I came across this Chatham House report by (lead author) Caroline Baylon and others, on cybersecurity in nuclear power plants.

Apparently the authors looked at some 50 incidents worldwide, with only a few having been publicly noted.

Apparently the operating engineers and cybersecurity people don't talk to each other much in language that the other understands. This happens quite frequently in all sorts of industries, it seems.

Operators apparently often believe their facilities are "air gapped": no connections to the Internet. But it seems they don't check, for often any "gap" is bridged. Someone installed a VPN to allow himher to work from home. Someone brings in hisher laptop, hooks it up to plant systems while at work, uses it for whatever while elsewhere, at home off-duty if an operator, or at the other workplace if a contractor. People don't reset default factory passwords on installed third-party kit. Monitoring systems are retrofitted, with networked reporting.

This sounds like the same old stuff. We could imagine it should be caught by a decent cybersecurity audit. There probably are such audits. But apparently they are not bringing up the things which have resulted in incidents. Or maybe they are now?

