Civil Nuclear Cyber Security Strategy 2022
Executive Summary
Electricity generated from nuclear power will play a vital role in supporting the UK’s long term
energy security, clean energy transition and achieving its net zero carbon emissions target by
2050. As the sector’s strategic importance and size increases, it is more crucial than ever that
civil nuclear organisations and their suppliers protect themselves against cyber security
threats, and plan effectively for cyber incidents.
The 2021 National Cyber Strategy sets the UK ambition to be a leading global cyber power,
protecting and promoting the UK’s interests in and through cyberspace. That vision is matched
in the civil nuclear sector, with this strategy sitting underneath the national framework and
supporting its delivery. Our goal is ‘A UK civil nuclear sector which effectively manages and
mitigates cyber risk in a collaborative and mature manner, is resilient in responding to and
recovering from incidents, and ensures an inclusive culture for all’.
Cyber security in the sector is on a positive trajectory and cyber maturity has improved over
the past five years with the support of this strategy’s predecessor, the 2017 Civil Nuclear Cyber
Security Strategy. However, there is more work to do, and the evolving nature of both the
threat and technology means we need to accelerate to keep pace with a changing external
environment.
Building on a comprehensive understanding of current sector strengths and challenges, this
strategy outlines four key objectives which the sector should achieve by 2026:
•
The sector appropriately prioritises cyber security as part of a holistic risk
management approach, underpinned by a common risk understanding, and
outcome-focused regulation;
•
The sector and its supply chain takes proactive action to mitigate cyber risks in the
face of evolving threats, legacy challenges and adoption of new technologies;
•
The sector enhances its resilience by preparing for, and responding collaboratively
to cyber incidents, minimising impacts and recovery time; and
•
The sector collaborates to increase cyber maturity, develop cyber skills and
promote a positive security culture.
These objectives will be delivered by a range of priority and supporting activities and overseen
by a programmatic approach to delivery. Key commitments include:
•
Rolling out Cyber Adversary Simulation (CyAS) assessments and other threatinformed testing activities across the sector’s critical Information Technology (IT)
and Operational Technology (OT) systems;
•
Setting baseline cyber security standards for the civil nuclear supply chain;
5