August 3, 2026

When digital communications became safety-critical

In brief

A network switch replacement at the Edwin I. Hatch Nuclear Power Plant’s Unit 1 on April 23, 2026, demonstrated how digital communications can directly affect industrial safety. The replacement switch was installed with Rapid Spanning Tree Protocol disabled, creating a network loop and a severe data storm. This overwhelmed communications within the GE Mark VI turbine control system, causing the turbine control valves to close while the reactor was operating at full power. At the same time, control-room displays and alarms became slow or frozen, preventing operators from recognizing the valve movement and rising reactor pressure soon enough to intervene before the reactor automatically shut down. The incident illustrates how one network failure can simultaneously disrupt controllers, alarms, interfaces and operator situational awareness.

The article argues that industrial networks should therefore be treated as safety-critical engineering systems rather than merely as information-technology infrastructure. Similar communication failures have previously affected nuclear plants, pipelines, electric utilities, water systems and manufacturing facilities without involving malicious cyberattacks. Existing cybersecurity frameworks address secure configuration and access protection but provide limited guidance on testing whether switches can safely support real-time control under realistic failure conditions. Facilities should include communication failures in safety analyses, validate replacement switches before deployment, identify common-mode failure points, establish redundancy and recovery strategies, and maintain independent monitoring paths so operators can still verify essential process conditions when the primary network fails.

Source: Control Global

Explore More Insightful Articles: