Kwang Seop Son, Inhye Hahm, Jae-Hwan Kim, Jae-gu Song
Cyber risk in nuclear facilities evolves over time due to changes in threat conditions, newly identified vulnerabilities, and modifications to security controls, even when system functions and safety boundaries remain unchanged. However, existing cyber risk assessment approaches for nuclear power plants lack a systematic mechanism for quantitative reassessment that reflects evolving security conditions. This study proposes a risk-informed cyber risk assessment framework that explicitly links security control effectiveness, threat conditions, and risk acceptance criteria within an iterative feedback structure. Instead of directly estimating attack probabilities, the framework quantifies the likelihood of cyber compromise through the assessment of security control difficulty and effectiveness, while cyber-induced consequences are evaluated using established consequence categorization schemes and probabilistic safety assessment models. By maintaining a consistent baseline reference, the framework enables quantitative comparison of cyber risk across successive reassessment cycles. The applicability of the proposed framework is demonstrated through a case study involving a Maintenance and Test Panel within a Reactor Protection System. The case study illustrates the establishment of baseline cyber risk, reassessment under newly identified vulnerability conditions, and the quantitative evaluation of security control enhancements introduced to restore acceptable risk levels. The results indicate that the proposed framework provides a structured and defensible approach for maintaining cyber risk within acceptable bounds under evolving threat conditions, supporting risk-informed cybersecurity decision-making for safety-critical digital assets in nuclear facilities.