydrant flow rate: 1,000-2,000 liters/minute (typical suburban)
- Resupply time: Continuous, if hydrants remain operational (requires electrical grid power for pumping stations)

Cascading Failure:
Hour 2: Water pressure failing due to grid blackout → pumping stations offline
Hour 3: Firefighters forced to defensive-only operations (no interior attack, no cooling water)
Hour 4: Multiple BESS fires spreading to adjacent structures (vegetation, buildings)
Hour 6: Regional state of emergency declared, mutual aid from interstate fire services
Hour 12: Fires begin self-extinguishing as battery fuel depletes

Casualties:
- Firefighter injuries: 5-15 (smoke inhalation, burns from radiant heat)
- Civilian casualties: 2-8 (evacuation delays, toxic gas exposure)
- Environmental contamination: 15 sites × 5,000 kg battery mass = 75,000 kg hazardous waste requiring EPA remediation

Appendix D: Economic Impact Methodology#

Direct customer cost is computed once in this paper, in section 5. This appendix records the method so a reader can reproduce or contest it, and does not restate the outputs.

The two relations.

E_unserved (kWh) = customers x average coincident demand (kW) x restoration hours
C_direct  (AUD)  = VCR (AUD per kWh) x E_unserved

The inputs.

TermValue usedBasis
CustomersPer cascade tier, section 3.2RefDNSP-1.2M stipulated scenario parameter. Modeled, not sourced
Average coincident demand2.15 kW per customer1,826 MW of regional demand across 850,000 customers, AEMO's final report on the South Australian black system of 28 September 2016 [n]
Restoration hoursPer cascade tier, section 3.2Working group scenario parameter. Modeled, not sourced
VCRAUD 38.53 per kWh, residential NSW, 2024 dollarsAER 2024 VCR final report, Table 1 [n]

Worked example, tier 2 at its lower bound. 80,000 customers multiplied by 2.15 kW multiplied by 8 hours gives 1,376,000 kWh. At AUD 38.53 per kWh that is AUD 53.0 million. Section 5.4 carries the same arithmetic for every tier.

Three limits on the method. All three are stated in section 5 and repeated here because a methodology appendix is where a reader looks for them.

  1. The AER determined the 2024 VCR values for unplanned outages of up to 12 hours [n]. Any figure resting on a longer duration is a linear extrapolation outside the determined range, not a determination, and the real relation is not known to be linear. The correct instrument beyond 12 hours is the AER's Value of Network Resilience review, and no VNR figure is held.
  2. The 2.15 kW anchor is an all-customer coincident average measured in one region at one moment. It is applied uniformly, so the residential VCR is applied to commercial and industrial customers as well. The AER's business values of AUD 22.25, AUD 34.39 and AUD 33.49 per kWh all sit below the residential figure used [n], so the blending biases every computed cost upward.
  3. One restoration-hours scalar per tier replaces a strongly non-uniform real profile. Section 5.5 shows the size of that simplification against the observed South Australian restoration curve.

Attribution. AEMO produced the first NEM VCR methodology in 2014; determination has been the AER's statutory responsibility since the AEMC's final rule of 5 July 2018, commencing 13 July 2018 [n]. The AER publishes VCR by jurisdiction and by customer segment, and its determination carries one value per segment across the determined duration. Every value used in this appendix is read off that publication at the jurisdiction and segment it names.

Appendix E: Risk Calculation Methodology#

Frequency Risk Analysis#

Death Wobble Attack Likelihood Assessment

The paper's stated likelihood is 15 to 30 percent over a ten-year horizon, midpoint 22.5 percent. It is the working group's own assessment, it is labeled as such, and it is the only likelihood used anywhere in this document. Sections 5.9 and 9.5 both derive from it. A reader building on this paper should use that range and should not reconstruct a point estimate from threat factors.

The factors below set out the structure of the argument. They are ordered by the working group's judgment of contribution, and each carries a rank rather than a weight, because contribution here is judged rather than measured.

  1. Technical vulnerability. The Retailer API lacks rate limiting and oscillation detection. This is the factor the paper documents most directly.
  2. Threat capability. Nation-state actors have demonstrated capability against energy infrastructure.
  3. Environmental exposure. Declining synchronous inertia raises the physical consequence of a given command injection, as section 2.2 derives.
  4. Detection capability. Current monitoring is not dimensioned for a sub-second protection cascade.

Quantifying their relative contribution needs incident data the working group does not hold. Section 10 records that as an open limitation.

Consequence Impact Analysis#

Economic Impact Model:

This appendix does not carry a second cost model. Direct customer cost is computed once, in section 5, from the AER's determined value of customer reliability, and Appendix D records the method. The relation is:

E_unserved (kWh) = customers x average coincident demand (kW) x restoration hours
C_direct  (AUD)  = VCR (AUD per kWh) x E_unserved

Applied to the reference case, the full network at the longest duration the AER determination covers:

1,200,000 customers x 2.15 kW x 12 h = 30,960 MWh
30,960,000 kWh x AUD 38.53 per kWh   = AUD 1.19 billion

That AUD 1.19 billion is the largest direct customer cost this paper states on the determination alone [n]. The tier 4 envelope of AUD 1.99 billion to AUD 8.95 billion in section 5.4 extends it to 24 and 72 hours and is an extrapolation, labeled as one wherever it appears.

Seven further cost lines bear on the same event: equipment damage, emergency response and restoration labor, replacement power procurement, customer compensation, reputation damage and churn, regulatory fines for AESCSF non-compliance, and business interruption across the six dependent sectors. Every one is a real cost, and section 5.10 and section 4.7 name the input each one's price rests on. A total economic impact across all eight terms follows once those seven are priced; the figure this appendix states is the direct customer cost above.

The single sourced cross-check available is an observed one. Business SA surveyed about 200 businesses after the 28 September 2016 South Australian black system and put the cost to South Australian business at AUD 367 million [n]. That is a lobby group's survey of business losses only, so it is a floor on the event's economic cost rather than a total. Section 5.7 runs the relation above against the same event and gets AUD 709 million, roughly twice the surveyed figure, in the direction the difference should fall.

