Projects

Arriva Plc – Digital Train Programme

Arriva Plc needed a cyber security specialist to conduct risk assessments and assurance activities for three Digital Train projects: CrossCountry Trains refurbishment fleet, Arriva Rail North New Trains fleet and refurbished rail fleet. Engaged to conduct IRAM2 risk assessments and define security requirements. Consulted with industry experts, Arriva staff and potential suppliers to determine a pragmatic approach for the security requirements alighted to the Department for Transport Rail Cyber Security guidance document February 2016. Delivered interim and final risk assessment reports and developed a risk treatment plans with recommended mitigation for the identified risks. Penetration testing scope developed including the need for a physical security review of each class of train.


Jaguar Land Rover – Sensitive Data Assessment

Jaguar Land Rover needed to understand the quantity of sensitive data contained in the estate. Engaged to produce a data risk report for 150 applications. Agreed scoring methodology; developed two-stage questionnaire for business application owners (BAO); identified appropriate BAOs; analysed questionnaires; provided weekly progress updates; and drafted/delivered final report. Succeeded in achieving a 95% response rate and identifying 18 high risk applications, while improving data quality.


Anglian Water – Security Management

Anglian Water were keen to migrate their outsourced IT provider to Capgemini with enhanced Information Security (IS) requirements. Engaged to develop/operate an ISO 27001 based Outsource Security Plan(OSP). Identified key business stakeholders; drafted/discussed initial OSP; refined/formalised OSP; developed security review/reporting/ response/training processes; and achieved client sign off. Succeeded in significantly improving the security posture of Anglian Water with no major incident during 2-and-a-half-year tenure.


MAG (Stansted Airport) – Service Migration

MAG required security controls in IT system & applications to provide business functionality during Stansted’s divestment from Heathrow. Engaged to lead the security of service migration. Identified key stakeholders for IS; oversaw network/IT architecture & project streams/ensured policy compliance; sat on architecture review board; reported on project progress; and advised IT stakeholders on security issues/Data Protection Act implications. Succeeded in completing the £multi-million on time & to all stakeholder satisfaction.