How a UK Utility Replaced Two SOCs With One UK-Sovereign Operation

In brief:

A UK utilities provider ran separate IT and OT security operations centres in separate countries. Correlation across them was manual, slow, and unreliable. e2e-assure replaced both with one UK-sovereign operation under Cumulo Enterprise. Alert noise fell 75 percent. Detection times improved 80 percent. Compliance reporting effort halved. All data now remains within UK borders.

Outcomes at a Glance

75%

Reduction in internal
analyst alert noise

80%

Faster detection times
across IT and OT estates

50%

Reduction in compliance
reporting effort

24/7

UK-sovereign SOC, all
data within UK borders

The Challenge: Dual SOCs, Manual Correlation, Sovereignty Gap

The organisation is a UK utilities provider operating critical national infrastructure. The environment is SCADA and DCS-heavy, spanning treatment and distribution sites across a wide geographic footprint. Regulatory obligations run deep: NCSC CAF, NIS2, IEC 62443, and sector-specific requirements from the regulator.

The client had invested in OT monitoring. On paper, the security architecture looked sound. An IT SOC handled endpoints, cloud, and corporate infrastructure from the UK. A specialist OT SOC monitored industrial control systems from a facility in mainland Europe. Both providers were competent within their own domains.

The problem was between them.

When a threat actor targets a utilities operator, they do not respect the boundary between IT and OT. An initial compromise on the corporate network, a phishing email, a stolen credential, a vulnerable VPN, is the entry point. The real target is the operational technology that controls physical processes. Tracking that movement requires a single view across both environments. The client did not have one.

Indicators of compromise flagged by one SOC had to be manually cross-referenced against alerts from the other. There was no shared platform. No unified case management. No automated correlation. The internal security team became the bridge, spending hours each week pulling alerts from two separate dashboards, trying to determine whether an IT event and an OT anomaly were part of the same incident or unrelated noise.

That manual correlation work was slow, inconsistent, and unsustainable. It also introduced a sovereignty problem. OT telemetry from UK critical national infrastructure was being processed and stored in mainland Europe. With the UK Cyber Security and Resilience Bill expected to tighten incident notification requirements and data residency obligations, the client needed to act before the regulatory landscape shifted under them.

Why the Existing Arrangement Was Structurally Insufficient

Neither provider was failing at their individual brief. The failure was structural.

  • Siloed SOC operations

    Two separate SOCs with no shared telemetry, no unified case management, and no automated correlation between IT and OT events. Every cross-environment investigation required manual work from the internal team.

  • Sovereignty gap

    OT telemetry from UK critical national infrastructure was processed and stored outside the UK. As compliance frameworks tighten around data residency and incident reporting, this created a regulatory exposure the client could not justify to the board.

  • Internal analyst burden

    The security team had become a manual integration layer between two providers. Analysts were spending their time on alert triage and cross-referencing rather than threat hunting, risk reduction, or strategic security work.

Why data sovereignty matters for UK CN: OT telemetry from regulated CNI sites carries data residency obligations under NCSC CAF and the forthcoming UK Cyber Security and Resilience Bill. Processing or storing that telemetry outside UK borders creates regulatory exposure that compounds as the legislative direction tightens. The dual-SOC arrangement was not future-proof.

The e2e-assure Approach: One Platform, One Team, One View

The client ran a formal tender process. The requirement was clear: a single, UK-sovereign SOC covering both IT and OT, with unified detection, automated correlation, and the compliance reporting to support upcoming regulatory changes. e2e-assure was selected to deliver the Cumulo Enterprise platform across the full estate.

Detection and Visibility Under Cumulo Enterprise

The OT Telemetry Analyser was deployed across the client’s operational sites, passively scanning SCADA and DCS protocols without disrupting live processes. OT assets were discovered, baselined, and grouped by process zone and criticality. Assets that had been monitored in isolation by the European SOC were now visible inside the same platform as the IT estate.

Cumulo correlates OT telemetry alongside EDR, cloud, identity, and log sources from the IT environment. A compromised credential on the corporate network that triggers lateral movement toward an industrial control system now appears as a single correlated incident. Not two tickets in two dashboards in two countries.

