Skip to main content

Cyber Security and Defending What’s Important

We read all the time about various data breaches that cause – potentially, anyway – a good deal of pain. Probably the best known example recently was the theft of over 40 million credit card numbers from Target last year, which has led to a lawsuit from the companies that had to replace all those cards and a class action suit from disgruntled customers.

We’ve no brief on Target’s cyber security strategy, except that we expect it to get a full review. But it certainly suggests the value of a good cyber security program:  defending what must be defended to ensure the public good.

Cyber security at nuclear energy plants – and all essential infrastructure - is extremely important because the potential for malicious mischief is very high – not from thieves as much as terrorists and others who want to cripple the electricity grid or cause a radioactive release. Stealing credit cards can be discomforting, but attacking a nuclear facility could have grave impacts.

For these and other reasons, nuclear facilities have been working on cyber security for about as long as digital items have filtered into them – most essential parts of a plant are analog in nature – and developed approaches to handling them even before the Nuclear Regulatory Commission became involved in the issue.

The NRC’s rulemaking on the issue are, for the most part, judicious and on-point, but they are also very broad in nature. The nuclear industry wants primary attention on cyber security threats that involve public safety and plant integrity – obvious enough, but in guarding against such threats, one must identify what is and is not essential.

Consequently, NEI submitted a petition to the NRC last June to reconsider the scope of the cyber security rule. (Comments on the petition are due today.) But if public safety is the issue, shouldn’t everything be coequal?

Nobody should doubt that the health and safety of the public is a paramount motivation for the industry and the Nuclear Regulatory Commission. Unsafe nuclear plants – or any large industrial operation – carry no benefits for operators or customers.

But both the industry and the NRC recognize that rules must be properly “scoped;” that is, they have to take in those elements that the rule is meant to cover and nothing more. If the rule is too broadly scoped, then the facility runs the risk of wasting resources  while creating no true value.

That can seem a little abstract, so let’s get concrete. As written, the cyber security rule covers items such as fax machines, hand-held calibration devices, radios and pagers, and calculators used by emergency preparedness personnel. These don’t have any potential to impact human safety nor could their misuse damage essential systems. They are basic business tools that an Information Technology department knows how to protect. The same is true of the computers that have no connection to the plant’s processes but are used for things like word processing or creating dull slide shows. If the NRC has to hear about a fax machine going down, it wastes time at both the plant and the agency.

Not wasting time and effort on the inessential also facilitates defense-in-depth. This just means protecting the same item in multiple ways. For example, cars keep their passengers alive in a crash through crash-resistant bumpers, crumple zones, seat belts, air bags, anti-lock breaking systems and even proximity sensors! Ideally, these work in tandem so that one tool does not interfere with any other tool and render it ineffective.

In a cyber security program, defense-in-depth includes implementing systems to prevent attacks, to detect an attack in progress and  to respond to an attack. These methods are intended to recover a system quickly and minimize any impact from the attack. They are also integrated, as in an automobile, to allow multiple methods to prevent, detect and recover from an attack.

So what NEI is asking is that the rule covers what the rule must cover to ensure public safety and the reliability of the facility, but not everything that has the slightest digital footprint. This is how physical design basis threats are handled in rulemaking. Cyber threats are also considered design basis threats, which means their damage impacts essential plant components. Bringing the cyber security rule into line with the other design basis threat rules creates a cleaner, more effective set of regulations. It ensures that what is protected is fully protected and that time is not wasted on trying to defend a fax machine.

---

We’ve written several posts on cyber security. It’s an important but somewhat under appreciated topic. Look here for more Nuclear Notes coverage.

---

Sometimes, under covered would be preferable to bad coverage, which is what ABC News supplied in a an exceptionally alarmist story in November:

A destructive “Trojan Horse” malware program has penetrated the software that runs much of the nation’s critical infrastructure and is poised to cause an economic catastrophe, according to the Department of Homeland Security.

National Security sources told ABC News there is evidence that the malware was inserted by hackers believed to be sponsored by the Russian government, and is a very serious threat.

The hacked software is used to control complex industrial operations like oil and gas pipelines, power transmission grids, water distribution and filtration systems, wind turbines and even some nuclear plants. Shutting down or damaging any of these vital public utilities could severely impact hundreds of thousands of Americans.

But none of the components at a nuclear power plant interact with external networks and cannot be impacted by malware of this kind. Additionally, the industry was aware of this threat because the Department of Homeland Security briefed it. ABC could have found this out by calling NEI or any nuclear facility (or any energy-related industrial outlet, I expect, though I can’t speak for them), but why wreck a good story with a drive to get at the truth? NEI let ABC know the salient information on Twitter, but no change to the story.

Bill Gross, NEI’s senior project manager, engineering, nuclear generation, contributed substantially to this post.

Comments

Popular posts from this blog

An Ohio School Board Is Working to Save Nuclear Plants

Ohio faces a decision soon about its two nuclear reactors, Davis-Besse and Perry, and on Wednesday, neighbors of one of those plants issued a cry for help. The reactors’ problem is that the price of electricity they sell on the high-voltage grid is depressed, mostly because of a surplus of natural gas. And the reactors do not get any revenue for the other benefits they provide. Some of those benefits are regional – emissions-free electricity, reliability with months of fuel on-site, and diversity in case of problems or price spikes with gas or coal, state and federal payroll taxes, and national economic stimulus as the plants buy fuel, supplies and services. Some of the benefits are highly localized, including employment and property taxes. One locality is already feeling the pinch: Oak Harbor on Lake Erie, home to Davis-Besse. The town has a middle school in a building that is 106 years old, and an elementary school from the 1950s, and on May 2 was scheduled to have a referendu

Why Ex-Im Bank Board Nominations Will Turn the Page on a Dysfunctional Chapter in Washington

In our present era of political discord, could Washington agree to support an agency that creates thousands of American jobs by enabling U.S. companies of all sizes to compete in foreign markets? What if that agency generated nearly billions of dollars more in revenue than the cost of its operations and returned that money – $7 billion over the past two decades – to U.S. taxpayers? In fact, that agency, the Export-Import Bank of the United States (Ex-Im Bank), was reauthorized by a large majority of Congress in 2015. To be sure, the matter was not without controversy. A bipartisan House coalition resorted to a rarely-used parliamentary maneuver in order to force a vote. But when Congress voted, Ex-Im Bank won a supermajority in the House and a large majority in the Senate. For almost two years, however, Ex-Im Bank has been unable to function fully because a single Senate committee chairman prevented the confirmation of nominees to its Board of Directors. Without a quorum

NEI Praises Connecticut Action in Support of Nuclear Energy

Earlier this week, Connecticut Gov. Dannel P. Malloy signed SB-1501 into law, legislation that puts nuclear energy on an equal footing with other non-emitting sources of energy in the state’s electricity marketplace. “Gov. Malloy and the state legislature deserve praise for their decision to support Dominion’s Millstone Power Station and the 1,500 Connecticut residents who work there," said NEI President and CEO Maria Korsnick. "By opening the door to Millstone having equal access to auctions open to other non-emitting sources of electricity, the state will help preserve $1.5 billion in economic activity, grid resiliency and reliability, and clean air that all residents of the state can enjoy," Korsnick said. Millstone Power Station Korsnick continued, "Connecticut is the third state to re-balance its electricity marketplace, joining New York and Illinois, which took their own legislative paths to preserving nuclear power plants in 2016. Now attention should