From Physical Security to Integrated Resilience: Why Cyber, OT and Field Delivery Now Have to Work Together
- Jul 14
- 13 min read

Security is no longer only about protecting people, sites, and assets. In complex operating environments, resilience now depends on physical operations, cyber capability, operational technology, and accountable field delivery working as one.
Five years ago, a major security tender could still be won largely on operational track record, personnel quality, and the ability to deliver in difficult environments.
Those factors still matter. In many markets, they matter more than ever. But they are no longer enough on their own.
Clients are increasingly asking security partners to demonstrate capability across software, hardware, cyber, operational technology, systems integration, logistics, infrastructure assessment, and long-term support. The reason is simple: the risks they face no longer sit in neat categories.
A physical site can be compromised through a digital access system
A school, port, hotel, logistics hub or industrial facility can have strong perimeter security but poor cyber visibility
A ransomware event can become an operational disruption
A weak remote access pathway can become a site-level vulnerability
A trusted insider can create exposure that no fence, camera or guard force can solve alone
That is the context behind the YAVA and SF Group partnership. Announced in May 2026, the partnership brings together SF Group's operational security, logistics, transport, and field deployment capability with YAVA’s cyber, systems audit, operational intelligence, and infrastructure assessment capability. It is designed for client environments where physical security, cyber resilience, operational continuity, and infrastructure visibility increasingly overlap.
Introduction: Security Has Become a Systems Problem
For organisations operating across critical infrastructure, energy, logistics, aviation, education, hospitality, technology infrastructure, and complex overseas markets, the security environment has changed.
The UK Government’s Cyber Security and Resilience Bill reflects the same direction of travel. It is intended to strengthen the cyber resilience of essential and digital services in the face of cyber criminals and state actors, and to protect the services people rely on day to day.
The UK National Cyber Security Centre has also warned that organisations must treat severe cyber threat as a credible operational risk. Its 2026 guidance stresses the need to understand critical systems, plan for degraded IT or OT environments, rehearse segmentation and isolation, and make sure leadership understands the trade-offs between security and operational continuity.
That matters because physical resilience and digital resilience are no longer separate disciplines. Cameras, access control, logistics platforms, building systems, industrial control systems, fleet management, port systems, communications infrastructure, and enterprise IT all sit inside the same operating reality.
If one layer fails, the whole organisation can be exposed.
The Integrated Resilience Landscape: Three Forces Changing Client Expectations
Physical Security Now Depends on Digital Assurance
Clients still need trusted people on the ground. They still need operational judgement, local knowledge, logistics capability, and practical delivery in difficult environments.
But they also need confidence in the systems those people rely on.
A site may appear secure because it has guards, fencing, cameras, and access control. Yet if the access control system is poorly configured, if remote access is unmanaged, if cameras sit on exposed networks, or if sensitive operational data is poorly protected, the physical posture may be weaker than it looks.
That is why clients are increasingly asking security partners to show how physical protection connects to cyber resilience, infrastructure visibility, and systems assurance.
Cyber Risk Is Becoming an Operational Risk
Cyber exposure now affects real-world operations. The education sector shows this clearly.
The UK Government’s 2025/2026 Cyber Security Breaches Survey found that 73% of secondary schools, 88% of further education colleges, and 98% of higher education institutions had identified cyber breaches or attacks in the previous 12 months. It also found that 27% of further and higher education institutions had experienced a breach or attack at least weekly, while one in ten further and higher education institutions and secondary schools experienced attacks at least daily.
Schools have spent years improving physical security. Yet the same institutions now hold large volumes of sensitive health, education, safeguarding, identity, and financial data. That makes cyber resilience part of duty of care.
For security providers, this changes the brief. Protecting a school, campus, hotel, port, or energy site means understanding the data, systems, and operational dependencies that sit behind the visible security layer.
OT and Infrastructure Systems Are Expanding the Attack Surface
Operational technology environments are particularly exposed because they connect digital systems to physical processes.
In industrial, logistics, port, transport, and infrastructure environments, the line between corporate IT and operational systems can be thin. Dragos’ 2025 OT Cybersecurity Year in Review found that 45% of service engagements had extremely limited or no visibility across OT networks, making detection, triage, and response difficult at scale. It also found that 20% of engagements had findings related to secure remote access.
In manufacturing environments, Dragos has also highlighted the risk created by shared IT and OT domains, weak segmentation, compromised remote access, and stolen credentials. Its 2026 analysis notes that ransomware does not need to touch a PLC or field device to stop production if it can affect SCADA, HMI, historian, or engineering workloads.
For clients, this means physical security, IT security, and OT security must be understood together.
For SF Group and YAVA, it is the reason an integrated partnership model matters.
The Conversation: Bruce Lyman, CEO, SF Group

What follows is an edited conversation with Bruce Lyman, CEO of SF Group.
The discussion covers why security tenders increasingly require software, hardware, and cyber capability, why SF chose to partner with YAVA rather than build every capability internally, and how clients experience an integrated security and technology relationship without confused accountability.
The conversation also explores why schools are an important example of the physical-digital security gap, how OT environments change the threat picture, and why security is moving from one-off engagements to long-term resilience partnerships.
Five years ago, a major security tender was won on operational track record and personnel quality. Today, the same tender increasingly demands software, hardware, and cyber capability alongside it. What triggered SF Group's decision to partner with a technology firm rather than try to build that arm internally, and why YAVA specifically?
For Lyman, the answer starts with a simple principle: focus on what you do best, and bring in the right specialist expertise where the client needs it.
“Stick with your knitting. How many business case studies demonstrate diluted effort when you try and do everything?”
— Bruce Lyman, CEO, SF Group
In complex operating environments, he argues, clients need honesty about where expertise sits. A security provider that tries to present itself as expert in everything risks creating exposure for the client.
“It is important to be able to assure a customer that the right expertise is being applied in support of their environment. Anything less is being dishonest and creating exposure for the client, which is immoral.”
— Bruce Lyman, CEO, SF Group
That is why SF Group chose partnership over internal dilution.
YAVA provides a complementary technology fit across cyber, systems audit, operational intelligence, infrastructure assessment, and technical deployment. But the decision was not only about capability. It was also about operating standards.
Lyman says the partnership works because YAVA understands the environments in which SF Group operates.
“YAVA has a very complementary technology fit, operates to the same moral standards, and is comfortable working in some of the more [challenging operating environments] of the world.”
— Bruce Lyman, CEO, SF Group
That matters because the client does not only need a technology vendor. The client needs a technically excellent partner that can operate in difficult, remote, or politically complex environments without losing sight of accountability, judgement, or delivery discipline.

There is a real risk in these partnerships that boundaries blur and clients end up with confused accountability. How is the YAVA—SF Group relationship structured to keep that clean? Who owns the client, who delivers what, and how does the client experience it?
The partnership is built around a clear accountability model.
SF Group owns the client relationship and remains accountable for the overall solution. YAVA delivers the specialist technology components within its area of expertise.
To the client, the intended experience is integrated. Behind the scenes, the responsibilities remain clear.
“SF Group owns the client relationship. We remain accountable for the overall solution, while YAVA delivers the specialist technology components within their area of expertise. To the client, it feels like one integrated service.”
— Bruce Lyman, CEO, SF Group
That clarity is important because partnerships can fail when commercial incentives begin to distort the client relationship.
Lyman says the YAVA–SF Group model was deliberately structured to avoid that.
“The relationship only works because both organisations agreed from the outset that partnership integrity comes before opportunism.”
— Bruce Lyman, CEO, SF Group
Those principles are written into how the two organisations work together. SF Group remains the accountable client partner. YAVA brings the specialist technology depth needed to assess, strengthen, and support the digital and infrastructure layers behind the security posture.
For the client, the value is not vendor complexity. It is one joined-up operating model with clear ownership.
What hidden cyber, data, or systems risks can sit behind traditionally physical security environments, and why are clients often surprised when those risks are uncovered?
Lyman says one of the biggest surprises is psychological.
Many organisations do not expect to be targeted. They underestimate the value of their data and the ways that data can be used against them.
“What surprises the client the most is the notion that someone might actually be paying them attention in the first place.”
— Bruce Lyman, CEO, SF Group
That assumption can be dangerous.
Businesses may understand the value of their physical assets, but not always the value of their operational, financial, personal or behavioural data. They may also underestimate how easily that data can be used to apply pressure, enable fraud, support insider compromise, disrupt operations or create reputational exposure.
The second surprise is often how easy access can be.
“They are surprised to discover how easy it is to get into their systems.”
