---
title: "Water Utility SCADA Security by Firevault - Control for wat…"
description: "Physically isolate treatment SCADA, distribution telemetry and dosing safety. Evidence for NIS2, EPA guidance and DWI security expectations."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control-for-utilities-water#webpage",
      "url": "https://fire-vault.com/control-for-utilities-water",
      "name": "Water Utility SCADA Security by Firevault - Control for wat…",
      "description": "Physically isolate treatment SCADA, distribution telemetry and dosing safety. Evidence for NIS2, EPA guidance and DWI security expectations.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control-for-utilities-water#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control-for-utilities-water#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Water Utility SCADA Security by Firevault - Control for wat…",
          "item": "https://fire-vault.com/control-for-utilities-water"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Create Your Vault](/get-started)

Utilities - Water and wastewater 

# Physical isolation for treatment, distribution and outstation telemetry 

Water companies run a central control room linked to thousands of remote sites over private telemetry. Control puts a real boundary between the office, the telemetry network, the plant SCADA and the dosing and pumping kit behind it.

Schedule a Demo[Back to Utilities](/control-for-utilities)

![Water treatment plant with tanks and pipework at dusk](/assets/sector-square-water-BtQfD35Z.jpg)

Exposure

How it worksExplore moreQuestions

The exposure in numbers 

01 

Plant SCADA isolation from corporate IT

100% Plant SCADA isolation from corporate IT 

02 

Persistent remote access to dosing controllers

Zero Persistent remote access to dosing controllers 

03 

Control modules deployed per water zone

6 Control modules deployed per water zone 

04 

Evidence for NIS2 and DWI security expectations

Full Evidence for NIS2 and DWI security expectations 

The Challenge 

## Water control systems carry public safety consequences and a thin attack surface to defend.

01 

### Dosing and public health

Treatment SCADA controls chemical dosing. A spoofed reading or unauthorised setpoint change can become a public health incident inside one shift.

02 

### Long-lived outstations

Outstation RTUs and PLCs were deployed over decades, are reachable over private APN telemetry and cannot all be patched at once.

03 

### Shared corporate paths

WIMS, asset management and billing share infrastructure with the office estate, creating paths into operations that should not exist.

Utilities - Water and wastewater

> When treatment SCADA, outstation telemetry and corporate IT share the same paths, every software vulnerability becomes a candidate for a dosing or supply incident.

The Scenario

### Scenario: Telemetry spoofing into a treatment plant

Attackers gain a foothold on the corporate estate and pivot through a shared engineering jump server into the treatment SCADA network. Spoofed turbidity readings are injected into the historian, prompting an automated dosing increase. The control room only realises after downstream quality alarms fire. Investigation takes weeks because the historian, the engineering workstation and the recovery archive all share the same domain. With Control, telemetry lands on a defined route through the industrial DMZ with origin and integrity checks. The treatment SCADA fabric is physically separate from corporate IT. Verified baselines for dosing setpoints are held on infrastructure that has no live network path to production and require multi-party authorisation to release.

"Once you start scoring incidents in litres of water or milligrams of chlorine, you stop arguing about the cost of physical separation."

Module deployment · water and wastewater network 

## Where each Control module is deployed across treatment and distribution telemetry.

Water and wastewater operators bridge a central control room to thousands of remote sites over private telemetry. Control puts a real boundary between the office, the telemetry network, the plant SCADA and the field devices that move and dose the water.

Grounded in NIST SP 800-82 Rev. 3, EPA Water Sector cybersecurity guidance, NIS2 Annex I and DWI security expectations.

L5 

Cloud / Internet

External

Customer portal 

Cloud analytics 

![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak ![FV-Validate module icon](/assets/vault-icon-DWJpRH8k.png)Validate 

Public traffic stops in the DMZ.

L4 

Enterprise

IT

SOC 

SIEM 

Billing 

Asset management 

Office, billing and customer services.

Office, billing and customer services.

![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate ![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak 

Office cannot reach the plant on its own.

L3.5 

Industrial DMZ

DMZ · trust boundary

Jump server 

Patch & AV 

Telemetry broker 

APN gateway 

Brokered exchange. Private APN telemetry lands here.