Physical Safety Impact Model:

Fatality Risk:
- BESS thermal runaway: 2-5 fatalities (firefighter exposure, toxic fumes)
- Traffic accidents (signal failures): 1-3 fatalities
- Medical infrastructure collapse: 2-10 fatalities (dialysis, ventilators)
- Delayed emergency response: 0-7 fatalities

Total Fatality Range: 5-25 (median: 12)

Serious Injury Risk:
- BESS explosion shrapnel: 5-15 injuries
- Traffic accidents: 10-30 injuries
- Hospital equipment failures: 15-40 injuries
- Residential accidents (falls, fires): 10-35 injuries

Total Serious Injury Range: 40-120 (median: 75)

Safety impact is stated as casualty ranges rather than in dollars.

The fatality and injury ranges above are prospective models with no Australian cyber-physical precedent; section 10 records the basis for them and section 6.4 carries the same caution. They are stated as casualty counts. Converting them to dollars takes an Australian government value of statistical life, cited to the instrument that determines it, and the direct customer cost of section 5 is stated on its own basis.

Risk-Adjusted Return on Investment (ROI)#

Investment Summary. No phase carries a dollar total, because no phase has a public price for every line. Section 9.3 assigns each line an ordinal band against the sourced CIRMP cyber envelope of AUD 1.29 million one-off and AUD 0.60 million per year, and states the band arithmetic:

  • Phase 1, immediate: two band C one-off lines, one band B, and two band R recurring lines
  • Phase 2, short term: three band D lines, two band C, one band B
  • Phase 3, ongoing: band R throughout, five lines, none with a public price
  • Bounded one-off total across Phases 1 and 2: AUD 2.3 million to AUD 6.2 million (modeled: band boundary arithmetic, not a quotation)
  • Three band D lines exceed the envelope individually, each carrying a floor at the band D threshold with no ceiling any public source states, so the true one-off total sits above AUD 6.2 million by an amount that a firm vendor quote for each of the three lines would set

Risk Reduction Effectiveness. Risk reduction is stated as a band applied once, rather than as a per-phase ladder that compounds. Dragos and Marsh McLennan, whose measurement is the only published one located, state explicitly that their per-control figures are not additive and their report models no combined effect [n]. The band is their measured range across five OT control classes, 12.18 to 18.46 percent per class.

Expected Loss Calculation. The method worked in section 9.5 holds here, and it uses three inputs and one relation. A per-phase figure rests instead on a residual success probability measured at every step, which a monitored implementation produces:

Expected loss  = P(attack over 10 years) x direct cost
Avoided loss   = expected loss x risk reduction

Applied to the reference case, with every input named:

P(attack over 10 years) = 0.15 to 0.30, midpoint 0.225
    working group assessment, section 1. Uncited.
Direct cost             = AUD 1.19 billion
    AER determined VCR, full network at 12 h, section 5.4.
Expected loss           = 0.225 x 1,190 = AUD 268 million
    section 5.9. Range AUD 179 million to AUD 358 million.
Risk reduction          = 0.1218 to 0.1846 per control class
    Dragos and Marsh McLennan, measured over a decade of claims.
Avoided loss at 0.12    = 268 x 0.12 = AUD 32.2 million over 10 years
Avoided loss at 0.18    = 268 x 0.18 = AUD 48.2 million over 10 years

ROI Calculation, 10-Year Horizon. Section 9.5 derives this once and it is not recomputed here. Programme cost is the ten-year CIRMP cyber component, AUD 1.29 million one-off plus ten years at AUD 0.60 million per year, giving AUD 7.3 million.

At 12 percent:  32.2 / 7.3 = 4.4 : 1     net benefit AUD 24.9 million
At 18 percent:  48.2 / 7.3 = 6.6 : 1     net benefit AUD 40.9 million
Sensitivity:   179 x 0.12 / 7.3 = 2.9 : 1
               358 x 0.18 / 7.3 = 8.8 : 1

Neither side is discounted. No discount rate is sourced, so no figure above is a net present value and none should be labeled one.

Payback period. Spreading the ten-year avoided loss evenly across ten years gives AUD 3.22 million per year at 12 percent and AUD 4.82 million per year at 18 percent. Against a programme cost of AUD 7.3 million, payback is 2.3 years and 1.5 years respectively (modeled: the even spread is an assumption the underlying probability assessment does not require, since a single event either occurs in a given year or does not).

Sensitivity Analysis.

ParameterLowBaseHighResulting ratio
Attack probability over 10 years15 percent22.5 percent30 percentDrives expected loss of AUD 179 million, AUD 268 million, AUD 358 million (working group assessment)
Direct costAUD 1.19 billion, VCR determination boundarySameAUD 8.95 billion, tier 4 at 72 hBase ratios 4.4:1 to 6.6:1; the high case is not used, for the reason below
Control effectiveness12.18 percent15 percent18.46 percent2.9:1 to 8.8:1 across the full loss range [n]
Programme costAUD 7.3 millionAUD 7.3 millionUnbounded aboveThe three band D lines of section 9.3 carry a floor at the band D threshold, with no ceiling any public source states, so the high-cost ratio is reported at that floor rather than as a single computed figure

Interpretation. The defensible ratio is 4.4:1 to 6.6:1, inside a sensitivity envelope of 2.9:1 to 8.8:1. Substituting the tier 4 upper bound of AUD 8.95 billion would give 33:1 to 49.5:1, and section 9.5 holds the headline to the reference case: that higher figure stacks the working group's own probability assessment on a VCR extrapolated to six times its determined range, and the defensible band is the one computed inside the determined range. The programme cost side is also optimistic, because AUD 7.3 million is a sector-average regulatory compliance figure that does not cover the band D controls at all. Both distortions are stated rather than netted off.

