Network resilience is judged on evidence. Where does yours live?

Electricity and gas network operators and interconnectors have to show effective systems and controls over risk and resilience, across IT, operational technology, contractors and physical assets. ERM+ links those risks to the controls, suppliers and incidents behind them, so the evidence is already assembled when it is asked for.

Who this page is for

  • Electricity transmission and distribution operators
  • Gas transmission and distribution networks
  • Interconnectors

Typically 100 to 1,000 employees, established and regulated, with the risk register, supplier oversight and resilience work still run largely by hand.

What you are asked to show, and where ERM+ holds it

Licence obligations and price control reporting

What it asks

Evidence that risk, asset and resilience management work as described in your business plan and regulatory returns.

What ERM+ holds

Risks linked to assets, controls and investment decisions, with history you can report from rather than rebuild each cycle.

NIS Regulations 2018

What it asks

Appropriate security measures for network and information systems, and incidents reported to the competent authority.

What ERM+ holds

IT and OT risks, their controls and security incidents in one record, with timestamps for when each was raised and escalated.

Business continuity and emergency planning

What it asks

Plans that hold up in a storm, a cyber event or a supplier failure, and proof they have been tested.

What ERM+ holds

Scenarios, test results and the dependencies they exercised, including field contractors and telecoms carriers.

Supply chain oversight

What it asks

Visibility of the vendors and contractors critical systems and field operations rely on.

What ERM+ holds

A supplier register linked to the systems, sites and risks each supplier supports, so shared dependencies are visible.

A summary to frame the conversation, not legal advice. The first call establishes exactly which requirements apply to your firm.

When a vendor or contractor fails, how quickly can you see every service that depended on it?

  • IT and OT risk sit in different places

    Corporate IT risk is in one register, operational technology in another, and the link between them is in someone’s head.

  • Contractors are part of the network

    Field services, telecoms carriers and system vendors carry operational risk that rarely appears next to the assets it affects.

  • Every regulatory cycle starts from scratch

    When evidence is assembled by hand for each submission, the same work is repeated and the audit trail is thin.

Who usually owns this

Head of Risk / CRO

Also: Head of Operational Resilience, Risk Director

What you are dealing with
The risk register, third-party oversight and the resilience framework sit in separate spreadsheets. There is no single view of risk, and every board pack is assembled by hand.
What ERM+ gives you
One view of every risk type, with controls, incidents and suppliers linked to it. Risk committee reporting straight from live data.
Usually prompted by
A supervisory letter, a third-party incident, or the next board risk committee.

Working with network operators

Owns and operates the physical, bi-directional gas pipeline between the UK and Belgium. An important part of the European energy supply chain, providing economic benefits and promoting security of supply across the UK and the EU.

  • Gas transmission services
  • 150 employees

Built by practitioners, priced below enterprise GRC

More than 50 years of risk experience between the co-founders and over 500 with our senior associates. Implementation in weeks, not months.

Meet the team

“ERM PLUS significantly reduced the time and resources for achieving regulatory compliance in risk and prudential management.”

Head of OpRisk · Asset Management Firm

“The expertise and professionalism of the ERM Plus team are unparalleled. Their strategic guidance and hands-on approach have been instrumental in achieving our business goals.”

Head of Risk · Retail Brokerage Firm

Twenty minutes will tell us both whether there is anything worth exploring.

We look at what you capture today, what your regulator will ask for, and whether there is a gap. If there is nothing there, no need to take it further.

A gap check, not a pitch. No project, no budget conversation, no access to sensitive data.