Client Case Studies

Case Study – Attack Tree Methodology » (PDF)

One of the largest energy utilities in the US has operations affecting regions of the country. The client required a dynamic enterprise view of their security risk as well as a prioritized remediation plan aimed at protecting their business operations. In a world defined by limited budgets, resources and time in the context of many vulnerabilities,attack points and attackers, N&ST needed to build a risk assessment methodology that would economically address these requirement across a large number of locations and technologies.

Case Study – Security Assessment » (PDF)

A major US metropolitan electrical utility required a ‘360 degree’ security review that includes the following:

  • Internal and external pen testing
  • Internal web and mainframe application testing
  • Remote access security assessment
  • Physical security test
  • Social engineering
  • Identification and security review of wireless LANs
  • SCADA network review and pen testing
  • Telephone network security review
  • Voice message security review
  • Security documentation evaluation

Case Study – SME Preparation for Audit » (PDF)

A major US Utility was facing an upcoming NERC CIP Compliance audit. While technically astute, many of the personnel associated with their NERC CIP implementations had little or no experience with the audit process. These Subject Matter Experts (“SMEs”) lacked the “soft skills” that must properly be used during an audit. The Utility wanted to 1) prepare its people for the rigors of the audit and 2) ensure the highest probability of a successful audit.



NEWS & EVENTS

4/19/2012 - FERC approves Version 4 of the NERC CIP Standards
As many of you are aware, CIP Version 4 was on this morning’s agenda at FERC’s public meeting.  This morning, FERC approved agenda item E-6 without comment.  For your information, HERE is the item from FERC’s meeting summary.
February 2012 Customer Testimonial
"I have never seen our technical staff actually ask for the same consultants again and again!" - Responsible Entity in the SPP region
March 2012 Customer Testimonial
"N&ST never sat around waiting for us to tell them what to do and came to us when they had questions, but never overburdened us. We are looking forward to working with them again in the future!" - Responsible Entity in the ERCOT region
January 2012 Customer Testimonial
"Anyone can come in and point to where the problem is, but N&ST was part of the team and worked just like we did. They were working consultants which is exactly what a small to medium size utility needs." - Responsible Entity in the SERC region