Risk, resilience, and readiness methodology

Our Approach

Risk and resilience work must match how critical infrastructure actually operates. Systems Risk Advisory helps utilities and infrastructure organizations connect cybersecurity, physical security, OT/ICS operations, emergency planning, leadership decisions, and recovery actions.

Systems Risk Advisory uses a practical, mission-focused approach to help critical infrastructure organizations understand risk, set priorities, and prepare for incidents that can affect essential services.

Our work starts with the service you must keep operating. We then examine the people, facilities, networks, control systems, vendors, procedures, and decisions that support that service. The result is a clear view of what matters most and what can be improved first.

A practical approach for real operating environments

Operational context first

Cybersecurity, physical security, and emergency readiness cannot be treated as separate paperwork exercises. They affect pumps, treatment processes, substations, field sites, operators, dispatch, leadership decisions, and public confidence.

We begin by understanding the mission, the consequences of disruption, and the constraints under which the organization operates.

Principal-led, team-supported execution

Systems Risk Advisory uses a principal-led model. Senior judgment guides the scope, analysis, findings, and recommendations.

When an engagement requires added depth, we coordinate specialized support in technical, operational, physical security, emergency management, planning, or training roles. Clients receive focused leadership with the right expertise for the assignment.

How we work

Define the mission and consequences

We identify the services, assets, processes, facilities, and decisions that matter most. This includes what must keep operating, what could create public health or safety consequences, and what would affect continuity of service.

Map the operating environment

We review how people, facilities, IT systems, OT/ICS, SCADA, vendors, field sites, remote access, communications, and procedures connect in practice.

Identify exposure and dependencies

We examine access paths, control points, single points of failure, cyber-physical dependencies, vendor reliance, emergency communications, and recovery limits.

Evaluate plans, roles, and decisions

We assess whether leadership, operators, IT staff, emergency managers, public information staff, and external partners know who decides, who acts, and how issues escalate.

Prioritize findings by risk and feasibility

We separate urgent exposure from long-term improvement work. Recommendations are grouped by consequence, likelihood, ownership, cost awareness, operational impact, and realistic sequence.

Support action, training, and exercises

We help clients turn findings into plan updates, task lists, tabletop exercises, workshops, briefings, and implementation roadmaps that can be used after the report is delivered.

What makes the approach different

Systems Risk Advisory is built for organizations that need clear decisions, not generic advice. Our approach is designed around the realities of small, mid-sized, and complex infrastructure organizations.

  • Cyber and physical risk are evaluated together where they affect operations.
  • OT/ICS and SCADA environments are treated as operating environments, not generic IT networks.
  • Findings are written for leaders, operators, engineers, IT staff, emergency managers, and boards.
  • Recommendations account for staffing, funding, downtime limits, vendor support, and public service obligations.
  • Plans are designed to be trained, exercised, revised, and used under pressure.
  • Engagements can combine assessment, planning, training, and exercise support when the client needs continuity from findings to action.

Questions we help clients answer

  • Who has access?
  • Where can they move?
  • What could they control?
  • What would fail first?
  • Who decides?
  • What must keep operating?
  • What can be fixed now?
  • What should be trained or exercised next?

Common work products

Every engagement is scoped to the client need. Typical work products may include:

Assessment reports

Clear findings, practical priorities, and recommended next steps for leadership and technical staff.

Risk registers and action trackers

Prioritized items that identify ownership, urgency, dependencies, and suggested sequence.

Executive briefings

Plain-language briefings for boards, councils, executives, and senior leaders.

Plan updates

Emergency response plans, incident response plans, ransomware readiness materials, and recovery procedures.

Exercise materials

Tabletop scenarios, injects, facilitator guides, participant materials, hotwash notes, and improvement items.

Training and workshop materials

Focused training for staff, managers, executives, operators, and cross-functional response teams.

Strong fit for water, wastewater, and public infrastructure

Water and wastewater utilities

Systems Risk Advisory has a strong focus on water and wastewater utilities. This includes AWIA Risk and Resilience Assessments, Emergency Response Plan updates, SCADA and OT security, remote access review, ransomware readiness, physical security, and tabletop exercises.

The approach works for utilities of different sizes, from small systems with limited staff to larger utilities with complex IT, OT, SCADA, vendor, and emergency management environments.

Critical infrastructure and public works

The same method applies to electric power, local government, public works, and other infrastructure organizations that rely on control systems, field operations, facilities, contractors, and continuity of service.

We focus on practical improvements that help organizations keep essential services running, communicate under pressure, and recover safely.

Typical engagement flow

Discovery and scope

Confirm the organization, services, facilities, systems, priorities, schedule, and expected deliverables.

Document and environment review

Review plans, diagrams, policies, procedures, inventories, prior reports, access paths, and operational context.

Interviews and field review

Meet with leadership, operations, IT, engineering, emergency management, security, and other stakeholders. Use onsite review when needed.

Analysis and prioritization

Develop findings, test assumptions, identify dependencies, and group recommendations by risk and practicality.

Briefings and deliverables

Provide draft findings, leadership briefings, final reports, plan updates, exercise materials, or other agreed deliverables.

Follow-through support

Support training, tabletop exercises, plan revisions, implementation planning, and future updates when requested.

Move from concern to clear priorities.

Systems Risk Advisory helps clients move from risk concerns to usable plans, trained people, practical priorities, and practiced response.