Skip to main content

Cyber Security and Defending What’s Important

We read all the time about various data breaches that cause – potentially, anyway – a good deal of pain. Probably the best known example recently was the theft of over 40 million credit card numbers from Target last year, which has led to a lawsuit from the companies that had to replace all those cards and a class action suit from disgruntled customers.

We’ve no brief on Target’s cyber security strategy, except that we expect it to get a full review. But it certainly suggests the value of a good cyber security program:  defending what must be defended to ensure the public good.

Cyber security at nuclear energy plants – and all essential infrastructure - is extremely important because the potential for malicious mischief is very high – not from thieves as much as terrorists and others who want to cripple the electricity grid or cause a radioactive release. Stealing credit cards can be discomforting, but attacking a nuclear facility could have grave impacts.

For these and other reasons, nuclear facilities have been working on cyber security for about as long as digital items have filtered into them – most essential parts of a plant are analog in nature – and developed approaches to handling them even before the Nuclear Regulatory Commission became involved in the issue.

The NRC’s rulemaking on the issue are, for the most part, judicious and on-point, but they are also very broad in nature. The nuclear industry wants primary attention on cyber security threats that involve public safety and plant integrity – obvious enough, but in guarding against such threats, one must identify what is and is not essential.

Consequently, NEI submitted a petition to the NRC last June to reconsider the scope of the cyber security rule. (Comments on the petition are due today.) But if public safety is the issue, shouldn’t everything be coequal?

Nobody should doubt that the health and safety of the public is a paramount motivation for the industry and the Nuclear Regulatory Commission. Unsafe nuclear plants – or any large industrial operation – carry no benefits for operators or customers.

But both the industry and the NRC recognize that rules must be properly “scoped;” that is, they have to take in those elements that the rule is meant to cover and nothing more. If the rule is too broadly scoped, then the facility runs the risk of wasting resources  while creating no true value.

That can seem a little abstract, so let’s get concrete. As written, the cyber security rule covers items such as fax machines, hand-held calibration devices, radios and pagers, and calculators used by emergency preparedness personnel. These don’t have any potential to impact human safety nor could their misuse damage essential systems. They are basic business tools that an Information Technology department knows how to protect. The same is true of the computers that have no connection to the plant’s processes but are used for things like word processing or creating dull slide shows. If the NRC has to hear about a fax machine going down, it wastes time at both the plant and the agency.

Not wasting time and effort on the inessential also facilitates defense-in-depth. This just means protecting the same item in multiple ways. For example, cars keep their passengers alive in a crash through crash-resistant bumpers, crumple zones, seat belts, air bags, anti-lock breaking systems and even proximity sensors! Ideally, these work in tandem so that one tool does not interfere with any other tool and render it ineffective.

In a cyber security program, defense-in-depth includes implementing systems to prevent attacks, to detect an attack in progress and  to respond to an attack. These methods are intended to recover a system quickly and minimize any impact from the attack. They are also integrated, as in an automobile, to allow multiple methods to prevent, detect and recover from an attack.

So what NEI is asking is that the rule covers what the rule must cover to ensure public safety and the reliability of the facility, but not everything that has the slightest digital footprint. This is how physical design basis threats are handled in rulemaking. Cyber threats are also considered design basis threats, which means their damage impacts essential plant components. Bringing the cyber security rule into line with the other design basis threat rules creates a cleaner, more effective set of regulations. It ensures that what is protected is fully protected and that time is not wasted on trying to defend a fax machine.

---

We’ve written several posts on cyber security. It’s an important but somewhat under appreciated topic. Look here for more Nuclear Notes coverage.

---

Sometimes, under covered would be preferable to bad coverage, which is what ABC News supplied in a an exceptionally alarmist story in November:

A destructive “Trojan Horse” malware program has penetrated the software that runs much of the nation’s critical infrastructure and is poised to cause an economic catastrophe, according to the Department of Homeland Security.

National Security sources told ABC News there is evidence that the malware was inserted by hackers believed to be sponsored by the Russian government, and is a very serious threat.

The hacked software is used to control complex industrial operations like oil and gas pipelines, power transmission grids, water distribution and filtration systems, wind turbines and even some nuclear plants. Shutting down or damaging any of these vital public utilities could severely impact hundreds of thousands of Americans.

But none of the components at a nuclear power plant interact with external networks and cannot be impacted by malware of this kind. Additionally, the industry was aware of this threat because the Department of Homeland Security briefed it. ABC could have found this out by calling NEI or any nuclear facility (or any energy-related industrial outlet, I expect, though I can’t speak for them), but why wreck a good story with a drive to get at the truth? NEI let ABC know the salient information on Twitter, but no change to the story.

Bill Gross, NEI’s senior project manager, engineering, nuclear generation, contributed substantially to this post.

Comments

Popular posts from this blog

Activists' Claims Distort Facts about Advanced Reactor Design

Below is from our rapid response team . Yesterday, regional anti-nuclear organizations asked federal nuclear energy regulators to launch an investigation into what it claims are “newly identified flaws” in Westinghouse’s advanced reactor design, the AP1000. During a teleconference releasing a report on the subject, participants urged the Nuclear Regulatory Commission to suspend license reviews of proposed AP1000 reactors. In its news release, even the groups making these allegations provide conflicting information on its findings. In one instance, the groups cite “dozens of corrosion holes” at reactor vessels and in another says that eight holes have been documented. In all cases, there is another containment mechanism that would provide a barrier to radiation release. Below, we examine why these claims are unwarranted and why the AP1000 design certification process should continue as designated by the NRC. Myth: In the AP1000 reactor design, the gap between the shield bu...

How many nuclear plants does it take to meet the world's energy needs?

Several weeks ago Joshua Pearce at Clarion University in Pennsylvania released a study titled “ Thermodynamic limitations to nuclear energy deployment as a greenhouse gas mitigation technology .” In the study he stated... nuclear energy production would have to increase by 10.5% per year from 2010 to 2050 to both replace fossil-fuel-energy use and meet the future energy demands. This line, of course, made the headlines and has been picked up by several outlets and blogs . When looking into his calculations for this statement, he made one assumption error that overstated the above sentence by nearly a factor of three. Page 121, Section 4.1 of the study states: Richard Smalley pointed out that in 2004, the global economy consumed the equivalent of 220 million barrels of oil per day, which converted into electricity terms is the equivalent of 14.5 TeraWatts (TW), or 14,500,000 MegaWatts (MW) (2005). … With a nuclear plant having about 1000 MW (1 GW) of capacity, we would need 14,500...

What Happens During a Refueling Outage?

You may have noticed over the past few weeks that a number of nuclear plants are shut down for refueling outages or are resuming operations after just returning from one. This type of routine outage usually occurs in the spring or fall when electricity demand is low so that nuclear reactors can replace about one-third of the spent fuel rods with new fuel and conduct other routine maintenance and repairs at the plant. To get a better sense of how refueling works at a nuclear energy facility, I spoke with Marcus Nichol, NEI’s senior project manager for used fuel storage and transportation, and asked him to explain the basics. Why does a nuclear plant need to replace one-third of its fuel? Nichol: The main purpose of a refueling outage is to replace older fuel that is depleted—meaning it can no longer efficiently produce energy from nuclear fission reactions—with new fuel. This “used fuel” has typically been used in the reactor for four-and-a-half to six years before it is pe...