Detection rules are mapped to MITRE ATT&CK for ICS. The rules are tuned to the client’s specific environment, not generic signatures. This is what drove the 75% reduction in alert noise. When detection understands the difference between normal operational traffic and genuine anomalies, analysts investigate real threats instead of chasing false positives generated by rules that were never built for industrial environments.

Response and Containment With UK-only Data Residency

SC-cleared analysts monitor the full IT and OT estate 24/7 from e2e-assure’s UK-based SOC. All telemetry, case data, and encryption keys remain within UK borders at every stage. The sovereignty gap is closed.

OT-specific playbooks and escalation procedures were developed with the client’s operational teams. Containment decisions that could affect physical processes follow pre-agreed protocols, ensuring the SOC does not take action that risks disruption to essential services without the right approvals in the right order.

Triage follows published SLAs with a full case audit trail. The client’s security team and operational leadership have direct analyst contact through Cumulo’s web interface and the SOC Channel app in Microsoft Teams. Live case visibility is available on any device, not locked behind a VPN or a portal that only the security team can access.

Compliance Reporting Compressed by Half

The bonus outcome of the engagement was the compliance reporting reduction. Live dashboards mapped to IEC 62443 and the NCSC Cyber Assessment Framework replaced the manual evidence assembly the internal team had been doing across two provider outputs.

Audit preparation, which had previously absorbed weeks of internal effort per cycle, dropped by 50 percent. The dashboards produce the same evidence the regulators ask for, derived from the same telemetry the SOC uses operationally. There is no parallel reporting layer to maintain.

For the executive team, this was the outcome that closed the business case at board level. Detection improvements justify the engagement on operational grounds. Audit overhead reduction justifies it on financial grounds.

We had two SOCs and no single picture. Our analysts were the ones stitching it together, and that is not a good use of their time or a reliable way to catch something moving between IT and OT. Now we have one view, one team, and the compliance dashboards were a bonus we were not expecting. The board noticed before we even presented it.

The Outcome in Numbers

The client now has a single, UK-sovereign SOC monitoring its entire IT and OT estate around the clock. The internal security team is no longer the manual integration layer between two providers. They are focused on threat hunting, risk reduction, and strategic work. The sovereignty concern that was becoming a regulatory liability has been resolved. And compliance reporting, which was never the primary driver for the engagement, has become one of its most visible wins at board level.

75%

Reduction in internal analyst alert noise

Unified, environment-tuned detection rules replaced the output of two siloed SOCs. The internal team stopped trawling through alerts trying to find connections. The connections are now made automatically inside Cumulo.

80%

Faster detection times

Correlated IT/OT telemetry in a single platform means threats that cross the IT/OT boundary are identified in minutes, not pieced together over hours by internal analysts working across two dashboards.

50%

Reduction in compliance reporting effort

Live dashboards mapped to IEC 62443 and NCSC CAF replaced a manual process that required extracting and reconciling reports from two separate SOC providers. The board now sees a single, current view of security posture.

24/7

UK-sovereign SOC coverage

All telemetry, case data, and encryption keys processed and stored within UK borders. SC-cleared analysts across all roles. The data residency question is answered before the regulator asks it.

The engagement is ongoing. The client is evaluating expansion of the Cumulo platform to cover additional operational sites as its infrastructure grows, with quarterly detection surface validation built into the service.

What This Means for UK CNI Organisations

Three patterns from this engagement transfer to other UK utilities, energy operators, transport authorities, and adjacent CNI organisations.

  • First, transformation programmes outpace IT-only security by default.
    New OT networks emerge faster than IT-trained tooling can map them. Continuous OT discovery is the only sustainable way to keep pace.
  • Second, defence supply chain compliance is moving from periodic attestation to continuous evidence.
    Defstan, NIS2 and the UK Cyber Security and Resilience Bill all tighten in that direction. Live dashboards mapped to recognised frameworks compress audit overhead while making evidence reviewable on demand.
  • Third, the analyst tier matters as much as the platform tier.    SC-cleared, UK-based analysts with OT-specific experience are the scarcest resource in the UK cyber labour market.  Outsourcing to a UK-sovereign provider is the only realistic way most defence supply chain manufacturers will obtain that depth in 2026.

