Bridewell was engaged to conduct a comprehensive Cyber Resilience Audit (CRA) against the organisation’s Cyber Assessment Framework (CAF) self assessment to ensure that it was accurate and supported with sufficient evidence to meet regulatory expectations.
The Challenge
The organisation operates a diverse and safety-critical technology landscape spanning enterprise systems and industrial control environments. Key challenges included complex interdependencies across IT and OT, multiple critical operational sites, and increasing regulatory scrutiny. The organisation needed to demonstrate that CAF outcomes were supported by both documented evidence and operational practice, delivered through a consistent multi-phase audit approach.
The Solution
Bridewell applied a structured, risk-based CRA methodology, aligned to CAF requirements and tailored to the organisation’s operational context using a phased approach.
Phased CRA Delivery
The audit was delivered across two phases: Phase 1 focused on Objectives A, C and D around; governance, risk management, security policies, awareness, detection and response. Phase 2 focused on technical application of controls aligned to objective B of the CAF, including; identity and access control, data security, system security and network resilience.
On-Site Assurance
During both phases, Bridewell conducted on-site visits to critical operational locations to validate physical and environmental security, review OT environments, and confirm alignment between cyber security and safety-critical processes. This ensured controls were implemented consistently in practice.
Evidence Validation
Bridewell performed detailed validation of CAF self-assessments through evidence sampling, stakeholder interviews and alignment to Indicators of Good Practice (IGPs). Where gaps or inconsistencies were identified, further clarification was obtained to ensure findings were robust and defensible.
Reporting
A structured variance analysis process was applied to identify differences between the organisation’s self-assessment and Bridewell’s independent review. Bridewell produced a comprehensive CRA report detailing these variances, alongside targeted remediation recommendations and areas of good practice, ensuring a clear, defensible, and regulator-ready cyber resilience posture.
The Results
Bridewell's structured CRA methodology enabled the organisation to obtain an independent and evidence-based view of its cyber resilience posture across both IT and OT environments. By combining experienced CAF assessors, a phased audit approach and on-site assurance activities, Bridewell delivered a streamlined and efficient assessment while minimising operational disruption.
The collaborative approach enabled an efficient audit delivery and reinforced confidence in the organisation’s ability to progress its cyber resilience programme. Clear and defensible reporting aligned to the CAF provided stakeholders with a comprehensive understanding of cyber resilience strengths, areas requiring improvement and overall organisational posture. This provided a reliable basis for governance discussions and informed decision-making by senior leadership and board-level stakeholders
To summarise:
- Independent verification of CAF self-assessment outcomes.
- A consistent and repeatable assessment methodology across IT and OT environments.
- Experienced assessors with strong understanding of Critical National Infrastructure and regulatory expectations.
- Clear, evidence-based reporting suitable for operational stakeholders, executive leadership and board-level audiences.
- Identification of gaps between documented processes and operational implementation through stakeholder engagement and on-site assurance activities.
- Actionable insights to support ongoing cyber resilience improvement and regulatory readiness.
The audit provided the organisation with an independent assessment of cyber resilience across its critical IT and OT environments, supported by detailed evidence validation and on-site assurance activities. The final CRA report delivered a clear and regulator-ready view of cyber resilience posture, identifying strengths, improvement opportunities and examples of good practice. Through Bridewell's structured assessment methodology, the organisation gained increased confidence in its CAF self-assessment and a stronger foundation to support ongoing cyber resilience improvement activities.
Gas Distribution Operator