Brokered exchange. Private APN telemetry lands here.

![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay ![FV-Validate module icon](/assets/vault-icon-DWJpRH8k.png)Validate 

Outstation telemetry arrives on a defined route only.

L3 

Operations systems

OT

WIMS 

Historian 

Engineering workstation 

Water information management and engineering tools.

Water information management and engineering tools.

![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate 

WIMS and SCADA sit on separate fabrics.

L2 

Supervisory control

OT

Treatment SCADA 

Network SCADA 

HMI 

Control room view of plants and the distribution network.

Control room view of plants and the distribution network.

![FV-Execute module icon](/assets/execute-icon-kJl5Gtmk.png)Execute 

Dosing and pump changes need approval before they move.

L1 

Basic control

Field

Plant PLCs 

Outstation RTUs 

Dosing controllers 

Treatment works, pumping stations, reservoirs.

Treatment works, pumping stations, reservoirs.

![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock 

Field kit ties to named engineers.

L0 

Physical

Field

Pumps 

Valves 

Quality sensors 

OSS 

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Treatment recipes, dosing safety limits, plant configurations, distribution network maps and the recovery sets you need after an incident.

Offline by design · secure by default 

Modules & symbols

![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak Physical sever 

![FV-Validate module icon](/assets/vault-icon-DWJpRH8k.png)Validate Integrity check 

![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate Zone boundary 

![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay Time-bound path 

![FV-Execute module icon](/assets/execute-icon-kJl5Gtmk.png)Execute Approved action 

![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock Named access 

DMZ boundary Trust transition 

OSS callout Off-network detail 

### Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

1.  ![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)
    
    Isolate
    
    At every Purdue boundary
    
    Office, telemetry, treatment and distribution sit on separate physical fabrics. A compromise on the corporate side cannot reach the plants or the outstations.
    
2.  ![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)
    
    Firebreak
    
    On the L5 to L4 link and the L4 to L3.5 link
    
    Real off switches on the boundaries that matter most when an incident is live.
    
3.  ![FV-Validate module icon](/assets/vault-icon-DWJpRH8k.png)
    
    Validate
    
    On the L5 to L4 link and inside the L3.5 DMZ
    
    Telemetry and engineering requests are checked for origin and integrity. A spoofed reading does not become a chemical dose.
    
4.  ![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)
    
    Relay
    
    Inside the L3.5 DMZ
    
    Outstation data flows into SCADA on scheduled routes. Outside the window, telemetry cannot reach control.
    
5.  ![FV-Execute module icon](/assets/execute-icon-kJl5Gtmk.png)
    
    Execute
    
    On the L2 to L1 link
    
    Treatment and network actions hold until the right authority signs them off.
    
6.  ![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)
    
    Lock
    
    On the L1 to L0 link
    
    Field devices tie to named engineers, the right device and the right authority.
    

