Civil Nuclear Cyber Security Strategy 2022 Executive Summary Electricity generated from nuclear power will play a vital role in supporting the UK’s long term energy security, clean energy transition and achieving its net zero carbon emissions target by 2050. As the sector’s strategic importance and size increases, it is more crucial than ever that civil nuclear organisations and their suppliers protect themselves against cyber security threats, and plan effectively for cyber incidents. The 2021 National Cyber Strategy sets the UK ambition to be a leading global cyber power, protecting and promoting the UK’s interests in and through cyberspace. That vision is matched in the civil nuclear sector, with this strategy sitting underneath the national framework and supporting its delivery. Our goal is ‘A UK civil nuclear sector which effectively manages and mitigates cyber risk in a collaborative and mature manner, is resilient in responding to and recovering from incidents, and ensures an inclusive culture for all’. Cyber security in the sector is on a positive trajectory and cyber maturity has improved over the past five years with the support of this strategy’s predecessor, the 2017 Civil Nuclear Cyber Security Strategy. However, there is more work to do, and the evolving nature of both the threat and technology means we need to accelerate to keep pace with a changing external environment. Building on a comprehensive understanding of current sector strengths and challenges, this strategy outlines four key objectives which the sector should achieve by 2026: • The sector appropriately prioritises cyber security as part of a holistic risk management approach, underpinned by a common risk understanding, and outcome-focused regulation; • The sector and its supply chain takes proactive action to mitigate cyber risks in the face of evolving threats, legacy challenges and adoption of new technologies; • The sector enhances its resilience by preparing for, and responding collaboratively to cyber incidents, minimising impacts and recovery time; and • The sector collaborates to increase cyber maturity, develop cyber skills and promote a positive security culture. These objectives will be delivered by a range of priority and supporting activities and overseen by a programmatic approach to delivery. Key commitments include: • Rolling out Cyber Adversary Simulation (CyAS) assessments and other threatinformed testing activities across the sector’s critical Information Technology (IT) and Operational Technology (OT) systems; • Setting baseline cyber security standards for the civil nuclear supply chain; 5

Select target paragraph3