NUCLEAR & SMR — 01

Nuclear Security

Physical security, procedural security, and electronic security do not operate in isolation at an operating nuclear facility. They should not be assessed that way either — GSS evaluates all three together, against the Design Basis Threat.

OPERATIONAL CONTEXT

Security that is only as strong as its weakest layer

Most protective strategies are not built badly — they are built in pieces. One vendor sizes the fence line and delay barriers. Another specifies cameras and intrusion sensors. A separate team writes the response procedures and staffs the complement. Each piece can pass its own review and the system can still fail, because the gaps that matter most sit at the seams between disciplines, not inside any one of them. GSS was founded in 2012 on the premise that nuclear security has to be delivered holistically rather than as a set of isolated services, and that is still the operating model.

Our assessments start from the Design Basis Threat, not from a facility's existing equipment list. Physical measures — barriers, hardening, standoff, delay — are evaluated against what the DBT actually grants an adversary in tools, numbers, and capability. Electronic measures — sensors, assessment, communications, systems integration — are evaluated under real operating conditions, not vendor specification sheets. Procedural measures — protective strategy, response, complement — are evaluated against the timeline the other two layers actually produce, not the timeline someone assumed when the plan was written.

The team doing this work includes former U.S. special operations operators, engineers, and executives who have run security organizations at the C-level, alongside a cyber-physical practice led by former U.S. NRC inspectors who helped author the cybersecurity regulations that govern U.S. plants today. That mix — operational, engineering, and regulatory experience in the same room — is what lets an assessment speak to how a facility actually defends itself, not just how its documentation says it does.

METHODOLOGY
01Threat Basis ReviewThe applicable Design Basis Threat is established before any layer of the site is assessed against it.
02Layered AssessmentPhysical, electronic, and procedural security evaluated together, from the controlled area boundary inward.
03Pathway & Vital Area AnalysisAdversary routes and vital areas identified and cross-checked against target sets.
04Protective Strategy DevelopmentResponse, complement, and procedures sized to the delay and detection the site actually provides.
05Documentation & Regulatory AlignmentFindings translated into licensing-basis documentation a regulator can review.
06SustainmentPeriodic reassessment as the threat basis, the facility, or the regulatory posture changes.
CORE CAPABILITIES
Design Basis Threat-based assessmentPhysical, procedural & electronic security integrationVital area & target set analysisProtective strategy developmentLicensing-basis documentation supportRegulatory engagement
RELEVANT ENVIRONMENTS
Operating nuclear power plantsSmall modular reactorsFuel cycle & research facilitiesOther high-consequence critical infrastructure

Get a security posture assessed against the threat it actually faces

Request a Consultation