Development of Risk Assessment and Minimization Models for Cyber Incidents in Interconnected Automotive and Power Systems

Authors

DOI:

https://doi.org/10.15407/intechsys.2026.03.085

Keywords:

cyber security, automotive transport, energy, risk assessment, Smart Grid, V2G, risk minimization, critical infrastructure, cascading effects, cyber resilience

Abstract

The paper investigates the critical problem of ensuring cyber resilience within the integrated ecosystems of automotive transport and energy infrastructure, which are becoming increasingly interdependent due to the mass adoption of electric vehicles and Smart Grid technologies. The study provides a comprehensive analysis of the threat landscape, focusing on specific attack vectors targeting electric vehicle charging stations (EVCS) and the communication protocols of the Vehicle-to-Grid (V2G) interface. It is demonstrated that vulnerabilities in the ISO/IEC 15118 and OCPP protocols can be exploited to initiate cascading failures that transcend the boundaries of the transport network and impact the stability of the regional power grid. The central contribution of this research is the development of a formalized mathematical model for multi-layer risk assessment, which utilizes a probabilistic approach to quantify the impact of cyber-physical attacks on system availability and data integrity. Unlike existing one-dimensional models, the proposed methodology accounts for the interconnectedness of nodes, where a security breach in a single vehicle or charging point acts as a catalyst for large-scale energy imbalances. The paper details a systematic risk minimization framework that integrates proactive and reactive measures: from the deployment of specialized intrusion detection systems (IDS) optimized for industrial control protocols to the implementation of adaptive load management algorithms that mitigate the effects of malicious demand-side manipulation. Simulation results presented in the study confirm that the proposed model effectively identifies high-risk convergence points with a sensitivity improvement of 15-20% compared to traditional NIST-based frameworks. The research findings provide a theoretical and practical basis for government agencies and critical infrastructure operators to develop robust cybersecurity strategies in the era of total digitalization of transport and energy assets. The developed models contribute to the creation of autonomous defense mechanisms capable of maintaining operational continuity under adversarial conditions.

References

On Approval of the List of Critical Infrastructure Objects: Resolution of the Cabinet of Ministers of Ukraine dated 09.10.2020 № 1109. URL: https://zakon.rada.gov.ua/laws/show/1109-2020-п [Accessed 12 Sep. 2025]

Modern trends in digitization of automotive transport and challenges to information security : training manual ed. S. V. Kovalenko. — Kyiv : Karavela, 2024. — 240 p.

On the Basic Principles of Ensuring Cybersecurity of Ukraine: Law of Ukraine dated 05.10.2017 № 2163-VIII, Revised 01.01.2024. URL: https://zakon.rada.gov.ua/laws/show/2163-19 [Accessed 05 Sep. 2025]

Security Architecture for Electric Vehicle Charging Infrastructure. Idaho National Laboratory. URL: https://inl.gov/ [Accessed 12 Mar. 2026]

DSTU ISO/IEC 27001:2023. Information technology. Security methods. Information security management systems. Requirements.

DSTU ISO/IEC 27005:2022. Information technology. Security methods. Information security risk management.

DORA (Digital Operational Resilience Act) requirements for energy and transport finance sectors. URL: https://www.eiopa.europa.eu/ [Accessed 25 Mar.2026]

Kovalenko Yu.V. Mathematical models of viral attack propagation in wireless sensor networks. Cybernetics and Systems Analysis, 2024, Issue 4, 110–118.

Cyber Resilience Act: Regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements. — Brussels, 2024. URL: https://digital-strategy.ec.europa.eu [Accessed 15 Oct. 2025]

RFC 8446 - The Transport Layer Security (TLS) Protocol Version 1.3 URL: https://datatracker.ietf.org/doc/html/rfc8446 [Accessed 05 Apr. 2026]

DSTU 3008:2015. Information and documentation. Reports in the field of science and technology. Structure and rules of design.

Cyber resilience manual for transport system operators. SSSCIP, Kyiv, 2025, 92 p.[Accessed 18 Apr. 2026]

Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS 2 Directive). URL: https://eur-lex.europa.eu/eli/dir/2022/2555/oj [Accessed 12 Sep. 2025]

Al-Sharif A.A. Cyber-Physical Security of Vehicle-to-Grid Systems. Review. IEEE Access, 2023, Vol. 11, 15432–15450.

Ivanova T.P. Estimation of cascading effects of cyber incidents in Smart Grid networks. Energy and Automation, 2024, Issue 3, 22–30.

Petrov V.V. Risk modeling in complex transport and energy systems. Monograph, KNAHU, Kharkiv, 2024, 215 p.

Smart Grid Cybersecurity Strategy Ytand Requirements. NIST IR 7628. URL: https://csrc.nist.gov/ [Accessed 15 Feb.2026]

Cybersecurity of Electric Vehicle Charging Infrastructure. European Union Agency for Cybersecurity (ENISA). URL: https://www.enisa.europa.eu [Accessed 05 Dec. 2025]

Korchenko O.H. Construction of information protection systems. Cybersecurity. Textbook, Naukova Dumka, Kyiv, 2023, 512 p.

ISO 15118-20:2022. Road vehicles. Vehicle to grid communication interface. Part 20: 2nd generation network and application protocol requirements.

Open Charge Alliance - Connecting the EV charging industry. URL: https://www.openchargealliance.org [Accessed 28 Oct. 2025]

ISO/SAE 21434:2021. Road vehicles. Cybersecurity engineering.

NIST SP 800-82 Rev. 3. Guide to Operational Technology (OT) Security. NIST, 2023, 120 p.

IEC 62443-4-2:2019. Security for industrial automation and control systems. Part 4-2: Technical security requirements for IACS components.

Analysis of hacker groups' activity in the energy sector of Ukraine in 2024-2025. CERT-UA report. URL: https://cert.gov.ua/ [Accessed 10 Jan. 2026] Methodology for cyber risk assessment of energy enterprises. Ed. Kozlov A.M., Lviv Polytechnic, Lviv, 2024, 140 p.

Hnatiuk S.O. Modern methods of counteracting MitM attacks in industrial networks. Information Security, 2024, Vol. 26 (2) 88–96.

Symonenko R.K. Implementation of the Zero Trust concept in OT environments. Information Processing Systems, 2025, Issue 1, 60–68.

Danylenko V.M. et al. Specifics of protecting intelligent transport systems under martial law. Bulletin of KNAHU, 2025, Issue 104, 45–52.

Smyrnov O.V. Authentication mechanisms in V2G networks based on Blockchain technology. Modern information technologies in the field of security and defense, 2025, Vol. 53 (2), 114–121.

Downloads

Published

2026-08-25

How to Cite

Pokhodenko, B. (2026). Development of Risk Assessment and Minimization Models for Cyber Incidents in Interconnected Automotive and Power Systems. Information Technologies and Systems, 9(3), 85–101. https://doi.org/10.15407/intechsys.2026.03.085

Issue

Section

Cybersecurity and Information Protection