Abstract
State and non-state actors are increasingly using cyberspace as a platform to execute hybrid warfare. As multiple incidents in India have shown critical infrastructures, particularly nuclear infrastructures, have been lucrative targets of cyber-attacks. Considering India’s well-progressing civilian and military nuclear infrastructures, it is apposite to raise the question of how safe these nuclear infrastructures are from cyber threats. This article suggests that India’s nuclear infrastructures will remain exposed to cyber-attacks due to their strategic significance for India’s national security. These threats will continue to exploit the zero-day vulnerabilities in the cyber-physical systems of these infrastructures. Further, the article looks into the threat sources, consequences and mitigation strategies against cyber-attacks on nuclear infrastructures. In an attempt to explore mitigation strategies, the article discusses certain cyber-attack scenarios and the consequences on India’s nuclear infrastructures. The article concludes that while certain technological cyber-defence mechanisms are in place, there is a need for legislative and diplomatic measures for developing a comprehensive set of measures to deter cyber threats to India’s nuclear infrastructures.
Introduction
In 2020, officials identified a cyber-attack on Mumbai’s electrical grid. According to the diagnostic report, the malware originated in China. One year prior, the Kudankulam nuclear power plant’s administrative systems became the target of a cyber-attack by the North Korean-based Lazarus Group. These are two among the many events that brought attention to the growing number of cyber-attacks on India’s critical infrastructures and questioned the country’s cyber resiliency. Therefore, it is pertinent to assess how secure India’s nuclear infrastructures are from cyber threats.
The focus is on cyber threats as enemy actors frequently engage them in warfare for bigger dividends with less investment, unlike conventional means, like bombing. The uncertainty and ambiguity associated with cyber-attacks make them practicable even for non-state actors. Cyberspace, a swiftly evolving global commons, has penetrated every quarter of modern society. With the expansion of the fourth Industrial Revolution, 1 cyberspace has become more relevant. Critical infrastructures depend on cyber technology that facilitates smooth processing and data transfer for efficient performance. The degree of inter-dependency between infrastructures has made cyberspace indispensable. Importantly, cyber technology’s dual-use nature has made it a viable medium for both state and non-state actors for benign and malignant purposes alike. States function with the support of their inter-connected critical infrastructures, such as banking, power and transport. A malfunctioning network of critical infrastructures can inflict a crippling effect on the state, and this degree of dependence is taken hostage by hackers. Incidents of cyber-attacks, for example, on power grids, banking and finance sectors, have highlighted the existing susceptibility of these systems and the calibre of cyberweapons. Among high-stake infrastructures, nuclear infrastructures are also being targeted by perpetrators of cyber-attacks.
India’s nuclear infrastructures include nuclear power plants and nuclear forces. A nuclear power plant is an industrial installation, which houses nuclear reactors, used for civilian, commercial, military and research purposes. The plant consists of highly-sensitive components, such as steam generators, control rods, centrifuges, steam lines, turbines and transformers. The nuclear forces comprise nuclear warheads, delivery systems and the Nuclear Command, Control and Communications (NC3). These infrastructures are extremely critical for India’s national security, making them susceptible to enemy attacks. Relying on cyberspace for their operations has further made these infrastructures vulnerable. Kudankulam-like cyber-attack incidents confirm the presence of technical loopholes in these infrastructures, which hackers exploit.
With India enlarging its civil nuclear programme and nuclear weapons being a pivot in South Asian geopolitics, the criticality of nuclear infrastructures ought to be safeguarded. The ramifications of a cyber-attack on these infrastructures can range from access to sensitive data and power disruption to the release of radioactive materials. The malefactor can be a state actor, non-state actor or a collaborative group. Cyber conflict is a persistent mode adopted by these actors as part of hybrid warfare, eventually dragging the conflict into the grey zone- the lacuna between peace and war. It is crucial to examine the root causes of such warfare and the nature of perpetrators (Poornima, 2021). Additionally, the degrees of costs and consequences of cyber-attacks on nuclear infrastructures can help the pursuit of framing mitigation strategies. Such strategies are important to acknowledge and avoid or limit the cyber threats to these installations.
India’s critical information infrastructure is a vast, well-knitted network consisting of various organs, such as railways, power grids and nuclear infrastructures. Nuclear installations, civil and military, are potential and high-level targets for cyber-attacks due to the repercussions that endanger national security. In this context, this article will pursue some crucial questions: why are nuclear infrastructures vulnerable to cyber threats? What are the consequences of cyber-attacks on these infrastructures, and how to attenuate them? The article firstly explores the concept of hybrid warfare and the role of cyber technology in it. Then, it investigates the cyber threat to nuclear infrastructures taking the case of India. In doing so, the article will explain how nuclear installations are vulnerable to cyber conflicts and how they present as a target for hybrid warfare by both state and non-state actors. Finally, the article assesses current measures and possible strategies to eliminate or contain cyber threats to nuclear infrastructures in India.
