Creating a Strong Foundation With CIE
CIE is a DOE-led strategy that establishes cybersecurity as a core design principle within engineered systems, particularly across energy and other critical infrastructure sectors. Rather than adding protections after commissioning, CIE incorporates security into components, tools and processes from the outset.
The DOE National CIE strategy is organized around four pillars — awareness, education, current infrastructure and future infrastructure — that collectively guide implementation and promote a culture of secure-by-design engineering.
A related methodology, developed by Idaho National Laboratory (INL), is Consequence-Driven Cyber-Informed Engineering (CCE). CCE begins with the assumption that a capable adversary can breach perimeter defenses. It prioritizes consequence reduction through four deliberate phases: consequence prioritization, system-of-systems analysis, consequence-based targeting, and mitigations and protections.
Together, CIE and CCE cultivate a security-minded engineering culture. While CIE builds resilience into every phase of system design, CCE helps engineers systematically identify and eliminate the most severe failure modes. Used jointly, they create a layered foundation for both proactive defense and rapid recovery.
