The Challenge
Our client is a UK-based water company that is within scope of the NIS Regulations and required by their competent authority, the Drinking Water Inspectorate (DWI), to submit a self-assessment against the National Cyber Security Centre (NCSC) Cyber Assessment Framework (CAF).
To comply with the 16 initial outcomes set out by the DWI, our client had put a cyber resilience improvement program in place to make the necessary changes. Our client was regularly tracking their position against the outcomes and were rating themselves as Fully Achieved against 8 of the 16.
The Solution
Based on our extensive experience with the CAF and the water sector, this water company chose Bridewell to validate this position. Where the company had assessed itself as ‘Fully Achieved’ against an outcome, Bridewell was to assess each individual Indicator of Good Practice (IGP) to validate the position. Where the company had assessed itself as ‘Not Achieved’ against an outcome, Bridewell was to review the proposed remediation to verify if the outcome would be ‘Fully Achieved’ once delivered.
Typically, we would perform this type of assessment by reviewing relevant documentation and interviewing key stakeholders from a range of different teams to gain full understanding of the implementation, management, and operation of cyber security measures to meet IGPs.
However, on this occasion, the client only requested assessment through interviews with the information security team. Whilst this differed from our usual approach and meant we were unable to provide any assurance over the controls in place, the approach allowed us to quickly gain adequate understanding of the state of cyber security across the 16 outcomes.
The Results
Bridewell provided a comprehensive report with the findings from the assessment, detailing:
Our assessment of attainment against each IGP for the 8 outcomes the client had rated themselves as fully achieved with full explanation and recommendations for improvement for any IGPs we believed were not being met.
Our assessment of the plans in place to meet the deficient IGPs across the 8 outcomes the client felt they were not meeting, with recommendations for additional measures that should be adopted where we felt current plans would not deliver attainment against any of the outcomes IGPs.
Executive summary detailing the approach to the assessment and the main findings.