The UK Needs To Move Faster On Nuclear Energy Cybersecurity

The new Labour government’s ‘Great British Energy’ bill sets out an ambitious agenda for the UK’s transition to net zero. The bill establishes a new publicly owned energy company to own and advance clean energy projects, including new nuclear power plants.

The government has said that it wants to invest in the long-term security of the nuclear power sector, focusing on its role as an engine for good jobs and for helping the UK achieve energy security and advancing towards its net-zero goals.

It has also declared its intention to make the UK a world leader in the construction and operation of small modular reactors - a new generation of smaller nuclear reactors that can be operated remotely even at locations unsuitable for a large nuclear power plant. SMRs are also expected to be much more affordable than traditional nuclear plants once they are produced at scale.

The energy transition provides an opportunity to reinvest in the UK’s nuclear energy sector that has languished over the last decade. Since the UK sold most of the states’ nuclear power plants to French energy company EDF in 2008, governments have done little to invest in the wider sector.

In 2022, the government attempted to revitalize nuclear energy as an important part of the UK’s attempt to reach energy independence, but despite aiming to approve a new reactor every year until 2030, progress has been slow. The Sizewell C site in Suffolk that was immediately announced in 2022 as going ahead still struggles to attract required funding.

Gaps Identified In Nuclear Cybersecurity

While the renewed and more energetic focus on nuclear energy is good news for UK industry, the cybersecurity of the UK’s nuclear energy industry has been called into question. This has been highlighted by the repeated gaps found during inspections by the Office of the Nuclear Regulator (ONR) at the Sellafield nuclear storage site.

While Sellafield is not a nuclear power plant but an end storage site for nuclear waste, it forms an important part of the UK’s nuclear ecosystem. The risks of cybersecurity gaps in the civil nuclear infrastructure include the potential theft of sensitive information, or in a worst case, a reduction in the reliability of energy production, damage to infrastructure, or the release of radiation.

While these are worst-case assumptions, there is precedent for cyberattacks causing physical damage, as in the Stuxnet attack in 2010 on Iran’s nuclear facilities. The fact that the ONR repeatedly found gaps in Sellafield’s cybersecurity from 2019 to 2023 that could not be fully resolved during that time highlights that the cybersecurity of the UK’s nuclear infrastructure remains a concern. 

The UK is not the only state struggling with the cybersecurity of critical national infrastructure. This is now a global issue with several critical sectors, including health services and energy providers, being identified as priority targets. Renewed investment in the sector provides the new government with an opportunity to take decisive steps to address the known gaps and to further build cybersecurity capacity.

Accelerating Implementation

In 2022, the previous UK government published the ‘Civil Nuclear Cybersecurity Strategy’. This document sets out a good set of goals for better securing the UK’s civil nuclear infrastructure. However, its completed implementation date was set for 2026–27 – leaving gaps in the cybersecurity of the UK’s civil nuclear infrastructure over that time.

Many of the document’s recommendations have been part of cybersecurity best practice for a long time. There thus may well be scope to review this strategy now to see which actions could be implemented sooner, particularly since secretary of state for energy security and net zero Ed Miliband has placed a renewed focus on nuclear energy.

Nuclear energy infrastructure is increasingly facing cyber threats, with national infrastructures and the International Atomic Energy Agency targeted alike. These threats stem from hostile state actors and from opportunistic cybercriminals. This risk is also increasing because the UK is rushing to build out new electricity grid infrastructure in order to meet its legally binding decarbonization goals, putting additional pressure on swift implementation.

International legal protections for civil nuclear infrastructure, as a critical infrastructure, exist. An established body of best practices and guidelines to protect against cyber threats is in place. What is missing is better implementation. Our recent Chatham House publication offers recommendations at various levels for how this could be strengthened.

Three Priorities For The UK

Three recommendations should be immediate priorities for the UK.
 
One is to speed up the implementation of the cybersecurity strategy. One area where this is possible is to improve incident response exercises. The 2022 strategy sets the delivery date of improved incident response exercises for 2026–27. Such exercises are an important part of cybersecurity best practice. As such, there is already much expertise from other sectors and international partners that the UK government can draw on. This includes the International Atomic Energy Agency (IAEA), which has updated guidance on available cybersecurity response exercises.

