Skip to main content

On Chatham House and Nuclear Cyber Security

The following is a guest post by Bill Gross, Manager, Security Integration and Coordination at Nuclear Energy Institute.

On October 6, 2015 the U.S. Department of Homeland Security (DHS) issued an unclassified version of a report assessing cyber security for the Nuclear Reactors, Materials, and Waste sector. The report was developed with input from the Idaho National Laboratory (INL), the DHS Industrial Control Systems Computer Emergency Response Team (ICS-CERT), the U.S. Nuclear Regulatory Commission (NRC) and others.

The report affirms that the nuclear plant cyber security program, “combined with the industry’s exacting standards and culture of back-up safety systems, will make it extremely difficult for an external adversary to cause a radioactive release.”

It is a breath of fresh air to see such conclusions from an independent cyber security assessment.

The recognition is well earned. The power plants and the NRC have been aggressive at addressing the cyber threat. A concerted industry-wide effort began shortly after the events of September 11, 2001, establishing a cyber security task force that is still active today. The industry voluntarily adopted a cyber security program in 2006 and implemented the program in 2008. In 2007 the NRC amended their Design Basis Threat requirements to include a cyber attack as an explicit adversary attribute, and followed this with mandatory cyber security programmatic requirements in 2009. The key findings of the DHS report affirm the good work the sector has, and continues to achieve.

But the industry's journey has included several learning opportunities. On May 5, 2015, Chatham House (a recognized highly-influential London-based think tank) issued a report entitled, “Cyber Security at Civil Nuclear Facilities; Understanding the Risks.” The Chatham House report takes a look at status of cyber security for nuclear facilities around the world. The report summarizes several historical digital-related events at U.S. Nuclear Plants. While these events, from 2003, 2006, and 2008, had no safety impact, they informed industry efforts to address the risks associated with increasing reliance on digital technologies in the plants.

Some of the enhancements we have put into place include implementing cyber security training applicable to all plant personnel, including visiting contractors and support personnel. The plants have established multi-disciplinary cyber security assessment teams that include individuals representing a wide range of expertise, including IT, cyber security, instrumentation and control, nuclear security, operations and engineering. The digital components within the facility that must be protected against cyber attacks have been identified. The plants have implemented robust controls over the use of portable media (e.g., thumb drives) and portable devices (e.g., laptops) and apply those controls to both plant personnel and visiting contractors. The plants have implemented “data diodes” that allow the plants to extract performance data from the plant while precluding a cyber attack from outside the plant. Digital assets most necessary for ensuring safety and security have been assessed, and necessary cyber security controls have been implemented. Insider mitigation programs have been enhanced.

We’ve learned from those early lessons, and our sector continues to learn – including relying on up-to-date intelligence. As noted in the DHS report:
DHS coordinates a monthly unclassified threat briefing via teleconference for the Nuclear Reactors, Materials, and Waste Sector. The Sector also receives quarterly classified threat briefings. The monthly and quarterly briefings address both cyber and physical threats to the Sector.
On the one hand, the Chatham House report provides recommendations that are sound, and are generally consistent with the lessons learned in U.S. plants’ decade-plus history of enhancing its cyber posture. It is my personal opinion that the recommendations starting with Chapter 7, “Meeting the Challenges: the Way Forward” are prudent for any utility establishing a cyber security program.

