The System behind the System: The Twin Assurance Problem in High-Integrity Engineering

High-integrity engineering has traditionally focused on assuring “the product”: the software, the hardware, the system, the platform that performs the intended function. Safety, security and dependability claims are typically developed around the emergent behaviour of that product in operation. However, modern systems increasingly depend on complex environments responsible for developing, configuring, deploying, updating and sustaining the product throughout its lifecycle.

This creates what can be described as a Twin Assurance Problem.

Confidence in the product is no longer sufficient on its own. We must also establish confidence in the socio-technical systems, processes, tools and people responsible for the product’s development. This challenge becomes particularly acute as organisations adopt AI-assisted engineering, automated toolchains, continuous delivery practices and increasingly interconnected supply chains.

This presentation proposes a framework for distinguishing between assurance of the product and assurance of its environment while recognising that both ultimately contribute to overall system dependability. Drawing on examples from safety-critical and security-critical domains, it explores how the safety-security of a system and its environment can be meaningfully analysed through a common co-assurance lens. The presentation argues that many current assurance approaches focus heavily on the product while treating the supporting environment as a secondary concern.

As engineering becomes increasingly automated and adaptive, this distinction becomes more difficult to sustain. A Twin Assurance perspective provides a means of reasoning about trust, evidence and confidence across both domains, helping organisations address emerging assurance challenges without abandoning established engineering principles.

Speaker

Nikita Johnson Needle

Lead Engineer - OT Cyber Security, Rolls Royce SMR

Nikita Johnson is a Lead Engineer for OT Cyber Security at Rolls-Royce SMR working at the intersection of safety, security and assurance for safety-critical systems. Their work focuses on the development, certification and assurance of complex cyber-physical systems, with particular emphasis on demonstrating confidence in security claims for high-consequence applications.

Nikita’s experience spans industry, academia and standards development. Nikita previously worked as a Product Security Engineer at Rolls-Royce, served as co-chair of a EUROCAE working group on aeronautical security, and held research positions including Innovation Fellow at the University of Sheffield and Assuring Autonomy Researcher at the University of York, contributing to research on trustworthy and dependable systems.

Nikita’s specialist interests include assurance cases, safety-security co-assurance, risk management and the challenge of providing convincing evidence that increasingly complex systems remain dependable in the face of evolving threats.

Sponsored by

Official Media Partners

Aerospace Innovations

Sponsored and Organised by