Industries

Sectors we work in

Regulated industries, high-consequence organisations and operators of critical services — alongside commercial organisations where physical and personnel risk is material.

Requirements differ considerably by sector. A distributed telecommunications estate, a high-value research facility and a regulated water site each present a distinct threat picture and distinct operating constraints. We scope to that context rather than applying a standard control checklist.

Core sectors

Where our approach is particularly relevant

Energy & utilities, telecommunications and data centres & secure facilities are principal areas of focus, where physical access can carry significant operational, regulatory and information-security consequence.

Sector 01

Energy & utilities

Generation, transmission, distribution and water operators, including sites designated as Critical National Infrastructure, where physical access carries direct operational, safety and regulatory consequence.

Typical security challenges

  • Large, remote and often unstaffed sites with long response times
  • Perimeters that must remain serviceable for heavy plant and third-party access
  • Extensive contractor and outage populations with temporary access needs
  • Operational technology reachable from physically accessible locations
  • Safety requirements that constrain what security measures may be applied
  • Statutory duties under NIS and evolving UK resilience legislation

Typical threat actors

  • Organised acquisitive crime targeting metal, plant and fuel
  • Issue-motivated groups seeking disruption or publicity
  • Insiders and contractors with legitimate but over-broad access
  • Hostile reconnaissance preceding disruption of supply
  • State-aligned actors, where the site is nationally significant

Typical consultancy support

  • Assessment of dispersed estates using a representative site sample
  • Perimeter, detection and response review against realistic response times
  • Contractor and outage access controls, including key and pass management
  • Assurance aligned to regulatory obligations and audit requirements
  • Prioritised investment cases for capital security programmes

Sector 02

Telecommunications

Exchanges, transmission sites, landing stations, mast sites and geographically distributed estates supporting critical services, where remote and unstaffed locations create particular exposure.

Typical security challenges

  • Thousands of small sites at wide geographic dispersion
  • Unstaffed locations reliant on locks, alarms and third-party response
  • Shared and co-located tenancies with divided security responsibility
  • Field engineer access models that are difficult to audit at scale
  • Physical access to equipment carrying customer and national traffic
  • Consistency of standards across sites acquired at different times

Typical threat actors

  • Acquisitive criminals targeting copper, batteries and equipment
  • Actors seeking service disruption at points of concentration
  • Insiders and subcontracted field personnel
  • Hostile reconnaissance of routing and dependency concentrations
  • Commercially motivated actors seeking network or customer information

Typical consultancy support

  • Sampling strategy that produces estate-wide conclusions affordably
  • Review of unstaffed-site standards, alarm response and escalation
  • Assessment of engineer and subcontractor access arrangements
  • Physical dependency mapping for concentration and single points of failure
  • A consistent standard that can be applied across an acquired estate

Sector 03

Data centres & secure facilities

Colocation and enterprise data centres, secure storage and high-assurance facilities, where physical security underpins the commitments made to customers and regulators.

Typical security challenges

  • Contractual and certification commitments that must be demonstrably met
  • High volumes of customer, contractor and delivery access
  • Multi-tenant halls where separation must be maintained physically
  • Reliance on layered controls whose combined effect is rarely tested end to end
  • Maintenance routes, plant rooms and roof access outside the main access path
  • Tailgating and escort discipline at scale

Typical threat actors

  • Commercially motivated actors seeking access to customer equipment
  • Insiders and contractors with routine escorted or unescorted access
  • Acquisitive criminals targeting high-value hardware
  • Actors seeking service disruption to a concentrated dependency
  • Hostile reconnaissance conducted under a legitimate pretext

Typical consultancy support

  • End-to-end testing of layered controls against a defined objective
  • Review of escort, delivery and maintenance access procedures
  • Assessment of separation between tenancies and between halls
  • Independent evidence to support customer assurance and certification
  • Re-assessment on a defined cycle to evidence sustained control

Further sectors

Where the same approach applies

The same assessment applies; the threat picture and constraints differ.

Government & public sector

Public access balanced against assurance obligations and defined standards.

Departments, agencies, local authorities and arm's-length bodies requiring independent evaluation of protective security arrangements, frequently against defined government standards.

Typical security challenges

  • Public-facing buildings that must remain accessible and welcoming
  • Estates shared between organisations with different security requirements
  • Assurance obligations against defined government standards
  • Mixed populations of staff, contractors, visitors and service users
  • Legacy buildings where structural change is constrained
  • Findings that must satisfy audit, board and ministerial scrutiny

Typical threat actors

  • Issue-motivated groups and protest activity
  • Individuals presenting a fixated or grievance-driven threat
  • Insiders and contracted service personnel
  • Hostile reconnaissance of publicly accessible approaches
  • State-aligned actors, where the function is sensitive

Typical consultancy support

  • Independent assessment usable as evidence in an assurance return
  • Review of the balance between public access and protective measures
  • Personnel security review across the employment lifecycle
  • Maturity assessment against recognised standards and good practice
  • Reporting written for audit committee and accounting officer audiences

Financial services

Branch networks, dealing floors and cash operations across a changing estate.

Banks, insurers and asset managers with branch networks, dealing environments, cash operations and sensitive processing facilities.

Typical security challenges

  • Branch networks combining public access with cash and sensitive data
  • Dealing floors and processing sites with concentrated information value
  • Third-party cash, cleaning and facilities personnel with routine access
  • Regulatory expectation for operational resilience and third-party control
  • Security arrangements that must not impede customer service
  • Consistency across a large and frequently changing estate

Typical threat actors

  • Organised acquisitive crime targeting cash and valuables
  • Commercially motivated actors seeking market-sensitive information
  • Insiders with privileged physical or system access
  • Social engineering against reception and front-of-house staff
  • Hostile reconnaissance ahead of a targeted approach

Typical consultancy support

  • Representative sampling across a branch or office network
  • Assessment of front-of-house identity verification and challenge
  • Personnel and insider risk review, including third-party staff
  • Independent assurance supporting operational resilience reporting
  • Prioritised measures that do not degrade the customer experience

Manufacturing & industrial

Continuous operation, high goods movement and large contracted populations.

Production facilities, warehousing and supply chains where disruption, product tampering or loss of intellectual property carries significant commercial consequence.

Typical security challenges

  • Continuous operation that limits when assessment activity can occur
  • High vehicle and goods movement through the perimeter
  • Agency, seasonal and shift populations with rapid turnover
  • Production areas where safety rules govern access and movement
  • Intellectual property held in physical form on the production floor
  • Extended supply chains with inherited security assumptions

Typical threat actors

  • Organised acquisitive crime targeting stock and materials
  • Commercially motivated actors seeking process or design information
  • Insiders, agency staff and hauliers
  • Actors seeking product tampering or reputational damage
  • Hostile reconnaissance disguised within routine deliveries

Typical consultancy support

  • Assessment scheduled around production and shutdown windows
  • Goods-in, goods-out and vehicle access control review
  • Personnel security review covering agency and seasonal populations
  • Supply chain and third-party security arrangements
  • Measures proportionate to commercial rather than theoretical loss

Life sciences & pharmaceuticals

Controlled substances, research value and regulated inspection exposure.

Research, development and manufacturing sites where regulatory compliance, controlled substances and intellectual property require demonstrable protection.

Typical security challenges

  • Controlled substances requiring auditable physical custody
  • Research areas whose value is concentrated in a small physical footprint
  • Regulated environments where inspection findings carry direct consequence
  • Collaboration and visiting-researcher access models
  • Cold chain and sample integrity dependent on physical control
  • Animal research or ethically sensitive work attracting activist attention

Typical threat actors

  • Issue-motivated groups and activist organisations
  • Commercially motivated actors seeking research and trial information
  • Insiders and visiting research personnel
  • Acquisitive criminals targeting controlled substances
  • Hostile reconnaissance ahead of protest or intrusion

Typical consultancy support

  • Assessment aligned to regulatory and inspection expectations
  • Review of custody, storage and audit arrangements for controlled material
  • Visitor, collaborator and researcher access review
  • Assessment of protest and intrusion resilience without alarmist framing
  • Evidence suitable for regulator and board reporting

Transport & logistics

Public and operational areas meeting, at high throughput.

Terminals, depots, distribution centres and transport infrastructure, where public access, high throughput and continuity requirements must be reconciled.

Typical security challenges

  • Public access alongside restricted operational areas
  • High vehicle throughput with limited dwell time for checks
  • Large driver and haulier populations outside direct employment
  • Perimeters extended by rail, water or airside boundaries
  • Continuity requirements that make disruption costly within minutes
  • Regulated access regimes with independent audit exposure

Typical threat actors

  • Organised acquisitive crime targeting freight in transit and at rest
  • Actors seeking to introduce items into a controlled supply chain
  • Insiders, drivers and third-party handling staff
  • Issue-motivated groups targeting visible infrastructure
  • Hostile reconnaissance of access and egress routes

Typical consultancy support

  • Assessment of the boundary between public and operational areas
  • Vehicle, driver and freight access control review
  • Personnel security review across contracted populations
  • Testing calibrated to avoid any operational disruption
  • Assurance aligned to regulated access regimes

Corporate & professional services

Open, client-facing offices holding confidential information.

Multi-site organisations holding confidential client information, or where insider access represents a credible and material risk.

Typical security challenges

  • Open, hospitality-led offices designed to feel unrestricted
  • Confidential client information held in physical and digital form
  • Serviced and multi-tenant buildings with shared landlord controls
  • Hybrid working that weakens familiarity and challenge culture
  • Client contractual obligations on information handling
  • Reception and meeting-room routes that bypass access control

Typical threat actors

  • Commercially motivated actors seeking client or deal information
  • Social engineering against reception and hospitality staff
  • Insiders with broad and rarely reviewed access
  • Opportunistic intruders exploiting an open floor plan
  • Hostile reconnaissance under a supplier or candidate pretext

Typical consultancy support

  • Assessment that respects an open and client-facing culture
  • Review of landlord and tenant security responsibility boundaries
  • Identity verification and challenge culture assessment
  • Insider risk and privileged access review
  • Evidence to satisfy client security questionnaires and audits

Regulated and high-consequence organisations

Where sector-specific security obligations apply, findings need to be defensible to more than one audience. Our reporting supports internal audit, board assurance and regulatory engagement alongside operational remediation, and can be aligned to obligations under the NIS Regulations and forthcoming resilience legislation.

Smaller commercial organisations

Not every organisation requires an estate-wide programme. A single-site assessment is often the most useful starting point. Scope, duration and cost are agreed in advance, and if we do not believe an engagement would deliver proportionate value we will say so at the scoping stage.

Next step

Discuss your sector, your estate and your obligations.

An initial conversation is exploratory and confidential. We are happy to talk through sector context before any proposal is prepared.