
Cybersecurity for Nuclear Facilities
Dawon supports the protection of digital assets, instrumentation and control systems, engineering environments, and external dependencies across nuclear facilities. Its safety aligned approach provides operational and asset intelligence, threat detection, risk management, and regulatory evidence without interfering with critical operations.
Safety, Security and Operational Continuity Are Interdependent
Nuclear facilities combine safety critical digital functions, long lived control systems, highly governed engineering processes, and specialized supplier dependencies. As facilities modernize and advanced reactor programs introduce new digital technologies, cybersecurity must be integrated throughout the engineering and operational lifecycle.

Safety Critical Digital Functions
Systems supporting safety, security, safeguards, and emergency preparedness require tightly governed access, monitoring, and change control.
Sophisticated and Targeted Threats
Nuclear organizations must prepare for persistent adversaries, supply chain compromise, and attacks designed to manipulate industrial systems.
Long Lived and Qualified Systems
Cybersecurity measures must align with established system architectures, qualification requirements, maintenance procedures, and operational constraints.
Engineering and Third Party Access
Engineering workstations, removable media, OEM access, contractors, and software suppliers require continuous oversight and traceability.
Digital Modernization and Advanced Reactors
New reactor designs, remote operations, and increased digital connectivity introduce security requirements that must be addressed during design and procurement.
Every Level Inward Adds Another Enforced Boundary
External Dependencies
OEM · CONTRACTORS · SUPPLY CHAIN · CORPORATE IT
- ENFORCED BOUNDARY
Controlled Access
REMOTE SESSIONS · REMOVABLE MEDIA · ENGINEERING WORKSTATIONS
- ENFORCED BOUNDARY
Plant OT
BALANCE OF PLANT · PLANT DATA NETWORK · HISTORIAN
- ENFORCED BOUNDARY
Instrumentation and Control
DCS · PLC · RTU · PROTECTION AND CONTROL
- ENFORCED BOUNDARYLEVEL 4
Sensitive Digital Functions
SAFETY · SECURITY · EMERGENCY PREPAREDNESS
- Governed inward paths: engineering access, removable media, firmware
- One way data flow outward, through a boundary device at every level
Defense increases inward · Source: NRC Regulatory Guide 5.71
Dawon observes each of these levels passively and records what it sees as evidence: asset and communication baselines, boundary crossings, configuration and firmware change, and the risk decisions taken against them.
Security Across the Facility Lifecycle
Cybersecurity requirements evolve throughout a nuclear facility's lifecycle. Dawon supports operating plants, engineering and maintenance activities, third party and supplier access, modernization programs, and new reactor projects from initial design through commissioning and operation.
- 01
Design
Requirements defined
- 02
Commissioning
Baselines established
- 03
Operation
Operational intelligence maintained
- 04
Maintenance
Privileged activity monitored
- 05
Modernization
Requirements carried forward
Existing Nuclear Facilities
Maintain continuous intelligence across operational networks, establish approved asset and communication baselines, and identify unauthorized changes without disrupting plant operations.
Engineering and Maintenance
Monitor privileged engineering activity, configuration changes, firmware updates, removable media use, and access to control system environments.
Third Party and Supplier Access
Assess OEM connections, contractor access, software dependencies, and maintenance pathways affecting sensitive systems.
Modernization and Advanced Reactors
Integrate cybersecurity requirements into the design, procurement, commissioning, and operation of modernized facilities, SMRs, and microreactors.
Safety Aligned Monitoring and Risk Management
Asset Intelligence
Identify assets and communications without active scanning or interference with operational systems.
Change and Threat Detection
Detect unauthorized devices, abnormal communications, configuration changes, firmware activity, and suspicious engineering actions.
Operational Risk Assessment
Evaluate findings according to system function, asset criticality, operational dependencies, and potential safety consequences.
Incident Readiness and Response
Maintain scenario specific response procedures that support coordination between security, engineering, operations, and leadership teams.
Continuous Evidence Management
Record findings, exceptions, remediation activity, control status, and risk decisions for investigations and regulatory assessments.
Dawon can be deployed on premises and within isolated environments without dependency on public cloud infrastructure.
Supporting Secure and Compliant Nuclear Operations
Dawon connects operational evidence with cybersecurity requirements applicable to each facility and jurisdiction. Relevant frameworks may include NRC 10 CFR 73.54, NRC Regulatory Guide 5.71, the IAEA Nuclear Security Series, ISA/IEC 62443, and applicable national nuclear regulations.
- NRC 10 CFR 73.54
- NRC Regulatory Guide 5.71
- IAEA Nuclear Security Series
- ISA/IEC 62443
- National nuclear regulations
Improved intelligence across sensitive digital and operational systems
Earlier identification of unauthorized activity and system changes
Stronger governance of suppliers, contractors, and maintenance access
Better coordination during cybersecurity incidents
Current, traceable evidence for inspections and assessments
Security requirements integrated into modernization and advanced reactor programs

Discuss Your Nuclear Cybersecurity Requirements
Speak with Team Dawon about your facility, modernization program, or advanced reactor project.

