Cloud computing is increasingly being adopted in nuclear and radiological monitoring systems to address the limitations of traditional on-premises infrastructures. Radiation Detection Systems (RDS), which rely on distributed sensor networks, generate large volumes of data requiring scalable storage, real-time processing, and secure transmission. While cloud integration enhances flexibility, mobility, and cost efficiency, it introduces significant cybersecurity challenges, particularly in high-consequence nuclear environments. This conceptual study evaluates the integration of cloud computing architectures with nuclear sensor networks and proposes a risk-informed cybersecurity framework tailored for cloud-enabled RDS, using a structured STRIDE threat-to-layer mapping and a qualitative likelihood-impact risk scoring exercise grounded in documented case studies. Key enabling technologies, including Sensor Cloud architectures, Everything-as-a-Service (XaaS), and multi-tenancy models, are examined alongside the Shared Responsibility Model governing cloud security. Threat scenarios such as supply chain compromise, advanced persistent threats, and cyber-physical attacks are analyzed using real-world case studies, including Operation Cloud Hopper and the Triton incident. This analysis indicates that cloud platforms enhance scalability, data availability, and disaster recovery capabilities, but introduce risks related to reduced system visibility, expanded attack surfaces, and dependency on third-party service providers, with supply-chain compromise and sensor-data falsification emerging as the highest-priority risks under the qualitative scoring applied here. A layered cybersecurity framework aligned with IAEA Nuclear Security Series guidance and international cybersecurity standards is proposed, addressing data protection in transit, at rest, and during processing. This study suggests that cloud computing may be securely adopted in nuclear sensor networks when supported by robust governance, regulatory alignment, and risk-informed cybersecurity controls; this conclusion is conceptual and desk-based, and would require expert validation, simulation, or pilot deployment before being treated as an operational recommendation.
Securing cloud-enabled radiation detection systems: a risk-informed cybersecurity framework for nuclear sensor networks
Christopher M. Spirito
