Trusted, Then Verified: How BPM Helped Secure a Regional Water System 

Ryan Ferran • September 11, 2026

Services: Cybersecurity Services


The Water Authority serves roughly 100,000 residents across a multi-county service area, operating a water treatment plant, a groundwater well field, more than 40 remote pump stations and reservoir sites, and over 1,100 miles of distribution main. Every measurement that keeps the system safe, pressure, turbidity, chlorine residual, flow, travels across an Operational Technology (OT) network before anyone acts on it. The Authority’s leadership had come to understand that the health of the water system and the security of its networks had quietly become the same question, and they wanted a defensible, evidence-based answer.  

Problem  

The Water Authority’s documentation said its control environment was isolated: clean architecture diagrams, a reviewed firewall rule set, and vendor attestations. What it lacked was proof. No one had sat down at a workstation in the business office and tried, in a controlled way, to reach a programmable logic controller at a pump station.  

Six years of aggressive modernization, new remote telemetry, a plant historian, and standing remote access for three integrators, had introduced dozens of new pathways into a network originally designed around the assumption that physical presence was required to touch it. Regulatory pressure from America’s Water Infrastructure Act, state primacy agency expectations, and an approaching cyber insurance renewal all demanded empirical testing rather than testimony. The constraint was equally clear: whatever BPM did could not interrupt treatment or distribution for a single minute, a bar earlier vendors’ proposed methods had failed to clear with the Authority’s own operations staff.  

BPM proposed an on-site engagement built on a simple premise: the only way to know where a boundary holds is to stand on both sides of it and try to cross. Over two weeks, the team tested the Electronic Security Perimeter and Physical Security Perimeter across plants, pump stations, the operations center, and the business office, pairing asset identification and impact analysis with active testing so that nothing was touched until the team understood what it was testing and what would happen if it responded badly.  

That discipline surfaced findings the Authority’s diagrams never showed:  

  • An asset inventory turned up more than 40 devices with no existing documentation, including legacy radio telemetry units that had run for eleven years under a lapsed maintenance contract.  
  • Network mapping found seven paths carrying data across the IT/OT boundary, three of them undocumented, while an unsecured WiFi access point let the team reach the OT network from the parking lot.  
  • Visits to eleven remote sites turned up unsecured SCADA cabinets, live network ports in unlocked enclosures, and a shared operator credential taped to an unattended workstation.  

The penetration test itself was the heart of the engagement: from a standard employee workstation, the team identified a path from the IT network to the OT network and used it to gain write access to SCADA operations, without causing a single process interruption, alarm, or change in water quality. BPM issued 31 prioritized recommendations, six of them achievable within thirty days at effectively no cost.  

“The real risk in an OT environment isn’t the path you’ve documented, it’s the one nobody has tested,” said Ryan Ferran, Advisory Senior Manager at BPM. “Every finding in this engagement started as an assumption someone was confident about, until we stood in the room and tried it.”  

BPM returned six months later to verify remediation, not just to confirm that change tickets had closed, but to confirm the same attack paths no longer worked. Retesting showed the path from the IT network to the Human Machine Interface (HMI) was gone. All six thirty-day items were complete, and 26 of the 31 total recommendations were closed, with the remaining five capital items funded for the following fiscal year.  

Three changes proved more durable than any single fix. The Water Authority now has a verified device inventory covering every OT asset, with ownership and criticality assigned. Security logs from control system servers are now forwarded and monitored alongside process alarms, a change that mattered during the retest itself, when the Authority’s own staff detected and questioned BPM’s test activity before the team disclosed it. And change control now includes a boundary impact question, closing the mechanism that had quietly produced multiple undocumented network paths over six years.  

That documented record, of what was attempted, what held, what did not, and what was fixed, was accepted without follow-up questions by the Authority’s board, its state primacy agency, and its insurer, and it contributed to a favorable outcome at the Authority’s next insurance renewal. Perhaps more telling, the operations staff who had once refused earlier assessment proposals became advocates for the next testing cycle, evidence that careful methodology and visible respect for operational risk can turn skepticism into partnership. BPM’s Cybersecurity services help organizations identify vulnerabilities, test their defenses and verify that remediation efforts effectively reduce risk.