Home / Industries / Critical infrastructure
MyRISK Trace · utilities, energy, transport and telecoms
Technical evidence does not turn into accountable management decisions.
Cyber, OT, resilience, physical operations, supplier dependency and service continuity have become one accountability problem. The evidence exists at the technical layer. The decision it supported is what nobody can produce.
Why now
Risk stopped being isolated by function.
A contractor, maintenance, OT, safety or cyber issue can now become a continuity and assurance event. The functions that own each piece report separately, and the picture only assembles after something has happened.
Your operational teams hold detailed evidence — logs, assessments, exercise findings, dependency maps. What is thin is the record of what management concluded from it, when, on what basis, and with what conditions attached.
The technical record proves what happened. It does not prove the decision was reasonable.
What usually starts the conversation
- The SOCI annual report on your risk management programme — board-approved, within 90 days of financial year end
- An exercise or business continuity refresh that exposed a gap
- A supplier failure, or a near miss with one
- An incident response review asking who decided what, and when
- Critical asset and dependency mapping work already under way
- Executive concern following an event elsewhere in the sector
Where it bites first
Five decisions worth being able to replay
01
A safety or environmental trade-off
An operational call weighing production against a safety or environmental consequence — the reasoning is usually careful and rarely recorded where it can be found later.
02
A supplier resilience decision
Why this provider for a critical dependency, what was assessed, and which conditions were attached.
03
An OT or legacy risk acceptance
A constraint accepted because replacement is not feasible yet. On what basis, for how long, and reviewed by whom.
04
An incident decision trail
During and after an event: who had authority, what was known at each point, and what was decided on that basis.
05
A continuity or tolerance decision
A recovery objective set, a workaround approved, an interdependency accepted — and whether it still holds.
—
Not a cyber story
Cyber is inseparable from operations here, and it is one strand rather than the subject. Safety, asset condition, contractor dependency and continuity carry the same weight, and most of what is listed above raises no cyber question at all.
What you already have
The instrumentation is not the gap.
Operators at this scale have asset management systems, OT monitoring, incident management, a risk function, exercise programmes and board reporting. Each is capable and each holds part of the record.
What none of them holds is the management decision as it stood: the evidence in front of the people who made it, the alternatives weighed, the authority exercised, and what has drifted since. Trace sits alongside and holds that.
What a Trace record preserves
- The evidence that existed at the time, and the policy version that applied
- The rationale, assumptions and alternatives considered
- Who had authority, and what exactly was approved
- Conditions, expiry and review dates
- Drift — whether changed circumstances unsettle the approval
The first step
One decision, and one thing to bring
The check takes two minutes and asks for nothing. The Diagnostic runs a full replay against one decision you name, and its output includes what is missing — which is the part worth having before someone else asks for it.
Bring one thing: one recent operational decision and whatever record of it exists. A redacted extract or a walkthrough is fine; nothing sensitive goes through a public form.
If the entry point is a failed workflow
Where what brought you here is an audit finding, or an assurance process that produces files nobody uses, the first work is diagnosis rather than a decision record.
Contractors and suppliers inside your ecosystem usually need a rhythm rather than a replay — that is Essentials.
For your reviewers
The boundaries, in writing
What this is not
- Whether your position satisfies an obligation is your assessment and your regulator's, never a vendor's. No product determines that for you, and one that implies otherwise is selling you a risk rather than removing one.
- MyRISK does not sell into the compliance-platform category, which is a positioning choice rather than a limit: Core is an assurance layer and can hold controls, evidence, owners and reporting against an obligation. The argument here is about the decisions taken around them.
- Not a safety, engineering or environmental assurance opinion. The record holds what was decided and why; the technical judgement remains yours.
- Not an OT security product, and not a monitoring tool. It records decisions, not conditions.
- Trace complements your asset, OT, incident and GRC systems. It replaces none of them.
Pick the operational decision you would least like to be asked about.
The one where the reasoning was sound, the record is thin, and the circumstances have moved since. That is the one worth replaying while there is still time.