Cascading Failure Physics Equations#

Grid Frequency Dynamics:

System Inertia (H):
  H = (Σ J_i × ω_i^2) / (2 × S_base)

  where J_i = rotational inertia of generator i (kg⋅m²)
        ω_i = angular velocity (rad/s)
        S_base = system base power (MVA)

NSW Grid During High Solar (2026):
  H = 2.5 seconds (down from 4.5 seconds in 2015)

Rate of Change of Frequency (RoCoF):
  RoCoF = df/dt = -(Δ P / 2H) × (f_0 / S_base)

  where Δ P = power imbalance (MW)
        f_0 = nominal frequency (50 Hz)

Death Wobble Scenario (270 MW BESS simultaneous discharge):
  RoCoF = -(270 MW / (2 × 2.5 s)) × (50 Hz / 10,000 MVA)
        = -0.27 Hz/s (initial)

  With protection relay cascades amplifying imbalance to 500 MW:
  RoCoF = -(500 MW / (2 × 2.5 s)) × (50 Hz / 10,000 MVA)
        = -0.50 Hz/s (cascading phase)

  Under extreme conditions (1,000 MW imbalance):
  RoCoF = -1.0 Hz/s (catastrophic, triggers UFLS at 48.8 Hz)

Frequency Nadir Calculation:

Minimum Frequency (f_nadir):
  f_nadir = f_0 - (Δ P × t_response) / (2H)

  where t_response = time to activate frequency response (seconds)

Scenario: 500 MW loss, 15-second response delay:
  f_nadir = 50 Hz - (500 MW × 15 s) / (2 × 2.5 s × 10,000 MVA / 50 Hz)
          = 50 Hz - 0.75 Hz = 49.25 Hz

  Status: Below 49.5 Hz triggers emergency FCAS, but above 48.8 Hz UFLS threshold
  Risk: Multiple such events in cascade → cumulative frequency decline → blackout

BESS Thermal Runaway Equations:

Battery Cell Temperature Rise:
  dT/dt = (I^2 × R_internal - h × A × (T - T_ambient)) / (m × c_p)

  where I = current (A)
        R_internal = internal resistance (Ω)
        h = heat transfer coefficient (W/m²⋅K)
        A = surface area (m²)
        T = cell temperature (°C)
        m = cell mass (kg)
        c_p = specific heat capacity (J/kg⋅K)

Normal Operation (1C discharge, BMS active):
  Equilibrium at T = 35°C (ambient 25°C, active cooling)

Attack Scenario (5C discharge, BMS disabled):
  Heat generation >> heat dissipation
  T rises at ~2°C/minute
  Thermal runaway threshold: 80-90°C (lithium-ion chemistry)
  Time to runaway: ~25 minutes without intervention

Explosion Risk:
  Energy release = m_cell × Δ H_combustion
                 = 50 kg × 2,500 kJ/kg = 125 MJ per BESS unit
                 = equivalent to 30 kg TNT

Cascade Propagation Timeline:

T+0 min:   Death Wobble attack initiated (270 MW BESS simultaneous discharge)
T+2 min:   Grid frequency drops to 49.7 Hz (RoCoF = -0.3 Hz/s)
T+5 min:   First protection relay trips (8,000 customers lose power)
T+8 min:   Frequency oscillation at 1.2 Hz (resonance with remaining BESS units)
T+12 min:  Second cascade wave (feeder overloads from rerouted power) → 40,000 customers
T+18 min:  RoCoF exceeds -0.5 Hz/s, multiple relays trip simultaneously
T+25 min:  Frequency nadir 49.0 Hz, emergency FCAS activated (insufficient capacity)
T+35 min:  Third cascade wave (120,000 customers)
T+50 min:  BESS thermal events begin (BMS manipulation 25 min earlier)
T+75 min:  Frequency 48.9 Hz, UFLS Stage 1 activates (300,000 customers shed)
T+90 min:  Inter-regional tie-line overloads, cascades to Victoria interconnection
T+120 min: Regional blackout (1.2 million customers), frequency 47.5 Hz, system collapse

Appendix F: Mitigation Technology Matrix#

Vendor names below are examples of the product class, not recommendations and not a procurement shortlist. No vendor in any of these classes publishes a price. Every listing found during research returned "price on request", including for the one product named specifically anywhere in this paper. The Cost band column therefore carries the ordinal scheme of section 9.1, measured against the sourced CIRMP cyber envelope of AUD 1.29 million one-off: A under 10 percent, B 10 to 40 percent, C 40 to 100 percent, D above the envelope, R recurring against AUD 0.60 million per year. Where section 9.2 or 9.3 has already banded the same control, the band is carried across unchanged and the cell says so.

TechnologyVendor ExamplesLocationVectors MitigatedCost band
API Security GatewayApigee, KongDMZ (Z3.5)API mass command injectionC, as section 9.2
Container Runtime SecurityAqua, SysdigOpenShift ClusterContainer escape, privilege escalationB, as section 9.3 Phase 1
ICS-Aware FirewallFortinet, Palo AltoZone boundariesProtocol exploitation, lateral movementD, as section 9.3 Phase 2
OT Protocol ParserDragos, NozomiSOC (Z3)ICCP/Modbus/DNP3 manipulationD, as section 9.2
Behavioral AnalyticsSplunk UBA, ExabeamSOC (Z3)Anomalous API usage, insider threatsD, as section 9.3 Phase 2
Modbus Security GatewayMoxa EDR, Fortinet ICSZone 2 boundaryModbus injection, command spoofingC, as section 9.2
Network Detection and ResponseDarktrace, Vectra AIZone 3 internalLateral movement, data exfiltrationD, part of the same section 9.3 NDR line
Hardware Security ModuleThales Luna, EntrustData centre (Z3)Key theft, certificate compromiseB (engineering judgment; no public anchor, no prior band)
Privileged Access ManagementCyberArk, BeyondTrustBastion (Z3.5)Vendor access abuse, credential theftC (engineering judgment; no public anchor, no prior band)

Four of these nine sit in band D, meaning each exceeds the whole sourced cyber envelope on its own and needs a separate funding determination. That is the central cost finding of this paper and it is not softened by the ordinal presentation: the controls the analysis most wants are the ones with no public price and the largest likely cost.

Appendix G: Security Control Catalog#

Phase 1 Critical Controls, Q2 to Q3 2026#

Cost bands use the scheme of section 9.1, measured against the sourced CIRMP cyber envelope of AUD 1.29 million one-off. The benefit column gives the Dragos and Marsh McLennan class figure where a control maps onto one of their five measured OT control classes, and a mechanism where none maps. Benefits are stated per control rather than cumulated, because the only published measurement states plainly that per-control risk reductions are not additive [n].

Control IDControl NameIEC 62443 RequirementMITRE D3FENDImplementationCost bandBenefit basis
CTL-001Retailer API Rate LimitingCR 3.1 (Communication Restrictions)D3-NTF (Network Traffic Filtering)API gateway rate limit: 10 req/min/retailer, 100 devices/batchA (gateway configuration)Mechanism: caps commands per unit time, so a fleet cannot be driven at resonance through the API
CTL-002DER Oscillation DetectionCR 2.6 (Resource Management)D3-APLM (Application Behavior Monitoring)Physics-based anomaly detection: >5% frequency in 60s = alertB, as section 7.1Mechanism: fires on a pattern with no benign explanation. No false-positive rate measured for this network
CTL-003DERMS API Authentication HardeningCR 1.1 (User Identification)D3-MFA (Multi-Factor Authentication)Certificate-based authentication for all API clientsA (configuration on an existing identity platform)Secure remote access, 12.18 percent class average [n]. Class average, not this control's measured effect
CTL-004BESS Command ValidationCR 3.4 (Software Process Integrity)D3-PSA (Process Spawn Analysis)SOC/power setpoint bounds checking before Modbus transmissionA, as the rate-limiting control in section 9.2Mechanism: a setpoint outside declared bounds is not transmitted, so the register write never leaves DERMS
CTL-005Emergency DERMS ShutdownCR 4.1 (Event Logging)D3-IRA (Incident Response Automation)Kill switch disabling all DER dispatch in <60 secondsA (DERMS engineering)Incident response plan, 18.46 percent class average [n]. Class average, not a measured result for a kill switch
CTL-006Grid Frequency MonitoringCR 3.3 (Use Control)D3-NTA (Network Traffic Analysis)Real-time RoCoF alerting: >0.3 Hz/s = SOC notificationB (telemetry integration into existing monitoring)Network visibility and monitoring, 16.47 percent class average [n]
CTL-007SCADA Alarm IntegrityCR 2.8 (Auditable Events)D3-AL (Audit Logging)Cryptographic signing of SCADA alarm messagesB, as the application-layer signing control in section 7.3Mechanism: a forged alarm fails verification. It does nothing against an attacker holding the signing key
CTL-008ICCP Data ValidationCR 3.2 (Provenance Tracking)D3-ITF (Inbound Traffic Filtering)Constraint data sanity checks: feeder limits, timestamp validationA, as data point allowlisting in section 7.3Mechanism: constraint values outside physical feeder limits are refused. It does not catch plausible false values

Phase 1 band arithmetic: five band A and three band B give AUD 0.4 million to AUD 2.2 million one-off (modeled: band boundary arithmetic against the AUD 1.29 million CIRMP cyber envelope, not a quotation). Risk reduction is stated per control rather than cumulated.

Phase 2 Enhanced Controls, Q4 2026 to Q1 2027#

Control IDControl NameIEC 62443 RequirementMITRE D3FENDImplementationCost bandBenefit basis
CTL-009BESS Network SegmentationCR 3.1 (Network Segmentation)D3-NI (Network Isolation)VLAN isolation for each BESS, firewall rulesC, as section 7.4 (54 sites)Defensible architecture, 17.09 percent class average [n]
CTL-010ICCP EncryptionCR 4.3 (Use of Cryptography)D3-EC (Encrypted Communication)TLS 1.3 for ICCP between DERMS and ADMSB (bespoke engineering across two platforms)Mechanism: removes the passive-observer and on-path-injection paths. It does nothing against a compromised endpoint at either end
CTL-011Modbus ReplacementCR 4.3 (Use of Cryptography)D3-EC (Encrypted Communication)Migrate to DNP3 Secure Authentication v5D (fleet-wide protocol migration across 54 sites; exceeds the envelope on its own)Mechanism: authenticated writes cannot be forged, which closes the register-write path of section 2.4.1 at its root rather than filtering it
CTL-012Container Security HardeningCR 2.4 (Mobile Code Integrity)D3-SJA (System Call Analysis)Pod Security Standards (restricted), Falco runtime monitoringB, as section 9.3 Phase 1Defensible architecture, 17.09 percent class average [n]
CTL-013Firmware VerificationCR 3.4 (Software Integrity)D3-FBA (File-Based Behavior Analysis)Cryptographic signature validation for BESS firmware updatesB, as the BMS firmware control in section 9.2Mechanism: an unsigned or altered firmware image does not install. It does nothing against a signed malicious image from a compromised vendor
CTL-014UEBA for DERMS APICR 2.9 (Session Integrity)D3-UBA (User Behavior Analysis)Machine learning baseline for normal retailer API usage patternsD, as the UEBA and NDR line in section 9.3 Phase 2Network visibility and monitoring, 16.47 percent class average [n]

Phase 2 band arithmetic: the four bounded lines, three band B and one band C, give AUD 0.9 million to AUD 2.9 million one-off (modeled: band boundary arithmetic, not a quotation). CTL-011 and CTL-014 sit in band D, have no upper bound, and are excluded, so the real figure is higher by an unknown amount. Risk reduction is stated per control rather than cumulated.

Phase 3 Advanced Controls, Q2 to Q4 2027#

Control IDControl NameIEC 62443 RequirementMITRE D3FENDImplementationCost bandBenefit basis
CTL-015AI-Based Cascade PredictionCR 2.6 (Resource Management)D3-APLM (Application Behavior Monitoring)ML model predicting cascading failure from SCADA telemetryD (bespoke model development with no public anchor and no bounded scope)No benchmark class maps, and no predictive accuracy has been measured for this network. The control is speculative and is ranked last for that reason
CTL-016Supply Chain SBOMCR 1.13 (Supply Chain Security)D3-SICA (Software Component Analysis)Continuous SBOM tracking for mPrest, SwitchDin, all vendorsC, as the supply chain risk management programme in section 9.3 Phase 2Mechanism: a component inventory is what makes a vendor advisory actionable at all. It detects nothing on its own
CTL-017OT Deception GridCR 2.5 (Backup)D3-D (Decoy)Honeypot BESS controllers, fake DERMS API endpointsB (engineering judgment; no public anchor)Mechanism: a decoy controller has no legitimate traffic, so any interaction with it is an alert with no false-positive population by construction
CTL-018Quantum-Resistant CryptographyCR 4.3 (Use of Cryptography)D3-EC (Encrypted Communication)Post-quantum algorithms for long-term key protectionD (fleet-wide cryptographic replacement; no public anchor)Mechanism addresses a future capability, not a current one. No benefit is claimed against any threat modeled in this paper

Phase 3 band arithmetic: the two bounded lines, one band B and one band C, give AUD 0.7 million to AUD 1.8 million one-off (modeled: band boundary arithmetic, not a quotation). CTL-015 and CTL-018 sit in band D and are excluded. Risk reduction is stated per control rather than cumulated.

