Services / Cybersecurity & compliance
Regulatory compliance, done by someone who has actually sat in the plant
CAF, NIS and NIS2, CIS Controls, IEC 62443. Business analysis and programme delivery for operational technology environments where the security control and the turbine are part of the same conversation.
from £3,500
Fixed-scope assessments, priced in writing. Embedded programme analysis from £595 a day.

Who this is for
Regulated operators with a deadline and a framework
Energy generation and networks. Water. Transport. Healthcare. Manufacturing with real plant behind it. Organisations that fall under NIS, are being assessed against the Cyber Assessment Framework, or have decided that CIS Controls are the sensible way to get their estate under control.
Usually the trigger is one of three things: a regulator has been in touch, an audit is coming, or somebody senior has looked at the OT estate and realised nobody can produce an asset inventory.
Typical engagements
- CAF readiness and gap assessment, Basic or Enhanced Profile
- NIS and NIS2 compliance programme analysis
- CIS Controls implementation, IG1 through IG2
- OT/IT security requirements and architecture documentation
- Supplier and contract assurance against compliance obligations
- Audit-ready evidence and risk attestation packs
- Embedded business analysis on an existing security portfolio
Track record
Where this has actually been done
Not theory. These are engagements delivered, not frameworks read about.

Power generation
Drax Power Station
NIS compliance programme across the cyber security portfolio. Supplier obligations reviewed against CAF Enhanced Profile, contractual gaps identified, remediation scoped and taken through governance.

Electricity interconnectors
National Grid Ventures
NIS portfolio lead across Dispatch systems at interconnector sites. Twelve workstreams defined, current and future-state security architectures established, audit and attestation documentation produced.

Healthcare
Pharmacy2U
CIS Controls transformation across roughly a thousand devices in a 24/7 pharmacy operation. IG1 to IG2 roadmap, aligned to NHS DSP Toolkit and GDPR, built on existing tooling.
Frameworks and standards
- NCSC Cyber Assessment Framework — Basic and Enhanced Profile
- NIS Regulations and NIS2 Directive
- CIS Controls v8, Implementation Groups 1 and 2
- ISA/IEC 62443 and the Purdue model
- NIST Cybersecurity Framework
- ISO 27001
- NHS Data Security and Protection Toolkit
- UK GDPR
Credentials
- SC clearance — current and valid
- CISSP and CISM — both in progress
- BEng (Hons) Internet Engineering, Aston University
- Twenty years of business analysis, the last several in OT security and CNI
- Industry-first vehicle telematics patent; JLR Innovista Awards finalist
Engaged through STR Lines Limited. Comfortable working inside or outside IR35 — tell me the determination and I will work to it rather than argue about it.
What it costs
Published, like everything else here
CAF readiness & gap assessment
from £4,500
CIS Controls gap analysis & roadmap
from £3,500
Embedded programme analysis
from £595 / day
Fixed-price assessments are exactly that — a defined scope, a defined deliverable and a number agreed before anything starts. Longer programme work runs at a day rate because pretending to fix-price eighteen months of regulatory change would mean padding the number to cover the risk, and you would be paying for that padding.
Excludes VAT. For context, the median advertised UK cyber security contract rate in 2026 sits around £457 a day, with OT-specific roles typically £510–£555. The premium here is SC clearance and CNI delivery experience rather than a brand name on the invoice.
When I'm not the right call
- You need a penetration test. That is a specialist discipline and I am not a tester. I will organise it, triage the findings and turn them into a remediation plan — but somebody else should hold the tools.
- You want a 24/7 SOC. That is a service, not a consultant. Different purchase entirely.
- You need twelve consultants on site by Monday. A large consultancy can do that. I cannot, and I would rather say so now.
- You want a certificate rather than a change. If the intention is a document that satisfies a regulator while nothing operational changes, we will disappoint each other.
Start with a conversation
Half an hour, no fee. Tell me which framework you are being held to, what the deadline is, and where you think the gaps are. I will tell you honestly whether the problem is the size you think it is — and occasionally it is smaller.