Hybrid Warfare and Cyber Technology
‘Hybrid warfare’ has become a commonly used term to describe the evolving characteristics of warfare in the twenty-first century. There is no universally accepted definition of hybrid warfare. In fact, there is disagreement in the strategic and academic circles over the novelty of this concept. Hybrid warfare is commonly interpreted as the use of conventional means complemented by irregular, unconventional means of warfare. Considering this perspective, hybrid warfare has been practised since ancient times, figuring in Sun Tzu’s Art of War from the fifth century
The original conception of hybrid warfare excluded political and economic aspects associated with states since it focussed on non-state actors. From 2014, since the beginning of Russia’s operations in Ukraine, the discourse on hybrid warfare began to emphasise state actors as well. Some scholars opined that ‘non-linear war’ and not the Western definition of hybrid warfare explains Russia’s strategy in Eastern Ukraine and Crimea. Russia’s strategy includes ‘information, cyber, and economic, diplomatic, political and social means’, transcending the modes specified in Hoffman’s definition of hybrid warfare. The justification is that non-linear warfare involves a range of unconventional approaches specifically executed by states. It is different from hybrid warfare that non-state actors adopt with or without state support (Koffman & Rojansky, 2015, pp. 6–7; Schanuafer, 2017, p. 19). The growing discourse on hybrid warfare has, nonetheless, widened the scope of the threats as observed in this definition: ‘…a customised capability produced through a principle-agent relationship for the purpose of seriously decreasing or adversely changing vital elements or instruments of a defender’s national power’ (Cilluffo & Clark, 2012, p. 49). These elements are diverse and involve highly sophisticated technologies. Cyber technology has thus taken a significant part in hybrid warfare.
Hybrid warfare’s desirability among state and non-state actors is due to two traits: deniability and ambiguity. Cyber technology offers these advantages to perpetrators and, at the same time, delivers the targeted goals at a low cost without any physical barrier. Hybrid warfare thus incorporates cyber weapons in modern warfighting. Cyber-attacks pose attribution challenges to states as tracing the attack back to the perpetrator is complicated. Ambiguity arises about who the responsible party is as it gets tricky to produce credible evidence. Even after technical evidence is acquired, the attacker will have the edge to deny allegations by altering the details regarding their identity. It is also possible that the attacker belonging to one state could launch a cyber weapon from another state’s territory, misleading the forensic investigation. Cyberspace’s ambiguous nature can lead to misattribution with the potential to stir up new geopolitical crises, therefore leaving the issue of attribution both technically and politically challenging (Brake, 2015).
Paradoxically, while states are developing technologies that can detect and prevent cyber-attacks and identify the source, cyber attackers’ capability and technological capacity have also improved. Sophisticated cyber weapons are developed to have only minimal links with the attacker, thereby delaying and rendering obscure forensic data acquisition. As the number of cyber-attacks increases, the issue of ambiguity gets intensified with new weapons and techniques coming into play (Finaly & Payne, 2019; Skopik & Pahi, 2020, p. 4). Therefore, ambiguity in attribution makes cyber technology one of the most viable means for hybrid warfare and, at the same time, potentially malignant.
Attribution is a dicey endeavour, especially for states, as the consequences could be expensive. There is no cheat code or ready reckoner to guide the attribution process. Rid and Buchanan (2015) acknowledged this constraint when they proposed the Q model of attribution of cyber-attacks. The model consists of three levels of investigation before attributing a cyber-attack. The levels are (a) tactical, (b) operational and (c) strategic. Depending on the degree of the damage caused by the attack, the affected state or organisation can invoke the appropriate level of investigation after making a cost-benefit analysis. If the attack was minor, it is logical not to escalate the issue and instead invest in improving cyber resilience. In contrast, a major attack causing behavioural change or shutdown of the target system could provoke serious scrutiny and proportionate retaliation measures.
At the tactical level, the probe is on ‘how’ the cyber-attack was executed. It inspects issues, like the malware involved, the cyber tactic used and the system’s glitch. This level contributes to developing more robust defences to avoid further attacks. The operational level revolves around the ‘what’, that is, the reason behind the cyber-attack. It transcends technical aspects into the broader geopolitical circumstance to understand the cause of the attack. The process involves exploring attacks of similar nature to gather a better understanding of the referent attack. The final stage is comprehensive as it goes to the root of the problem to identify ‘who’ waged the attack and ‘why’ did they do so. This level helps devise a suitable response to the cyber-attack by narrowing down the probable actors responsible for the attack (Rid & Buchanan, 2015, pp. 7–8). It is essential to go through all three levels for careful attribution and dissemination of the information. Nevertheless, this is not a fool-proof model as the investigation of cyber-attacks has layers of complexity involving ambiguity and deniability.
A severe challenge for states is to keep up with the pace and narrow down the uncertainty that might otherwise expose the vulnerability of the states’ security architectures. Cyber technology has become an essential element of states’ national power. These states use cyberspace to connect their critical infrastructures. A cyber-attack on one or more of these infrastructures will have cascading effects on state functioning and the state’s geopolitical dynamics, especially when there are heightened tensions in its relationship with its adversaries. This way, cyber-attacks produce ripple effects that may not be part of the attacker’s intentions.
What makes critical infrastructures critical is the degree to which states depend on them, the interdependency among them and to some extent, the symbolism attached to them that contributes to the states’ image. Disruption in one sector could inflict a ‘snowball effect’ on the others as they are founded on cyber-physical systems. Cyber-physical systems (CPS) are integrated systems, which involve ‘digital, analogue, physical and human components engineered for function through integrated physics and logic’ (National Institute of Standards and Technology, n.d.). They improve the efficacy of critical information systems, like smart grids used in the power sector. CPS connects these systems and is highly sought targets for cyber-attacks. While several security mechanisms exist, cyber-attackers identify loopholes in these highly networked systems that cyber weapons, such as viruses, worms and trojans can penetrate. These cyber weapons are deployed to execute different cyber tactics to disturb or disrupt the target. A computer virus works similar to a flu virus, that is, once injected, it finds its way to infect other systems and upset their behaviour. The function of a computer worm differs from a virus in that the former does not alter the computer’s operations but slows down the processing by consuming the computer’s resources. A Trojan horse is mainly used to access and steal data and is more dangerous than spyware, which is also deployed for collecting information. The malware can be utilised as per the intended goal of the attacker (Digicert, n.d.).
