01
The binder
The cybersecurity documentation for your survey, insurance renewal, or AWIA update, organized in the order the reviewer reads it.
Water, waterfront, power, and manufacturing
You run the plant, the distribution system, and most of the paperwork. Now the insurance renewal, the board, and in some states the sanitary survey are all asking about cybersecurity.
We find the unexpected ways into your plant's controls, tell you what to fix first, and fix it if you want us to. Most of it is remote, and we don't touch a running PLC. The assessment takes three weeks and comes with the paperwork, at one price you can usually sign yourself.
Look your system up, see the price, and buy it. No form, no quote, and no sales call unless you want one. Or have your own IT provider handle it.
01
The cybersecurity documentation for your survey, insurance renewal, or AWIA update, organized in the order the reviewer reads it.
02
Accurate answers to your insurance carrier's cybersecurity questionnaire. Where an answer would cost you at renewal, we fix that item before you send it.
03
What to fix, in order of risk, with the cost of each item and the funding that can pay for it. One page, ready for the board.
Fixed price, whether it takes us three days or eight.
What we find
The person who set up remote access retired. Nobody's sure their login still works.
There's one password for the HMI and everybody on shift knows it.
The HMI runs on a PC that's several Windows versions behind.
Somebody put a cell modem on a lift station years back. Nobody's looked at it since.
Backups are on a drive sitting right next to the server they're backing up.
A pump vendor still has a way in from a contract that ended in 2019.
All of it can be fixed without taking the plant down.
The July 2026 attacks
The last week of July 2026, somebody got into better than thirty Minnesota systems in about two days. South St. Paul, Plymouth, Maple Plain, Braham. Clayton County down in Georgia too, which put out a boil-water advisory. By early August, water systems in at least twelve states had reported intrusions.
Some plants went to manual operation, and Braham's was offline for hours. No public health impact was reported.
Those controllers could be reached from the internet. If you run a Rockwell MicroLogix, or any controller that answers from outside, we check whether yours can be reached, and close it off.
Sources: Minnesota IT Services; MPR News; CISA, EPA, and FBI alert on water sector PLCs, July 30, 2026.
Got a question first? Talk to an engineer. 877.387.7733, 7–6 CT, M–F.
Or if you'd rather look yourself first, the five-question check takes two minutes and doesn't ask for anything.
Services
The work underneath is the same. What changes is the document you end up with, and who it is written for. One price, set by the size of your system.
You have a sanitary survey coming up
If your state includes cybersecurity in the survey, we take that part. We walk the plant, fix what can be fixed before the inspector arrives, and put together the paperwork for that section.
Who is asking: Your state drinking water program, where it includes cyber in the survey
Who can pay: Operating budget. Under the no-bid line in every state we have checked
The renewal questionnaire is sitting on your desk
Underwriters now ask whether logging in takes a second step, how people get in from outside, and whether the plant network is kept separate. We answer it accurately. Where an answer would cost you at renewal, we fix that item before you send it.
Who is asking: Your carrier and whoever underwrites it
Who can pay: Operating budget
Your AWIA emergency response plan is due
AWIA updates come every five years and cover physical and cyber together. Systems serving 3,301 to 49,999 people certified the risk and resilience assessment by June 30, 2026, and owe the updated emergency response plan by December 31, 2026. We take the cyber sections. Fixed fee.
Who is asking: EPA, every five years
Who can pay: Drinking Water State Revolving Fund, where your state allows it
There's money available and the paperwork is the holdup
EPA says the Drinking Water State Revolving Fund can pay for cybersecurity, and some states add their own programs. The application runs about forty pages. We write it, and work out what it should pay for.
Who is asking: None. This one is optional
Who can pay: Drinking Water State Revolving Fund, and state programs
There was an alert, or something happened a county over
In late July 2026, attackers got into more than thirty Minnesota systems in about two days. Operators switched to manual and no public health impact was reported. We check whether your controllers can be reached from the internet, and write one page for the board.
Who is asking: Your board, council, or general manager
Who can pay: Operating budget
What we cover
WaterISAC publishes twelve Cybersecurity Fundamentals for water and wastewater utilities, and narrowed them to eight for small systems. Those eight are what we cover.
| Fundamental | What we do about it |
|---|---|
| 01 Plan for Incidents, Emergencies, and Disasters | We write the response plan for the plant and the call list, and make sure the logging an investigation depends on is actually turned on. |
| 02 Minimize Control System Exposure | We find every path between your control system and the outside, close the ones nobody needs, and secure the remote access you do need. |
| 03 Create a Cyber Secure Culture and Protect from Insider Risks | We document who has access and why, and give you the short version your operators will actually follow. |
| 04 Implement System Monitoring for Threat Detection and Alerting | We stand up monitoring sized for your plant and route the alerts somewhere a person will see them. |
| 05 Account for Critical Assets | We build the inventory: PLCs, HMIs, radios, modems, and the things somebody added years ago and forgot. |
| 06 Enforce Access Controls | A second step to log in from outside, everyone on their own login instead of a shared one, and vendor access you can switch off. |
| 07 Embrace Risk-Based Vulnerability Management | We rank what is actually exploitable in your environment and tell you what to leave alone. |
| 08 Secure the Supply Chain | We list every third party with a way in and put terms and an off switch on each one. |
What we don't do.
Safeguard from Unauthorized Physical Access — Fences, gates, hatches, and locks stay with the people who own them today.
Install Independent Cyber-Physical Safety Systems — Process safety engineering. We will tell you when you need it and we do not sell it.
Free programs, and what they assume
There are good free programs out there. Vendors that give small utilities security software for the plant at no cost. Federal advisories. The sector's own published fundamentals. We point clients at all of it, and we use it ourselves.
Each of them assumes the utility supplies the hardware, makes the network changes, and has the skills to set it up on a running plant.
That is the part we do. Your licensed operator runs the plant; our engineers set up and run the security.
The same guidance the free programs give, carried out, at a set price.
What it costs
Every state sets a line below which a town or district can buy without formal bids: $13,200 in Pennsylvania, $17,500 in New Jersey, $25,000 for a Texas water district. Our assessment prices sit under all of them, and under the $15,000 federal line when State Revolving Fund money pays. Under the line you write the PO yourself. No RFP, no bids. Your own signing limit is set by your board or council, so check it against the price for your size.
| Your system | Population served | Assessment |
|---|---|---|
| Small system | Under 3,300 served | $2,900 |
| Mid-size system | 3,300 – 50,000 served | $4,900 |
| Large system | Over 50,000 served | $17,900 |
One price, one job, one document at the end. No hourly billing, no change orders. See all pricing, including fixes and ongoing coverage.
Find your system
Every community water system in the country is in the federal record. We pull yours up, show you what applies at your size, and give you the price. No form first.
Source: EPA SDWIS federal reporting, active community water systems.
Who you get
A method used in more than 500 assessments of live plants, written down so it comes out the same every time, whoever runs it. A senior control-system engineer signs off on your report before it goes out.
25+ yrs
of our founder's work inside live plant control systems
500+
plant-safe assessments and penetration tests worldwide
4,500+
people trained on plant cybersecurity
Our founder, Jonathan Pollet, is a founding contributor and editor of ISA/IEC 62443 and the early NERC CIP standards.
Most of the work gets done remotely. If we need eyes on something in person, we tell you before you sign, not after.
What we cover: the cyber side. Networks, remote access, and the control systems behind them. Fences, gates, process safety and water quality are still yours. And we don't touch a running PLC.