CYBERSECURITY — 01

Cyber-Physical Security

A digital access control panel and the door it operates are one attack surface, not two. GSS assesses cyber and physical security together, across the full lifecycle from design through authority to operate.

OPERATIONAL CONTEXT

Two programs that don't talk to each other leave the gap between them undefended

Most facilities run physical security and cybersecurity as separate functions with separate budgets, separate assessments, and separate reporting lines. That division made sense when a facility's control systems were analog and its network was an office IT problem. It stops making sense the moment a digitally controlled barrier, sensor, or access panel becomes part of the protective strategy — because an adversary does not respect the org chart that separates the two teams.

GSS treats cyber-physical security as a single discipline. The same engagement that assesses a barrier's delay time or a sensor's detection probability also assesses the network, credentials, and control logic that operate it, because a compromised controller can defeat a well-designed physical countermeasure without anyone breaching a fence line.

The team leading this work includes former U.S. NRC inspectors who authored the cybersecurity regulations now governing U.S. plants. That background matters for a specific reason: it means the program is built to the standard a regulator will actually apply, not a generic industry framework retrofitted to a nuclear or critical-infrastructure environment after the fact.

METHODOLOGY
01System MappingPhysical protection elements and their digital control paths inventoried together, not as separate lists.
02Convergence AssessmentPoints where a cyber compromise would defeat a physical countermeasure, or vice versa, identified explicitly.
03Risk-Based ScopingControls selected against consequence to the protected function, not a generic checklist.
04Design IntegrationCyber requirements built into new-build and upgrade physical security design from the outset.
05Authority to OperateDocumentation and evidence packaged to support regulator or authorizing-official review.
06SustainmentOngoing maintenance of the converged program as systems, threats, and regulation change.
CORE CAPABILITIES
Converged cyber/physical assessmentOT/ICS security architectureNew-build cyber-physical designAuthority-to-operate supportRegulatory alignment (NRC and adjacent frameworks)Program sustainment
RELEVANT ENVIRONMENTS
Operating nuclear facilitiesSmall modular reactorsNew nuclear buildOther high-consequence critical infrastructure

Assess cyber and physical security as the one system they actually are

Request a Consultation