The second priority is ensuring the cybersecurity of small modular reactors (SMRs). As SMR technology is still under development, it provides an important opportunity to consider cybersecurity from the design stage. The UK has an opportunity to become a standard-setter for cybersecurity by design. This would be a win for cybersecurity and for UK engineering capabilities and industry. SMRs are attracting greater interest as a potentially cheaper and more versatile way of gaining access to nuclear power, once developed at scale. As such, a well-designed and reputable fleet of SMRs could also turn into an export opportunity in the longer term. This would be a benefit for the UK economy, and good for the UK’s geopolitical standing as China and Russia use the export of nuclear reactor technology to leverage their geopolitical positions.

The third priority is connecting work on the cybersecurity of nuclear infrastructure better with other UK government cybersecurity efforts. The background note accompanying the King’s speech outlining the new government’s legislative agenda mentioned plans to introduce a cyber security and resilience bill, to better protect the UK’s essential public services from cyberattacks. The bill will strengthen cybersecurity rules and reporting mechanisms for private sector companies that provide important public services in the UK. This provides a prime opportunity to better integrate cybersecurity efforts across different UK sectors.

The Labour government’s commitment to nuclear energy provides important opportunities to the UK. Not least among them is the opportunity to rapidly improve the cybersecurity of an important part of the state’s critical national infrastructure.

Dr Marion Messmer is Senior Research Fellow, International Security Programme at Chatham House

Image: Ideogram

You Might Also Read: 

The UK Nuclear Industry Needs To Take Cybersecurity More Seriously:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Overcoming Obstacles To Zero Trust Adoption
What Sets Next-Generation Firewalls Apart From Traditional Firewalls? »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Intelligence-sec

Intelligence-sec

Intelligence-Sec is a fully integrated Conferences and Exhibitions Company managing and producing topical events for the security industry.

IEEE Computer Society

IEEE Computer Society

The IEEE Computer Society is the world's leading membership organization dedicated to computer science and technology.

Intruder

Intruder

Intruder is a cloud-based vulnerability scanner that finds cyber security weaknesses in your digital infrastructure, to avoid costly data breaches.

Allegro Software

Allegro Software

Allegro provide secure software for the Internet of Things.

CERT-PA

CERT-PA

CERT-PA is the national Computer Emergency Response Team for Italian government institutions.

Swedish Civil Contingencies Agency (MSB)

Swedish Civil Contingencies Agency (MSB)

MSB's Information Assurance Department is responsible for supporting and coordinating work relating to Sweden's national societal information security.

Exida

Exida

Exida is a leading product certification and knowledge company specializing in industrial automation system safety, security, and availability.

Bl4ckswan

Bl4ckswan

Bl4ckswan is a Management Consulting firm specialized in the delivery of information security and compliance services.

Recovery Point Systems

Recovery Point Systems

Recovery Point is a leading national provider of IT secure and compliant infrastructure and business resilience services.

Axcient

Axcient

Axcient offers MSPs the most secure backup and disaster recovery technology stack with a proven Business Availability suite.

CUJO AI

CUJO AI

CUJO AI is the global leader in the development and application of artificial intelligence to improve the security, control and privacy of connected devices in homes and businesses.

SOSA

SOSA

SOSA facilitates new growth opportunities by connecting the dots between industry verticals and innovation ecosystems around the world.

FastNetMon

FastNetMon

FastNetMon is a very high performance DDoS detection and mitigation tool which could detect malicious traffic in your network and immediately block it.

SecurityGen

SecurityGen

SecurityGen is a global cybersecurity start-up focused on telecom security, with a focus on 5G networks.

Awareness Software Limited (ASL)

Awareness Software Limited (ASL)

As Hosting Specialists, Awareness Software offer practical and affordable hosting solutions including backup and disaster recovery and a range of cybersecurity services.

Robust Intelligence

Robust Intelligence

Robust Intelligence enables enterprises to secure their AI transformation with an automated solution to protect against security and safety threats.