Nuclear Regulatory Support
A protective strategy that works on site still has to be demonstrated in a regulator's own terms, on paper, under inspection. GSS builds that bridge.
A sound protective strategy is not automatically a defensible one
Operational effectiveness and regulatory demonstrability are related but not identical problems. A facility can run an adequate protective strategy in practice while its basis documentation has fallen behind — written for an earlier configuration, an earlier threat basis, or an earlier version of the site than the one that actually exists today. That gap rarely shows up until an inspection or an audit finds it, at which point it is a finding rather than a conversation.
GSS's cyber-physical practice is led by former U.S. NRC inspectors who helped author the cybersecurity regulations governing U.S. plants today, and that regulator-side experience shapes how the broader team approaches basis documentation and inspection readiness generally: written the way a regulator actually reads it, structured to make the connection between requirement and evidence explicit rather than assumed. Gap analysis, documentation development, and mock inspections are used to find the disconnects before a real inspection does.
Licensees operating across more than one region face an additional layer — different regulatory regimes, different documentation conventions, different expectations for how a protective strategy is demonstrated. GSS's regulatory support work spans facilities across North America, Europe, and the Middle East, and is scoped to the specific regime a given site answers to rather than treated as one template applied everywhere.