— Bruce Lyman, CEO, SF Group
The third surprise is often more uncomfortable: the possibility that exposure may not be theoretical. In some cases, the issue is not only that systems are vulnerable, but that the organisation has limited visibility into whether those systems have already been accessed, observed or misused.
The real shock is often the discovery that the organisation may have had far less visibility than it assumed.
For Lyman, schools provide one of the clearest global examples of a physical security environment being overtaken by cyber exposure.
Over the last two decades, many schools have invested heavily in physical security: fences, biometrics, alarms, visitor screening, locked premises during school hours, and more sophisticated safeguarding procedures.
Yet over the last five to ten years, schools have also become persistent cyber targets.
They hold sensitive health, education, safeguarding, identity, and financial data. That data can be valuable to criminals, coercive actors and anyone seeking to exploit vulnerable individuals.
The UK Government’s 2025/2026 education cyber findings show the scale of the challenge. While most education institutions have formal cyber policies and business continuity plans, no tier of the education sector had a majority of institutions covering all of the NCSC’s 10 Steps to Cyber Security. Only 14% of primary schools, 23% of secondary schools, 33% of further education institutions and 45% of higher education institutions had covered every step.
For Lyman, the social contract around education changes the standard.
“The social contract we have with schools to protect our children means that investment in cyber cannot be anything less than comprehensive.”
— Bruce Lyman, CEO, SF Group
That is why physical security and cyber security can no longer be treated as separate protective layers. In environments that hold sensitive data and serve vulnerable populations, both are part of the same duty of care.

The line between IT security and operational technology security—SCADA, building controls, port systems, fleet management—is where many real-world breaches now happen. How does SF Group, with YAVA, approach OT environments differently from corporate IT, and why does that matter to clients?
Lyman says the starting point is mindset.
SF Group brings the perspective of people who understand how protected places are entered, how routines are observed, how weaknesses are identified, and how human behaviour can become the route through layered security.
“We are fortunate to have a skill set that allows us to start with the poacher-turned-gamekeeper approach.”
— Bruce Lyman, CEO, SF Group
That matters because the biggest threat is not always the technology itself.
It is often the person interacting with it, administering it, bypassing it, maintaining it, or being manipulated through it.
“The biggest threat still remains the person, not the technology.”
— Bruce Lyman, CEO, SF Group
Recent insider threat analysis supports the need to think beyond the idea of the isolated lone wolf. Security analyst Michael Robinson analysed 1,000 insider threat cases from 15,000 legal filings, revealing that trusted employees, including top executives and high-performers, are often the perpetrators. He found that in 31% of cases, insiders worked in pairs or small groups.
For Lyman, that reinforces the importance of culture, values, and organisational discipline.
Layered security cannot only mean guards, cameras, firewalls, and monitoring tools. It also has to include how people are treated, how access is managed, how concerns are raised, how integrity is reinforced, and how early signs of collusion or disaffection are detected.
“Companies are not always alert to the idea that layered security must include issues of culture, honour, integrity, values, and treating staff well.”
— Bruce Lyman, CEO, SF Group
OT environments make that more important because they create additional pathways into the organisation.
SCADA systems, building controls, port systems, fleet management platforms, industrial systems, access control, and communications infrastructure often sit at the intersection of digital and physical operations. They may also involve legacy technology, third-party maintenance, remote access, limited visibility, and long asset lifecycles.
That is a different risk profile from corporate IT.
In corporate IT, the primary concern may be data, identity, applications, and enterprise systems. In OT, the concern extends to operational continuity, physical safety, process control, site resilience, and the ability to keep functioning when systems are degraded.
YAVA’s role is critical here because it brings the technical capability to assess those systems, identify exposure, improve visibility, strengthen controls, and support remediation in the operating environment.
SF Group brings the field security, operational judgement, and client accountability. YAVA brings the technical depth needed to understand where the digital layer creates physical exposure.
Together, the partnership helps clients see the whole risk picture.
How does adding a technology layer transform what was a one-off security contract into a long-term commercial relationship for SF Group? And is this partnership model the future of the industry?
Security is no longer something that can be reviewed periodically, improved once and then left alone. The threat environment is continuous, adaptive and asymmetric.
“The hostile actor only ever has to win once, whereas you, the defender, have to win every single day.”
— Bruce Lyman, CEO, SF Group
That changes the logic of security delivery.