Control Effectiveness Validation#

Testing Requirements:

  • CTL-001 to CTL-008: Red team penetration testing (Q3 2026)
  • CTL-009 to CTL-014: Purple team adversary emulation (Q2 2027)
  • CTL-015 to CTL-018: Operational validation over 12-month period (2027-2028)

Metrics:

  • Mean Time to Detect (MTTD): Target <5 minutes for Death Wobble attack
  • Mean Time to Respond (MTTR): Target <15 minutes for DERMS isolation
  • False Positive Rate: Target less than 1 percent for oscillation detection
  • Coverage: 100 percent of MITRE ATT&CK for ICS techniques by Phase 3 completion

Appendix H: Vulnerability Catalog#

CVE Analysis with EE Impact Assessment#

CVE IDComponentCVSSExploitabilityEE ImpactMitigation Status
CVE-2024-1234*mPrest DERMS API9.8Unauthenticated remote code executionCATASTROPHIC: Full DER controlVendor patch pending
CVE-2023-5678*SwitchDin Utility Server8.1Authentication bypassHIGH: BESS protocol manipulationWorkaround applied
CVE-2024-9012*Modbus TCP Stack7.5Cleartext credential interceptionHIGH: BESS BMS accessProtocol replacement required
CVE-2023-4567*OpenShift Container Runtime8.8Container escape to hostHIGH: Lateral movement to SCADAPatch applied Q4 2025
CVE-2024-3456*ICCP Protocol Implementation6.5Man-in-the-middle attackMEDIUM: Constraint data spoofingEncryption planned Phase 2
CVE-2023-7890*Rolls-Royce BMS Firmware7.2Hardcoded credentialsMEDIUM: Individual BESS compromiseFirmware update scheduled
CVE-2024-2345*Greensync Dex API5.3Information disclosureLOW: Telemetry data leakageMonitoring enhanced

Note: CVE identifiers are illustrative placeholders pending actual vulnerability disclosures. This table structure enables rapid updating as new vulnerabilities emerge.

EE-Specific Vulnerability Findings (Non-CVE)#

IDComponentDescriptionAttack VectorImpact RatingRemediation Timeline
EE-VULN-001Retailer APINo rate limiting on batch commandsSupply chain compromiseCATASTROPHICPhase 1 (Q2 2026)
EE-VULN-002DERMS MonitoringNo oscillation detection for DER commandsDirect API accessHIGHPhase 1 (Q2 2026)
EE-VULN-003BESS NetworkFlat Layer 2 network between batteriesPhysical access to one BESSHIGHPhase 2 (Q3 2026)
EE-VULN-004ICCP AdapterNo application-layer signing of constraint dataMITM on ICCP linkHIGHPhase 2 (Q4 2026)
EE-VULN-005Firmware UpdatesNo cryptographic verification of BESS firmwareSupply chain injectionMEDIUMPhase 2 (Q3 2026)
EE-VULN-006TelemetrySOC data exposed via unauthenticated SNMPNetwork reconnaissanceLOWPhase 3 (Q1 2027)

Appendix I: MITRE ATT&CK for ICS Mapping#

Primary Attack Techniques Applicable to Death Wobble Scenario#

TacticTechnique IDTechnique NameEE Attack PathDetection CapabilityMitigation Priority
Initial AccessT0817Drive-by CompromisePhishing targeting retailer employees with DERMS accessLOW (no email security)CRITICAL
T0886Remote ServicesVPN compromise for direct DERMS API accessMEDIUM (VPN logging)HIGH
ExecutionT0871Execution through APIRetailer API batch command injectionNONECRITICAL
T0834Native APIDERMS RESTful API exploitationLOW (basic API logging)CRITICAL
PersistenceT0889Modify ProgramMalicious DERMS configuration persistenceNONEHIGH
T0859Valid AccountsCompromised retailer credentials maintainedLOW (no UEBA)HIGH
Privilege EscalationT0890Exploitation for Privilege EscalationContainer escape to OpenShift nodeMEDIUM (runtime monitoring)HIGH
Defense EvasionT0872Indicator Removal on HostLog deletion post-attackLOW (no centralized logging)MEDIUM
T0858Change Operating ModeBESS mode switching to evade anomaly detectionNONEHIGH
Lateral MovementT0866Exploitation of Remote ServicesICCP protocol exploitation to reach ADMSLOWHIGH
T0859Valid AccountsPivot using shared service accountsLOWMEDIUM
CollectionT0802Automated CollectionSCADA telemetry harvesting for reconnaissanceLOWLOW
T0868Detect Operating ModeBESS SOC and grid frequency monitoringNONEMEDIUM
Command and ControlT0885Commonly Used PortHTTPS (443) for C2 blending with legitimate trafficLOWMEDIUM
T0869Standard Application Layer ProtocolICCP/DNP3 for covert C2 channelNONEMEDIUM
Inhibit Response FunctionT0800Activate Firmware Update ModeDisable BESS protection logic via BMS manipulationNONEHIGH
T0816Device Restart/ShutdownEmergency shutdown of batteries to amplify impactLOWHIGH
T0804Block Reporting MessageSuppress SCADA alarms during attackLOWMEDIUM
Impair Process ControlT0806Brute Force I/ORapid charge/discharge cycling (Death Wobble attack)NONECRITICAL
T0836Modify ParameterSOC limits, power setpoints alteredLOWCRITICAL
T0855Unauthorized Command MessageFraudulent DERMS dispatch commandsLOWCRITICAL
ImpactT0879Damage to PropertyBESS thermal runaway from thermal management overrideLOWCRITICAL
T0826Loss of AvailabilityGrid blackout from cascading frequency collapseMEDIUMCRITICAL
T0828Loss of Productivity and RevenueCustomer outages, equipment damageMEDIUMHIGH
T0837Loss of ProtectionProtection relay disabling during attackNONEHIGH
T0880Loss of SafetyInjuries/fatalities from blackout consequencesLOWCRITICAL

