
Physical security
Assessing the security of a proposed facial recognition system.
How we’ve helped owners, operators and investors of critical assets protect what matters, for a fraction of the expected cost.
Case studies
Investment & Asset Management · One of Europe's largest renewable investors
Unable to insure their power generation assets against cyber attack, the client invited a tender from their site operator to improve cybersecurity. The operator's proposal required a three-year programme of work (£1m of CapEx and £1.2m of OpEx per site) which would have eroded the returns from the assets very significantly and was out of appetite. It was also built on a regulatory compliance model, despite the assets falling beneath the regulatory threshold.
We worked with the client and site personnel to understand the financial exposure of the sites to cyber events. Based on that analysis and the client's budget appetite, we designed a pragmatic solution to reduce risk at a much lower cost than the operator's proposal, built around the cyber threats the sites actually faced rather than compliance against non-applicable standards, and not reliant on the existing site operator.
Outcome
Aligned to the key requirements for cyber insurance to support future placement, and delivered with minimal planned interruption, without disrupting power generation.
Energy & Utilities · Templeborough Power Station
The owner of a biomass renewable power station wanted to implement a programme to improve cybersecurity, but did not want to rely on the existing site operator to implement the changes or operate the solution going forward. There was no in-house expertise in running cybersecurity improvement programmes, delivery involved multiple technologies and third-party vendors that needed coordinating, and the changes had to be rapidly implemented within a planned short outage window.
We oversaw the planning, programme management and technical delivery of the entire implementation, creating the high-level and low-level technical designs along with the associated governance policies, procedures and processes, and undertaking extensive technical integration work on the ground at the site. We also identified additional risks at site due to redundant technology, and put in place a comprehensive training and handover workstream for the client and site personnel.
Outcome
The work raised resilience and cybersecurity maturity through new technology and governance, and de-risked the site by decommissioning redundant technology no longer in use.
More recent work

Physical security
Assessing the security of a proposed facial recognition system.

Perimeter security
Deploying a solution to protect the site's perimeter defences.

Data security
Risk assessment and remediation of the site's data egress solution.

Third-party assurance
Designing a third-party assurance regime for the UK public sector.
And more across energy, manufacturing, infrastructure and investment.
Contact
We work with a small number of senior leadership teams each year on high-value, high-stakes challenges. If yours is one of them, get in touch.