There is no global consensus on what constitutes cyber weapons. The Tallinn Manual defines cyber weapons as ‘cyber means of warfare that are used, designed or intended to be used to cause injury to, or death of, persons or damage to, or destruction of, objects, that is, causing the consequences required for qualification of a cyber operation as an attack’ (Schmitt, 2013, p. 119). They consist of a delivery system that cracks into the target network and a payload that carries out the function of the cyber weapon, for example, to access or destroy data (Mallick, 2021, p. 10). Cyber tactics are methods processed by cyber weapons to conduct a cyber-attack. They can be in the form of distributed denial of service (DDoS) attacks, espionage, cyber subterfuge or sabotage. A notable feature of cyber weapons is that it is difficult to decipher their mission, whether they were launched for causing disruption or for accessing confidential data or other similar purposes. They can also be easily replicated and misused by other actors, thus making them an efficient tool to perforate into critical infrastructures. Nuclear installations are no exception.
History has witnessed some nuclear accidents, the remnants of which continue to persist until today. The Three Mile Island accident of 1979 led to drastic revamps in the security of nuclear plants in the USA. A partial meltdown in a reactor in the plant due to human and technical errors resulted in minor radioactive releases. Though it did not cause human casualties, the accident heavily influenced the US’ civil nuclear programme (United States Nuclear Regulatory Commission [USNRC], 2018b). The International Atomic Energy Agency’s International Nuclear Event Scale pegged the incident at Level 5, that is, accidents with wider consequences. A catastrophic Level 7 nuclear accident hit Soviet Union’s Chernobyl nuclear power plant in 1986 and cost several lives. The impact of radioactive leakage and the ensuing fire killed 30 people, including onsite workers and fire-fighters. One hundred thirty-four others were exposed to radioactive sickness. The leak contaminated the highly populated regions of Belarus, Ukraine and present-day Russia, leading to the relocation of about 335,000 people (United States Nuclear Regulatory Commission [USNRC], 2018a; World Nuclear Association, 2021). Most recently, an earthquake and tsunami led to a Level 7 accident at the Fukushima nuclear power station in 2011. The accident took 18,000 lives and displaced many more. The disaster destroyed the surrounding localities that cost trillions of yen for renovation (International Atomic Energy Agency [IAEA], n.d.). Adding to the concerns of nuclear disasters caused by human errors or force of nature, the discourse on nuclear terrorism as a ‘low probability but high consequence’ event brewed in the 1970s. After the 2001 attacks on the USA, the discourse took to the mainstream. It worked as a catalyst for debates among security analysts and policymakers about the prospects of terrorists misusing radioactive materials (Pomper & Tarini, 2017, p. 2; Su & Heb, 2021).
The human health and environmental ramifications of the Chernobyl and Fukushima nuclear accidents have demonstrated the severity of nuclear accidents. With cyber weapons being frequently used to disrupt the functioning of critical infrastructures, the sustenance of nuclear security is imperative.
Cyber Threats to Nuclear Infrastructures
Before probing the cyber threats to nuclear infrastructures, there is a need to understand what nuclear security means. The International Atomic Energy Agency defines nuclear security as ‘the prevention of, detection of, and response to, criminal or intentional unauthorised acts involving or directed at nuclear material, other radioactive material, associated facilities or associated activities’ (International Atomic Energy Agency [IAEA], 2015, p. 18). Cyber-attacks on nuclear infrastructures have been demonstrated and tested time and again. Several incidences of a breach in the nuclear power plant systems have resulted in a temporary breakdown, as in the case of Iran’s nuclear enrichment facility in Natanz after a cyber-attack in 2021. In other incidences, like the attack on India’s Kudankulam power plant, minor breaches have raised alarms about the security of these infrastructures. Though cyber-attacks have not yet caused nuclear catastrophe due to the release of radioactive materials, the possibility of such scenarios cannot be neglected. Computer systems through the internet connect modern nuclear infrastructures for their operations. Cyber weapons exploit the loopholes or design flaws that exist in these systems. Every computer system will have loopholes or patches that are unknown to resolve. This ‘zero-day’ software vulnerability gives hackers the upper hand over these systems (Stouffer, 2021). While cyber security specialists keep developing designs to fix the weaknesses, cyber-attackers figure out newer vulnerabilities in the system’s defences.
The Supervisory Control and Data Acquisition (SCADA) programme controls the primary system operations in mega infrastructures, like nuclear power plants. SCADA is a human-machine interface, which provides real-time data on the nuclear power plant’s functioning and can be acquired through a centralised system. It allows access to sensitive sections of the plant, such as the centrifuges, generators and turbines (Wijaksono et al., 2016, p. 1). SCADA is the primary target of any cyber weapon, through which other parts and functions of the nuclear power plant can be disturbed. After infiltrating the computer, the malware compromises the SCADA software. Since the SCADA has direct interaction with the plant’s critical components, the malware can alter their function and disturb the operation of the power plant irrespective of the type, make and sophistication of the reactors (Horner, 2018, p. 7).
Likewise, every state’s respective NC3 systems control operations related to the use of nuclear weapons. They integrate the nuclear force’s hardware, software and human aspects. They involve cyber technology to a large extent for processing, collating and transmitting data. These systems help the person-in-charge direct the nuclear forces and operate weapons after receiving attack-related decisions from the command’s headquarters that has been made based on sensors and early warning functions. NC3 makes sure that these weapons are launch-ready and also not prone to accidental use. Every nuclear-armed state has a different NC3 structure based on its nuclear policies. A robust NC3 can boost the power of nuclear weapons and add to the strength of the nuclear enterprise. Striking the NC3 of an adversary can debilitate their nuclear arsenal. The centrality of the NC3 to the nuclear forces deems an intrusion in the system highly risky, causing infelicitous events, including false flagging by the early warning information system and misperception by a state that it is under a nuclear attack.
