Why Nuclear OT Security Is Different

Nuclear facilities present a threat model with characteristics that place them in a distinct category from other critical infrastructure sectors. The consequences of a successful cyberattack that causes loss of control over a nuclear process are potentially catastrophic and irreversible. Regulatory frameworks recognise this: nuclear cybersecurity requirements are more prescriptive, more audited, and carry greater legal consequence than equivalent obligations in water, energy, or manufacturing.

At the same time, nuclear facilities are deliberately targeted by sophisticated nation-state threat actors for both intelligence collection and capability pre-positioning. The sector’s unique combination of maximum consequence and high-value targeting creates a security challenge that requires controls beyond standard OT best practice.

Regulatory Framework: NRC and IAEA

US Nuclear Regulatory Commission (10 CFR 73.54)

The NRC’s cybersecurity rule for nuclear power plants (10 CFR 73.54, effective 2010 with ongoing updates) requires licensees to protect digital computer and communication systems and networks from cyberattacks. Key requirements:

  • Establishment of a Cybersecurity Program with a Cybersecurity Plan submitted to and approved by the NRC
  • Identification of Critical Digital Assets (CDAs) — digital systems important to safety, security, or emergency preparedness
  • Implementation of defensive architecture to isolate CDAs from external networks and from non-critical plant systems
  • Ongoing monitoring of all CDAs for anomalous behaviour
  • Incident response capabilities with mandatory reporting to the NRC

The NRC’s definition of CDAs and the required defensive architecture around them is the most rigorous regulatory definition of OT protection requirements in US critical infrastructure. Licensees face periodic inspections and can face civil penalties for non-compliance.

IAEA Nuclear Security Series

The International Atomic Energy Agency’s Nuclear Security Series documents provide the international framework for nuclear cybersecurity:

  • NSS No. 42-G: Computer Security for Nuclear Security provides the overall framework
  • NSS No. 17-T: Computer Security Techniques for Nuclear Facilities provides technical guidance
  • NSS No. 33-T: Computer Security of Instrumentation and Control Systems at Nuclear Facilities addresses OT-specific requirements

The IAEA framework uses a graded approach where security measures are proportionate to the consequence of a successful attack on each system. The highest-grade systems — those directly controlling safety functions — require the most stringent isolation and access controls.

Nation-State Targeting of Nuclear Facilities

Nuclear facilities are among the most persistently targeted OT environments by sophisticated state-sponsored actors. Documented campaigns include:

Lazarus Group / DPRK targeting (ongoing)

North Korean actors have repeatedly targeted nuclear energy companies, nuclear research institutions, and uranium enrichment operators across multiple countries. DPRK targeting serves a dual intelligence purpose: collecting technical information about nuclear fuel cycles, reactor designs, and proliferation-sensitive technology, while also mapping control system architectures for potential future use.

The 2017 HACKFAST campaign involved spearphishing of nuclear plant employees, with some intrusions reaching the IT/OT boundary of US-based nuclear facilities. Multiple campaigns since 2022 have targeted nuclear research laboratories in the US, France, South Korea, and India.

Russian GRU/FSB campaigns

Sandworm (GRU Unit 74455) has demonstrated willingness to target energy sector OT environments with destructive intent, as evidenced by attacks on Ukrainian power infrastructure. Russia’s targeting of Western nuclear facilities is primarily assessed to be in an intelligence collection and pre-positioning phase, though the capability for destructive operations has been demonstrated in adjacent sectors.

The 2018 Dragonfly 2.0 campaign (attributed to a Russia-aligned threat actor) specifically targeted US nuclear facilities and achieved access to the IT networks of at least two nuclear plant operators. The attackers appear to have conducted reconnaissance of network architecture rather than attempting to cross the IT/OT boundary — but the intrusions established that nuclear plant IT networks are reachable through standard phishing and credential theft.

Iran IRGC / Charming Kitten

Iranian threat actors have targeted nuclear research institutions in countries with which Iran has bilateral nuclear disputes. Israeli nuclear research facilities and researchers connected to the IAEA have been persistently targeted. The targeting appears oriented toward intelligence collection on Western and Israeli nuclear programmes rather than toward disruption of commercial nuclear generation.

The Air-Gap Architecture Challenge

Nuclear OT cybersecurity relies heavily on air-gapping — physical separation of safety-critical control systems from networks connected to the internet or to corporate IT infrastructure. In principle, an air-gapped CDA cannot be reached from an external attacker’s network position.

In practice, air-gaps present several recurring challenges:

Data transfer requirements: Plant engineers must transfer software updates, configuration changes, and diagnostic data across the air gap. This is typically done via removable media — USB drives and optical discs — creating a vector that bypasses network controls. Stuxnet, the seminal case in nuclear OT attack, traversed an air-gapped environment via infected USB drives.

Vendor remote access: Equipment vendors require access for maintenance and troubleshooting. Temporary connections to vendor networks, even through well-controlled jump servers, create temporary air-gap bridging that must be carefully managed.

Gradual architecture erosion: Nuclear facilities operate for 40-60 years. Systems designed as air-gapped may accumulate connections over time as operational requirements change. Periodic architecture reviews are required to identify unintended connectivity that has been introduced since the original design.

Wireless and unintended coupling: Wireless signals can cross physical air gaps. Covert channel research has demonstrated that power consumption, electromagnetic emissions, and acoustic signals from air-gapped systems can carry data. While exploiting these channels is sophisticated, the threat model for nuclear facilities includes sophisticated adversaries.

Sector-Specific Defensive Guidance

Critical Digital Asset inventory and boundary protection

The NRC requirement for CDA identification is the foundation. Every system with potential to affect safety, security, or emergency response functions should be enumerated, with its data flows mapped and its boundary with non-CDA systems documented. Unexpected data flows across this boundary are among the highest-priority alerts in a nuclear facility’s security monitoring programme.

Removable media controls

Removable media is the most plausible path across an air gap for most adversaries. Required controls: media scanning on dedicated isolated systems before introduction to the protected environment, read-only media where feasible for software distribution, serialisation and inventory of all authorised media, and prohibition of personally owned devices in protected areas.

Supply chain security for digital I&C systems

Digital instrumentation and control systems in nuclear facilities are long-lifecycle products supplied by a small number of specialised vendors (Framatome, Rolls-Royce Nuclear, Emerson Nuclear). Supply chain compromise of these vendors represents a high-consequence risk. Organisations should require software bills of materials from I&C vendors and monitor vendor security posture as part of third-party risk management.

Insider threat programme

Nuclear facilities operate insider threat programmes as a regulatory requirement under NRC’s access authorisation rules. The cybersecurity dimension of insider threat — a malicious or compromised insider with legitimate access to CDAs — requires integration of cybersecurity monitoring with the broader personnel reliability programme.

Exercise and testing

The NRC requires periodic testing of cybersecurity controls including simulated attacks. For nuclear facilities, the equivalent of a conventional penetration test requires careful scoping to avoid disrupting safety systems. Tabletop exercises using scenarios derived from documented threat actor campaigns (DPRK targeting of I&C vendor supply chains, Russian spearphishing of engineer accounts) are the standard approach for testing incident response without physical risk.

Nuclear OT cybersecurity is a mature regulatory discipline, but the threat landscape has continued to evolve faster than some older facilities’ security programmes. The convergence of sophisticated nation-state targeting with the unique consequences of nuclear system compromise makes this one of the highest-stakes environments in critical infrastructure security.

Tags
nuclearNRCIAEAOT securityICScritical infrastructureLazarusRussiacyber-nuclearair-gap2026