Attack Sequence Mapping: Death Wobble Scenario#

[Initial Access: T0817 Phishing]
  → [Execution: T0871 Retailer API]
    → [Impair Process: T0806 Rapid Charge/Discharge]
      → [Inhibit Response: T0804 Block SCADA Alarms]
        → [Impact: T0826 Grid Blackout, T0880 Safety Loss]

Detection Gap Analysis#

Coverage Score by Tactic:

  • Initial Access: 20 percent (email security gaps)
  • Execution: 15 percent (API monitoring insufficient)
  • Persistence: 10 percent (no configuration integrity monitoring)
  • Privilege Escalation: 40 percent (container runtime monitoring partial)
  • Defense Evasion: 5 percent (minimal forensic capability)
  • Lateral Movement: 25 percent (network segmentation monitoring)
  • Collection: 30 percent (basic SCADA telemetry logging)
  • Command & Control: 20 percent (no protocol behavior analysis)
  • Inhibit Response: 5 percent (BESS-level monitoring absent)
  • Impair Process Control: 0 percent (no physics-based anomaly detection)
  • Impact: 50 percent (grid frequency monitoring, customer outage detection)

Overall Detection Capability: 18.6 percent (INSUFFICIENT)


Document Control:

  • Version: 1.0
  • - Date: February 12, 2026
  • Classification: CONFIDENTIAL - CRITICAL INFRASTRUCTURE SECURITY
  • Review Cycle: Quarterly
  • Next Review: May 12, 2026
  • Distribution: Board of Directors, CISO, Chief Risk Officer, Grid Operations, Emergency Response (Executive Summary: broader distribution)
  • Retention: 5 years from publication date
  • Classification Rationale: Contains detailed vulnerability information, attack methodologies, and cascading failure models for critical national infrastructure

Related Documents:

  • EE-CTI-004: BESS Architecture Vulnerability Assessment, Bawley Point Community Battery
  • EE-CTI-005: DERMS Security Architecture Review, mPrest Platform
  • EE-CTI-003: Comprehensive Threat Assessment 2026
  • RefDNSP-1.2M DERMS High Level Architecture (HLD)
  • AEMO Power System Frequency Risk Review 2024

Appendix J: References and Bibliography#

Primary Sources - McKenney Research#

McKenney, J. (2024). The Grid's Precarious Pulse: Death Wobble and Frequency Instability from Coordinated DER Attacks. Eigenia Labs, Working Group WG-04-CF. Published at /papers/death-wobble-frequency-instability

McKenney, J. (2025). Cascading Failure Analysis: South Australia 2016, UK 2019, and Iberian Peninsula 2025 Blackouts. Eigenia Labs, Working Group WG-04-CF. (This document.)

McKenney, J. (2024). ERCOT and WECC Renewable Integration Challenges: Inverter-Based Resource Reliability Under Stress Conditions. Eigenia Labs, Working Group WG-04-CF. Written and published within WG-04-CF. Sections 1.2, 2.2 and 10 of this document take the ERCOT, NERC and LBNL figures they state from it. It is cited for its reading of the primary reports rather than as the source of record for what ERCOT, NERC or LBNL published; each of those carries its own entry below.

Primary Sources - Inverter-Based Resource Disturbance Reports#

North American Electric Reliability Corporation and Texas Reliability Entity. (2021). Odessa Disturbance, Texas Events: May 9, 2021 and June 26, 2021. Atlanta: NERC. https://www.nerc.com/globalassets/our-work/reports/event-reports/odessa_disturbance_report.pdf

North American Electric Reliability Corporation and Texas Reliability Entity. (2022). 2022 Odessa Disturbance, Texas Event: June 4, 2022. Atlanta: NERC. https://www.nerc.com/comm/RSTC_Reliability_Guidelines/NERC_2022_Odessa_Disturbance_Report%20(1).pdf

Lawrence Berkeley National Laboratory. (2024). Queued Up: 2024 Edition. Characteristics of Power Plants Seeking Transmission Interconnection. Berkeley: LBNL. https://emp.lbl.gov/sites/default/files/2024-04/Queued%20Up%202024%20Edition_1.pdf

Electric Reliability Council of Texas. (2024). ERCOT Monthly, Issued April 2024 (March 2024 Look Back). Austin: ERCOT. https://www.ercot.com/files/docs/2024/04/30/ERCOT-Monthly-April-2024.pdf

Regulatory and Standards Documents#

Australian Energy Market Operator (AEMO). (2024). Power System Frequency Risk Review: Transition to Renewable Energy Dominance. Melbourne: AEMO Publications.

Australian Energy Sector Cyber Security Framework (AESCSF). (2023). Security Profile 2 (SP2) Requirements for Distribution Networks. Canberra: Department of Home Affairs.

IEC 62443-3-3:2013. Industrial communication networks, Network and system security, Part 3-3: System security requirements and security levels. Geneva: International Electrotechnical Commission.

NERC CIP-014-3. Physical Security: Transmission Stations and Transmission Substations. Atlanta: North American Electric Reliability Corporation.

Security of Critical Infrastructure Act 2018 (SOCI Act). Risk Management Program Requirements for Electricity Sector Assets. Canberra: Australian Government.

Threat Intelligence and Incident Reports#

Australian Cyber Security Centre (ACSC). (2025). VOLTZITE Campaign: Pre-Positioning in Australian Critical Infrastructure. Canberra: Australian Signals Directorate.

CISA. (2024). Volt Typhoon: Living-off-the-Land Techniques in Energy Sector Intrusions. Alert AA24-038A. Washington, DC: Cybersecurity and Infrastructure Security Agency.

Dragos, Inc. (2025). FrostyGoop: Modbus TCP Weaponization in European Heating Infrastructure. Hanover, MD: Dragos Industrial Cybersecurity.

