The Office for Nuclear Regulation prosecuted Sellafield Ltd, which runs the nuclear site in Cumbria, under the Nuclear Industries Security Regulations 2003. The charges concerned information technology security offences over a period running from 2019 to early 2023. In August 2024 the company was found to have failed to comply with an approved security plan.
Prosecuted For The State Of The Defences
Almost everything in this database is a record of an incident. This is a record of a condition: the regulator did not need an intrusion to bring a case, only a failure to meet the plan the operator was working to.
That is unusual and worth marking. Where enforcement appears in this file set it is nearly always after a breach and directed at the response — how late the notification was, how the disclosure was worded. Here the offence is the posture itself.
A Four-Year Period, Not A Date
The charges span 2019 to early 2023. Nothing about that is a moment; it describes years in which required controls were not where they were supposed to be.
For a site holding one of the world’s largest stores of untreated nuclear waste, the absence of a named breach is not reassurance. It is the same problem recorded at the Polish heat plant, where an intrusion sat unrecognised for months: nobody can point to what did not get detected.
Compiled from regulator statements and public reporting, listed below. The case concerns compliance with a security plan; no breach of the site’s systems has been established publicly and we are not asserting one. Corrections: corrections@forensicpost.com.
- Sellafield to be prosecuted over alleged cyber compliance failureComputer Weekly
- Sellafield enters guilty plea following cybersecurity failingsNew Civil Engineer