Water SCADA Cyber Threat & Resilience Model

Mid-Sized Municipal Water Treatment Plant (12 MGD Capacity) • CISA/EPA OT Security Benchmark
CRITICAL_SAFETY_BREACH
Attack Scenarios (CISA Vectors) Purdue L1–L3
Attack Injection Control
Real-Time Audit Log
[00:00:01] System telemetry online. Modbus port 502 listening.
[00:00:45] CRITICAL: Unauthorized remote setpoint override sent to PLC-02.
Free Chlorine Residual (Dosing)
8.40 PPM
EPA Safe Limit: 0.20 – 4.00 PPM
Distribution Main Pressure
118 PSI
Nominal Range: 45 – 75 PSI
Clearwell Tank Storage
94 % Fill
Normal Capacity: 30 – 85%
Treated Effluent Outflow
11.8 MGD
Rated Plant Capacity: 12.0 MGD
PHYSICAL PROCESS LEVEL 0 (Hydraulic & Chemical Treatment Stream) TOXIC OVERFEED IN PROGRESS
PURDUE ARCHITECTURE (Levels 1 to 4) — Click Nodes to Inspect Tap link or node to audit security
Node Inspector: Click any node above (Cellular Gateway, SCADA Server, Dosing PLC, Sensor) to inspect communication protocol, vulnerabilities, and hardware fail-safe status.
Defensive Hardening Controls Score: 28/100
Incident Consequence Metrics
Time to Compromise: 45 sec
Peak Chlorine Dosing: 8.40 PPM
Hydraulic Overpressure Risk: Zone 2 Main Hazard
EPA/CISA Compliance Posture: NON-COMPLIANT

CISA / EPA Water Utility Cybersecurity Posture Report

Cross-Sector Cybersecurity Performance Goals (CPGs) & Physical Process Defense Audit
28
CRITICAL OT SECURITY DEFICIT: Physical Process At Risk
Plant architecture permits unauthenticated internet access directly to process controllers without hardware interlocks.
Priority Recommended Remediations
  • Disconnect internet-facing SCADA ports / enforce OT perimeter VPN with MFA
  • Implement physical mechanical limit switch on sodium hypochlorite dosing pump
  • Deploy out-of-band redundant chlorine residual sensor with independent shutdown relay
Active Threat Vector Grounding

Recent cyber attacks on U.S. municipal water utilities (e.g. Aliquippa, PA) leveraged exposed cellular routers and default passwords on programmable controllers (Unitronics). Defenses must combine zero-trust network isolation with physical mechanical safeguards that no cyber adversary can override over software.

Enjoy this tool? Build your own with Super