ESET Research. (2022). INDUSTROYER2: Sandworm Attacks Ukrainian Energy Infrastructure During 2022 Invasion. Bratislava: ESET.

CERT-UA. (2022). Technical Analysis: INDUSTROYER2 Malware Targeting ICS Protocols. Alert UAC-0082. Kyiv: Computer Emergency Response Team of Ukraine.

Grid Frequency and Renewable Integration Research#

Kundur, P., Balu, N. J., & Lauby, M. G. (1994). Power System Stability and Control. New York: McGraw-Hill. (Classic reference for frequency dynamics)

Miller, N. W., Shao, M., Pajic, S., & D'Aquila, R. (2014). "Western Wind and Solar Integration Study Phase 3: Frequency Response and Transient Stability." NREL Technical Report NREL/SR-5D00-62906. Golden, CO: National Renewable Energy Laboratory.

Ulbig, A., Borsche, T. S., & Andersson, G. (2014). "Impact of Low Rotational Inertia on Power System Stability and Operation." IFAC Proceedings Volumes, 47(3), 7290-7297. DOI: 10.3182/20140824-6-ZA-1003.02615

Australian Energy Market Operator (AEMO). (2019). Transfer Limit Advice: System Strength in South Australia. Melbourne: AEMO. (Analysis of 2016 blackout)

National Grid ESO. (2019). Technical Report on the events of 9 August 2019. Warwick, UK: National Grid. (UK blackout investigation)

Battery Energy Storage System (BESS) Safety#

Doughty, D., & Roth, E. P. (2012). "A General Discussion of Li Ion Battery Safety." The Electrochemical Society Interface, 21(2), 37-44.

Ouyang, D., Chen, M., Huang, Q., Weng, J., Wang, Z., & Wang, J. (2019). "A Review on the Thermal Hazards of the Lithium-Ion Battery and the Corresponding Countermeasures." Applied Sciences, 9(12), 2483. DOI: 10.3390/app9122483

NFPA 855. (2020). Standard for the Installation of Stationary Energy Storage Systems. Quincy, MA: National Fire Protection Association.

ICS Cybersecurity Research#

Langner, R. (2011). "Stuxnet: Dissecting a Cyberwarfare Weapon." IEEE Security & Privacy, 9(3), 49-51. DOI: 10.1109/MSP.2011.67

Lee, R. M., Assante, M. J., & Conway, T. (2016). Analysis of the Cyber Attack on the Ukrainian Power Grid. Washington, DC: SANS Industrial Control Systems.

Hemsley, K. E., & Fisher, R. E. (2018). History of Industrial Control System Cyber Incidents. INL/CON-18-44411. Idaho Falls, ID: Idaho National Laboratory.

MITRE Corporation. (2023). ATT&CK for Industrial Control Systems (ICS) Framework. Bedford, MA: MITRE. Retrieved from https://attack.mitre.org/matrices/ics/

Economic Impact and Risk Analysis#

Amin, M. (2011). "Energy Infrastructure Defense Systems." Proceedings of the IEEE, 99(1), 58-82. DOI: 10.1109/JPROC.2010.2081670

Executive Office of the President. (2013). Economic Benefits of Increasing Electric Grid Resilience to Weather Outages. Washington, DC: President's Council of Economic Advisers and U.S. Department of Energy.

Petit, F. D., Bassett, G. W., Buehring, W. A., Collins, M. J., Dickinson, D. C., Fisher, R. E., ... & Peerenboom, J. P. (2015). Resilience Measurement Index: An Indicator of Critical Infrastructure Resilience. ANL/DIS-15-15. Argonne, IL: Argonne National Laboratory.

Interdependent Infrastructure Analysis#

Rinaldi, S. M., Peerenboom, J. P., & Kelly, T. K. (2001). "Identifying, Understanding, and Analyzing Critical Infrastructure Interdependencies." IEEE Control Systems Magazine, 21(6), 11-25. DOI: 10.1109/37.969131

Ouyang, M. (2014). "Review on modeling and simulation of interdependent critical infrastructure systems." Reliability Engineering & System Safety, 121, 43-60. DOI: 10.1016/j.ress.2013.06.040

Zimmerman, R., & Restrepo, C. E. (2006). "The Next Step: Quantifying Infrastructure Interdependencies to Improve Security." International Journal of Critical Infrastructures, 2(2-3), 215-230.

RefDNSP-1.2M Internal Documents#

RefDNSP-1.2M (2025). DERMS High Level Architecture (HLD): mPrest Platform Deployment. RefDNSP-1.2M

RefDNSP-1.2M (2025). BESS Deployment Standard Operating Procedures. RefDNSP-1.2M

RefDNSP-1.2M (2024). Cybersecurity Incident Response Plan: Version 2.3. RefDNSP-1.2M

RefDNSP-1.2M (2025). EE-CTI-004: BESS Architecture Vulnerability Assessment, Bawley Point Community Battery. RefDNSP-1.2M Cybersecurity Intelligence.

RefDNSP-1.2M (2025). EE-CTI-007: DERMS Security Architecture Review, Cloud Integration Risks and Mitigations. RefDNSP-1.2M Cybersecurity Intelligence.

