You may be about to become a regulated organisation.
The Cyber Security and Resilience Bill brings managed service providers, load-control operators and much of the energy supply chain under cyber regulation for the first time. Ridgeway Security helps those organisations work out what applies to them, and get ready before a regulator asks.
Am I in scope?
This is where almost every conversation starts. The full detail arrives later, in secondary legislation. But the direction of travel is already clear enough to plan against. Any of the following makes it worth a conversation now.
- You provide managed IT, cloud or security services to other businesses
- You hold an Ofgem licence: generation, supply, distribution or an IDNO
- You aggregate flexibility, or control load across customer sites
- You sell software, hardware or services into utilities, and your customers have started sending you security questionnaires
- You are already a NIS operator in water, transport, health or digital infrastructure
- You already report against the CAF and need to move to version 4.0
Two things happening alongside the Bill
DESNZ and Ofgem have consulted on baseline cyber requirements for all licensees, with enhanced obligations for the most significant operators. That reaches a long way past the handful of companies used to being regulated on cyber.
Separately, the NCSC's move to CAF 4.0 means organisations that were comfortable with their last assessment are now being measured against changed expectations.
If none of that sounds like you, say so on the call and we will tell you as much. We would rather lose half an hour than sell you an assessment you do not need.
What we do
Five services, all delivered at senior level. There is no leverage model here and no junior consultant learning the sector on your budget. You work directly with the consultant who writes the report.
CAF readiness assessment
A gap assessment against the NCSC Cyber Assessment Framework, with findings prioritised by regulatory exposure and a costed remediation roadmap you can take to a board. The usual place to start.
Compliance advisory
Scope determination, incident reporting readiness and evidence preparation for engagement with Ofgem, or whichever authority ends up regulating you. Written so your operations team can act on it.
Virtual CISO
Retained security leadership for organisations that need direction, board reporting and someone to hold the regulatory relationship, but not a full-time hire.
Cyber Essentials
Guided implementation of the five controls, through to certification. The government-backed baseline, and increasingly what procurement teams across the energy supply chain ask for first.
Microsoft Defender setup
Endpoint protection, email security and alerting configured properly across your Microsoft 365 estate, usually on licences you already pay for and are not using.
Fees are quoted after the scoping call, once the scope is actually known. Ask for the rate card and you will get one.
How an engagement runs
Short, and deliberately easy to stop after any stage.
A call, at no cost
Thirty minutes. We work out whether regulation reaches you, and whether there is anything here worth paying for.
A fixed-fee assessment
An agreed scope, a fixed price and a defined end date. You get a findings report and a roadmap that survives contact with a budget cycle.
Support, only if you want it
Some clients take the roadmap and run it themselves. Others keep us on retainer. Both are fine. The report is written to stand on its own.
Who we work with
Large consultancies price the mid-market out. Most of the organisations now coming into scope are doing critical work without anyone in-house who owns compliance.
- Managed service providers
- Energy suppliers and generators
- IDNOs and network operators
- Flexibility and load-control businesses
- OEMs and integrators selling into utilities
- Water companies
- Suppliers to regulated finance and health
About Ridgeway Security
Ridgeway Security was founded by Matthew James, whose career in cyber security has centred on the systems that keep Great Britain's critical national infrastructure running.
That matters less as a credential than as a habit. Working inside critical national infrastructure teaches you what a regulator actually reads, why a control that looks sensible on paper fails on a site with three people and one maintenance window a year, and how to tell a finding that matters from a finding that fills a report.
Ridgeway Security exists because that kind of experience is normally priced for organisations that can afford a Big Four engagement, and the organisations about to need it most cannot. We keep overheads minimal and pass the difference on.
We take a small number of clients at a time. That is the honest trade-off: senior attention on every engagement, and occasionally a wait for a start date.
Worth saying plainly
- One consultant, start to finishThe person on the scoping call is the person who does the work.
- Fixed fees wherever possibleScope agreed up front, so the invoice is not a surprise.
- IndependentWe resell nothing and take no vendor commission, so the roadmap recommends only what you need.
- Plain EnglishReports written for the board and for the engineers, not for the framework.
Book a free scoping call
Thirty minutes, no charge and no pitch. Tell us roughly what your organisation does, and we will tell you whether the new rules reach you, what a regulator is likely to want to see, and how much of it you can do without hiring anyone.
Prefer email? hello@ridgewaysecurity.co.uk