01
The binder
Everything for the cyber part of your survey, in the order the inspector reads it. You hand it over. You don't put it together.
For water & wastewater operators
You run the plant. And the distribution system. And most of the paperwork. Now the survey's asking about cybersecurity, so is the insurance renewal, and the board wants to know what you told them.
Hand it to us. Most of it we can do without coming out there. Three weeks and you've got the paperwork, for one price, small enough you can sign it yourself.
Look your system up, see the price, and buy it. No form, no quote, no sales call. Or have your own IT provider handle it.
01
Everything for the cyber part of your survey, in the order the inspector reads it. You hand it over. You don't put it together.
02
Your carrier's questionnaire, filled out straight. If two or three answers would've cost you at renewal, we fix those first, then you send it.
03
What to fix, worst first, what each one runs, and which grant will cover it. Fits on a page, so you can hand it to the board.
Fixed price, whether it takes us three days or eight.
What we find
The guy who set up remote access retired. Nobody's sure his login still works.
There's one password for the HMI and everybody on shift knows it.
The HMI runs on a PC that's several Windows versions behind.
Somebody put a cell modem on a lift station years back. Nobody's looked at it since.
Backups are on a drive sitting right next to the server they're backing up.
A pump vendor still has a way in from a contract that ended in 2019.
All of it can be fixed without taking the plant down.
The July attacks
Last week of July, somebody got into better than thirty Minnesota systems in about two days. South St. Paul, Plymouth, Maple Plain, Braham. Clayton County down in Georgia too, and systems in at least a dozen other states. One of them had to put out a boil order.
The operators caught it, switched to manual, and no water was contaminated.
Those controllers could be reached from the internet. If you run a Rockwell, a Modicon, or a Siemens S7, we check whether yours can, and close it off.
Sources: Facilities Dive reporting on the July 26–27 campaign; CISA, FBI, and EPA advisories on PLC targeting.
Got a question first? Talk to an engineer. (555) 014-8300, 7–6 CT, M–F.
Or if you'd rather look yourself first, the five-question check takes two minutes and doesn't ask for anything.
Services
The work underneath is the same. What changes is the document you end up with, and who it is written for. One price, set by the size of your system.
You have a sanitary survey coming up
We take the cyber part of the survey. We walk the plant, fix what can be fixed before the inspector arrives, and put together the paperwork for that section.
Who is asking: Your state drinking water program, for the cyber part of the survey
Who can pay: Operating budget. Under the purchase limit in most towns
The renewal questionnaire is sitting on your desk
Underwriters now ask whether logging in takes a second step, how people get in from outside, and whether the plant network is kept separate. We fill it out straight. If two or three answers would've cost you at renewal, we fix those first, then you send it.
Who is asking: Your carrier and whoever underwrites it
Who can pay: Operating budget
Your AWIA recertification is coming due
Your risk and resilience assessment has a date on it, and it covers physical and cyber together. We take the cyber section. Fixed fee.
Who is asking: EPA, on a set cycle
Who can pay: State Revolving Fund, in most states
There's money available and the paperwork is the holdup
SRF, BRIC, and state programs fund cyber fixes. The application runs about forty pages. We write it, and work out what it should pay for.
Who is asking: None. This one is optional
Who can pay: SRF, FEMA BRIC, and state cyber grant programs
There was an alert, or something happened a county over
In late July, attackers got into more than thirty Minnesota systems in about two days. Operators switched to manual and no water was contaminated. We check whether your controllers can be reached from the internet, and write one page for the board.
Who is asking: Your board, council, or general manager
Who can pay: Operating budget
What we cover
WaterISAC publishes twelve Cybersecurity Fundamentals for water and wastewater utilities, and narrowed them to eight for small systems. Those eight are what we cover.
| Fundamental | What we do about it |
|---|---|
| 01 Plan for Incidents, Emergencies, and Disasters | We write the response plan for the plant and the call list, and make sure the logging an investigation depends on is actually turned on. |
| 02 Minimize Control System Exposure | We find every path between your control system and the outside, close the ones nobody needs, and secure the remote access you do need. |
| 03 Create a Cyber Secure Culture and Protect from Insider Risks | We document who has access and why, and give you the short version your operators will actually follow. |
| 04 Implement System Monitoring for Threat Detection and Alerting | We stand up monitoring sized for a plant your size and route the alerts somewhere a person will see them. |
| 05 Account for Critical Assets | We build the inventory: PLCs, HMIs, radios, modems, and the things somebody added years ago and forgot. |
| 06 Enforce Access Controls | A second step to log in from outside, everyone on their own login instead of a shared one, and vendor access you can switch off. |
| 07 Embrace Risk-Based Vulnerability Management | We rank what is actually exploitable in your environment and tell you what to leave alone. |
| 08 Secure the Supply Chain | We list every third party with a way in and put terms and an off switch on each one. |
What we don't do.
Safeguard from Unauthorized Physical Access — Fences, gates, hatches, and locks stay with the people who own them today.
Install Independent Cyber-Physical Safety Systems — Process safety engineering. We will tell you when you need it and we do not sell it.
Free programs, and what they assume
There are good free programs out there. Vendors that give small utilities security software for the plant at no cost. Federal advisories. The sector's own published fundamentals. We point clients at all of it, and we use it ourselves.
Each of them assumes the utility supplies the hardware, makes the network changes, and has the skills to set it up on a running plant.
That is the part we do. Your licensed operator runs the plant; our engineers set up and run the security.
We set it up, and we run it. The same guidance the free programs give, carried out, at a set price.
What it costs
Most towns have a limit on what you can buy without going out for bids. Usually somewhere between $3,000 and $10,000. Under that, you write the PO yourself. No RFP, no bids, nothing on the council agenda. The entry price sits below the low end of that range.
| Your system | Population served | Assessment |
|---|---|---|
| Small system | Under 3,300 served | $2,900 |
| Mid-size system | 3,300 – 50,000 served | $4,900 |
| Large system | Over 50,000 served | $17,900 |
One price, one job, one document at the end. No hourly billing, no change orders.
Find your system
Every community water system in the country is in the federal record. We pull yours up, show you what applies at your size, and give you the price. No form first.
Source: EPA SDWIS federal reporting, active community water systems.
Who you get
A method run on more than 500 live plants, written down so it comes out the same every time, whoever runs it. A senior control-system engineer signs off on your report before it leaves the building.
25+ yrs
inside live plant control systems
500+
plant-safe assessments and penetration tests worldwide
4,500+
people trained on plant cybersecurity
A founding contributor and editor of ISA/IEC 62443 and the early NERC CIP standards.
Most of the work gets done remotely. If we need eyes on something in person, we tell you before you sign, not after.
What we cover: the cyber side. Networks, remote access, and the control systems behind them. Fences, gates, process safety and water quality are still yours. And we don't touch a running PLC.