In a traditional physical break-in, the attacker often had to compromise visible barriers. They might leave damage, force entry, trigger alarms, move physical evidence, or expose an insider who had to remove something tangible.
Digital compromise can be different. It can be designed to avoid detection. It can take place remotely. It can happen outside normal operating hours or continuously. It can target data, systems, credentials, access pathways, suppliers, or operational platforms. It can sit quietly until the attacker is ready to act.
“Digital technology and digital media theft can be designed and executed in such a way that it is hard to detect, harder to see when it is happening, and happens around the clock.”
— Bruce Lyman, CEO, SF Group
That is why more companies are looking at physical and digital security together.
If designed well, says Lyman, the combined model gives clients what military planners might call covering arcs of fire: overlapping layers of protection, visibility and response.
It also changes the relationship between client and provider. Instead of a single contract for a defined security task, the relationship can become an ongoing resilience partnership.
That may include recurring audits, cyber monitoring, infrastructure assessment, support agreements, technology maintenance, hardware refresh cycles, operational intelligence, and periodic review of physical and digital vulnerabilities.
The point is not simply to create a longer commercial relationship. It is to give clients a more rounded and durable view of their security posture as the operating environment changes.
For Lyman, this is where the partnership model has real value. The future of the industry is not every security provider trying to become a technology company, or every technology provider trying to become an operational security firm. It is about trusted specialists working together in a way that gives clients clearer accountability, deeper expertise and a more complete resilience model.
In high-risk environments, a one-stop shop is not always the safest answer.
The better model may be integrated delivery with clear accountability, specialist boundaries and strong partnership principles.
Where YAVA Fits: Making the Digital Layer Deliverable
YAVA provides the technical layer that helps turn security strategy into operational resilience.
As an infrastructure resilience and operational intelligence company, YAVA supports cyber capability, systems audit, infrastructure visibility, operational technology, software platforms, enterprise IT, hardware integration, data systems, and deployment in complex environments.
Those capabilities matter because many clients do not lack awareness of risk. They lack the technical ability to see, assess, improve, and evidence their actual operating posture.
A client may know that cyber matters. It may know that OT systems are important. It may know that its infrastructure has grown in layers over time. But without practical assessment and remediation, that awareness does not reduce exposure.
YAVA helps close that gap.
It can support cyber and systems audits, infrastructure resilience assessments, operational intelligence, technology integration, hardware and software deployment, and ongoing support where clients need durable capability rather than one-off advice.
SF Group remains the accountable operational security partner. YAVA strengthens the cyber, infrastructure, and technology dimensions that now sit behind effective security.
Together, the partnership gives clients a more complete model: operational judgement on the ground, technical visibility across systems, and a delivery structure designed for complex markets.
What This Means for Clients
Clients operating in complex environments need security partners who understand that risk now moves across physical, digital, and human layers.
A fence may protect a perimeter, but not a database. A cyber policy may describe control, but not prove that a remote access pathway is secure. A camera network may support visibility, but it may also create vulnerability if poorly configured. A trusted employee may support operations, but also become the route through which external actors gain access.
That is why integrated resilience is becoming a practical requirement.
For clients, the YAVA–SF Group partnership offers three clear benefits.
It keeps accountability clean. SF Group owns the client relationship and remains responsible for the overall solution.
It brings specialist capability where it belongs. YAVA delivers the cyber, systems, infrastructure and technology components within its field of expertise.
It reflects the way risk now behaves. Physical security, cyber resilience, OT visibility, operational continuity, and human factors increasingly have to be managed together.
The future of security is not only more guards, better cameras, or stronger firewalls.
It is the ability to connect those layers into one coherent operating model.
Speak to YAVA About Your Security, Technology, or Infrastructure Requirements
Whether you are reviewing your security posture in a complex environment, assessing your cyber and infrastructure exposure, or exploring integrated physical and digital resilience for a critical project, YAVA and SF Group offer a combined capability built for the conditions that now exist.
Email us at media@yava.com or contact us via www.yava.com/contactus.
Follow YAVA
LinkedIn @YAVA_COM (https://www.linkedin.com/company/yava-com/)
Instagram @YAVA_com (https://www.instagram.com/yava_com/)
X / Twitter @YAVA__COM (https://x.com/YAVA__COM)





Comments