The UK Needs To Move Faster On Nuclear Energy Cybersecurity

The new Labour government’s ‘Great British Energy’ bill sets out an ambitious agenda for the UK’s transition to net zero. The bill establishes a new publicly owned energy company to own and advance clean energy projects, including new nuclear power plants.

The government has said that it wants to invest in the long-term security of the nuclear power sector, focusing on its role as an engine for good jobs and for helping the UK achieve energy security and advancing towards its net-zero goals.

It has also declared its intention to make the UK a world leader in the construction and operation of small modular reactors - a new generation of smaller nuclear reactors that can be operated remotely even at locations unsuitable for a large nuclear power plant. SMRs are also expected to be much more affordable than traditional nuclear plants once they are produced at scale.

The energy transition provides an opportunity to reinvest in the UK’s nuclear energy sector that has languished over the last decade. Since the UK sold most of the states’ nuclear power plants to French energy company EDF in 2008, governments have done little to invest in the wider sector.

In 2022, the government attempted to revitalize nuclear energy as an important part of the UK’s attempt to reach energy independence, but despite aiming to approve a new reactor every year until 2030, progress has been slow. The Sizewell C site in Suffolk that was immediately announced in 2022 as going ahead still struggles to attract required funding.

Gaps Identified In Nuclear Cybersecurity

While the renewed and more energetic focus on nuclear energy is good news for UK industry, the cybersecurity of the UK’s nuclear energy industry has been called into question. This has been highlighted by the repeated gaps found during inspections by the Office of the Nuclear Regulator (ONR) at the Sellafield nuclear storage site.

While Sellafield is not a nuclear power plant but an end storage site for nuclear waste, it forms an important part of the UK’s nuclear ecosystem. The risks of cybersecurity gaps in the civil nuclear infrastructure include the potential theft of sensitive information, or in a worst case, a reduction in the reliability of energy production, damage to infrastructure, or the release of radiation.

While these are worst-case assumptions, there is precedent for cyberattacks causing physical damage, as in the Stuxnet attack in 2010 on Iran’s nuclear facilities. The fact that the ONR repeatedly found gaps in Sellafield’s cybersecurity from 2019 to 2023 that could not be fully resolved during that time highlights that the cybersecurity of the UK’s nuclear infrastructure remains a concern. 

The UK is not the only state struggling with the cybersecurity of critical national infrastructure. This is now a global issue with several critical sectors, including health services and energy providers, being identified as priority targets. Renewed investment in the sector provides the new government with an opportunity to take decisive steps to address the known gaps and to further build cybersecurity capacity.

Accelerating Implementation

In 2022, the previous UK government published the ‘Civil Nuclear Cybersecurity Strategy’. This document sets out a good set of goals for better securing the UK’s civil nuclear infrastructure. However, its completed implementation date was set for 2026–27 – leaving gaps in the cybersecurity of the UK’s civil nuclear infrastructure over that time.

Many of the document’s recommendations have been part of cybersecurity best practice for a long time. There thus may well be scope to review this strategy now to see which actions could be implemented sooner, particularly since secretary of state for energy security and net zero Ed Miliband has placed a renewed focus on nuclear energy.

Nuclear energy infrastructure is increasingly facing cyber threats, with national infrastructures and the International Atomic Energy Agency targeted alike. These threats stem from hostile state actors and from opportunistic cybercriminals. This risk is also increasing because the UK is rushing to build out new electricity grid infrastructure in order to meet its legally binding decarbonization goals, putting additional pressure on swift implementation.

International legal protections for civil nuclear infrastructure, as a critical infrastructure, exist. An established body of best practices and guidelines to protect against cyber threats is in place. What is missing is better implementation. Our recent Chatham House publication offers recommendations at various levels for how this could be strengthened.

Three Priorities For The UK

Three recommendations should be immediate priorities for the UK.
 
One is to speed up the implementation of the cybersecurity strategy. One area where this is possible is to improve incident response exercises. The 2022 strategy sets the delivery date of improved incident response exercises for 2026–27. Such exercises are an important part of cybersecurity best practice. As such, there is already much expertise from other sectors and international partners that the UK government can draw on. This includes the International Atomic Energy Agency (IAEA), which has updated guidance on available cybersecurity response exercises.

