
Operating reality
Most of this estate has nobody standing in it.
Treatment works are staffed. Lift stations, booster sets, reservoirs, borehole sites and outfalls generally are not. They report over cellular or licensed radio, they are visited on a maintenance round rather than continuously observed, and the first indication that something is wrong is usually a telemetry alarm rather than a person. That changes what detection has to mean and what physical and credential control has to carry.
The consequence profile is also distinct. In most industries the worst realistic outcome is lost production. Here it runs to chemical dosing, to a compliance sample, and to what reaches a consumer's tap or a watercourse. That single fact should drive prioritization more than any asset count, and it is the reason dosing and analyzer logic is treated with the same restraint as a safety instrumented system.
The constraints are real and they are not a failure of diligence. Teams are small, often with one person carrying both IT and SCADA. Capital moves on a municipal or regulatory determination cycle, not on a quarter. RTU and PLC estates are ageing and sometimes past vendor support. Operators know all of this better than any advisor does.
So the value is in prioritization and compensating control, not in replacement plans that will never be funded. A device that cannot be changed for years can still be given a defensible position: what can reach it, what it can reach, who holds the credential, and what would be noticed if it behaved differently.
The worst day in this sector is not lost production. It is what reaches a tap or a watercourse, and that should set the order of the work.
Operational priorities
Four things water programs have to get right.
These are the priorities that decide whether a water program actually moves, ahead of any question about tooling.
01 · Prioritize by public health consequence
Work is ranked by what a compromise could do to water quality, dosing, containment and compliance sampling. That ordering puts a small number of systems far above the rest of the estate, and it is the argument that carries a capital case with a board or a council.
02 · Design for sites nobody visits
Remote assets need controls that hold without a person present: credentials that are not shared across the estate, telemetry paths that are authenticated rather than merely reachable, physical access that is recorded, and alarm behavior that would look wrong if a site were interfered with.
03 · Compensating controls, honestly costed
Where an RTU or PLC cannot be replaced within the funding cycle, the answer is a defensible position around it rather than a plan that assumes replacement. Each control is written with what it does and does not mitigate, so the residual risk is stated rather than implied.
04 · A program that outlasts one person
In small teams, capability that lives in one head disappears with that person. Standards, configuration baselines, runbooks and supplier requirements are written down and handed over, so the next appointment inherits a program rather than a folder of passwords.
In scope
Five environments we work in.
Dosing logic is treated with the same restraint as a safety instrumented system. It is reviewed by documentation and configuration, and it is never a cybersecurity testbed.
Treatment SCADA
Works SCADA and its servers, operator stations, plant PLCs and the control of intake, screening, filtration, disinfection, sludge handling and final discharge at staffed sites, with the local historian and alarm layer above them.
What we commonly find is one flat works network, where SCADA, site CCTV, the works office and a contractor's laptop all hold the same connectivity because nothing in the original scope required otherwise. We work from configuration, drawings and passively collected traffic. No controller is polled, nothing is scanned, and no activity is scheduled across a critical process step without the works manager agreeing the timing first.
Remote sites and telemetry
Lift and pump stations, booster sets, reservoirs, boreholes, storm overflows and outfalls, together with the cellular, licensed radio and leased paths that carry them back to the control room.
These sites rest unusually heavily on credentials and physical access, because nobody is standing in them. The recurring findings are one credential shared across the whole estate, telemetry that is reachable rather than authenticated, and outstations still holding their commissioning configuration. We assess from telemetry configuration, carrier records and control-room polling data rather than by probing outstations, and design controls a maintenance round can genuinely sustain.
Dosing and analyzers
Chemical dosing control for coagulation, pH correction and disinfection, the online analyzers that verify it, and the setpoint limits and interlocks around them.
This environment is handled with the same restraint as a safety instrumented system: documentation and configuration review only, never interrogated live, never used to demonstrate a finding. What configuration does establish is which paths can reach a dosing setpoint, which credentials can change one, whether limit and interlock logic sits where a compromised supervisory layer cannot alter it, and what the control room would actually see if a setpoint moved.
Operations network
The operations LAN, the historian, regulatory and compliance reporting, work and asset management, and the interface to customer, metering and billing systems.
This is where the utility's two halves meet, and the corporate side has legitimate reasons to cross. We rebuild the picture from firewall rule sets and routing, give every permitted flow a direction and a named owner, and design a boundary that can be evidenced without breaking the reporting a compliance obligation depends on. Where one person carries both sides, the design and the runbooks are written so the position still holds while that person is on leave.