For utilities organisations evaluating 24/7 SOC coverage, Unified IT/OT Threat Detection covers how e2e-assure structures detection and response for environments like this one.

Why e2e-assure

e2e-assure operates a UK-based SOC with SC-cleared analysts across every role. Cumulo Enterprise unifies IT and OT detection inside one case workflow. All telemetry, case data, and encryption keys remain within UK borders at every stage.

Compliance dashboards are mapped to the NCSC Cyber Assessment Framework, NIS2, and IEC 62443 by design. Audit evidence is produced from the same platform that runs live detection, which is what compresses audit cycles without adding overhead.

The engagement model is built around UK CNI assurance from the design stage, not adapted to it later.

Running dual SOCs across IT and OT?

Schedule a discovery call to learn how a single UK-sovereign SOC can unify your detection and close the sovereignty gap.

Related Service

Unified IT/OT Threat Detection – one platform, one team, one view across your entire estate.

Frequently Asked Questions

Why does UK data sovereignty matter for OT monitoring at a CNI operator?

OT telemetry from regulated UK critical national infrastructure carries data residency obligations under the NCSC Cyber Assessment Framework and the forthcoming UK Cyber Security and Resilience Bill. Processing or storing that telemetry in a foreign jurisdiction creates regulatory exposure that compounds as the legislative direction tightens. A UK-sovereign SOC keeps every telemetry record, case file, and encryption key inside UK borders at every stage of processing, which is what the framework anticipates and what most operators will need to demonstrate before the next compliance cycle.

They replace separate IT and OT SOC providers with a single platform that ingests telemetry from both estates and produces one case workflow across both. Cumulo Enterprise correlates EDR, identity, cloud, and log telemetry with OT protocol telemetry from SCADA, DCS, and PLC systems. The result is one team triaging one set of cases against one compliance evidence base, rather than two teams producing two parallel artefacts that an internal analyst has to stitch together.

The NCSC Cyber Assessment Framework is the UK government’s structured framework for assessing how operators of essential services manage cyber risk. It covers governance, asset management, risk management, supply chain, identity and access, system security, resilient networks and systems, monitoring, response and recovery. CAF profiles apply to utilities, energy operators, and other CNI sectors, and provide the evidence basis for NIS2 compliance assessments in the UK context.

The Bill is expected to tighten incident notification timelines, data residency expectations, and supplier obligations across CNI sectors. Operators using offshore OT SOC arrangements face increasing exposure under the new requirements. Many CNI operators are now reviewing existing SOC arrangements ahead of the Bill’s commencement, prioritising UK-sovereign providers with SC-cleared analyst pools and demonstrable data residency in their procurement criteria.

In this engagement, compliance reporting effort fell by 50 percent. The reduction came from replacing manual evidence assembly across two provider outputs with live dashboards mapped to IEC 62443 and the NCSC Cyber Assessment Framework. The same telemetry that runs operational detection produces the audit evidence, so there is no parallel reporting layer. Outcomes vary by operator, but a step-change reduction is consistent across CNI operators moving from manual cross-provider assembly to platform-driven dashboards.

The OT Telemetry Analyser supports Modbus, DNP3, OPC-UA, and the common SCADA, DCS, and PLC protocols found across UK utilities estates. Coverage is passive, which means no packets are injected, no configurations are modified, and no operational risk is introduced by the act of monitoring. Where engagements require additional protocol depth, partnerships with EmberOT and Trinity OT extend the supported set.

The deployment timeline depends on site count, network segmentation, and existing documentation, but discovery, baselining, and live operation can be achieved within a single quarter for most UK utilities. The longer activities are typically the formal procurement and the transition planning with the outgoing provider, both of which should be scoped at the start of the engagement rather than at the end.

Both engagements address UK CNI operators with regulatory obligations around UK data residency. The utility consolidated dual SOCs into one unified operation. The energy provider considered building an internal SOC and chose to outsource after running the cost stack. The platform and operating model are consistent; the procurement triggers differ. Both case studies are linked in the related resources section.

Ready to Unify Your IT and OT Security?

Schedule a discovery call with our expert team to learn how a single UK-sovereign SOC can replace dual arrangements and close the sovereignty gap.