---
title: "Secure Water Treatment SCADA Networks | Control"
url: https://fire-vault.com/control-for-water
description: "Safeguard water treatment plants and pumping stations. Physically segment and control all network access to your critical OT and SCADA systems. Discover."
lang: en-GB
---

Water

# Treatment Plant and Distribution SCADA Path Control

Water treatment and distribution systems directly affect public health. When control systems are compromised, attackers can alter chemical dosing, disrupt supply, or contaminate drinking water for entire populations.

- SCADA compromise
- Chemical dosing tampering
- Ransomware
- Third-party vendor access

Back to Control: https://fire-vault.com/solutions/control

Control at a glance

Image: Water treatment facility at night with pipes and aeration tanks (https://fire-vault.com/assets/water-aybC1Izu.jpg)

Control removes the physical path. Blueprints show where each module sits.

Overview

## A real boundary between corporate IT and the chemistry of public water.

Read the Control for Water playbook: https://fire-vault.com/playbook/firebreak-water

Water infrastructure presents attackers with the opportunity for catastrophic physical harm. Control uses physical isolation to render treatment SCADA, dosing controllers and distribution telemetry disconnected from corporate IT and the wider internet. Fast to deploy, non-disruptive, and fully aligned to NIS2, DWI and Ofwat expectations, with immutable evidence ready for audit.

The exposure in numbers

01

Treatment SCADA isolation from corporate IT

100% Treatment SCADA isolation from corporate IT

02

Persistent remote access to dosing systems

Zero Persistent remote access to dosing systems

03

Operational zones with independent governance

5 Operational zones with independent governance

04

NIS2 and DWI compliance evidence

Full NIS2 and DWI compliance evidence

The Challenge

## Water infrastructure faces direct public health threats.

01

### Chemical Dosing Risks

Compromised control systems could alter chlorine dosing or pH levels in treatment processes, directly threatening public health on a massive scale.

02

### Remote Pumping Stations

Hundreds of remote pumping stations and reservoirs rely on SCADA communications with limited local security, creating distributed entry points.

03

### IT/OT Convergence

Smart water network modernisation creates network paths between corporate IT and operational technology that attackers can traverse.

Pain points

- Software-only defences can be bypassed by zero-day exploits targeting SCADA systems.
- Third-party SCADA vendor access creates persistent connectivity risks.
- Chemical treatment and pump control systems require strict access governance.
- NIS2, DWI and Ofwat security expectations require demonstrable segmentation and resilience.

Water

> When a water treatment control system is reachable from the corporate network, every phishing email becomes a potential path to altering the chemical composition of a city's drinking water.

The Scenario

### Scenario: Water Treatment SCADA Compromise

Attackers compromise a water company's corporate network through a targeted phishing campaign against the finance department. They move laterally until they reach a historian server that bridges the IT and OT networks. From there, they access the treatment plant SCADA system and modify chemical dosing parameters for chlorine and fluoride. The changes are subtle enough to avoid immediate alarm triggers but sufficient to affect water quality across the distribution area. With Control, the treatment SCADA network is physically disconnected from corporate IT. The historian server operates in a controlled zone with authorised, time-limited data transfer to corporate systems. The attack path from finance workstations to dosing controls does not exist.

"The historian server was our biggest vulnerability. It sat on both the IT and OT networks because the business needed water quality data in their dashboards. It was the bridge that gave attackers a direct path from email to the chlorine dosing system."

Module deployment · water utility network

## Where each Control module is deployed across treatment and distribution.

Water companies run the same Purdue stack as power, with telemetry reaching every treatment plant, reservoir and pumping station. Control puts a real boundary between the office, the telemetry network and the SCADA that moves and treats the water.

Grounded in NIST SP 800-82 Rev. 3, EPA Water Sector cybersecurity guidance and NIS2 Annex I.

L5

Cloud / Internet

External

Customer portal

Cloud services

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate

Public traffic stops in the DMZ.

L4

Enterprise

IT

SOC

SIEM

Billing

Office, billing, customer services.

Office, billing, customer services.

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak

Office cannot reach the plant on its own.

L3.5

Industrial DMZ

DMZ · trust boundary

Jump server

Patch & AV

Telemetry broker

Brokered exchange. No straight-through paths into the plant.

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate

Telemetry lands on a defined route only.

L3

Operations systems

OT

Historian

Engineering workstation

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate

Engineering and SCADA on separate fabrics.

L2

Supervisory control

OT

Treatment SCADA

Distribution SCADA

Control room view of treatment and the network.

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute

Treatment changes are approved before they move.

L1

Basic control

Field

PLCs

RTUs

Dosing controllers

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock

Field kit ties to named engineers.

L0

Physical

Field

Pumps

Valves

Sensors

OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Treatment recipes, plant configurations, distribution network maps and the recovery sets you need after an incident.

