Home>Operational Assurance

Operational assurance

One accountable service. Evidence you can act on.

Operational assurance connects the way a managed service is designed and run with the evidence needed to review it: service health, incidents, changes, policy activity, responsibilities, known gaps and agreed actions. It is not a reporting add-on. It is what becomes possible when connectivity, security and observability are operated as one service, by one team, with a single point of accountability.

What is Governance Debt?

Your infrastructure is distributed. Multiple networks, clouds, security controls and suppliers – some chosen deliberately, others inherited through acquisition or stood up quickly to meet an urgent requirement, and most bought as separate point solutions through separate contracts.

Most providers run their own part well. But services rarely fail inside one neat technology silo. They fail where responsibility is fragmented, in the space between suppliers, where no single party owns the end-to-end route, the policy, the telemetry and the operational authority together.

As the estate changes, the gap between how each service is meant to run and how it actually runs keeps widening. That accumulating gap is governance debt, and it comes due every time somebody asks a question the estate cannot answer.

When an auditor asks which system caused an outage, I have to go back to three different teams.

When Governance Debt comes due

Many organisations assemble service and control evidence only when a review, audit or regulatory submission approaches. Teams pull screenshots from tools, reconstruct changes, reconcile supplier reports and chase owners for missing context. The data may exist, but it was not designed to answer the governance question.

That is governance debt being repaid manually, by the people least able to spare the time, against a deadline set by somebody else.

One service, one record

Cloud Gateway runs connectivity, security and observability as one service, integrated through one Unified Control Plane and delivered by one UK-based team. Responsibility sits in one place, as does the record of how it runs.

Three things follow from that operating model:

Orchestration

Services are designed, provisioned and changed as one, not stitched together after the fact, so the change record is a single continuous account rather than four partial ones.

Service intelligence

Telemetry and service context are connected across the services in scope, so signals become understanding rather than another dashboard to interpret.

Assurance

Evidence that proves control and performance, rather than asking anyone to take it on trust.

Cloud Gateway defines which operational records the selected service should create, how they relate to the service boundary, who owns each decision and where limitations are recorded. Observe presents the available service view. Operational assurance is the use of that evidence for service review, governance and audit readiness.

How it helps your team

Service leadership

Review whether the service is operating as agreed, and which risks or actions need attention.

Risk and governance

Assess control and supplier performance using traceable operational evidence rather than unsupported assertions.

Audit readiness

Reduce the manual work needed to locate and reconcile records for an assessment or assurance cycle.

Executive reporting

Translate service operation into a concise account of condition, material events, decisions, risk and action.

The same record for every framework

CAF and DSPT

The Cyber Assessment Framework is the National Cyber Security Centre’s framework for assessing cyber resilience in organisations responsible for essential services. Since September 2024 the NHS Data Security and Protection Toolkit has aligned to it, so NHS trusts, ICBs, ALBs and CSUs now report against CAF objectives, principles and outcomes rather than the previous checklist. That shift moved the burden from ticking boxes to demonstrating outcomes, which requires operational evidence.

ITHC

An IT Health Check is an independent technical security assessment required for connection to public sector networks including HSCN and PSN, and for various other regulated services. It is typically required annually, or after material changes to the system being assessed.

What any of them will ask a managed service for

Change records showing who changed what, when, why and with what approval. Patch and firmware evidence with completion detail. Policy enforcement, including rules, blocks and exceptions. Incident history with actions and resolution times. Service-level delivery against what was contracted. Access governance showing who has access to what, validated and reviewed.

Ensuring responsibility stays clear

Cloud Gateway can provide the operational evidence and reporting expressly included in the managed
service. The customer remains accountable for its regulatory submission, control framework, risk
decisions, legal interpretation and relationship with its auditor or regulator. Operational evidence is not
an audit opinion, certification or guarantee of compliance.

Operational assurance underpins every service

Observe Essentials provides a monthly assurance summary for eligible Cloud Gateway managed services: available service-health evidence, material incidents, completed changes, open issues, data coverage, known limitations and agreed actions. It is an operational service report, built to support a service review rather than to serve as an audit opinion.

More specialised evidence outputs need a defined scope and data model before we will offer them, which is deliberate. We would rather tell you what the service can evidence than promise a pack and reconcile the difference later.

Trusted where failure is not an option.

We work with organisations that cannot afford to fail: NHS trusts, central government, local authorities and police forces, plus the tech innovators who serve them. Delivery is fully managed or co-managed with guardrails, backed by a 24/7 UK-based Network Operations Centre.

Where the evidence comes from

01

A monthly account of health and activity

The standard service-health view and the monthly assurance summary for eligible managed services in your agreement.

02

Evidence of security policy and controls

Managed Firewall and the Protect services are where policy, configuration and change evidence originates.

03

A standing record of your connection

Documented evidence for the connection you are being assessed on, rather than assembling it from scratch.

Define the evidence before the next review cycle.

Bring one critical service that crosses networks, clouds or suppliers. We will map who is accountable for what today, where the gaps sit, and what evidence that service can produce.