Executive Summary
The UK civil nuclear supply chain will:
HM Government will:
aw
n
o Increase its capability and capacity to understand and manage cyber security
risks where required;
o Ensure that they have processes in place to notify duty holders of cyber
incidents or vulnerabilities;
o Ensure that known cyber security vulnerabilities are mitigated, so far as is
reasonably practicable; and,
o Undertake appropriate risk management processes that pre-emptively
reduce the associated risks.
ith
dr
o Enable cyber transformation by the UK civil nuclear sector;
o Contribute to, and influence international and national policy, guidance and
regulation for the good and benefit of all;
o Provide an appropriate national and civil nuclear sector policy and regulatory
framework;
o Provide timely threat and vulnerability intelligence to stakeholders;
o Use National Cyber Security Programme funding to support the overall
purpose, aims and responsibilities of this strategy; and,
o Lead the management of major cyber security incidents that are both serious
and affect more than one member of the UK civil nuclear sector.
The Office for Nuclear Regulation and Information Commissioner will:
W
o Enable cyber transformation by the UK civil nuclear sector;
o Develop and implement outcome focussed regulation of cyber security and
cyber resilience;
o Adopt a proportionate, accountable, consistent, targeted, and transparent
approach to regulation, in accordance with The Regulators Code5;
o Hold the civil nuclear sector to account, on behalf of the public, for delivery of
a safe, secure civil nuclear sector; and,
o Contribute to and influence international and national policy guidance and
regulation.
5
https://www.gov.uk/government/publications/regulators-code
4