The SCADA and NC3 systems are heavily inter-connected cyber-physical systems. No amount of air-gapping, that is, isolation of the systems from external connections or the internet, will guarantee a 100% protection from cyber-attacks. In 2018, the US’ Government Accountability Office (GAO) conducted a Department of Defence-sponsored experiment to test the cyber resilience of the weapon systems. The result showed that the analysts could get into the systems undetected and control the functions with basic cyber tools and tactics. They concluded that many other ‘mission-critical cyber vulnerabilities’ are highly likely to have gone unidentified due to the test’s feasibility issues (GAO, 2018).
The SCADA software or NC3 is under the constant monitoring of security personnel. This human-machine interface places these sensitive mediums in cyber-attacks’ reach both from proximity and distance. The triggers can be plenty—from a disgruntled employee’s single-handed or outsider-influenced revenge mission to an entirely external act of sabotage, terrorism or to cause any geopolitical instability (Han & Celikpala, 2016, pp. 55–56). To focus on building cyber-resilient measures, delving into the nature of cyber attackers is essential.
Shades of Cyber Attackers
The insider-outsider debate on who poses the most threat has been never-ending. While outsiders are the most probable perpetrators of cyber-attacks, the insider threat is far more malignant due to the higher success rate (Giandomenico & de Groot, 2020). Moreover, the suspicion falls on outsider threats based on obviousness. Nevertheless, the insider threat cannot be discounted. The motivation and intention of the attacker play a significant role in the execution of the attack. The perpetrator either makes a conscious decision based on triggers that are innate to the individual or are externally induced or accidentally paves the way to a cyber-attack. As per a cyber security report, in 2020, 70% of attacks were carried out by outsiders while the remaining 30% was insider activity. Fifty-five per cent of these attacks were connected to organised criminal groups (Verizon, 2021, p. 12).
Insider Source
The threat from inside can be in multiple forms and are severe as the traitor sometimes have high-level security clearance and are aware of the standard operating procedures followed in the nuclear site. The probable offenders are dissatisfied personnel who, feeling ungratified in their work environment, intend to disturb the status quo. Their goal can range from just creating chaos to selling sensitive information for monetary benefits. These intentions could be motivated by a sense of revenge, boredom or similar self-gratifying urges. Such motivations can render the person susceptible to outside influence by actors who hold overlapping interests. The person then becomes a conduit for the external actors to carry forward their agenda that could be wider, in terms of possessing confidential data related to the nuclear infrastructure, sabotaging the operations or mobilising public sentiments against the nuclear infrastructures by raising alarms of a security breach. A US Navy nuclear engineer was found guilty in February 2022 for attempting to sell nuclear-related sensitive details to foreign actors (Schapiro, 2022). Such incidences confirm the credibility of insider threats.
Another type of insider threat emerges from secret agents hired by external actors to infiltrate the security architecture in the nuclear facility. They are inducted as security personnel with the potential to rise above the ranks and get security clearance. The motivation of such offenders is to steal technical information that could benefit their handler for monetary gains or reasons of revenge and gratification. Such cases will be difficult to discern if the agent and the handler maintain very minimal, untraceable contact and highlight the importance and relevance of human intelligence as part of cyber resilience. One more category of insider threat arises from a negligent employee who fails to monitor the security system or follow security protocols due to complacency, therefore, infecting the system (Wall, 2012; see also Gheyas & Abdallah, 2016, pp. 7–9).
Outsider Source
External actors are the most prevalent threat sources of cyber-attacks. These actors can be state, non-state or cooperative groups with aligned interests. State actors are involved in cyber conflicts to gain strategic advantage against their adversaries as cyberspace allows transboundary, discrete offensive operations. Israel has been a notable state, which constantly uses its cyber prowess to destabilise its adversaries’ goals and interests. The Stuxnet attack demonstrated the capability of Israel to use a cyber weapon to disrupt Iran’s nuclear ambitions. The Stuxnet is a computer worm injected into the enrichment facility’s control systems in Iran’s Natanz province. The malware infected the security network and damaged the centrifuges. The attack caused a setback in Iran’s nuclear programme for several years (MacAskill, 2011). Since then, the worm has been replicated and modified to perform similar cyber offences by different actors (Zetter, 2011).
States, such as Russia, Iran and North Korea have also been banking on cyber technology as vital for their strategies. Cyberspace offers states and criminal non-state actors ample opportunities to carry forward their hybrid warfare (Rugge, 2018). Nuclear infrastructures are attractive targets for terrorists to cause chaos or terrorise people. They can use the chaos as a distraction to gain access to radioactive materials that could be misused later or passed on to other rogue actors. Extremist groups who oppose nuclear technology can also build a public narrative against nuclear infrastructures by attacking these infrastructures with a cyber weapon. Recreational hackers with no strategic goal can launch a cyber-attack to test or prove their capability. Though the probability of such incidents seems meagre owing to the critical nature of industrial sectors, like nuclear infrastructures, it cannot be kept out of the purview while assessing and developing security measures (Han & Celikpala, 2016, p. 56).
Realising the emerging cyber threats to nuclear infrastructures and the lingering threat actors, states worldwide have been formulating strategies to bolster the cyber resilience of these critical infrastructures. India is among those states in pursuit of building strategies to deter cyber threats. Therefore, it is relevant to discuss the ramifications of threats to India’s nuclear infrastructure, the existing mitigation strategies and ways to fortify further the security of the cyber-physical systems running these nuclear infrastructures.
