Skip to main content
STRJ Digital Consultancy

Available

Call Jaipal on 07595 333762
Call Jaipal Book a free call

Services / Cybersecurity & compliance

Regulatory compliance, done by someone who has actually sat in the plant

CAF, NIS and NIS2, CIS Controls, IEC 62443. Business analysis and programme delivery for operational technology environments where the security control and the turbine are part of the same conversation.

from £3,500

Fixed-scope assessments, priced in writing. Embedded programme analysis from £595 a day.

An engineer reading instrument panels in a power station control room

Who this is for

Regulated operators with a deadline and a framework

Energy generation and networks. Water. Transport. Healthcare. Manufacturing with real plant behind it. Organisations that fall under NIS, are being assessed against the Cyber Assessment Framework, or have decided that CIS Controls are the sensible way to get their estate under control.

Usually the trigger is one of three things: a regulator has been in touch, an audit is coming, or somebody senior has looked at the OT estate and realised nobody can produce an asset inventory.

Typical engagements

  • CAF readiness and gap assessment, Basic or Enhanced Profile
  • NIS and NIS2 compliance programme analysis
  • CIS Controls implementation, IG1 through IG2
  • OT/IT security requirements and architecture documentation
  • Supplier and contract assurance against compliance obligations
  • Audit-ready evidence and risk attestation packs
  • Embedded business analysis on an existing security portfolio

Track record

Where this has actually been done

Not theory. These are engagements delivered, not frameworks read about.

An engineer checking an electrical control box at a power plant

Power generation

Drax Power Station

NIS compliance programme across the cyber security portfolio. Supplier obligations reviewed against CAF Enhanced Profile, contractual gaps identified, remediation scoped and taken through governance.

Electricity transmission pylons and power lines at dusk

Electricity interconnectors

National Grid Ventures

NIS portfolio lead across Dispatch systems at interconnector sites. Twelve workstreams defined, current and future-state security architectures established, audit and attestation documentation produced.

A pharmacist working at a dispensary counter

Healthcare

Pharmacy2U

CIS Controls transformation across roughly a thousand devices in a 24/7 pharmacy operation. IG1 to IG2 roadmap, aligned to NHS DSP Toolkit and GDPR, built on existing tooling.

Frameworks and standards

  • NCSC Cyber Assessment Framework — Basic and Enhanced Profile
  • NIS Regulations and NIS2 Directive
  • CIS Controls v8, Implementation Groups 1 and 2
  • ISA/IEC 62443 and the Purdue model
  • NIST Cybersecurity Framework
  • ISO 27001
  • NHS Data Security and Protection Toolkit
  • UK GDPR

Credentials

  • SC clearance — current and valid
  • CISSP and CISM — both in progress
  • BEng (Hons) Internet Engineering, Aston University
  • Twenty years of business analysis, the last several in OT security and CNI
  • Industry-first vehicle telematics patent; JLR Innovista Awards finalist

Engaged through STR Lines Limited. Comfortable working inside or outside IR35 — tell me the determination and I will work to it rather than argue about it.

What it costs

Published, like everything else here

CAF readiness & gap assessment

from £4,500

CIS Controls gap analysis & roadmap

from £3,500

Embedded programme analysis

from £595 / day

Fixed-price assessments are exactly that — a defined scope, a defined deliverable and a number agreed before anything starts. Longer programme work runs at a day rate because pretending to fix-price eighteen months of regulatory change would mean padding the number to cover the risk, and you would be paying for that padding.

Excludes VAT. For context, the median advertised UK cyber security contract rate in 2026 sits around £457 a day, with OT-specific roles typically £510–£555. The premium here is SC clearance and CNI delivery experience rather than a brand name on the invoice.

When I'm not the right call

  • You need a penetration test. That is a specialist discipline and I am not a tester. I will organise it, triage the findings and turn them into a remediation plan — but somebody else should hold the tools.
  • You want a 24/7 SOC. That is a service, not a consultant. Different purchase entirely.
  • You need twelve consultants on site by Monday. A large consultancy can do that. I cannot, and I would rather say so now.
  • You want a certificate rather than a change. If the intention is a document that satisfies a regulator while nothing operational changes, we will disappoint each other.

Start with a conversation

Half an hour, no fee. Tell me which framework you are being held to, what the deadline is, and where you think the gaps are. I will tell you honestly whether the problem is the size you think it is — and occasionally it is smaller.

Jaipal Singh SC cleared Industry-first telematics patent 20 years in business analysis BEng, Aston University