Cyber-Physical Security
A digital access control panel and the door it operates are one attack surface, not two. GSS assesses cyber and physical security together, across the full lifecycle from design through authority to operate.
Two programs that don't talk to each other leave the gap between them undefended
Most facilities run physical security and cybersecurity as separate functions with separate budgets, separate assessments, and separate reporting lines. That division made sense when a facility's control systems were analog and its network was an office IT problem. It stops making sense the moment a digitally controlled barrier, sensor, or access panel becomes part of the protective strategy — because an adversary does not respect the org chart that separates the two teams.
GSS treats cyber-physical security as a single discipline. The same engagement that assesses a barrier's delay time or a sensor's detection probability also assesses the network, credentials, and control logic that operate it, because a compromised controller can defeat a well-designed physical countermeasure without anyone breaching a fence line.
The team leading this work includes former U.S. NRC inspectors who authored the cybersecurity regulations now governing U.S. plants. That background matters for a specific reason: it means the program is built to the standard a regulator will actually apply, not a generic industry framework retrofitted to a nuclear or critical-infrastructure environment after the fact.