The situation

An industrial operations company with obligations under NERC CIP (Critical Infrastructure Protection) standards engaged WorldSafe after an internal audit flagged discrepancies between their documented security procedures and what was actually happening in the field. They were not out of compliance — their documentation was current, their training records were complete, and their last external audit had passed without findings. The problem was subtler than a compliance gap.

The compliance team had verified documentation. The security team had documented processes. What no one had verified was whether the compliance documentation and the security processes were actually the same thing — and whether the people responsible for executing them understood their role well enough to do it under the conditions an actual incident would create.

What we assessed

WorldSafe conducted a full site assessment covering physical security infrastructure, access control, personnel security protocols, and regulatory alignment. The physical assessment produced 7 findings, all of which were addressable through operational changes rather than capital investment. None were critical from a NERC CIP compliance perspective — the documentation accurately reflected the intended program.

The more significant findings came from the tabletop exercise WorldSafe facilitated in the second phase of the engagement. The scenario was designed around a realistic intrusion event at a critical asset location — the kind of event NERC CIP's physical security standards are specifically designed to address.

5Execution gaps found in tabletop
1QTo full remediation
L2WorldSafe Certified achieved

What the tabletop revealed

Within the first 20 minutes of the scenario, 5 execution gaps surfaced that no amount of documentation review would have found:

Remediation and outcome

All 5 execution gaps were addressed within one quarter. The remediation included updated documentation, a revised notification chain with verified contact information, a redesigned shift handoff protocol, and a second tabletop exercise at the end of the quarter to confirm that the changes held under simulated pressure. The second exercise passed.

The company achieved WorldSafe Certified Level 2 following the second tabletop. Their Director of Security Operations noted that the certification had become a meaningful tool in conversations with regulators and insurance underwriters — both of whom had asked about their security program verification process in the months following their last audit.

The engagement produced something the internal audit had correctly identified as a problem but couldn't define: the difference between a program that exists on paper and a program that can be executed by real people under actual conditions.

Compliance isn't the same as capability.

WorldSafe assessments and tabletop exercises verify whether your program works — not just whether it's documented. Start with a consultation.

Book a consultation