The UK civil nuclear sector occupies a unique position within the nation’s Critical National Infrastructure (CNI). It supports energy security, national prosperity, scientific innovation, environmental remediation, and, through its close links with the wider nuclear enterprise, contributes to the UK’s defence and national security objectives. Yet for many board members and executive teams, cyber security remains a subject that can appear highly technical and difficult to navigate. CIISec Fellow Daren Green, Chief Information Security Officer at Nuclear Restoration Services Ltd shares his perspective and advice in this article.
The unique challenge
The challenge facing senior leaders is not to become cyber security experts, but to develop sufficient understanding to govern cyber risk effectively and appreciate its relationship to safety, security, resilience, and mission delivery.
Unlike many industries, the UK civil nuclear sector operates across a geographically dispersed estate stretching from Dounreay in northern Scotland to Sizewell on the Suffolk coast, with facilities located throughout England, Scotland, and Wales. These sites include operational nuclear facilities, fuel manufacturing plants, research establishments, waste management facilities, and some of the most complex decommissioning projects anywhere in the world. Many are located in remote areas where specialist skills, connectivity, and resilience arrangements can present additional operational challenges.
The sector itself is also undergoing significant transformation. Alongside the safe management and decommissioning of the UK’s nuclear legacy by organisations across the Nuclear Decommissioning Authority (NDA) Group, the industry is simultaneously delivering a new generation of nuclear capability. This includes the construction of Hinkley Point C, plans for Sizewell C, ongoing fusion and advanced reactor research, and the growing ambition to deploy Small Modular Reactors (SMRs) as part of the UK’s future energy mix. These developments create a diverse and increasingly interconnected digital ecosystem requiring robust cyber security from design through to operation and eventual decommissioning.
As boards begin their cyber journey, many initially view cyber security as an IT issue involving laptops, networks, and data protection. However, a deeper understanding quickly reveals that cyber security within a nuclear environment extends far beyond traditional information technology.
Nuclear organisations operate a complex blend of Information Technology (IT), Operational Technology (OT), industrial control systems, scientific instrumentation, physical protection systems, and legacy assets that may have been in service for decades. Many of these systems were designed before modern cyber threats emerged and cannot simply be upgraded or replaced without considering safety cases, operational impacts, and regulatory approval.
Informed consumers of cyber risk information
This is often the point at which boards begin to appreciate the unique challenges faced by the sector. Cyber security decisions are rarely made in isolation. In a nuclear environment, every decision must balance security, safety, operational availability, regulatory compliance, and commercial objectives. A solution that appears straightforward in a conventional corporate environment may be significantly more complex when deployed within a licensed nuclear facility.
The regulatory landscape introduces additional complexity. Organisations must meet expectations from bodies such as the Office for Nuclear Regulation (ONR), National Cyber Security Centre (NCSC), Department for Energy Security and Net Zero (DESNZ), and wider government assurance frameworks. Cyber Essentials Plus, GovAssure, the NCSC Cyber Assessment Framework (CAF), and sector-specific requirements all contribute to a demanding assurance environment. Effective governance therefore requires boards to understand not only cyber threats but also the consequences of failing to manage them effectively.
Importantly, boards are not expected to become Suitably Qualified and Experienced Personnel (SQEP) in cyber security. Their role is different. They must become informed consumers of cyber risk information who can challenge constructively, support investment decisions, and provide confidence that cyber risks are being effectively managed.
The most successful boards treat cyber security as an enterprise risk rather than a technical specialty. They focus discussions on business consequences, operational resilience, supply chain dependencies, safety implications, and recovery capabilities. They participate in cyber exercises, improve their cyber literacy, and establish trusted relationships with their Chief Information Security Officer (CISO) and specialist teams.
Ultimately, mature boards recognise that cyber security is not about protecting technology for its own sake. It is about protecting the organisation’s ability to safely deliver its mission, maintain stakeholder and regulatory confidence, safeguard national interests, and support the future of the UK’s nuclear Programme.
While board members may never become cyber specialists, they can become informed and effective stewards of cyber risk. The journey from limited awareness to informed stewardship is one of the most important steps any nuclear organisation can take in strengthening its resilience against an increasingly complex threat landscape.
Click to view the full infographic

Further Discussion
For those interested in exploring these challenges further, the CIISec Nuclear Hub Conference will take place on 15 October 2026 at The Engine Rooms, Birchwood Park, Warrington (online streamed option available). The conference brings together leaders from across the civil nuclear, cyber security, resilience, regulatory, and critical infrastructure communities to discuss emerging threats, lessons learned, professional development, governance, and the future challenges facing the sector. It provides an excellent opportunity for Board members, executives, cyber professionals, and industry stakeholders to continue the conversation around strengthening cyber resilience across the UK’s civil nuclear enterprise.