Featured In

[![TechRadar Pro logo](/press/techradar-pro-logo.svg) ](https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough "Read about Firevault on TechRadar Pro") [![Yahoo Finance logo](/assets/yahoo-finance-logo-white-aNkUpCH7.png) ](https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html "Read about Firevault on Yahoo Finance") [![Channel Insider logo](/assets/channel-insider-logo-white-CFFo4iu7.png) ](https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/ "Read about Firevault on Channel Insider") [![Security Buyer logo](/assets/security-buyer-logo-white-o6oIaBWz.png) ](https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/ "Read about Firevault on Security Buyer") [![SecurityBrief logo](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAT8AAAA1CAYAAAA3Sux5AAAL+0lEQVR4nO2dT4gdSRnAf++Ri5ODEcTJvoB0PIjgxdkFlejsTkBExFlhzWhEWPDkYWfXxZfoRSK73vKPJQrePHjamLhg5iAswrzNkFVyyBz04kqYJ2tmM6CQS2bxss9Dvcrr6emu+qq7ql/3e/WDZv50dVW9ftVff1Xfn+qMRiMiEY/cBpZTf78M/HpKfYlECukIhd8Z4IalzBbwIjCs2KdIO1kHfmU436mrI5FIih5wKvX3fWAb7MKvrFq4BTxb8tpI++gBDwTlogCM1IFEWVvr5vxzBSX0qsyHl8fX71SoI9IeXvVUz8hyLHlqJ1LMEmrpIn3fH6I0+6ZzGdVfm+ADOJ4Vfn1g02NnEqoJ0Ug7+Jyw3ELFdr5f8frQPMQuwCXHLdSzUzc94B4H12wBFlFLGpdr75Gc2yj5JSYt/NYJ9+GiAJxtficstx+0F9Nn0VM9q6hZ04jqLwwX3rScdxIuNZI1sonQwq+HebHaB1EAzi43BWWeDt6L2eQxShOsA2cB0gDWKdlvLfzu+euLkbhmM7t0gI2Cc+cYW9gipVgF7tTQzl4NbfimrNL2UAs/ibq+gRKWnczRRQ1uCW+59jDSKp5HjYkT40OPlyvT7NSMcIrwU2CbUWMrcPuhyMqtLnCzi+yGrqEGdt7UdYQa3BI3hkTS00jr2R0fcanDL48D138TOEq+BrhG89zXzljO76HkUnYcjgCOAL8UNCJZ0wH1ZmjjukEkEpot4CwHZ1kfB54BnkNNbZvAPnAcpRQdG/9vd2q9MfOK5fwl08kjwJf99YVrzLbwy9Nu50W7yX5235971u/jXSYacZoBk2WBW9iF4Mr4mtDs03zr/Gct539jOpnn5FyF+57rW8fNN6rnse2LOW18lHPoczYVPI12Yyg6XFwKbPclfU8WLGV3OCjkzlD82Ueoe6S549CPvPMSzlvaWBHeE+l31RPUJV2H+0hQ5nlBmWeE7c0DNluFUXh3gT/764s3a5EeWC6WnFVUiFVV3yj9wJ93vO4GcsGVWM67tm3ihdTvn7KUTYCnxr9LPOXT/TxVWEqhHZRDLtr/RFhOEgEgrc+3dnTdcv5/HtpIUC+KPmq81+FL2Bu3tUJD1v67wC8E5aRv5t1xnScMh4nXHNoy8Rjl+OiKNDTGhA6xaSsuhoqmWv+GnuqZhlPvPyzn/57526SVpp+BpdT/d1CRXJdR4/0xSnPvWOqT3o8eh2cCD8ZtbXJ45rMiqLPMbMF4X1ymvdIPP2KytpF3mK674NAfG8uocCMJWtvzSXaq1xZc7oPP78snPjVnE0V+jVX4keX8wKEuvf5+Gbsv71+YaP1FPGc5v4R65h5gnwmk2eTwMkpIloEF1zU/rdX4fiNKhZQri4K6V6iu7RUhyXTSZgbT7kABEu8EWyiXhKse6kjTwV+InOYKsuf1rxXbuYUSsFX6r9d0a0ELP9t0NIsWglpVrsIt/H/haRYxhwdtBmwb2j0FnmW+ZzkviUYaOLRnUzR62I0iZZ416Trofco/h7fx66ozoob0Z/oL2aWcF/4p8i1/UnrIb9qQw9Ela8Jri9qoSzDt1NTOvPN26nfXF3oW2zTR1bjXR72Es8dtJlNFEyGm2Glsa41FPCSMe5vEOl6J9NvoHHZLkwmtsro86NJp4QngZM7/b6KEoKTfWUHnEmd8lcOCtwOcFl6f0O5EnpdQ4+M0Ki09yEMas+yTfy8l9+eS4doOB9PlSxxzXxP3+jBlEjWs5hzL2DWuDWRuMFUoY7XuI9cWhygD2QZyQ1kZo6WUD49k/nEW+DfV1vQSlKDx9YVJHgppvxMmlkBpMocuxRriANW/O9gXeF+ifXtZHOXwQzGgPZ/jOubp7QXyvR0SQd11RT2Yxl9ZrjLp/2XKW8clKfBOUHyv+pY6llHGyJvjej7InLdph3nXPDX+3yhvHeIcfrSUVdSXVvThJALW5e0q0UT0+p708+XFBebxFUGZnwvbbAodmu/hb+NsyeuuWc77NnQUYQzPcmTIREPuo5a5dEx+3qzKhkRrPor5JXFlXMaENkZqFywXV5e8a564cpkWYV3W1EwUSXfJW2PbsS1bf5Pxz5cEdfke4CGNOr5p8xTdlbzlD9s6dF3+f+dR2k3VfH5blBNwJmxuTmvIXp772DXPIOMxO+3NotfUQBZ3WEQfFYfnOg0OZZD4uqCM6wDvYhbooResI/lsYB63P6D5uQb1LKqsEPCdjUXivypNhgLwQ8xeF0GWjGzCL40WXAnlrJerTObv02QB+GKAekP4P06Dl+1FWsVVzMKvz8ElkxVLfVWiWoqulVpLywjAEN/nC/Yi7AAfE9ZnmxV9lSkLP80Q9QUsAK/j9sDfGF+blGjXF8do1xS0brLhU21n4Fj+m5bztvXAIi4BPzWcXwL+hH1sXrTUk+W3DmWlSGZOicf2vuSxridUyeqyz8Q44mr2/0SFdqsSBZ+Z96bdgQAMHcraQuPKzlxsO9xto/Lo2TRL19C9EEarYwHqNJGEqFSb0U2HZLF1G7k6vkB5h0of7OEv8D3SDj5vOe+Sjiw0kvW5NsaMNw6J5udi5JB41f+M6bpQPALen2L7EqTaadwQSoZtvElju6VO7aGxJfEMzaMpt++FMmt+JiSOn19DlkYLwrlc/B77IvMSblbANzE71A7x725Q1657s8AadiFnW78e+OmKlSHmqd4n6+lGIW9jVoqu49ew+a7Hup7gW/hJ+O8U2swi2QbwHm7C1xYonzjUJWHFc32zju1h7NEcV6WkxrbK8BbmRMMrlHcwr40uMtO9z+nVO+OfEi1I4gidRidDNR0g1+h8ptpy9da3rUOFzkYzb9hSXIWOrXXhP1Nu3zbDW8R91rZQcCSunZPSBb4hKCedXkkCkXX2mKGgbB+5hrOAW3JNSRabRew+jXqfBxtvpH4fCsqbpmjzmibrxYrXm15ATdl4S/LdvmMvEhxbMhGXrCwXUdmk844dAhmkusiNDyOUJrSOeuB13v8llEV4hPsAkkwlNsftJgXnk/F5yZ6m6QVraVaShEmMsn6b6f0IdHpuCem3pcRJFCba6kMOpv6eVxY5vN+Ey/4Tb5Rsd1jyOgkJ6gWvnyEJTRgDkmmtpJ/r2N13gq75SffbXUTN9V02FkqTnWIXbYSe166PnHiDzN9PI9dq+5SP4MhawV3DqaJv4oS8l5x0ilU2E4uP6AIdolaVJkXgDLFPS0eo5/7HKBe3Y6jNrNYF14JyTQuSQUcLv2ep522S58PUpYbEheQ/INvIvsAqrNHcTZ/nEVusbx5lEv2GoknpxD6D7NldprxnwvGS11lJ+/mF9mEq8gEcYU9rE6pt8O9+kqXIylgmGeas4yOLkI0mGS5caVq2nRHVM2abCCoX0sJvQLgP0sWs/ewTbuCbkilqOoRZ1zENVq11hqq/jUw76UUedQhkCSGFTBV2CTMOTxM4GCIb4aE/yNBT/UPkCUF1+ixfG5/r1PPSKedJ/Gm/J5ENiJOUv9ezJvg0PsdAES7a/rQFsk442vSlkw5+lgc2xnUNPNRlpCi8TfrwmiibIfY41dTd15lkq3VlQLUkrlrgDh2uOYnqsxTXTNuuvorZtN+++JdD2eOEdSoeei7nmz0mY6nsXim6Hp/l/2k5r8dmmbRfG6jn3mVZYliinSd0RiORnaOH2gLvO+QbB/ZQ2UCu4f9N2Qe+zWFr9B7wISpO94/AH/A/WBPgW6gU9HkW1yHwN1S4j4+F6DPAKxz8rPreXiD/bWhzQM9alk3lq1jWOsAXHPohZR34Lvnf/11UqGSZuiUD31UB6GDf+NvEB7gbHk1tlqnPlDTBdWysoJ6fdP7MR+Of76H2Cn63RL2aSp9dKvwikVkjhPCLtIgq+fwikbYiiUSqkrE50gKi5heZNxJkDvOnqS+LS2QKRM0vMk/0kUcKDQL2I9IAppHSKhIJTQ+Vtux9VO7GT+OW/j2043ukAUThF5lFXkVNbxPck20MidsczAVx2huJHCRqfXNCFH6RyISmhpBFAhCnvZGIQu9kGJkTouYXmXeuI48/j8wQUfhFZpG7gjI6drbxG+1EwhCdnCPzQDpetenZUSI18X+Dj/KN9NJspQAAAABJRU5ErkJggg==) ](https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks "Read about Firevault on SecurityBrief") 