Offline by design · secure by default

Modules & symbols

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak Physical sever

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate Integrity check

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate Zone boundary

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay Time-bound path

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute Approved action

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock Named access

DMZ boundary Trust transition

OSS callout Off-network detail

### Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

1. Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
   Isolate
   At every Purdue boundary
   Office, telemetry, treatment and distribution sit on separate physical fabrics. A compromise on the corporate side cannot reach the plants.
2. Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
   Firebreak
   On the L5 to L4 link and the L4 to L3.5 link
   A real hardware off switch on the public and office boundaries, cutting the live path between corporate and the treatment plants.
3. Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
   Validate
   On the L5 to L4 link and inside the L3.5 DMZ
   Before any reading or request reaches operations, Validate checks its origin and integrity. A spoofed telemetry value does not become a chemical dose.
4. Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
   Relay
   Inside the L3.5 DMZ
   Sensor and pump data flows into SCADA on a scheduled, controlled route. Outside that route, telemetry cannot reach into control.
5. Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
   Execute
   On the L2 to L1 link
   Cross-plant actions need the right approval and the right state. Single clicks do not move treatment kit.
6. Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
   Lock
   On the L1 to L0 link
   Field devices tie to named engineers, the right device and the right authority.

Featured In

Read about Firevault on TechRadar Pro: https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough
Read about Firevault on Yahoo Finance: https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html
Read about Firevault on Channel Insider: https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/
Read about Firevault on Security Buyer: https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/
Read about Firevault on SecurityBrief: https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks

Capabilities

## What you get with every deployment

01

### Sovereign Water Data

All treatment and distribution control data remains within the agreed jurisdiction in secured Firevault Bunkers, meeting Ofwat and DWI requirements.

02

### Multi-Party Process Control

Changes to treatment parameters require authorisation from both operations and water quality teams, preventing unilateral modifications.

03

### DWI and NIS2 Evidence

Automated compliance logging maps directly to Drinking Water Inspectorate requirements and NIS2 Article 21 outcomes for water companies.

04

### Cellular SCADA Failover

Out-of-band management via cellular connectivity ensures control over treatment systems independent of primary communications infrastructure.

05

### Process Change Audit

Every dosing parameter change, valve operation, and access authorisation is recorded in tamper-proof logs for DWI and regulatory audit.

06

### Safe State Recovery

Verified baselines of treatment configuration enable rapid restoration to known-safe operating parameters during compromise scenarios.

Demo to Live

## Adoption Guide

Step 1

#### Water Network Assessment

Map all network paths between corporate IT, treatment SCADA, distribution SCADA, water quality systems, and remote pumping stations.

Step 2

#### Treatment Zone Design

Design physically separated zones for treatment, distribution, quality monitoring, and corporate systems with Control modules at each boundary.

Step 3

#### Single Works Pilot

Deploy at one treatment works with full SCADA isolation, multi-party process authorisation, and compliance logging to validate operational procedures.

Step 4

#### Company-Wide Deployment

Phased deployment across all treatment works and pumping stations with verified configuration baselines, continuous compliance evidence, and cellular management.

Step 1

#### Water Network Assessment

Step 2

#### Treatment Zone Design

Step 3

#### Single Works Pilot

Step 4

#### Company-Wide Deployment

Organise a Demo: https://fire-vault.com/contact

Relevant Control Blueprints

## Deployment patterns that apply here

CP-05 FIRE+VAULT

### Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

View blueprint
https://fire-vault.com/control-blueprints/cp-05

CP-04 FIRE

### Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

View blueprint
https://fire-vault.com/control-blueprints/cp-04

CP-02 FIRE

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

View blueprint
https://fire-vault.com/control-blueprints/cp-02

## Explore More

### Control for Utilities

Physical isolation for power grid and utility SCADA.

Learn more about Control for Utilities
https://fire-vault.com/control-for-utilities

### Control for Critical Infrastructure

National-grade security for essential services.

Learn more about Control for Critical Infrastructure
https://fire-vault.com/control-for-critical-infrastructure

### IT/OT Convergence Threat

Physically separate IT from operational technology.

Learn more about IT/OT Convergence Threat
https://fire-vault.com/control-for-it-ot-convergence

Questions

## Frequently Asked

Water blueprint - PoC

### Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-for-water#webpage",
    "url": "https://fire-vault.com/control-for-water",
    "name": "Secure Water Treatment SCADA Networks",
    "description": "Safeguard water treatment plants and pumping stations. Physically segment and control all network access to your critical OT and SCADA systems. Discover.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-for-water#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-for-water#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Secure Water Treatment SCADA Networks",
        "item": "https://fire-vault.com/control-for-water"
      }
    ]
  }
]
```