
The engagement focused on activating latent AI/ML capabilities already embedded within the client’s existing technology investments, rather than introducing entirely new platforms. This approach maximised return on investment while minimising deployment risk.
The assessment covers nine connected security and operational towers, creating a shared view of where existing capabilities, dependencies and constraints shape the opportunity for AI/ML:
•IT Infrastructure and Cloud •CISO & Head of Cybersecurity •Identity and Access Management
•OT Security •Plant & Operations •Application Security •Governance Risk & Compliance •Network Infrastructure •SOC &Incident Response
Securing and governing critical technology environments across corporate and operational domains.
Activating AI features within current platforms to make better use of approved technology investments.
Enhancing visibility and automating manual processes to reduce workload and improve incident response times.
Ensuring absolute adherence to safety protocols, particularly in OT environments where all AI solutions must remain advisory-only.
How NTT DATA helps
Inputs, dependencies, activities and outputs. Establishes the scope, decision owners and evidence required, so the assessment begins with a clear view of what must be understood and what each stage must produce.

Processes, tooling and CNI considerations. Maps how security and operational work is performed today, including the approved technology estate and the constraints that apply across critical national infrastructure.

Problem, benefit, metrics, feasibility and tooling alignment. Creates a consistent basis for comparing opportunities across towers, linking each use case to a defined problem, an observable benefit and the capabilities already available.

Independent assessment of approved tools only, integration effort and risk. Tests whether existing platforms can support the intended use case and identifies the practical integration, governance and operational implications before any pilot is proposed.

Ranking of use cases based on impact, feasibility and risk; effort bands for future pilots. Gives leaders a transparent way to distinguish near-term opportunities from use cases that require further evidence, dependency resolution or control design.

Milestones and dependencies SME constraints. Sequences the work around the availability of subject-matter experts, operational windows and technology dependencies, keeping ambition aligned with delivery reality.

Consolidated pack and executive recommendations. Brings the evidence, prioritisation and roadmap into one decision-ready view, giving executives a clear basis for sponsorship, governance and next-step planning.


The recommended approach is phased, beginning with high-priority use cases that deliver immediate value and building towards a comprehensive AI-augmented security posture.
A clear roadmap to operationalise AI/ML across SGN’s security and operations estate.
A structured catalogue of 42 AI/ML opportunities provides a concrete foundation for moving from assessment to implementation across SGN’s security and operations estate.
Coverage across nine security and operational towers creates an estate-wide view of where AI/ML can add value, spanning IT, cyber, identity, OT, operations, applications, governance, networks and incident response.
The roadmap prioritises activating AI capabilities already embedded within SGN’s existing technology investments, helping accelerate adoption while limiting unnecessary new tooling and integration complexity.
Use cases are structured around impact, feasibility and risk, creating a phased route from high-priority opportunities towards broader AI-augmented security while respecting critical operational and OT constraints.