nuclear-news

The News That Matters about the Nuclear Industry Fukushima Chernobyl Mayak Three Mile Island Atomic Testing Radiation Isotope

Sellafield Ltd fined £332,500 for cyber security shortfalls

Office for Nuclear Regulation, 2 October 2024

Sellafield Limited was today fined £332,500 for cyber security shortfalls during a four-year period following a prosecution brought by the Office for Nuclear Regulation (ONR).

The offences relate to Sellafield Ltd’s management of the security around its information technology systems between 2019 to 2023 and its breaches of the Nuclear Industries Security Regulations 2003.

An investigation by ONR, the UK’s independent nuclear regulator, found that Sellafield Ltd failed to meet the standards, procedures and arrangements, set out in its own approved plan for cyber security and for protecting sensitive nuclear information.

Significant shortfalls were present for a considerable length of time, said ONR.

It was found that Sellafield Ltd allowed this unsatisfactory performance to persist, meaning that its information technology systems were vulnerable to unauthorised access and loss of data.  

However, there is no evidence that any vulnerabilities at Sellafield Ltd have been exploited as a result of the identified failings.

In 2023, an ONR inspector noted that a successful ransomware attack could impact on important ‘high-hazard risk reduction’ work at the site with a subsequent return to normal IT operations potentially taking up to 18 months.

Internally, Sellafield Ltd themselves had also observed how a successful phishing attack or malicious insider might trigger the loss or compromise of key systems of data.

A successful attack could have disrupted operations, damaged facilities and delayed important decommissioning activities.

At a hearing in June at Westminster Magistrates Court, the company pleaded guilty to three offences:………………………………………………………………………….

…………………..As part of the sentencing determination, District Judge Goldspring ruled the breaches represented a medium culpability (high end).

Sellafield in Cumbria is one of Europe’s largest industrial complexes, managing more radioactive waste in one place than any other nuclear facility in the world…………………………………… https://www.onr.org.uk/news/all-news/2024/10/sellafield-ltd-fined-332-500-for-cyber-security-shortfalls/

October 5, 2024 - Posted by | UK

No comments yet.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.