India’s Nuclear Infrastructure: Cyber Threats and Mitigation Strategies
India’s conception of a civil nuclear programme began much before the devastating effects of atomic energy were demonstrated in Hiroshima and Nagasaki. The chief architect of the nuclear programme, Dr Homi J. Bhabha, envisaged peaceful use of nuclear technology to cater to India’s energy demands after independence. The nuclear programme, therefore, took momentum after India’s independence in 1947 with the introduction of the Atomic Energy Act, 1948. Studies explored the feasibility of setting up nuclear power plants to generate nuclear power, eventually setting the platform for establishing plants in India’s northern, western and southern parts, away from coalfields concentrated in the east (Sethna, 1979, p. 5). By the late 1960s, Indian atomic scientists devised the three-stage nuclear fuel cycle strategy that would allow India to become self-sustaining in terms of the production of nuclear power.
As a fast-developing state, India’s energy requirements are projected to shoot up in the coming years. India’s share of global energy consumption is expected to reach 11% in 2040 from 6% in 2019 due to its economic development and population growth (BP Energy Outlook, 2019). India’s post-COVID-19 energy demand is set to see the fastest growth globally, with a jump of 35% between 2019 and 2030 (International Energy Agency, 2021). While India’s dependency on coal is close to 70%, the state will see notable diversification of energy sources in the coming decades by gradually stepping up the reliance on renewable sources of energy. Parallelly, India seeks to devise climate-sensitive policies to meet its sustainable development goals. The state’s renewable energy capacity stands at 38.27% of the overall installed power capacity as of 2021 (India Brand Equity Foundation [IBEF], 2021).
India’s largely indigenous nuclear programme consists of 23 operational reactors in seven power plants, with eight more under planning and construction. These power plants generate 6,780 MW of nuclear power, contributing to approximately 3.2% of India’s energy source pool. The government has aimed to raise the bar to 5% (22,480 MW) by 2031 (Press Information Bureau, 2021). Some of these reactors are research reactors used for purposes apart from power generation, namely for medical research and making nuclear weapons. India declared itself as a nuclear-armed power after its second round of tests in 1998 (Nuclear Weapon Archive, 2001). For India, nuclear weapons are weapons of deterrence to a more significant degree than weapons of prestige. The country’s nuclear doctrine has confirmed India’s position on No First Use, showing India’s willingness to use nuclear weapons for retaliation only when under a nuclear attack.
The nuclear power plants and the nuclear arsenal are weighty components of India’s nuclear infrastructure. The ramifications of cyber-attacks on these infrastructures will be severe, leaving a long-lasting effect on society. It is important to individually analyse the possible scenarios of cyber-attacks on India’s nuclear power plants and nuclear arsenal and their consequences.
The scale of repercussions can extend along a broad spectrum depending on the attacker’s goal. The DTrack trojan that attempted to penetrate the administrative computer systems in the Kudankulam nuclear power plant in Tamil Nadu, India, is reported to have been deployed to download and transfer information from the plant’s control system. The malware had hardcoded credentials to access the internal network of the nuclear plant, proof that it was a targeted attack. Had the trojan been left undetected, it could have perforated into the computer’s SCADA software to spy on the plant’s functioning. North Korea-related Lazarus Group had allegedly written the codes for the malware (Gavriel, 2019). Since the attack did not cause any disturbance to the nuclear plant, the government did not dig deeper into the perpetrator’s identity. Instead, officials acknowledged the necessity of strengthening India’s cyber security measures and upgrading the cyber security policy (Paliwal, 2019).
The Stuxnet worm that infected the systems at the Natanz facility in Iran in 2010 reprogrammed the centrifuge to malfunction and eventually, wear out. For months together, the worm controlled the centrifuge to work at varying speeds. It increased the speed from 63,000 to 84,600 rpm for about 15 minutes and drastically decreased it to 120 rpm before increasing it again. At least 164 centrifuges in the facility were subjected to this predicament and went unnoticed by employees for a long time. The Iranians had to decommission 20% of the centrifuges in the facility due to erratic patterns (Langer, 2013). Though contested by Iranian officials, the sabotage attempt on the Natanz facility in 2021 seems to be a cyber-attack that caused an explosion leading to failure in the generator that fed power to the centrifuges for Uranium enrichment (Bergman et al., 2021; Chulov, 2021). These incidences have demonstrated some possible ways nuclear power plants can be attacked; this should be of great concern to India.
The consequence of these attacks was mostly limited to the concerned state working on bolstering its cyber defences to prevent further attacks. Following the Natanz attack in 2010, reports show a spike in cyber-attacks on infrastructures in the USA and allied states, like Israel and Saudi Arabia, mainly the financial and power sectors (Sen, 2015). Post the 2021 attack on Natanz, Iran declared its plan to accelerate uranium enrichment to 60%, which presented a hurdle for the Iranian nuclear negotiations (Fassihi et al., 2021). Such restricted post-attack actions emerge from attribution issues. Lack of concrete evidence and mere speculation about ‘who’ the perpetrator was and ‘why’ they did so had restricted the investigation to the ‘what’ and ‘how’. The existing geopolitical situation, not forensic details, induced Iran’s accusation of Israel for the 2021 attack. Israel’s prowess in cyber conflict, its explicit rivalry with Iran and corroboration of its involvement in the 2010 Stuxnet attack has made the state the chief suspect. Otherwise, the narrative has wildly been revolving around suppositions. India could find itself in the same situation if forensics, which can be easily manipulated, leads to Pakistan or China. Irrespective of whether any of these states executed the cyber-attack, the inter-state tensions could further flare-up, disturbing the geopolitical stability.
