Overview
LIPA owns Long Island's electric transmission and distribution system; PSEG Long Island operates it day to day under a long-term operating services agreement. Given the criticality of grid operations to public safety and regional infrastructure, LIPA periodically commissions independent cybersecurity assessments of its operating contractor's security posture. For its most recent assessment, LIPA selected Optic Cyber Solutions to conduct the technical work — and engaged tieBridge to sit above the entire lifecycle of that engagement, as the independent party responsible for shaping what would be assessed, helping select who would do the assessing, and confirming that the resulting recommendations actually turned into remediation.
Because the subject matter is security-sensitive by nature, this case study describes tieBridge's oversight role and methodology rather than the content of the assessment itself.
The challenge
- A cybersecurity assessment of critical grid infrastructure needed to be independent and credible, and structured against a recognized framework rather than a vendor's proprietary checklist.
- LIPA, as principal, does not operate the systems being assessed — PSEG Long Island does — so the engagement had to be scoped, negotiated, and executed across two organizations at once, not just between LIPA and a single vendor.
- The procurement itself was a specialized, technical purchase: an RFP for a cybersecurity assessment has to be detailed enough to attract and fairly evaluate qualified specialist firms, without prematurely disclosing sensitive information about the systems being assessed.
- A finished assessment report only has value if its recommendations are acted on — the real risk was that findings would sit on a shelf once the assessment contractor's engagement ended.
Our role across the engagement lifecycle
Rather than a single, bounded task, tieBridge's role spanned the full arc of the engagement — a level of continuity that let the same team carry context from how the assessment was scoped all the way through to whether its recommendations were actually implemented:
- Requirements & RFP development — translating LIPA's cybersecurity oversight objectives into a structured set of requirements and a competitive RFP.
- RFP evaluation support — supporting LIPA in evaluating proposals received from prospective assessment firms.
- Contractor selection support — supporting LIPA's selection of Optic Cyber Solutions as the assessment contractor.
- Contract negotiation support — supporting negotiation of the resulting contract terms.
- Scope of Work refinement — working directly with Optic Cyber to refine the Scope of Work before assessment work began.
- Assessment execution oversight — providing independent oversight throughout the life of the assessment.
- Remediation oversight — continuing on after the assessment concluded to oversee the remediation efforts arising from its recommendations.
Procuring something you can't fully describe in public
Writing a competitive RFP for a cybersecurity assessment is a genuine balancing act: the requirements have to be specific enough to let qualified firms scope their proposals accurately and let LIPA compare responses on a fair, apples-to-apples basis, without disclosing sensitive detail about the very systems the assessment would examine. tieBridge developed the requirements and RFP with that tension built in, then carried the same context into evaluating responses and supporting contractor selection — so the standard used to select a contractor stayed consistent with the standard used to define the work in the first place.
A roadmap, not a static report
The assessment was structured around the NIST Cybersecurity Framework (CSF) 2.0: an independent "Current State" profile of PSEG Long Island's cybersecurity posture, compared against a "Target State" profile, with the resulting gap analysis translated into a prioritized improvement roadmap. tieBridge's oversight pressed for that last step — organizing the gaps identified into four concrete workstreams (Build Assurance and Drive Governance; Evaluate and Communicate Resilience Requirements; Expand Security Integration and Validation Processes; and Enable Proactive Detection and Rapid Response), each with its own action plan — so the deliverable was something LIPA and PSEG Long Island could actually execute against, not just a static snapshot in time.
Staying at the table after the assessment ended
Assessment engagements often end at the final report, leaving remediation to happen — or not — without independent oversight. tieBridge's mandate explicitly continued past that point: having helped scope, negotiate, and oversee the assessment itself, the team stayed engaged to oversee the remediation efforts that followed, providing continuity between what the assessment recommended and what LIPA and PSEG Long Island actually did about it.
Impact
- Gave LIPA a single, continuous line of independent oversight spanning procurement through remediation — closing the handoff gaps that typically open up between contracting, assessment execution, and follow-through.
- Delivered an RFP and evaluation process specific enough to attract and fairly compare qualified cybersecurity assessment firms, without compromising sensitive information about the systems under review.
- Ensured the final Scope of Work reflected operational realities refined jointly with the assessment contractor, rather than untested assumptions carried over from the RFP stage.
- Anchored the assessment against the NIST Cybersecurity Framework 2.0, giving LIPA and PSEG Long Island a benchmarked, comparable Current State and Target State profile rather than a one-off, vendor-specific scorecard.
- Converted assessment findings into a structured, four-workstream roadmap with concrete action plans — and kept independent oversight in place through the remediation phase so those plans did not stall once the assessment contractor's engagement ended.