On the other hand, the Chatham House report paints a fairly gloomy picture - even of the U.S. facilities that have well-established programs. For example, the document chastises the US plants for trying to clarify that the focus of the cyber security program is on the protection of assets that have a nexus to ensuring safety and security. The report states:
The Nuclear Energy Institute, a lobbying group which represents the nuclear industry’s interests to the US government, put in a request in August 2014 to reduce the number of systems in nuclear plants that would have to be included.
The report fails to assess the efficacy of the industry position - yet later on recommends precisely what the industry request sought to achieve:
It will be important for nuclear facilities to identify the most crucial parts of the plant from a cyber security perspective (notably, their critical cyber assets) in order to grant those the highest levels of protection. As Source 3 states, ‘It needs to be a graded approach; we can’t afford to do everything for every system.’ Prioritization of the cyber risks is therefore key. [Emphasis theirs]
As another example, the report makes the following unsubstantiated claim:
When countries do issue guidance, the cyber security measures that they recommend may not be rigorous enough. In the United States, the guidance issued by the Nuclear Regulatory Commission (NRC) is not sufficient to protect against the cyber security threat.
I disagree with this statement. The NRC’s cyber security rules require the plants to defend against a well-trained, dedicated and determined adversary who is willing to kill or be killed in an effort to achieve a radiological release. The NRC spent years developing guidance that provides acceptable methods to defend against that threat. The NRC’s approved guidance is supported by cyber security standards developed by the National Institute of Standards and Technology (NIST), and embodies the findings by standards organizations and agencies such as the International Society of Automation (ISA), and the Institute of Electrical and Electronics Engineers (IEEE), as well as guidance from the DHS.

The claim appears inconsistent with the DHS assessment, which affirms, “Compliance with the strict regulatory requirements of the Nuclear Reactors, Materials, and Waste Sector makes Sector assets difficult targets for physical or cyber attack.”

The U.S. plants are doing the right things for cyber security, and we welcome the opportunity to share recommended practices and lessons learned with nuclear facilities working to establish cyber security programs.

Comments

Popular posts from this blog

Activists' Claims Distort Facts about Advanced Reactor Design

Below is from our rapid response team . Yesterday, regional anti-nuclear organizations asked federal nuclear energy regulators to launch an investigation into what it claims are “newly identified flaws” in Westinghouse’s advanced reactor design, the AP1000. During a teleconference releasing a report on the subject, participants urged the Nuclear Regulatory Commission to suspend license reviews of proposed AP1000 reactors. In its news release, even the groups making these allegations provide conflicting information on its findings. In one instance, the groups cite “dozens of corrosion holes” at reactor vessels and in another says that eight holes have been documented. In all cases, there is another containment mechanism that would provide a barrier to radiation release. Below, we examine why these claims are unwarranted and why the AP1000 design certification process should continue as designated by the NRC. Myth: In the AP1000 reactor design, the gap between the shield bu...

How many nuclear plants does it take to meet the world's energy needs?

Several weeks ago Joshua Pearce at Clarion University in Pennsylvania released a study titled “ Thermodynamic limitations to nuclear energy deployment as a greenhouse gas mitigation technology .” In the study he stated... nuclear energy production would have to increase by 10.5% per year from 2010 to 2050 to both replace fossil-fuel-energy use and meet the future energy demands. This line, of course, made the headlines and has been picked up by several outlets and blogs . When looking into his calculations for this statement, he made one assumption error that overstated the above sentence by nearly a factor of three. Page 121, Section 4.1 of the study states: Richard Smalley pointed out that in 2004, the global economy consumed the equivalent of 220 million barrels of oil per day, which converted into electricity terms is the equivalent of 14.5 TeraWatts (TW), or 14,500,000 MegaWatts (MW) (2005). … With a nuclear plant having about 1000 MW (1 GW) of capacity, we would need 14,500...

What Happens During a Refueling Outage?

You may have noticed over the past few weeks that a number of nuclear plants are shut down for refueling outages or are resuming operations after just returning from one. This type of routine outage usually occurs in the spring or fall when electricity demand is low so that nuclear reactors can replace about one-third of the spent fuel rods with new fuel and conduct other routine maintenance and repairs at the plant. To get a better sense of how refueling works at a nuclear energy facility, I spoke with Marcus Nichol, NEI’s senior project manager for used fuel storage and transportation, and asked him to explain the basics. Why does a nuclear plant need to replace one-third of its fuel? Nichol: The main purpose of a refueling outage is to replace older fuel that is depleted—meaning it can no longer efficiently produce energy from nuclear fission reactions—with new fuel. This “used fuel” has typically been used in the reactor for four-and-a-half to six years before it is pe...