Recent Breaches
Breaches
View All →
Utilities - Water and wastewater

Physical isolation for treatment, distribution and outstation telemetry

Water companies run a central control room linked to thousands of remote sites over private telemetry. Firevault Control puts a real boundary between the office, the telemetry network, the plant SCADA and the dosing and pumping kit behind it.

Back to Utilities
Control

Utilities - Water and wastewater

When treatment SCADA, outstation telemetry and corporate IT share the same paths, every software vulnerability becomes a candidate for a dosing or supply incident.

100%

Plant SCADA isolation from corporate IT

Zero

Persistent remote access to dosing controllers

6

Control modules deployed per water zone

Full

Evidence for NIS2 and DWI security expectations

The Challenge

Water control systems carry public safety consequences and a thin attack surface to defend.

Dosing and public health

Treatment SCADA controls chemical dosing. A spoofed reading or unauthorised setpoint change can become a public health incident inside one shift.

Long-lived outstations

Outstation RTUs and PLCs were deployed over decades, are reachable over private APN telemetry and cannot all be patched at once.

Shared corporate paths

WIMS, asset management and billing share infrastructure with the office estate, creating paths into operations that should not exist.

The Scenario

Scenario: Telemetry spoofing into a treatment plant

Attackers gain a foothold on the corporate estate and pivot through a shared engineering jump server into the treatment SCADA network. Spoofed turbidity readings are injected into the historian, prompting an automated dosing increase. The control room only realises after downstream quality alarms fire. Investigation takes weeks because the historian, the engineering workstation and the recovery archive all share the same domain. With Firevault Control, telemetry lands on a defined route through the industrial DMZ with origin and integrity checks. The treatment SCADA fabric is physically separate from corporate IT. Verified baselines for dosing setpoints are held on infrastructure that has no live network path to production and require multi-party authorisation to release.

"Once you start scoring incidents in litres of water or milligrams of chlorine, you stop arguing about the cost of physical separation."

Module deployment · water and wastewater network

Where each Control module is deployed across treatment and distribution telemetry.

Water and wastewater operators bridge a central control room to thousands of remote sites over private telemetry. Control puts a real boundary between the office, the telemetry network, the plant SCADA and the field devices that move and dose the water.

Grounded in NIST SP 800-82 Rev. 3, EPA Water Sector cybersecurity guidance, NIS2 Annex I and DWI security expectations.

L5

Cloud / Internet

External

Customer portal
Cloud analytics
FirebreakValidate

Public traffic stops in the DMZ.

L4

Enterprise

IT

SOC
SIEM
Billing
Asset management

Office, billing and customer services.

Office, billing and customer services.

IsolateFirebreak

Office cannot reach the plant on its own.

L3.5

Industrial DMZ

DMZ · trust boundary

Jump server
Patch & AV
Telemetry broker
APN gateway

Brokered exchange. Private APN telemetry lands here.

Brokered exchange. Private APN telemetry lands here.

RelayValidate

Outstation telemetry arrives on a defined route only.

L3

Operations systems

OT

WIMS
Historian
Engineering workstation

Water information management and engineering tools.

Water information management and engineering tools.

Isolate

WIMS and SCADA sit on separate fabrics.

L2

Supervisory control

OT

Treatment SCADA
Network SCADA
HMI

Control room view of plants and the distribution network.

Control room view of plants and the distribution network.

Execute

Dosing and pump changes need approval before they move.

L1

Basic control

Field

Plant PLCs
Outstation RTUs
Dosing controllers

Treatment works, pumping stations, reservoirs.

Treatment works, pumping stations, reservoirs.

Lock

Field kit ties to named engineers.

L0

Physical

Field

Pumps
Valves
Quality sensors
OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Treatment recipes, dosing safety limits, plant configurations, distribution network maps and the recovery sets you need after an incident.

Offline by design · secure by default

Modules & symbols

FirebreakPhysical sever
ValidateIntegrity check
IsolateZone boundary
RelayTime-bound path
ExecuteApproved action
LockNamed access
DMZ boundaryTrust transition
OSS calloutOff-network detail

Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

  1. Isolate

    At every Purdue boundary

    Office, telemetry, treatment and distribution sit on separate physical fabrics. A compromise on the corporate side cannot reach the plants or the outstations.

  2. Firebreak

    On the L5 to L4 link and the L4 to L3.5 link

    Real off switches on the boundaries that matter most when an incident is live.

  3. Validate

    On the L5 to L4 link and inside the L3.5 DMZ

    Telemetry and engineering requests are checked for origin and integrity. A spoofed reading does not become a chemical dose.

  4. Relay

    Inside the L3.5 DMZ

    Outstation data flows into SCADA on scheduled routes. Outside the window, telemetry cannot reach control.

  5. Execute

    On the L2 to L1 link

    Treatment and network actions hold until the right authority signs them off.

  6. Lock

    On the L1 to L0 link

    Field devices tie to named engineers, the right device and the right authority.

Featured In

TechRadar ProSecurity BuyerYahoo FinanceSecurityBriefChannel Insider

Key Capabilities

Sovereign water data

Operational and customer data remains within the agreed jurisdiction in carefully selected Firevault Bunkers.

Multi-party control

Dosing and major network changes require sign-off from both control room and security teams.

Regulatory evidence

Continuous compliance evidence aligned to NIS2, EPA Water Sector guidance and DWI security expectations.

Out-of-band management

Cellular and dedicated paths keep the control plane reachable when primary telemetry is compromised.

Tamper-proof logging

Every access, configuration change and dosing command lands in immutable logs on physically separate infrastructure.

Verified configuration baselines

Verified baselines of plant and network configuration enable a known-good restore of control-plane state.

Demo to Live

Adoption Guide

Step 1

Network assessment

Map every path between corporate IT, WIMS, treatment SCADA and outstation telemetry to identify convergence and persistent vendor connections.

Step 2

Zone architecture design

Design physically separated zones aligned to your plants and distribution estate, with Control modules at each boundary.

Step 3

Non-production pilot

Deploy in a test environment mirroring a treatment works and outstation pair with full zone separation, multi-party authorisation and compliance logging.

Step 4

Operational deployment

Full deployment across the water estate with verified configuration baselines, continuous compliance evidence and 24/7 out-of-band management.

Step 1

Network assessment

Map every path between corporate IT, WIMS, treatment SCADA and outstation telemetry to identify convergence and persistent vendor connections.

Step 2

Zone architecture design

Design physically separated zones aligned to your plants and distribution estate, with Control modules at each boundary.

Step 3

Non-production pilot

Deploy in a test environment mirroring a treatment works and outstation pair with full zone separation, multi-party authorisation and compliance logging.

Step 4

Operational deployment

Full deployment across the water estate with verified configuration baselines, continuous compliance evidence and 24/7 out-of-band management.

Questions

Frequently Asked

Water blueprint - PoC

Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.

    Firevault

    Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.

    © 2026 Firevault Limited. Disconnect to Protect®