For Projects · Service
Systems &
Assurance
Security outcomes that are demonstrated, not merely intended. Traceable from risk scenario to verification evidence, embedded from the earliest design stages.
The diagnostic
Three questions that predict assurance failure
What you get
What structured assurance delivers
Traceable requirements hierarchy
On recent transport projects, we've issued 100+ individually tracked security requirements per engagement, each traced from its originating risk scenario, with named designer response columns and compliance status tracking. Every requirement has a source, every design response has a justification, and assurance teams can follow the thread end-to-end.
Verification and validation planning
V&V strategies that define how each security requirement will be demonstrated as met: inspection, analysis, test, and review methods appropriate to the requirement type and project stage.
SFAIRP arguments that hold under scrutiny
Structured safety cases and security arguments built on evidence, not assertions. We use formal methods, including attack tree analysis and quantified risk assessment, to demonstrate that security treatments are proportionate to the threat. These arguments are designed to withstand regulatory review, independent audit, and governance challenge.
Audit-ready governance at every gate
A coherent assurance position that holds through delivery, not a compliance exercise conducted at the last gate when it's too late to fix anything. We work across commissioning assurance, as-built compliance reviews, and independent verification for both client and contractor organisations.
Method
How we work
Assurance is not an audit conducted at the end of a project. We embed assurance thinking from the earliest stages, ensuring security requirements are well-formed, testable, and traceable before they become expensive to change. We work within established systems engineering frameworks and integrate with project management, safety, and design teams.
For: Project directors, assurance managers, safety teams, and governance bodies who need confidence that security requirements are being met as design progresses.
In practice
See this in practice
Talk it through with a principal
A 30-minute diagnostic call is the fastest way to test whether your project’s security posture holds up. No deck, no pitch.