Capabilities / Risk, Security and Resilience

Risk, Security and Resilience

Overview

YAVA finds out whether physical, cyber and human controls actually work, scores what it finds, and puts it right. This capability group includes the Risk Intelligence Platform (RIP) and the engineering remediation that follows.

Risk, Security and Resilience in practice

Problems we are brought in for

Where this work matters.

01

Declared risk, not observed risk

Assessments based on documents and questionnaires that show what should be in place, not what is.

02

Findings with no route to fix

Reports that identify problems but leave the organisation to find someone to solve them.

03

No evidence for insurers

Risk positions that cannot be evidenced to underwriters, so cover is priced on assumption.

Services

What sits under risk, security and resilience.

Each service below is delivered on its own or combined with others. Finding out whether physical, cyber and human controls actually work, then putting them right.

Technical risk assessments

Engineering-led assessment of whether a system or estate actually holds up, not just whether it is documented.

Physical security assessments

On-site assessment of physical security: perimeter, access, surveillance and how an incident could be evidenced.

Cybersecurity assessments

Assessment of cyber controls across the estate, tested against how an attacker would actually move.

IT and OT security reviews

Security review across both IT and operational technology, including the boundary between them.

Insurance risk engineering

Engineering-led validation that gives underwriters real evidence to price against, and asset owners a plan to reduce risk.

Business continuity

Planning and testing so an operation can keep running, or recover quickly, when something fails.

Crisis preparedness

Preparing people and systems to respond to a serious incident before it happens.

Remediation planning

A prioritised, costed plan to fix what an assessment finds, in order of impact.

Monitoring and response

Ongoing monitoring and a defined response path so issues are caught and handled.

How we deliver

Delivery.

Engineers assess the asset on site across three layers, score it out of 100, and set out a prioritised plan. Where you want it, the same team delivers the remediation and rescores.

Scope01Remote review02On site03Score04Report and brief05Remediate06
Fig. Risk Intelligence process. Each layer is inspected on site, scored, and either reported or put right by the same engineers.

How it connects

Integration.

Assessment and remediation come from one team. Because we can fix what we find, you buy risk reduction rather than risk identification.

One accountable team

YAVA advises, builds, integrates, deploys and supports. This capability is one part of a single lifecycle, not a standalone product.

Applicable experience

Evidence.

Representative work relevant to this capability. Some engagements are anonymised by client where confidentiality requires it.

Honest evidence

YAVA does not publish invented clients, projects or results. Where a client is not named, the engagement is described by sector, region and year, with accurate technical detail.

FAQ

Common questions.

Is this the same as the Risk Intelligence Platform?

Risk Intelligence (RIP) is the core of this capability group. The group also covers the specific assessments, insurance risk engineering and remediation around it.

Do you only assess, or do you fix things too?

Both. The distinctive part is that the same engineers can deliver the remediation and rescore the asset afterwards.

Can the output be used with our insurer?

Yes. We produce an insurer-ready brief that evidences what is in place at the asset, to support pricing and renewal.

Can YAVA work in remote or low-connectivity environments?

Yes. Much of our work is at remote and high-risk sites. We design for intermittent connectivity and can deploy field engineers where support on the ground is limited.

Who is accountable once the system is live?

The same team that advises and builds also supports the system in operation, so there is a single line of accountability to the client rather than a hand-off between firms.

How is a piece of work scoped and priced?

Each engagement is scoped and priced on its own terms, with the deliverables, service levels and assumptions agreed and written down before work begins.

Can you work alongside our existing suppliers?

Yes. We routinely deliver inside existing frameworks and alongside incumbent suppliers, including on systems built by others.

Contact

Tell us what needs to work.

Whether you need advice on what to build, a system delivered and deployed, or an asset assessed and put right, a short conversation will tell you whether we fit the problem.

Start a conversation