The second priority is ensuring the cybersecurity of small modular reactors (SMRs). As SMR technology is still under development, it provides an important opportunity to consider cybersecurity from the design stage. The UK has an opportunity to become a standard-setter for cybersecurity by design. This would be a win for cybersecurity and for UK engineering capabilities and industry. SMRs are attracting greater interest as a potentially cheaper and more versatile way of gaining access to nuclear power, once developed at scale. As such, a well-designed and reputable fleet of SMRs could also turn into an export opportunity in the longer term. This would be a benefit for the UK economy, and good for the UK’s geopolitical standing as China and Russia use the export of nuclear reactor technology to leverage their geopolitical positions.

The third priority is connecting work on the cybersecurity of nuclear infrastructure better with other UK government cybersecurity efforts. The background note accompanying the King’s speech outlining the new government’s legislative agenda mentioned plans to introduce a cyber security and resilience bill, to better protect the UK’s essential public services from cyberattacks. The bill will strengthen cybersecurity rules and reporting mechanisms for private sector companies that provide important public services in the UK. This provides a prime opportunity to better integrate cybersecurity efforts across different UK sectors.

The Labour government’s commitment to nuclear energy provides important opportunities to the UK. Not least among them is the opportunity to rapidly improve the cybersecurity of an important part of the state’s critical national infrastructure.

Dr Marion Messmer is Senior Research Fellow, International Security Programme at Chatham House

Image: Ideogram

You Might Also Read: 

The UK Nuclear Industry Needs To Take Cybersecurity More Seriously:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Overcoming Obstacles To Zero Trust Adoption
What Sets Next-Generation Firewalls Apart From Traditional Firewalls? »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

4N6

4N6

4N6 is a privately-owned firm founded with the goal of providing expert knowledge of computer forensics.

Remediant

Remediant

Remediant is the leader in Precision Privileged Access Management. We protect organizations from ransomware and data theft via stolen credentials and lateral movement.

TruSTAR Technology

TruSTAR Technology

TruSTAR is a threat intelligence exchange platform built to protect and incentivize information sharing.

Real Random

Real Random

Real Random is on a mission to enhance existing and new crypto-systems with its revolutionary solution to generating numbers that are Truly Random.

Telelogos

Telelogos

Telelogos is a European provider of Enterprise Mobility Management software, Digital Signage software and Data Transfer and Synchronization software.

Trusted CI

Trusted CI

Trusted CI, the NSF Cybersecurity Center of Excellence is comprised of cybersecurity experts who have spent decades working with science and engineering communities.

Exire Technologies

Exire Technologies

Exire Technologies is comprised of a team of professionals who are specialised in cybersecurity and a value added reseller and integrator of ICT security systems.

Vivitec

Vivitec

Vivitec security services are tailored for your business, industry, risk, technology, and size to ensure great protection and planned response for the inevitable cyber-attacks on your business.

AEWIN Technologies

AEWIN Technologies

AEWIN is professional in the fields of Network Appliance, Cyber Security, Server, Edge Computing and an ODM/OEM expert.

ADVA Optical Networking

ADVA Optical Networking

ADVA is a company founded on innovation and focused on helping our customers succeed. Our technology forms the building blocks of a shared digital future and empowers networks across the globe.

NANO Corp

NANO Corp

At NANO Corp, we keep your network visible, understandable, operational and secure with state-of-the-art technology.

Metallic.io

Metallic.io

Metallic (formerly TrapX) is a SaaS portfolio for enterprise-grade backup and recovery, designed to protect your data from corruption, deletion, ransomware, and other threats.

CyberMaxx

CyberMaxx

At CyberMaxx, our approach to cybersecurity provides end-to-end coverage for our customers – we use offense to fuel defense.

CyberMontana

CyberMontana

CyberMontana is a statewide initiative providing cybersecurity awareness, training, and workforce development for businesses and residents of Montana.

SafeLiShare

SafeLiShare

SafeLiShare’s data security platform unifies encryption strategies for organizations with hybrid and multi-cloud infrastructures, ensuring data is secure regardless of its location.

Sandfly Security

Sandfly Security

Sandfly focuses on Linux security that is high performance, high stability, high compatibility, and low risk.