Capabilities

## What you get with every deployment

01 

### Sovereign water data

Operational and customer data remains within the agreed jurisdiction in carefully selected Firevault Bunkers.

02 

### Multi-party control

Dosing and major network changes require sign-off from both control room and security teams.

03 

### Regulatory evidence

Continuous compliance evidence aligned to NIS2, EPA Water Sector guidance and DWI security expectations.

04 

### Out-of-band management

Cellular and dedicated paths keep the control plane reachable when primary telemetry is compromised.

05 

### Tamper-proof logging

Every access, configuration change and dosing command lands in immutable logs on physically separate infrastructure.

06 

### Verified configuration baselines

Verified baselines of plant and network configuration enable a known-good restore of control-plane state.

Demo to Live

## Adoption Guide

Step 1 

#### Network assessment

Map every path between corporate IT, WIMS, treatment SCADA and outstation telemetry to identify convergence and persistent vendor connections.

Step 2 

#### Zone architecture design

Design physically separated zones aligned to your plants and distribution estate, with Control modules at each boundary.

Step 3 

#### Non-production pilot

Deploy in a test environment mirroring a treatment works and outstation pair with full zone separation, multi-party authorisation and compliance logging.

Step 4 

#### Operational deployment

Full deployment across the water estate with verified configuration baselines, continuous compliance evidence and 24/7 out-of-band management.

Step 1 

#### Network assessment

Map every path between corporate IT, WIMS, treatment SCADA and outstation telemetry to identify convergence and persistent vendor connections.

Step 2 

#### Zone architecture design

Design physically separated zones aligned to your plants and distribution estate, with Control modules at each boundary.

Step 3 

#### Non-production pilot

Deploy in a test environment mirroring a treatment works and outstation pair with full zone separation, multi-party authorisation and compliance logging.

Step 4 

#### Operational deployment

Full deployment across the water estate with verified configuration baselines, continuous compliance evidence and 24/7 out-of-band management.

[Organise a Demo](/contact)

## Explore More

[

### Control for Utilities

The parent view across power, water and gas networks.

Learn more about Control for Utilities ](/control-for-utilities)[

### Control for Water (sector view)

The standalone water sector page with broader regulatory context.

Learn more about Control for Water (sector view) ](/control-for-water)[

### Control for Energy

Transmission, distribution and substation control.

Learn more about Control for Energy ](/control-for-energy)[

### IT/OT Convergence Threat

Physically separate IT from operational technology.

Learn more about IT/OT Convergence Threat ](/control-for-it-ot-convergence)

Questions

## Frequently Asked

How does Control work with existing treatment SCADA? 

Can outstation telemetry still reach the control room? 

How does this affect maintenance and OEM access? 

What about smart meter and AMI data? 

Water blueprint - PoC

### Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.

Book a PoC conversation