Global Hyperscaler Transforms Subsea Cable Risk Management and Compliance with Bridewell banner image

Global Hyperscaler Transforms Subsea Cable Risk Management and Compliance with Bridewell

As a trusted partner, Bridewell delivered a comprehensive governance framework that transformed risk management and regulatory compliance for subsea cable operations.
Subsea cable systems are the backbone of global internet connectivity, carrying over 95% of intercontinental data traffic. Their operational integrity is critical to commerce, communication, and national security. As demand for bandwidth grows with the rise of cloud and AI technologies, our client recognized the need to enhance capability, capacity, and compliance across subsea cable infrastructure.

Our client, a global hyperscaler, chose to partner with us to address these challenges, with the aim of delivering integrated compliance and risk management solutions, focusing on access management, vendor assessments, and U.S. Government audit readiness.

Cable System Access: Automated Management for Security and Compliance

Subsea cable system operators, based out of the U.S., need to comply with National Security Agreements (NSAs) that restrict access to sensitive subsea cable facilities, systems and information, requiring robust controls for both physical and logical access. Cable systems, which fall under the remit of an NSA, are known as a Regulated Cable System.

Organizations and individuals, such as engineers and Network Operating Center (NOC) analysts, who require physical and/or logical access to Regulated Cable Systems, are required to undergo a thorough screening process and are subject to approval by the U.S. Government. This screening process is a regulatory requirement and requires annual reports to be submitted to the appropriate government agencies.

Bridewell designed and implemented an automated access management system tailored to our client’s requirements. This system:

  1. Centralized the database of approved personnel.
  2. Automated request and approval workflows.
  3. Integrated with our client’s access control hardware/software.
  4. Maintained audit logs for compliance tracking.
  5. Allowed a straightforward review of access control lists for each Regulated Cable System.
  6. Provided expiration alerts for re-verification of access rights.

The Results

  • Efficiency: Reduced manual approval times from days to hours.
  • Accuracy: Automated verification minimized human error.
  • Compliance: Real-time logging and reporting supported regulatory audits seamlessly.

Streamlined Vendor Assessments: Standardization and Automation

Our client’s vendor assessment process was manual, slow, and lacked consistent risk treatment and tracking. This resulted in:

  • Inconsistent risk treatment: Without standardized criteria, vendors were assessed subjectively, leading to uneven enforcement of compliance and security requirements.
  • Lack of audit readiness: Without a formal assessment process, it became difficult to demonstrate due diligence during audits and apply a consistent approach.
  • Regulatory misalignment: The lack of a formalized vendor risk assessment approach led to inconsistencies and differing approaches to managing key vendors supporting Regulated Cable Systems.

Bridewell developed a structured vendor tiering standard which analyzed a series of inputs to determine the rigor and depth necessary to assess a vendor on an initial and ongoing basis. It also standardized physical and logical security requirements for vendors mapped to ISO 27001. The output included:

  • In-depth compliance assessments based upon NSA requirements.
  • Annual audits and assessments, including site visits to NOCs and Cable Landing Stations (CLSs).
  • Online vendor self-assessment questionnaires.
  • Automated scoring based on predefined security criteria.
  • Centralized evidence submission and feedback.

The Results

  • Speed: Assessment turnaround reduced from weeks to days.
  • Consistency: Automated scoring ensured adherence to standards.
  • Insight: Aggregated data enabled proactive risk management.

NSA Regulatory Requirements: Integrated Risk Control Framework

Our client needed to align NSA processes with a unified risk taxonomy and ensure ongoing compliance. At the time, there was no formal risk or control framework related to the design, build and operational phases of a subsea cable system.

The impacts that resulted were:

  • Regulatory exposure: The hyperscaler was left exposed to compliance failure against the Regulated Cable System NSAs.
  • Inconsistent risk management: The absence of standardized controls resulted in risk identification and mitigation being ad hoc and reactive, increasing the likelihood of gaps in security, access control and incident response.
  • Operational vulnerabilities: Design and build phases lacked formal oversight and defined standards for control implementation, leading to inconsistent design, control implementation, potential vulnerabilities, reportable incidents and service disruptions.

Bridewell implemented a subsea cable system focused risk and control framework that aligned with the full cable system lifecycle (design, build, operate):

  • Designed and implemented a subsea risk framework which aligned with the hyperscaler’s hierarchical risk taxonomy.
  • Designed and implemented a subsea control framework which allocated risks to the various cross-functional teams through all phases of the cable system lifecycle, including risks related to the physical and environmental security of CLSs and NOCs. Conducted risk and control assessments, working with cross-functional teams to address any gaps and areas for improvement.
  • Automated and digitized the risk and control frameworks and assessment through the deployment of specialist Governance, Risk and Compliance (GRC) tooling.
  • Implemented governance through a formalized risk and compliance committee.

The Results

  • Consistency: Single methodology for risk and control ownership, identification and mitigation.
  • Visibility: Centralized documentation improved audit readiness.

Managing U.S. Government Audits: Proactive Readiness

Subsea cable operators are subject to rigorous and recurring audits by U.S. Government agencies to verify compliance with mitigation instruments such as NSAs and other regulatory frameworks. These audits assess not only technical and operational controls but also governance, documentation, and vendor oversight across the entire cable system lifecycle.

Such audits involve the gathering of an enormous amount of evidence, not just across the internal operational teams, but also with all the relevant vendors who manage, support, monitor and maintain the Principal Equipment across the Regulated Cable System infrastructure.

Operators must maintain comprehensive records of access, vendor assessments, incident response plans and physical security measures – failure to produce timely and accurate documentation during audits can result in non-compliance findings, triggering remediation orders or penalties.

Bridewell leveraged the subsea cable system risk and control frameworks to conduct regular “mock audits”, simulating government audit tasks. This process included:

  • Evidence gathering.
  • Policy and documentation review.
  • Deep-dive control assessment.
  • Report writing with mitigation plans.
  • Follow-up actions.

The Results

  • Readiness: Identified and closed gaps before formal audits, easing the process for the live audit with the regulators.
  • Risk reduction: Enhanced preparedness and reduced audit-related risks, providing confidence.

Conclusion

As a trusted partner, Bridewell delivered a comprehensive governance framework that transformed risk management and regulatory compliance for subsea cable operations. Key outcomes included:

  • Reduced administrative overhead.
  • Increased process efficiency.
  • Enhanced audit preparedness.
  • Increased confidence.
  • Strengthened operational security.

These initiatives significantly improved the hyperscaler’s security and compliance posture, ensuring uninterrupted global connectivity and adherence to stringent regulatory requirements.

Global Hyperscaler


Industry

Technology