Skip to main content

Nuclear Cyber Security and Its Discontents

The minority (that is, the Republicans) on the Senate Homeland Security and Governmental Affairs committee released a report that shows a number of federal agencies, including the Nuclear Regulatory Commission, exercising lax cyber security. In some instances, the brew is rather weak – antivirus software has not been updated at some agencies, which probably has Symantec worried - but there’s some substantial stuff in it, too.

This sums up the report’s finding on the NRC:

Yet just about every aspect of that process [addressing cyber security weaknesses] appears to be broken at the NRC. Problems were identified but never scheduled to be fixed; fixes were scheduled but not completed; fixes were recorded as complete when they were not.

The first thing to note is that this has nothing whatever to do with cyber security at nuclear energy facilities. In some ways, this report confuses network security with what is a much broader topic. Government agency network security has been low hanging fruit when one seeks an issue to publicize, which doesn’t mean it shouldn’t be addressed.

Bill Gross, NEI senior project manager, engineering, who has done a lot of work on nuclear facility cyber security, wrote a blog post for us early last year outlining some of the steps the industry has taken to address the subject. Well worth a read for anyone interested in this issue. His conclusion:

No cyber security program will be 100% perfect.  These interim measures well position the plants to ensure that the public health and safety are maintained, and that the sites will reliably continue to make their significant contribution to the nation’s electrical supply.

---

We can’t really answer for the NRC and what it might need to do to digitally clean its house. We can say that this is a partisan report. Sen. Tom Coburn (R-Okla.), the committee’s ranking member, keeps the pot at a simmer in presenting the report’s findings on his We site.

“Weaknesses in the federal government’s own cyber security have put at risk the electrical grid, our financial markets, our emergency response systems and our citizens’ personal information,” Dr. Coburn said.  “While politicians like to propose complex new regulations, massive new programs, and billions in new spending to improve cyber security, there are very basic – and critically important – precautions that could protect our infrastructure and our citizens’ private information that we simply aren’t doing.”

So, yes, partisan. I’m not sure the report addresses risks to infrastructure or financial markets – agencies overseeing them, perhaps, but that’s not the same thing. It seems to both want and not want regulation; it just depends on what’s being regulated. It’ll be interesting to see how or even if the NRC responds to this report.

Comments

Popular posts from this blog

Activists' Claims Distort Facts about Advanced Reactor Design

Below is from our rapid response team . Yesterday, regional anti-nuclear organizations asked federal nuclear energy regulators to launch an investigation into what it claims are “newly identified flaws” in Westinghouse’s advanced reactor design, the AP1000. During a teleconference releasing a report on the subject, participants urged the Nuclear Regulatory Commission to suspend license reviews of proposed AP1000 reactors. In its news release, even the groups making these allegations provide conflicting information on its findings. In one instance, the groups cite “dozens of corrosion holes” at reactor vessels and in another says that eight holes have been documented. In all cases, there is another containment mechanism that would provide a barrier to radiation release. Below, we examine why these claims are unwarranted and why the AP1000 design certification process should continue as designated by the NRC. Myth: In the AP1000 reactor design, the gap between the shield bu...

How many nuclear plants does it take to meet the world's energy needs?

Several weeks ago Joshua Pearce at Clarion University in Pennsylvania released a study titled “ Thermodynamic limitations to nuclear energy deployment as a greenhouse gas mitigation technology .” In the study he stated... nuclear energy production would have to increase by 10.5% per year from 2010 to 2050 to both replace fossil-fuel-energy use and meet the future energy demands. This line, of course, made the headlines and has been picked up by several outlets and blogs . When looking into his calculations for this statement, he made one assumption error that overstated the above sentence by nearly a factor of three. Page 121, Section 4.1 of the study states: Richard Smalley pointed out that in 2004, the global economy consumed the equivalent of 220 million barrels of oil per day, which converted into electricity terms is the equivalent of 14.5 TeraWatts (TW), or 14,500,000 MegaWatts (MW) (2005). … With a nuclear plant having about 1000 MW (1 GW) of capacity, we would need 14,500...

What Happens During a Refueling Outage?

You may have noticed over the past few weeks that a number of nuclear plants are shut down for refueling outages or are resuming operations after just returning from one. This type of routine outage usually occurs in the spring or fall when electricity demand is low so that nuclear reactors can replace about one-third of the spent fuel rods with new fuel and conduct other routine maintenance and repairs at the plant. To get a better sense of how refueling works at a nuclear energy facility, I spoke with Marcus Nichol, NEI’s senior project manager for used fuel storage and transportation, and asked him to explain the basics. Why does a nuclear plant need to replace one-third of its fuel? Nichol: The main purpose of a refueling outage is to replace older fuel that is depleted—meaning it can no longer efficiently produce energy from nuclear fission reactions—with new fuel. This “used fuel” has typically been used in the reactor for four-and-a-half to six years before it is pe...