Appendix K: Glossary#

TermDefinitionEE Context
ADMSAdvanced Distribution Management System. Grid control and optimization platform.GE Vernova platform managing EE distribution network
AEMOAustralian Energy Market Operator. National grid coordinator.National grid operator, maintains frequency standards
AESCSFAustralian Energy Sector Cyber Security Framework. Industry security standard.Regulatory compliance framework for energy sector
BESSBattery Energy Storage System. Lithium-ion battery for grid stabilization.54 community batteries (270 MW aggregate) in EE network
BMSBattery Management System. Controls charging and monitors cell health.Controls individual BESS cells, thermal management, SOC
Cascading FailureMulti-stage system collapse where initial failure triggers subsequent failuresGrid-wide blackout from localized DER attack
DERDistributed Energy ResourceSolar PV, batteries, EVs, smart hot water (278,622 controllable devices)
DERMSDistributed Energy Resource Management System. Orchestrates solar, batteries, and loads.mPrest platform orchestrating DER dispatch
DNP3Distributed Network Protocol 3SCADA protocol for substation communications
DNSPDistribution Network Service Provider. Regional electricity distributor.
Death WobbleGrid frequency oscillation attack inducing resonance cascade0.5-2 Hz charge/discharge cycling causing RoCoF exceedance
Demand ResponseCoordinated load reduction or increase to support grid stabilityHot water heater control, BESS dispatch
FCASFrequency Control Ancillary ServicesGrid services providing frequency stability (EE provides via BESS)
FeederDistribution line delivering electricity from substation to customers32,000+ substations in EE network
FFRFast Frequency ResponseSub-second frequency support from batteries/inverters
Grid InertiaRotational energy in synchronous generators providing frequency stabilityDeclining from 4-6 sec to 2-3 sec with renewable penetration
ICCPInter-Control Center Communications Protocol (IEC 60870-6/TASE.2). Grid data exchange.Protocol linking DERMS to ADMS for constraint data
IEC 62443International industrial cybersecurity standard. Defines security zones, levels, and controls.
InverterPower electronics converting DC (solar/battery) to AC (grid)All DER assets are inverter-based resources
LotLLiving off the LandAttack technique using legitimate system tools to evade detection
Modbus TCPLegacy industrial control protocol for SCADA/PLC communications. Widely deployed, no built-in security.Used in BESS controllers (cleartext, no authentication)
NERC CIPNorth American Electric Reliability Corporation Critical Infrastructure ProtectionInternational reference for grid security standards
OCPPOpen Charge Point ProtocolEV charger communications protocol
Power QualityStability of voltage, frequency, waveformDegraded by rapid DER power swings
Protection RelayAutomatic switch opening circuit during fault conditionsTriggers cascading outages during RoCoF events
Purdue ModelICS security architecture defining zones (L0-L4)EE uses IEC 62443 equivalent
RoCoF (Rate of Change of Frequency)Rate of Change of Frequency. Grid stability metric measured in Hz/s. Speed of frequency deviation.>1.0 Hz/s triggers protection relay cascades
SCADASupervisory Control and Data AcquisitionOT system monitoring/controlling substations
SOCState of ChargeBattery energy level (0-100%)
SOCI ActSecurity of Critical Infrastructure Act 2018. Australian critical infrastructure regulation.
Synchronous GeneratorTraditional rotating generator providing inertiaCoal/gas plants retiring, reducing system inertia
Thermal RunawayUncontrolled exothermic reaction in lithium-ion battery cells causing fire or explosion.Risk from BMS manipulation attack
UFLSUnder-Frequency Load SheddingAutomated load disconnection to prevent blackout (occurs at 48.8 Hz)
VPPVirtual Power Plant. Aggregated distributed energy resources for grid services.Aggregation of DER assets acting as single power resource

13. References#

Primary Sources#

McKenney, J. (2026). BESS Architecture Vulnerability Assessment: Bawley Point Community Battery Energy Storage System. RefDNSP-1.2M Internal Report EE-CTI-004.

McKenney, J. (2026). DERMS Security Architecture Review: mPrest Platform. RefDNSP-1.2M Internal Report EE-CTI-005.

Grid Stability and Death Wobble Analysis#

McKenney, J. (2024, April). Death wobble: The grid's precarious pulse - Frequency instability and cascading failure risk. Eigenia Group OTCE Intelligence Analysis.

McKenney, J. (2024, April). Grid vulnerability analysis: The grid's unseen tremors - Frequency stability, cascading risk, and the imperative for action. Eigenia Group Technical Report.

McKenney, J. (2025, May). The unseen current: Emerging threats to grid stability in renewable-dominated systems. Eigenia Group Intelligence Brief.

Standards and Frameworks#

Australian Energy Market Operator. (2024). Power System Frequency Risk Review. AEMO.

Basakarad, B., et al. (2020). ROCOF importance in electric power systems with high renewables share: A simulation case for Croatia. Faculty of Electrical Engineering and Computing, University of Zagreb. [Source for the swing-equation RoCoF relation and symbol definitions used in Section 2.2 and Appendix A]

Australian Energy Sector Cyber Security Framework. (2024). Framework Implementation Guidance, Security Profile 2. Commonwealth of Australia.

International Electrotechnical Commission. (2019). IEC 62443-3-3: Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels. IEC.

North American Electric Reliability Corporation. (2023). CIP-002 through CIP-014: Critical Infrastructure Protection Standards. NERC.

Threat Intelligence#

MITRE Corporation. (2025). ATT&CK for Industrial Control Systems. Retrieved from https://attack.mitre.org/matrices/ics/

Australian Signals Directorate. (2025). Annual Cyber Threat Report. Commonwealth of Australia.

Dragos, Inc. (2025). OT Cybersecurity Year in Review. Dragos Intelligence.

Industry Precedents and International Case Studies#

Australian Energy Market Operator (AEMO). (2017). Black system South Australia 28 September 2016 - Final report. AEMO. [Cited for the 456 MW sustained generation reduction over a period of less than seven seconds, the voltage-dip-count protection setting that produced it on eight of nine wind farms, the 1,826 MW regional demand, the 850,000 customers affected, and the Heywood Interconnector special protection scheme trip]

UK National Grid Electricity System Operator (ESO). (2019). Technical report on the events of 9 August 2019. National Grid ESO. [Cited in McKenney (2024, 2025) for the 0.125 Hz/s RoCoF relay disconnection threshold and the approximately 350 MW distributed generation cascade]

European Network of Transmission System Operators for Electricity (ENTSO-E). (2021-2024). System split analyses and frequency stability reports. ENTSO-E. [Cited in McKenney (2024) for >1 Hz/s unmanageable RoCoF threshold]

North American Electric Reliability Corporation (NERC). (2024). Large load task force reports and Eastern Interconnection 1,500 MW data center event. NERC. [Cited in McKenney (2024, 2025)]

Arizona Public Service. (2019). McMicken Battery Energy Storage System Event Report. APS.

National Transportation Safety Board. (2020). Battery Energy Storage System Fire Investigation. NTSB.


End of Document


Eigenia Labs Open Scientific Publishing Standard
Licensed CC BY 4.0
Exact Verification Audit: 285,220 chars