RECOMMENDATION
Adopt comprehensive cybersecurity frameworks that keep pace with threats
This recommendation is relevant to
- Protecting Facilities Against Sabotage
Countries and areas with nuclear facilities should mitigate cybersecurity vulnerabilities with the following actions:
- Require an active cybersecurity program during the construction of nuclear facilities that helps limit supply chain vulnerabilities and third-party risk through vendor vetting, equipment testing, and detection of potential zero-day vulnerabilities, undisclosed hardware or software flaws unknown to the developer for which no available security fixes exist
- Update regulations for sensitive digital asset protection to ensure that all safety- and security-related systems in nuclear facilities are included in cybersecurity planning and that protective measures are applied on the basis of the probability and potential impact of cyberattacks
- Establish requirements for annual tests and assessments of cybersecurity measures at all nuclear facilities, using realistic threat scenarios developed from current intelligence
- Mandate the inclusion of cyber threats in design basis threat documents to establish a consistent, regularly updated basis for security plans, tests, and assessments
- Require facility operators to implement mandatory cybersecurity awareness programs for all personnel with access to digital systems as a condition of licensing.
What the Data Show
Most countries and areas with nuclear facilities have cybersecurity requirements that are outdated in design, incomplete in scope, and insufficiently tested to keep pace with evolving threats.
Data Highlights
Among the 47 countries and Taiwan with nuclear facilities:
- Nine countries have no basic requirements to protect nuclear facilities from cyberattacks (Algeria, Argentina, Bangladesh, Egypt, Indonesia, Mexico, Morocco, North Korea, and Peru).
- Eleven countries have comprehensive requirements that include a cybersecurity program during facility construction to address supply chain vulnerabilities (Belgium, Canada, Finland, Hungary, Iran, Jordan, Slovenia, South Korea, Ukraine, the United Arab Emirates, and the United States).
- Fourteen countries (up from 11 in 2023) have a modern approach that protects assets on the basis of the function of the system they support, the probability that they could be compromised, and the potential severity of that outcome.
- Nineteen countries have requirements for mandatory cybersecurity awareness programs for personnel with access to digital systems.
- Twenty-nine countries and areas require tests and assessments of cybersecurity measures, but only 11 require that they be conducted at least annually.
Data Details
Cyberattacks targeting energy infrastructure and industrial control systems have rapidly intensified in frequency and sophistication over the past decade, outpacing countries’ ability to adapt to threats. The energy sector accounted for nearly 40 percent of all cyberattacks on critical infrastructure globally in 2023, and in the United States, such attacks increased by 70 percent between 2023 and 2024.
Supply chain security during procurement and construction is the most significant security vulnerability; nuclear facilities rely on complex networks of vendors, subcontractors, hardware manufacturers, software developers, and system integrators, each creating potential entry points for adversaries before a facility even comes online. Despite the clear risks, among the 48 countries and areas with nuclear facilities, the 2026 NTI Index finds that only 11 require facility operators to establish cybersecurity programs during facility construction. That is up from 7 in the 2023 NTI Index, with Belgium, Slovenia, the United Arab Emirates, and the United States accounting for the increase—but it is still far too low.
Cybersecurity continues to be essential once facilities are online, and the 2026 NTI Index also finds some progress in this area, but many remaining gaps leave facilities vulnerable to persistent digital threats. Eleven countries have no requirements for identifying and protecting sensitive digital assets: the programmable electronic devices, networks, and software that support safety, security, and emergency preparedness, including alarm and communication systems, surveillance systems, and access controls. The omission of these requirements is a substantial risk in 2026, as connected Internet of Things devices that play specific roles in maintaining nuclear security have been consistently exploited by adversaries. For example, closed-circuit television (CCTV) systems used for video surveillance have been exploited by hacking groups as an entry point to access sensitive systems (as occurred at the Monju nuclear power plant in Japan in 2014), and to map out security systems and gather personnel details from security logs (an approach used in the Energetic Bear attacks in 2014 and 2017). The vulnerability of connected devices has been shown more recently by Hezbollah-aligned hacking groups’ effective exploitation of CCTV systems to gather targeting intelligence for precise drone strikes. Among the 37 countries and areas that do have such requirements, only 14 use a modern “function-based” approach that protects assets on the basis of the function of the system they support, the probability that they could be compromised, and the potential severity of that outcome (up from 11 in the 2023 NTI Index).
More promisingly, the number of countries and areas with nuclear facilities that require tests and assessments of cybersecurity measures has grown from 16 to 29 since the 2016 NTI Index, but frequency matters as much as the requirement itself. Of those 29, only 11 require assessments at least annually—a low bar, given that cyber threats evolve on a timeline measured in weeks and months, not years.
See how your country can act on this recommendation
Actions to take
Adopt comprehensive cybersecurity frameworks that keep pace with threats
- Require an active cybersecurity program during the construction of nuclear facilities that helps limit supply chain vulnerabilities and third-party risk through vendor vetting, equipment testing, and detection of potential zero-day vulnerabilities, undisclosed hardware or software flaws unknown to the developer for which no available security fixes exist
- Update regulations for sensitive digital asset protection to ensure that all safety- and security-related systems in nuclear facilities are included in cybersecurity planning and that protective measures are applied on the basis of the probability and potential impact of cyberattacks
- Mandate the inclusion of cyber threats in design basis threat documents to establish a consistent, regularly updated basis for security plans, tests, and assessments
- Establish requirements for annual tests and assessments of cybersecurity measures at all nuclear facilities, using realistic threat scenarios developed from current intelligence
- Require all personnel to participate in training programs on cyber threats