The threat model is physical and digital convergence at gigawatt scale. Southern Nuclear operates eight nuclear units across the southeastern United States - Plant Farley in Alabama, and Plant Hatch and Plant Vogtle in Georgia - supplying carbon-free electricity to Alabama Power and Georgia Power. With more than 50 years of operational history, the company is also the entity that brought Plant Vogtle Units 3 & 4 online: the first newly constructed nuclear units to achieve commercial operation in the U.S. in three decades. Vogtle is now the largest generator of clean energy in the country. That kind of infrastructure doesn't just need monitoring - it needs defenders who understand that OT and IT aren't separate conversations.
The technical surface area spans nuclear power generation, nuclear fuel innovation, and nuclear safety - domains where a compromised system isn't a breach notification, it's a regulatory and public safety event. Southern Nuclear's cybersecurity teams operate within an industry that has received more than 10 consecutive Top Innovative Practice Awards, suggesting the organization invests in forward-leaning security and operational practices rather than compliance-minimum postures. The company employs thousands of professionals across its facilities and Birmingham, Alabama headquarters.
What makes this work distinct: the NRC framework, air-gapped and segmented control systems, and the reality that threat actors targeting critical infrastructure are increasingly sophisticated. Southern Nuclear's commitment to cutting-edge nuclear technology means the security stack has to keep pace with modernization - new reactor systems, digital instrumentation, and the expanded attack surface that comes with them. For cybersecurity professionals, this is an environment where domain expertise matters as much as tooling fluency, and where the stakes are written into federal regulation.