The actual apprehension is about a more severe consequence. For instance, a disruption in the generator or cooling systems of the power plant could have caused prolonged hours of a power shutdown or reactor meltdown, leading to the release of radioactive materials. Radioactive leaks in the air and water will adversely affect human health and the environment. One can expect a Chernobyl or Fukushima level accident provoked by these kinds of cyber-attacks, compounded by under-skilled staff. Cyber-attacks could cause a chain reaction that triggers large-scale accidents even though the attacker did not intend to inflict an incident of that degree. The IAEA has drawn attention to several scenarios that can roll out when a civil nuclear facility is attacked (International Atomic Energy Agency [IAEA], 2011, p. 39). It will be helpful to probe into such scenarios with reference to the Indian context.
Scenarios
Scenario building exercises can uncover logically plausible triggers and outcomes that ultimately aid preparedness. Drawing from cyber incidences on nuclear infrastructures, like the attack on the Natanz facility in Iran and Kudankulam plant in India, one can build a possible set of cyber-attack scenarios and how they can play out. This section discusses similar scenarios in the case of nuclear power plants and nuclear arsenal.
Case 1: Nuclear Power Plants
Case 2: Nuclear Weapon Systems
Nuclear weapons are, firstly, weapons of deterrence before anything else. They maintain strategic stability between states. The idea is that two nuclear-armed states are unlikely to go to war as parity in power is maintained by their respective nuclear forces. However, such a situation may give way to a stability-instability paradox. It means that despite little to no chance of nuclear-armed states going for total war, low-intensity or grey zone conflicts can persist without the propensity for massive retaliation (Kapur, 2017, p. 800). Additionally, the introduction of disruptive technologies, like cyber weapons may alter or disturb the strategic stability of stable deterrence with relative ease.
The NC3 systems are critical to the operation of nuclear weapons. A cyber-attack on the NC3 can decide nuclear weapons’ behaviour as per the attacker’s interest. The malware can be fitted during the NC3 development, activated when needed and not injected during the planned attack. There are two ways in which a hacked NC3 system can direct the operations of nuclear weapons. The first option enables a misled nuclear launch, while the second option disables a nuclear launch when required. The former is ‘enabling or positive control’ and the latter, ‘disabling or negative control’ (Futter, 2016a, b, p. 14). The processing of these controls will affect the use of nuclear weapons, especially during tense times of crisis.
Positive or Enabling Option
In this case, the hacker’s malware injected into the NC3 can cheat the early warning information systems by creating false flags about a nuclear attack. The false flags shown by the malware deceive the NC3 system to believe that an attack is underway when none is, thereby sending inaccurate data and signals to the central command. The misinformed commanders could give the go code for the launch of nuclear weapons, resulting in an inadvertent nuclear strike. If the state that suffered the strike possesses the second-strike capability, it might lead to mutually assured destruction, ruination any rational state would try to avoid. Non-state criminal actors or proxies supported by rogue states have more propensity to execute such cyber-attacks as they have significantly less stake.
Negative or Disabling Option
Another way of exploiting the NC3 systems is by dismantling the ability of the nuclear weapons to launch when there is a necessity. The cyber-attack can jam signals and prevent the message from being transmitted to the command and control, keeping the target state unaware of an imminent attack. The malware reprograms the NC3 to spoof the early warning system, including satellites, radars and sensors, so they malfunction and do not flag any threat. The malware can also steal information on the arsenal’s functions through this sabotage attack. While disabling a nuclear attack using the negative option is a welcome technique when a rogue state or non-state actor decides to launch the nuclear weapons so it can be prevented, it might prove to be counter-productive for states with second-strike capability, especially when they are already under attack (Bommakanti, 2018; Poornima, 2020, p. 116). Table 1 is an illustration of the two cyber-nuclear options.
India’s NC3 is dependent on ‘fibre-optic cable, radio and microwave links, satellite links between nuclear warhead sites, sufficient to support dispersed missile launcher sites and fighter-bomber units on various airfields’ (Hayes, 2021, p. 24). Apart from the central nuclear command authority, India has set up other command and control infrastructures with separate chains of command as a backup during emergencies. Although a robust NC3 system with adequate contingencies is in place, these systems’ heavy reliance on cyberspace ultimately exposes it to zero-day vulnerabilities and cyber-attacks.
Enabling and Disabling Option.
India, Pakistan and China share borders and are nuclear-armed. India’s ties with Pakistan and China are not cordial, while Pakistan and China are cosy. Recurring incidences of border incursions, diplomatic spats and prevailing public sentiments have only worsened the degree of mistrust in India-Pakistan and India-China relations. A rogue actor can exploit this lack of confidence between India and the two neighbours by initiating a cyber-attack. A cyber-attack on any of these states’ NC3 is a very appealing option for non-state criminal actors who seek to benefit from the resulting uncertainty and instability in Southern Asia.
Consequences of Nuclear Incidents
The list of scenarios of cyber-nuclear incidents is not exhaustive as there could be a myriad of triggers that will continue to bank on cyberspace to challenge the security of nuclear infrastructures. The consequences of these incidents could range from disorder in society and psychological and economic impacts to loss of lives and upset of regional or global stability. In popular culture, the symbolisation of nuclear power is paired with an ensnaring ‘Warning: Radiation Hazard’ sign painted in bright yellow that automatically casts an unsettling psychological trap. This conditioning renders the public gullible to narratives pointing at the lack of adequate nuclear security, which has already been influenced by cases of nuclear accidents, Fukushima being recent (Moser et al., 2013, pp. 128–130). Disturbance to the security architecture of nuclear infrastructures in any form, including cyber-attacks, will produce snowballing effects that engender social panic, which in turn could hurt the nuclear technology market or the state in a broader perspective. Other off-shoots include economic damages as billions of dollars are invested in constructing every nuclear power plant and procuring each nuclear reactor. The collateral damages of nuclear accidents are economically draining, taking years for reconstruction. The towns surrounding Fukushima nuclear plants are still mostly uninhabited and under renovation (Reynolds, 2021). Therefore, the destruction of these critical infrastructures will weigh heavily on the state’s exchequer. Nuclear security disturbance holds the capacity to rile relations between rival states and escalate tensions. This trend is frequently and overtly seen between Iran and Israel, significantly shaping Middle Eastern geopolitics (Ramberg, 2021). Finally, such events could cast a stain on the reputation of the target state as its vulnerabilities will be laid bare. Being considered a regional power and a state with an influential stature in the international order, India cannot afford to give a chance for such exposures.
The fact that a nuclear disaster can inflict irrevocable destruction on society cannot be challenged. There is a requirement for adequate mitigation strategies and defence mechanisms to protect these critical infrastructures. To formulate effective strategies, the nature of cyber threats on nuclear infrastructures and the sources of threats have to be explored, which differs from one state to another. The nature, source and consequences of cyber-nuclear threats for India have been discussed earlier. The following section will assess the existing measures related to nuclear-cyber security in India and the need for additional strategies to bolster cyber security in nuclear infrastructures.
Mitigation Strategies: The Indian Context
The International Atomic Energy Agency has repeatedly emphasised that states build solid cyber resilience mechanisms to protect their nuclear infrastructure from cyber-attacks. The nuclear watchdog has produced a technical guidance manual on cyber threats to nuclear security. The manual provides a comprehensive account of various kinds of cyber threats, the impact on nuclear infrastructures and the means to regulate and secure computer systems in these infrastructures.
Implementing a Generic and Specific Cybersecurity Policy
India does not have a dedicated cyber security framework for nuclear infrastructures. The Department of Atomic Energy and the Atomic Energy Regulatory Board have not devised any regulatory scheme that attends to cyber threats to nuclear security. The defence-in-depth approach has been adopted for securing nuclear infrastructures, specifically from cyber threats (Bhabha Atomic Research Centre, n.d.). The approach uses several layers of defence and firewalls to block a cyber weapon from entering the system. It is an integrated framework with personnel, organisational, technical and structural layers. Technical and human intelligence plays a significant role in fortifying the defence-in-depth. As demonstrated by the cases of cyber-attacks on nuclear infrastructures, these layers have not been entirely unfailing. Since this has the component of a human-machine interface, a fool-proof firewall is not sufficient. Human error and agents infecting the system using a memory stick are possible ways malware can seep into the control system. The United States, through the ‘Nuclear Weapons Personnel Reliability Program’, has drawn a set of procedures and standards to vet the person before recruiting and investing responsibilities. The document also mentions the standards to disqualify an employee if found incompetent (Department of Defence, 1995). Along with a general and sector-specific cyber security policy, India can benefit from formulating a similar plan to guarantee employee integrity and competence.
The proposed National Cyber Security Strategy 2020 supposedly acknowledges India’s nuclear infrastructure threats from cyberspace (Data Security Council of India, 2020, p. 1). The cyber-attack on the Kudankulam nuclear power plant in 2019 gave impetus to the discussion on India’s cyber deterrence. The incident strengthened the fact that India’s critical information infrastructures are not entirely secured and showed the level of preparedness. The cyber strategy aims to boost India’s cyber resilience across domains. It will provide for the establishment of a single overseeing body for cyber security. The formulation of CERT-IN’s Cyber Crisis Management Plan that maps out counter-measures for cyber-attacks is under development (Lok Sabha, 2020). The management plan at the central level has not seen a credible headway and is still in the planning stage. However, Madhya Pradesh became the first state to develop a state crisis management plan in 2021 with the direction of the National Critical Information Infrastructure Protection Centre and the approval of CERT-IN (The Pioneer, 2021)
A coordinated plan is essential to enable a robust cyber defence for India’s nuclear infrastructures. Such plans can foster enhanced inter-sectoral cooperation for efficient incidence response or prevention measures. The plan should also involve regular evaluation of the systems’ cyber resilience status, proactive reporting of vulnerabilities and software upgradation to patch those vulnerabilities. However, a dedicated, sector-wise guidebook on cyber deterrence and crisis response measures is much more of a necessity. Every critical infrastructure will have different standards of operation and vulnerabilities, even though similar cyber-physical systems control them. The consequences of a cyber-nuclear attack would be much different and more devastating than a similar attack on another critical infrastructure. A more effective method of securing these systems is adopting specific cyber-resilience plans for each sector.
The cyber security strategy must include provisions for simultaneously bolstering comprehensive ‘left-of-launch’ and ‘right-of-launch’ cyber capabilities to deal with cyber-attacks. Left-of-launch capabilities include preventive measures, like neutralising a cyber threat before it is engaged and ensuring personnel integrity. A pre-emptive cyber-attack is an effective left-of-launch measure. In comparison, right-of-launch capabilities include measures to be activated after the launch of a cyber-attack, including the tightening of firewall or network defences and retaliation attacks. Experts believe that amping up left-of-launch capabilities will help reduce the burden on right-of-launch capabilities (Futter, 2016a, b).
Monitoring, Evaluating and Incentivising
As discussed before, malware can be injected into the system even during the development phase and employed later. The GAO recognised this issue and produced another report in 2021 as a follow-up for the 2018 edition. As per the 2021 report, the US DoD routinely evaluates weapons for cyber resilience and has enhanced better cyber security testing at the weapon development stage (GAO, 2021). This issue is pertinent even for India as it increasingly opens up the nuclear energy sector to private players. An official announcement in 2020 has made public-private participation in building research reactors easier (Business Insider, 2020). More the players, more the windows for threat. On the flip side, more stakeholders can contribute to building cyber resilience in nuclear infrastructures. Progressive reforms, like the relaxation of private participation in the nuclear sector must be accompanied by adequate regulatory frameworks to monitor nuclear security.
Apart from the formalisation and introduction of the National Cyber Security Strategy, evaluating the implementation and compliance of the strategy is imperative. Developing a compliance index and offering incentives to ensure the efficient execution of the strategy at the central, state and sectoral level is an indispensable part of tightening the cyber security strategy of India. Indices have proven to be fruitful for the gradual progress of different sectors in India. In the same way, cyber security indices can give impetus to better cyber resilience measures in these critical sectors, including in nuclear infrastructures.
Implementing Confidence-building Measures
The characteristics of hybrid warfare and cyber conflicts that fall in the grey zone emanate a lot of uncertainty and ambiguity. While working on the technological aspects, the international consensus among states has to be gained, acknowledging the emerging threats. In that process, implementing confidence-building measures, especially with adversaries, can prove beneficial for India during times of crisis, like in the case of an inadvertent cyber-nuclear attack. Confidence-building measures can include data-sharing, flagging of threats and sharing best practices in the field of nuclear-cyber security.
Call for an International Agreement
A core concern that discourses on cyber security indicate is the absence of a universally-accepted definition of terms associated with cyberspace. An international agreement on cyber security is a prerequisite for fostering a common understanding, thus assembling protocols and strategies that can help build cyber resilience as well as retaliatory measures permitted in the face of a cyber-attack. These agreements can potentially disincentivise at least state-based cyber attackers. It would be in India’s interest to garner international support to bring up an international agreement on cyber security.
Conclusion
With just a mouse click, it is possible to bring down industrial infrastructures, like nuclear infrastructures. Changing characteristics of warfare has given the grounds for hybrid warfare to thrive and deploy cyber technology for its advantage. The lack of precision and consensus regarding what constitutes hybrid warfare and the possible responses to tackle this means of warfare has given an extraordinary edge for those actors honing their hybrid warfare capabilities. Of many means, cyber technology has been among the most relied upon to carry out operations without being physically proximate to the target, with a massive amount of uncertainty. The pace at which cyber weapons have been evolving points at the manifestation of cyber conflicts and their role in affecting global stability.
The issues of deniability and ambiguity, making attribution dicey, have given cyber-attacks the catbird seat. Difficulty in swiftly processing forensics details hampers chances of tracing the address of the cyber-attack as it gives the hacker to morph or foul up the address, therefore, misdirecting forensic investigations. Attribution of attacks is necessary to know the what, why, who and how of the attack, which in turn can contribute to the identification of threat sources and formulation of mitigation strategies. Approaches like that established by the Q model can resolve the attribution hiccup to an extent, though it is not possible to develop an infallible model. This limitation is because of how cyber technology metamorphizes and presents newer zero-day vulnerabilities that can be exploited.
Evolving trends in warfare have given state and criminal non-state actors a lucrative alternative to traditional means of confrontation that needs physical presence and is expensive. Instead, attacking the critical infrastructures with a cyber weapon can inflict equal, if not more, damage to the target actors. Nuclear infrastructures are growingly becoming targets of such attacks as they can potentially provoke a broad spectrum of ramifications that can cause irrevocable destruction to the human race. Nuclear accidents in the past have revealed the various impacts on society, from human fatalities and economic depletion to environmental degradation. Cyber technology can inflict just the same amount of damage by attacking nuclear infrastructures. A cyber-attack on NC3 of India’s nuclear forces, a possibility that the state cannot neglect, can cause confusion and inadvertent repercussions that disturb geopolitical stability. Such threats can arise from within the state or outside, both being tricky to cull out.
India has employed the defence-in-depth approach to protecting nuclear infrastructures from cyber-attacks, involving complex layers of technical and personnel security measures. Nevertheless, the delay in the introduction of a national policy for cyber security has slowed down the efforts to strengthen the state’s cyber resilience. The speedy implementation of the National Cyber Security Strategy will benefit India’s cyber security efforts. Other supplementary means construe confidence-building measures, incentives for compliance with nuclear-cyber security measures, and garnering convergence on the need for an international agreement on cyber security. These initiatives are essential to attain a wholesome cyber defence mechanism.
The ubiquitous, transboundary, and cost-effective platform offered by cyberspace has bestowed the power of relevance and superiority on it. Quoting Oleksiy Yasinskiy, a cyber specialist, ‘Who controls cyberspace controls the world’ (Luhn, 2017). The discourse on cyber security must continually evolve to cater to the emerging cyber threats to critical information infrastructures, including nuclear infrastructures.
Footnotes
Acknowledgements
The author would like to thank the two anonymous reviewers for their comments on the article. An earlier and much shorter version of the article was submitted to the Centre for Land Warfare Studies (CLAWS) for its annual flagship Field Marshal Manekshaw Essay Competition (FMMEC) 2019–2020, and was published in the edited CLAWS book titled National Security Challenges: Young Scholars’ Perspective in 2020.
Declaration of Conflicting Interests
The author declared no potential conflicts of interest with respect to the research, authorship and/or publication of this article.
Funding
The author received no financial support for the research, authorship and/or publication of this article.
