Xcina Case Study

Telecommunications Security Act Compliance

Subject Matter Expert and Compliance Advisor for Telecommunications Provider

About the client

The organisation is a large UK B2B telecommunications network provider company. It provides fibre only, open access connectivity across the UK to ISPs.

Highlights and key components of the engagement

Xcina Consulting was engaged as a Telecoms Security Act (TSA) subject matter expert and compliance advisor.

Methodology and Approach

Our role was to:

  • Provide trusted advisor support services and act as the organisation’s dedicated TSA subject matter expert.
  • Review and update TSA trackers, marking the client’s compliance with TSA, as well as noting, where necessary, the next steps to be taken towards achieving compliance.
  • Review and update supporting document artefacts, including security policies, ensuring compliance with the Act’s requirements.
  • Prepare the relevant Cyber Assessment Framework (CAF) audit documentation in line with the TSA.
  • Conduct an annual internal control by control audit of the client’s compliance with the Act’s Code of Practice requirements.
  • Discuss audit findings throughout the audit to ensure no surprises in the draft audit report.
  • Draft the audit report and discuss it with the auditees, ensuring that all feedback is considered in the final report.
  • Identify non-compliances and opportunities for improvement, and provide recommendations to address findings
  • Work with top management to prioritise remediation of identified non-compliances
  • Update the related tracker documents with identified nonconformities to be remediated.

 

Results and Outcome

Over the course of several months, Xcina consultants served as the client’s TSA trusted advisor. This period covered the dates when specific measures in the associated Code of Practice formally became effective, and the creation of responses to the regulator against strict deadlines.

Xcina supported this programme of work, and the client has successfully completed two formal responses to the regulator’s (Ofcom) requests for information on how the organisation is meeting the TSA and its Code of Practice.

Xcina is currently leading the creation of the response document for a third request for information from the regulator.

What This Means for You

Whether you are at an early stage of the TSA journey or looking for continuous improvement, Xcina delivers:

  • Independent assessments against leading cyber maturity frameworks such as TSA, ISO27001, NIS2, DORA, NIST and CAF, identifying areas for improvement
  • Expert advice on complex security issues and best practices
  • Pragmatic implementation assistance to help achieve a defensible cyber maturity and compliance posture against the relevant requirements
  • A long-term partnership and ongoing assistance throughout your journey, not just a point-in-time assessment

 

To find out more about how we can assist you, please refer to our Information Governance Consultancy Services at https://xcinaconsulting.com/services/information-governance/

 

 

Industry and sector:

Telecoms

Solutions and service area:

Xcina’s objective:

Xcina Consulting was engaged as a Telecoms Security Act (TSA) subject matter expert and compliance advisor.

We’d love to hear from you

To discuss how the areas highlighted in this case study, or any other aspect of risk management, information governance or compliance impact your business, speak with our team, tell us what matters to you and find out how we can help you navigate complex issues to help you deliver long term value.

If you have any questions or comments, or if there’s anything you would like to see covered, please get in touch by emailing Xcina Consulting at info@xcinaconsulting.com. We’d love to hear from you.

David MacPhail

Information Security Senior Consultant

Speak to me directly by Email, or
Telephone: +44 (0)20 3745 7820

David MacPhail

Subscribe to Updates

Receive regular updates from our expert consultants as they provide clarification and guidance on issues impacting your organisation.

Subscribe >>