Skip to main content

UTSI

Edit Template

Case Study: Securing a Texas Water Facility Without Operational Disruption

Modernizing OT Cyber security for a Texas Water Utility

UTSI was engaged to perform a comprehensive cybersecurity health check across a Texas Municipal Utility District’s critical water infrastructure, comprising two water treatment plants and one wastewater facility. The evaluation aimed to benchmark the district’s operational technology (OT) environment against industry security standards, ensure continuous uptime for vital public services, and establish a clear roadmap to harden critical infrastructure against emerging cyber threats.

Problem

During a July 2026 infrastructure security assessment, UTSI identified critical operational technology (OT) cybersecurity gaps across a Texas MUD’s water facilities, including 1 wastewater treatment plant and 2 water plants. While physical security controls met all standards, the digital infrastructure possessed severe vulnerabilities:

  • Unprotected Perimeter: No firewalls were present between cellular modems and SCADA control systems. The only barrier was basic router NAT.

  • Insecure Remote Access: SCADA workstations ran up to four unmonitored remote access applications (RDP, ConnectWise, ScreenConnect, TightVNC) in unattended mode, exposing systems to worldwide threats.

  • Lack of Visibility: System assets, network traffic, and OT controllers lacked 24×7 security monitoring, intrusion detection, or rogue device discovery.

  • Workstation Hygiene: Windows SCADA hosts had out-of-date OS patches (>60 days), unencrypted protocols, missing/outdated antivirus signatures, and weak local security policies.

Solutions

UTSI deployed its REDCAT assessment tools and live traffic analyzers to extract over 150 security artifacts per workstation and perform network traffic analysis. UTSI then delivered a prioritized remediation blueprint:

  • Managed Firewalls: Architecture design to install managed firewalls at Water Plants 1 & 2 to filter TCP/UDP traffic, segment networks, and restrict remote access.

  • 24×7 SOC Monitoring: Integration of a Managed Security Service Provider (MSSP) Security Operations Center (SOC) using secure VPN tunnels for real-time monitoring, alert analysis, and incident response callouts.

  • Workstation Hardening: Step-by-step remediation procedures to patch Windows OS, enforce strict password/audit policies, restrict unencrypted protocols, and update/standardize endpoint security.

Results

  • Zero Operational Disruption: Complete assessment and artifact extraction executed without interrupting real-time water treatment control communications.
  • Clear Remediation Roadmap: Delivered comprehensive technical execution spreadsheets (.xlsx) enabling the systems integrator to immediately implement OS hardening and firewall access rules.
  • Future-Proofed Compliance: Established an architecture moving the district from an unprotected status to a resilient, monitored 24×7 OT environment with 180-day forensic log retention and monthly board reporting.
Interested in learning more?
Contact us via the form below or send an email to inquiry@utsi.com.

Leave a Reply

Your email address will not be published. Required fields are marked *

Leave a Reply

Your email address will not be published. Required fields are marked *