Vendor and maintenance access
Integrator and framework contractor connections, telemetry supplier access, panel builders, engineering laptops and every standing remote path into the estate.
In a lightly staffed utility these routes exist because the work genuinely depends on them, so removing them is not the answer. Each is inventoried against the agreement that created it, then brokered through a managed path with privileged credentials, a review interval and a revocation event tied to contract end. Findings are written as specification language you can attach to the next framework retender, rather than as a request for a supplier to volunteer a change mid-contract.
Related solutions
Where water engagements usually start.
Each stands alone, and each can be sized to a funding cycle. Most utilities begin with one works and one representative remote site before committing anything further.
Questions from this sector
What water and wastewater teams ask us first.
We have one person covering IT and SCADA. Who is going to carry this?
That constraint shapes the whole engagement rather than being noted and ignored. Scope is sized to what one person can maintain, controls are chosen for low operating overhead, and anything requiring continuous attention is either designed out or proposed as a managed service with the decision rights staying with you.
The other half of the answer is handover. Standards, baselines, runbooks and supplier requirements are written down and left with you, so the position survives that person moving on — which is the failure mode we see more often than any technical one.
Our capital is fixed by a determination cycle. We cannot fund a program like this.
Then the program has to be written to the cycle you are in, not the one an advisor would prefer. Work is separated into what can be done within operating expenditure now — access control, credential separation, firewall policy, backup and recovery, monitoring — and what genuinely needs capital and therefore needs a submission.
For the capital half, the deliverable is the argument as much as the design: consequence stated in public health and compliance terms, because that is what carries a case with a board, a council or a regulator. An asset count does not.
Half our outstations are past vendor support and we cannot replace them.
Nor should you be told to, on a timescale that does not exist. An unsupported RTU or PLC can still be given a defensible position: what can reach it, what it can reach, who holds the credential, and what the control room would notice if it behaved differently.
Each compensating control is written with what it does and does not mitigate, so the residual risk is stated plainly rather than implied. Replacement then enters the asset plan on its own merits and its own timescale, instead of becoming the precondition for doing anything at all.
Our remote sites run over a private cellular APN. Is that not enough?
It is a useful control and it is not a boundary. A private APN limits who can route to the outstations from the public network. It does not authenticate the telemetry itself, it does not prevent one compromised site reaching another if the APN is flat, and it does not cover what the carrier's own management plane can do.
The questions worth answering are whether outstations can talk to each other or only to the control room, whether the protocol authenticates anything, and what the arrangement with the carrier actually commits them to. All three can be established from configuration and contract.
We are a small utility. Is anyone really interested in us?
Deliberate targeting is not the common case, and we will not claim otherwise. What reaches small utilities is mostly untargeted — exposed remote access, reused credentials, commodity ransomware arriving through the corporate side and spreading because the boundary was never designed.
That is reassuring in one respect: the controls that address opportunistic exposure are the affordable ones, and they are early in the sequence. Prioritizing by consequence simply tells you which handful of systems deserve more than that.
Next step
Start with one works and one remote site.
That pair establishes effort, disruption and value across both halves of the estate, and produces the design pattern and the capital argument the rest of the program reuses.
- No active scanning — passive collection and configuration review only
- Dosing logic treated like SIS — reviewed on paper and by configuration, never interrogated live
- Sized to the funding cycle — prioritized and staged, not a replacement plan you cannot fund
- Written to be handed over — standards and runbooks your team owns and can maintain
- Vendor-independent — specifications written to be tendered competitively
Questions from this sector
What operators in this industry ask first.
What makes water and wastewater OT cybersecurity difficult?
Small teams, large geography and thin budgets. Treatment and pumping sites are often unstaffed, connected over cellular or radio, running long-lived controllers with limited monitoring, and maintained by one or two people who already have day jobs. The consequence, meanwhile, is public health and regulatory.
Does InnovAKT work with municipal utilities and smaller systems?
Yes. The work is scoped to what a small utility can actually operate: remote access first, because it is the most common path in; then backup and recovery, because restoration time is the real resilience question; then visibility. A control a utility cannot sustain is not a control.
How should a water utility prioritize with a limited budget?
By consequence and by reachability. Secure the paths that allow someone outside to reach a controller, prove you can rebuild a site's control system from backup, establish who holds remote access and remove what is no longer needed. Those three cost comparatively little and remove the most common ways an event actually starts.