The client required an OT cyber risk approach that reflected operational reality – not a generic IT-centric compliance exercise..
Client Context
A water utility operating critical SCADA and control systems, subject to regulatory obligations and increasing scrutiny of cyber risk governance..
Ask / Requirement
The water sector client engaged SIS to establish a pragmatic, risk-based Information Security Management System (ISMS) for ICT, SCADA, and control systems – to manage OT cyber risk to business-critical systems and meet regulatory and governance obligations.
Existing security practices lacked the structure needed to demonstrate defensibility across both ICT and SCADA environments.
What We Delivered
SIS delivered an ISO/IEC 27001-aligned ISMS, tailored to the client’s operational context, including governance, risk management processes, incident management, and business continuity considerations.
The ISMS was designed to be practical and maintainable by the client’s team – not a compliance artefact that would sit on a shelf. It reflected the realities of running water infrastructure, not a generic IT security template.
Outcome
The client achieved a defensible, auditable security framework that satisfied regulatory obligations and materially improved OT cyber risk management. The ISMS gave the client a structured basis for ongoing governance and a credible position in the event of an audit or incident review.
If you’d like to know more about our many years of experience in providing industrial cyber security solutions: