What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sellafield Ltd was prosecuted for failures in planned cyber-security controls, not because regulators found that an attacker had successfully compromised the site. The company pleaded guilty to three offences covering protection of sensitive information and required annual checks of its IT and operational-technology systems. In October 2024, the court fined it £332,500 and ordered it to pay £53,253.20 in prosecution costs.

Why was Sellafield prosecuted?

The Office for Nuclear Regulation (ONR) prosecuted Sellafield Ltd under the Nuclear Industries Security Regulations 2003. The offences concerned management of IT security from 2019 to 2023 and failures to meet obligations in the company’s approved cyber-security plan. Sellafield pleaded guilty to all three charges in June 2024.

The charges were about whether required protections and checks were in place. They were not a finding that a cyberattack had succeeded.

What cyber-security failures happened?

The three offences addressed separate weaknesses in the planned controls:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Protection of sensitive information: inadequate protection of Sensitive Nuclear Information on the IT network.
  • Operational technology (OT) checks: failure to arrange an annual authorised Check-scheme health check for OT systems by 19 March 2021.
  • IT checks: failure to arrange the equivalent annual authorised health check for IT systems by 1 March 2022.

IT systems support information and business operations; OT systems control or monitor physical industrial processes. The offences therefore covered both the information network and systems relevant to operating the site.

Was Sellafield hacked?

ONR said the long-running shortfalls left systems vulnerable to unauthorised access and data loss, but stated there was no evidence that the identified vulnerabilities had been exploited. That distinction matters: the prosecution concerned deficient security arrangements, not a confirmed breach or data theft.

In a 2023 warning, an ONR inspector said a successful ransomware attack could affect high-hazard risk-reduction work and that restoring normal IT operations could take up to 18 months. Sellafield’s own analysis identified phishing and a malicious insider as possible routes to loss or compromise of key systems and data. These were risk scenarios, not reports of attacks that had occurred.

How much was Sellafield fined?

Penalty Amount What it covers
Court fine £332,500 Fine imposed after the guilty pleas; ONR reported the sentence on 2 October 2024.
Prosecution costs £53,253.20 Costs ordered by the court, separate from the fine.

ONR assessed culpability as medium, at the high end of that category. After sentencing, ONR Senior Director of Regulation Paul Fyfe said the company’s ability to comply with certain obligations under the regulations over a four-year period had been poor.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why does cyber security matter at Sellafield?

Sellafield is a West Cumbrian site that has operated since the 1940s and employs approximately 11,000 people, according to ONR’s site profile. Its work now centres on decommissioning and clean-up, secure storage of special nuclear materials, and retrieving waste from legacy ponds and silos.

That mission makes cyber resilience relevant to more than ordinary business continuity. An IT disruption could impede risk-reduction work at a site handling high-hazard legacy materials. ONR’s ransomware warning described a potential consequence of an attack; it did not say that an attack had interrupted those operations.

What has changed since the prosecution?

Date Regulatory development
2021 ONR formally raised concerns about cyber-security adequacy and required short- and medium-term improvement strategies.
June 2024 Sellafield pleaded guilty to all three charges.
2 October 2024 The court imposed the fine and prosecution costs.
19 February 2025 ONR returned physical-security oversight to routine attention; cyber security remained at significantly enhanced attention.
19 November 2025 ONR lowered cyber-security attention from significantly enhanced to enhanced, citing substantial progress, added resources, stronger governance and appointment of a new Chief Information Security Officer. It said more work remained before routine attention could be considered.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is Sellafield’s cyber security fixed now?

ONR’s 19 November 2025 update indicates improvement, but not completion: cyber security moved to enhanced attention, rather than routine attention, and the regulator said further work was required. “Enhanced” and “significantly enhanced” describe levels of regulatory attention; the update does not establish that every weakness has been resolved or that future risk has been eliminated.

The National Audit Office separately reported difficulty recruiting cyber-security specialists and said Sellafield’s cyber risk was outside its corporate appetite. It also noted that broader staffing, project and delivery problems affected value for money. Those findings provide organisational context, but they do not change the legal basis or scope of the three cyber-security offences.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.