Nuclear plant cyber security - they still don't get it
There is still an "us" (nuclear) vs "them" (non-nuclear) approach being taken by the nuclear industry with respect to working with the non-nuclear community on control system cyber security. Specifically, the December issue of Nuclear News references a nuclear plant instrumentation and control system meeting specifically on cyber security that was held in
In the November issue of Power, there are two articles on nuclear plant networks- "Plantwide Data Networks Leverage Digital Technology to the Max" and "Upgrade your BWR Recirc Pumps with Adjustable Speed Drives". Both tout the value of advanced communication networks and neither addresses the cyber security vulnerabilities they open. In the first, it is suggested that the plantwide data network (PDN) include process control (DCS, PLCs, etc) and plant communications (public address, radios, cell phones, pagers, etc). It is also suggested that process monitoring, operator support, plant security (physical), and supplemental monitoring/testing be included. These are all good ideas (ironically, 10-15 years ago before cyber security was an issue, I was writing papers and sponsoring research at EPRI encouraging this approach), but they need to include cyber security considerations in which the article is essentially silent. The second article on BWR recirculation pumps going to variable speed drives seems to ignore the Browns Ferry 3 broadcast storm experience. Variable speed drives are definitely the way to go and networking the drives are a good idea, but "¦.you still need to address the cyber component you just opened.
Joe WeissAbout the Author
waltboyes
waltboyes
Leaders LogoLeaders relevant to this article: