When water stops, it's a public-health issue in hours.
Water and wastewater are critical national infrastructure. A cyber incident moves from “IT outage” to loss of supply, loss of treatment or loss of environmental control, fast.
It often does not start inside the utility. A compromised supplier, an exposed remote-access service or a misconfigured OT device can be enough to create real-world impact across treatment and distribution.
Regulators have responded. DWI, DEFRA and Ofwat now expect boards to demonstrate operational resilience under cyber stress, not just compliance on paper, with stricter obligations coming under the Cyber Security & Resilience Bill.
Hours
Not days
When supply or treatment fails, a cyber event becomes a public-health and environmental issue within hours. Groups have manipulated OT to overflow tanks, cut pressure and disrupt treatment.
100s
One supplier, sector-wide
The compromise of a single sector software supplier has already exposed hundreds of public utilities in one incident.
2018
A rising curve
Reported cyberattacks against water and wastewater utilities have increased sharply since 2018, with a record number of UK NIS reports.
Three capability areas
Our work is organised into three capability areas. Each maps directly onto the problems water operators face, across raw-water abstraction, treatment works, networks, wastewater and sludge, with a strong emphasis on continuous, measured resilience monitoring.
01
Industrial Resilience
Prepare for, withstand and recover from cyber incidents and operational disruption, and prove it continuously.
NEXION Cyber Resilience Platform
Continuous resilience monitoring
Readiness for major incidents
GRC
Penetration testing
02
Operational Technology
Secure and modernise the control systems and OT environments that run your works, networks and plants, with awareness and training so changes stick.
OT Programme Design & Delivery
OT architecture & engineering
Site enablement
Due diligence
Supply-Chain Security & GRC
Data & AI Governance
OT awareness & training
03
Industrial Tech & Innovation
Bring smart networks, digital twins and AI into a live water environment without losing control of risk.
Industrial domain advisory
Agentic BPMN
AI-ready data architecture
AI governance
Data governance
We are vendor-, tool- and standard-agnostic. We map to NIS/CAF, DWI and DEFRA guidance, Ofwat expectations and the UK Cyber Security & Resilience Bill, without locking you into any particular technology or vendor.
NIS / CAF
DWI / DEFRA
Ofwat
CS&R Bill
The three domains
We frame water-sector OT risk across three operational domains. The technologies and regulators differ by domain, but the questions are the same.
Can you keep safe water flowing and wastewater under control during a cyber incident?
Can you prevent cyber events from escalating into safety or environmental harm?
Can you recover critical systems and trusted data within agreed tolerances?
Can you show continuous, measured improvement in resilience to DWI, Ofwat and government?
01
01Water
Water treatment & supply
Abstraction, treatment works, disinfection, reservoirs and potable networks.
The problem
Water treatment and supply rely on a dense mix of OT: raw-water intake controls, coagulation and filtration, disinfection dosing, clear-water pumping, reservoir levels and distribution networks. Control runs on PLCs, RTUs, SCADA and HMI systems that often grew up piecemeal over decades. Many of these assets now sit on IP networks, are remotely monitored, or have OEM remote access enabled, and in some plants, remote-desktop tools or web HMIs have historically been exposed directly to the internet. This combination of legacy equipment and modern connectivity creates easy paths for attackers and makes lateral movement from IT into OT far more likely where segmentation is weak.
OT Programme Design & Delivery
Site Enablement
OT Supply-Chain GRC
Readiness for major incidents
Continuous resilience monitoring
How we solve it
Build a live asset inventory of PLCs, RTUs, HMIs and SCADA servers across abstraction, treatment and treated-water networks.
Segment treatment OT from business IT, and safety-critical functions like disinfection control from non-critical systems.
Remove public internet exposure of HMIs, PLCs and VPN portals; put remote access behind authenticated gateways with MFA.
Develop degraded-mode playbooks for works and control rooms, partial automation, manual sampling, local control, isolation.
Track resilience indicators over time with NEXION: critical-asset coverage, segmentation, backup integrity and exercise performance.
Continuity of safe water supply demonstrated under real cyber scenarios, not just assumed.
Reduced likelihood that one exposed system or supplier affects water quality or supply.
Faster, rehearsed recovery for treatment works and potable networks.
Continuously updated evidence for DWI and Ofwat of essential-service continuity.
02
02Water
Wastewater & drainage
Sewage treatment works, pumping stations, CSOs and sludge.
The problem
Wastewater and drainage combine thousands of remote pumping stations, combined sewer overflows (CSOs), treatment works and sludge plants, often with limited physical security, running on RTUs, radio telemetry, remote monitoring and central SCADA. The sector is already under intense scrutiny for environmental performance. Cyber incidents that cause loss of pumping, unplanned discharges or loss of effluent quality add a deliberate dimension: attacks that worsen pollution events or overwhelm ageing infrastructure. At many remote sites the boundary between IT and OT is thin, engineering laptops, telemetry links and ad-hoc remote access share the same pathways, making it easy for an attacker to move from one to the other.
OT Programme Design & Delivery
Site Enablement
OT Supply-Chain GRC
Penetration testing
Continuous resilience monitoring
How we solve it
Build an integrated view of the wastewater OT estate, pumping stations, CSOs, treatment works and sludge plants, and their shared platforms.
Design segmentation and access control for remote sites that respect physical constraints but still separate IT from process control.
Harden and monitor remote access: authenticated, time-bound maintenance with MFA and logging; remove ad-hoc remote desktop and modem access.
Map critical functions, preventing spills, maintaining consented effluent quality, to the systems and suppliers that support them.
Rehearse cyber-enabled pollution scenarios: loss of a pumping station, telemetry or control, and how you manage environmental risk while responding.
Reduced risk that cyber incidents translate into uncontrolled discharges or consent breaches.
Clear degraded-mode operation, with defined priorities when telemetry or control is impaired.
Stronger standing with regulators when pollution events occur, evidence cyber risk is managed.
Measured improvement in detection, response and recovery at remote sites.
03
03Water
Smart networks & emerging tech
Smart metering, DMAs, pressure management, leakage control, digital twins and AI-driven optimisation.
The problem
Water companies are investing heavily in smart networks: intelligent pressure control, district metered areas (DMAs), network sensors, smart meters and digital-twin platforms, relying on large numbers of connected devices, cloud services and vendor platforms acting on operational data. That connectivity is changing the attack surface. In many utilities a significant share of devices are unmanaged OT, IoT or network equipment, and undocumented external connections into OT, vendor tunnels, cloud connectors and exposed telemetry gateways, remain common. Governed poorly, the same AI tools that make networks efficient can make them more fragile and harder to recover.
OT Security Due Diligence
Data & AI Governance in OT
OT Supply-Chain GRC
Industrial domain advisory
Continuous resilience monitoring
How we solve it
Build an inventory of smart-network assets, sensors, loggers, smart meters, pressure systems and gateways, with firmware and ownership.
Design secure architectures for smart-network and digital-twin platforms, separating data acquisition, analytics and control.
Apply OT-appropriate identity and access control: unique credentials, MFA, time-boxed vendor accounts and rapid revocation.
Establish data governance for operational data feeding digital twins and AI, lineage, quality, retention and access.
Embed cyber and NIS/CAF alignment into business cases, design reviews and go-live criteria.
Smarter networks without a corresponding increase in cyber fragility.
Confidence that new sensors, meters and platforms aren't undermining your OT baseline.
Digital-twin and AI benefits built on trustworthy, well-governed operational data.
Ongoing, measurable insight into the resilience of your smart-network stack.
Outcomes that prove resilience, not just compliance
Water regulators now expect operators to show they can keep essential services running safely under cyber disruption. Our approach is built around five outcomes aligned with NIS/CAF, DWI, Ofwat and the UK Cyber Security & Resilience Bill, underpinned by continuous, measured monitoring.
01Continuity of essential water services under cyber stress
Define Minimum Viable Operational Levels for supply and wastewater, design degraded-mode playbooks for works, control rooms and networks, and embed them into business continuity and emergency planning.
02Controlled safety & environmental risk during cyber incidents
Map process hazards and environmental risks to cyber attack paths, protect disinfection and critical treatment controls, and run joint cyber-safety and cyber-environment exercises that prove compliant operation under response.
03Assured recovery time & data integrity
Set recovery priorities and tolerances for systems and data supporting water quality, supply and wastewater compliance; implement and test immutable backups and clean-room rebuilds; evidence restoration within agreed timeframes.
04Maintained regulatory & stakeholder confidence
Structure the programme around measurable outcomes aligned to CAF and water-sector expectations, with regulator-ready evidence packs and board reporting drawn from continuous monitoring.
05Reduced systemic & supply-chain disruption
Map interdependencies across OT vendors, MSPs, telemetry and radio providers, labs, cloud and telecoms, uplift resilience requirements for critical suppliers, and monitor supplier-related indicators continuously.
What we offer, and where it helps
Every capability maps to a specific water need across the three domains. Use this as the at-a-glance view of how we can help.
ALL
SUPPLY
WASTEWATER
SMART
Industrial Resilience
NEXION Cyber Resilience Platform
ALL
Continuous OT monitoring and a single view of resilience posture across works, networks and remote sites.
Continuous resilience monitoring
ALL
Live resilience indicators, asset coverage, segmentation, backup integrity and exercise performance.
Readiness for major incidents
ALL
Works-, control-room- and network-down playbooks, rehearsals and tested recovery.
Penetration testing
WASTEWATER
OT-safe validation of segmentation and remote-site access separation.
Operational Technology
OT Programme Design & Delivery
SUPPLY
WW
Multi-site OT security architecture and roadmap, delivered without disrupting operations.
Security Adoption & Site Enablement
SUPPLY
WW
On-the-ground rollout and commissioning across treatment works and remote stations.
OT Security Due Diligence
SUPPLY
SMART
Cyber assurance at capex, new works, smart-network programmes and platform go-lives.
OT Supply-Chain Security & GRC
ALL
Risk-tiering and continuous assurance of OEMs, MSPs, telemetry and cloud providers.
Industrial Tech & Innovation
Industrial domain advisory
ALL
Safety-cyber convergence and OT strategy from operator-side practitioners.
Agentic BPMN
ALL
Modelling and automating operational and assurance workflows for consistency and control.
Data & AI Governance in OT
SMART
Integrity and governance of smart-network and digital-twin data feeding analytics and AI.
AI governance & Data governance
ALL
Governing AI that touches operational decisions, on trusted operational data.
We come from the operational floor.
We have delivered OT security and resilience programmes across water, energy and other critical infrastructure. That matters here, where advice that ignores water-quality, environmental and customer-service realities does not survive contact with operations.
We are vendor-, tool- and standard-agnostic, we work with your existing SCADA, PLCs, telemetry and obligations, and we leave you with capability, not dependency. Above all, we help you measure resilience continuously.
Operator-side practitioners
Engineers who have programmed the PLCs, built the panels and recovered the plant across 25+ industrial sites.
Vendor-, tool- and standard-agnostic
We map to what you already run and the frameworks you answer to. We leave you with capability, not dependency.
Board to floor
Evidence the board can act on, delivered inside live operational constraints, not a slide deck.
Talk to a practitioner about water OT.
Engineers who have stood in the control room, not a slide deck.