The situation
An industrial operations company with obligations under NERC CIP (Critical Infrastructure Protection) standards engaged WorldSafe after an internal audit flagged discrepancies between their documented security procedures and what was actually happening in the field. They were not out of compliance — their documentation was current, their training records were complete, and their last external audit had passed without findings. The problem was subtler than a compliance gap.
The compliance team had verified documentation. The security team had documented processes. What no one had verified was whether the compliance documentation and the security processes were actually the same thing — and whether the people responsible for executing them understood their role well enough to do it under the conditions an actual incident would create.
What we assessed
WorldSafe conducted a full site assessment covering physical security infrastructure, access control, personnel security protocols, and regulatory alignment. The physical assessment produced 7 findings, all of which were addressable through operational changes rather than capital investment. None were critical from a NERC CIP compliance perspective — the documentation accurately reflected the intended program.
The more significant findings came from the tabletop exercise WorldSafe facilitated in the second phase of the engagement. The scenario was designed around a realistic intrusion event at a critical asset location — the kind of event NERC CIP's physical security standards are specifically designed to address.
What the tabletop revealed
Within the first 20 minutes of the scenario, 5 execution gaps surfaced that no amount of documentation review would have found:
- Decision authority ambiguity. Two people believed they held primary decision authority for escalating to law enforcement. Neither had communicated this assumption to the other. In the scenario, 8 minutes passed before the decision was made — time that, in an actual incident, compounds rapidly.
- Notification chain breakdown. The documented notification chain assumed availability of a specific system that was, in practice, used for other purposes during the hours when an intrusion was most likely. The backup notification procedure existed in the documentation but no one in the room had ever used it.
- Vendor coordination gap. A critical response procedure required coordination with a third-party monitoring vendor. No one in the exercise had a current contact at that vendor, and the phone number in the documentation had been disconnected when the vendor changed systems six months earlier.
- Shift handoff vulnerability. The scenario was set during a shift change period. The exercise revealed that the handoff protocol didn't include a security status briefing — meaning the incoming team had no situational awareness at exactly the moment when awareness mattered most.
- Recovery procedure ownership gap. The documented recovery procedure listed responsibilities by role title. One of those roles no longer existed under the current org structure. The people who had absorbed those responsibilities didn't know they had.
Remediation and outcome
All 5 execution gaps were addressed within one quarter. The remediation included updated documentation, a revised notification chain with verified contact information, a redesigned shift handoff protocol, and a second tabletop exercise at the end of the quarter to confirm that the changes held under simulated pressure. The second exercise passed.
The company achieved WorldSafe Certified Level 2 following the second tabletop. Their Director of Security Operations noted that the certification had become a meaningful tool in conversations with regulators and insurance underwriters — both of whom had asked about their security program verification process in the months following their last audit.
The engagement produced something the internal audit had correctly identified as a problem but couldn't define: the difference between a program that exists on paper and a program that can be executed by real people under actual conditions.
Compliance isn't the same as capability.
WorldSafe assessments and tabletop exercises verify whether your program works — not just whether it's documented. Start with a consultation.
Book a consultation