Securing European Power Grids: The Conclusion of the COCOON Project

After three years of research and real-world testing, the European project COCOON concludes its mission to strengthen the protection of power grids against growing digital threats. Funded by the Horizon Europe program, a consortium of 12 organizations developed and validated solutions to detect, identify and mitigate cyberattacks targeting critical electrical infrastructures.

The Andalusian Photovoltaic Pilot

The Spanish pilot, located at a 5 MW photovoltaic plant in Granada, pursued the following objectives:

  • Demonstrate the COCOON technology in a commercially operated facility.
  • Identify vulnerabilities and translate them into prioritized remediation actions.
  • Evaluate system performance under realistic cyberattack scenarios.
  • Validate a Technology Readiness Level 7 for the selected functionalities.

The operational architecture is governed by a Power Plant Controller, a technology provided by Ingelectus. This component manages the active and reactive power at the point of interconnection to ensure compliance with grid code requirements, while the entire system is safeguarded by a perimeter firewall.

The core of the cybersecurity deployment is the COCOON Programmable Node (CPN). Implemented on an edge computing device, this node executes passive traffic monitoring, vulnerability assessments, and anomaly detection. It integrates False Data Injection Identification, an Early Warning System, and an interactive dashboard into a single security shield.

The Validation Journey: From Laboratory to Field

Prior to field integration, the cybersecurity algorithms underwent an extensive validation journey at the University of Seville, advancing from offline simulations (Technology Readiness Level 3) to full plant deployment (Technology Readiness Level 7).

The testing progressed through a co-simulation framework to Controller Hardware in the Loop, utilizing a real-time digital simulator alongside physical replicas of the IT and OT components. The tests advanced a step further with Power System Hardware in the Loop, where the PV plant is no longer digitally simulated but reproduced using a scaled-down replica with physical power components. A key element validated by the University of Seville was the False Data Injection Identification (FDII) functionality, which relies on robust state estimation algorithms to ensure measurement integrity and enable the detection and identification of false data injection cyberattacks.

To ensure robust protection, the operational setup faced various simulated threats:

  • False Data Injection: Manipulation of plant measurements to test detection mechanisms.
  • Firewall Bypass: Testing the Firewall blocking capabilities against suspicious outbound traffic.
  • Man in the Middle: Interception and modification of internal plant communications.
  • Distributed Denial of Service: Traffic overloading targeting critical IT components.

The FDII tool provided the strongest validation evidence, combining extensive laboratory and field tests across different operating scenarios. During these tests, the system achieved a detection accuracy score above 85 percent for generation levels exceeding 50 percent of the nominal capacity. Furthermore, the tool recorded an execution time of under 50 milliseconds, supporting future control-oriented use.

Collaborative Effort and Broader European Context

Throughout the project, Ingelectus participated in configuring the demonstration scenario, supporting the risk assessment, defining attack scenarios, and evaluating the solutions, while coordinating the work package partners. The Andalusian pilot was executed in collaboration with Ingelectus, the University of Seville, Cuerva, the University of Cyprus, and the University of Glasgow, successfully linking academic research with the operational needs of a real installation.

This effort was part of a broader validation strategy featuring three additional pilot projects:

  • Greece (Distribution): A 20 kV feeder of the distribution system operator (HEDNO) integrating five photovoltaic plants into an energy community.
  • Greece (Transmission): The Selene Regional Control Center, utilizing an IT server infrastructure to run common grid models and analyze cross border power exchanges.
  • The Netherlands (Substation): A real time digital model of a substation in Delft, focusing on advanced anomaly detection for protection relays.

 

A Roadmap for Resilient Grids

Coordinated by the University of Cyprus, the consortium combined the capabilities of universities, technology companies, grid operators, and cybersecurity companies.

The deployment at the Hoyas Grandes facility proves that advanced threat detection can be seamlessly integrated into Distributed Renewable Energy Sources. By scaling the technology from offline simulation models to a fully operational environment, the COCOON project provides a validated blueprint for securing modern energy grids. The results confirm that continuous traffic monitoring, combined with the knowledge of computer science and power systems, is key to ensure the resilience of our Distributed Renewable Energy Resources against emerging cyber threats.

COCOON BY THE NUMBERS

  • Duration: 2023–2026
  • EU funding: €5.22 million
  • Partners: 12 European organizations
  • Countries with pilot projects: Greece, the Netherlands, and Spain
  • Pilot projects: 4
  • Pilot led by Ingelectus: 5 MW, 20 kV photovoltaic plant in Andalusia
  • Areas of work: Cyberattack detection, vulnerability analysis, risk assessment, incident response, and power system protection
  • Key technology: COCOON Programmable Node (CPN)
  • Spanish partners: Ingelectus, University of Seville, and Cuerva
  • Coordination: University of Cyprus

 

Share it on social media: