Water SectorICS/OTThreat IntelligenceIncident Response

Intelligence-Driven Tabletop Exercises for Water Utilities

Jason Faulhefer July 31, 2026 9 min read

Share this post

Most water utility tabletops rehearse a generic ransomware story. Here is how to build exercises from real intelligence about your own plant, your own vendors, and your own remote access paths.

Most water utility tabletop exercises start from a template. A generic ransomware note appears, the business side talks about billing, and the operations side nods along. Nobody learns much about their plant, because nothing in the scenario came from their plant.

An intelligence-driven exercise flips that. The scenario is assembled from what your collection plan already told you: the vendor tunnel nobody can account for, the internet-exposed HMI a scan found last quarter, the integrator that was breached in March. The exercise stops being a compliance artifact and becomes a test of decisions you will actually have to make.

Start with the requirement, not the story

Pick one or two priority intelligence requirements and build the scenario to stress them. If your PIR asks "which remote access paths into the plant could be used without operations noticing tonight," the scenario should open with credential reuse on a vendor account, not with encrypted file servers.

Good starting requirements for water utilities:

  • Remote access abuse against SCADA or the historian
  • Compromise at an integrator or systems vendor who holds plant credentials
  • Manipulation of chemical dosing setpoints or pump scheduling
  • Loss of telemetry from remote pump stations and tank sites

Each of those maps to a physical consequence, and physical consequence is what makes operators lean forward.

Build the injects from real evidence

Injects should look like artifacts your team would genuinely receive. Pull them from your own environment and from the reporting you already collect:

  1. A honeypot hit on Modbus or DNP3 from a hosting range you have seen before
  2. A vendor advisory for a PLC family you actually run
  3. An alert from the historian showing a setpoint change outside a maintenance window
  4. A sector notification describing intrusion activity at a similar sized utility
  5. A supplier email announcing a security incident with no technical detail

Redact where needed, but keep the shape. Analysts and operators recognize the difference between a real artifact and a paragraph written by a facilitator.

Put operations in the room

A water tabletop without a plant operator is a communications drill. The moment that matters is when someone asks whether the utility can keep producing safe water in manual mode, and for how long. That answer does not live in IT.

Invite the operations supervisor, the SCADA administrator, the lab lead, and someone from public communications. Give each of them a decision to make rather than a status to report.

Ask decision questions, not trivia

Weak questions ask what a protocol does. Strong questions force a tradeoff under uncertainty:

  • Do we isolate the SCADA network from the business network right now, knowing we lose remote visibility to five pump stations?
  • Do we disable the vendor tunnel during an active dosing adjustment?
  • At what point do we notify the primacy agency and the public, and who signs that message?
  • If telemetry is untrustworthy, how long can we run on manual rounds before staffing breaks?

Write the answers down as they are given. Those answers become playbook content.

Score the intelligence, not just the response

The point of an intelligence-driven exercise is to find gaps in collection and analysis, not only in response. After the exercise, review three things.

Detection gap. Which injects would your monitoring have produced on its own, and which arrived only because the facilitator handed them over? Anything in the second category is a collection gap.

Timeliness gap. How long would each artifact have taken to reach a decision maker in real life? A finding that arrives after the dosing change is already complete has little value.

Attribution and relevance gap. Did the team know whether the activity mattered to a water utility specifically, or did it treat every indicator as generic malware noise?

Turn the output into requirements

Every gap becomes a change somewhere. A missing detection becomes a new sensor placement or a new query. A missing source becomes a collection task. A confused decision becomes a documented playbook step with a named owner.

Then update the requirements themselves. If the exercise showed that nobody could enumerate vendor accounts, that is a standing requirement with a review date, not a one-time cleanup task.

Keep the cadence realistic

Two focused exercises a year beat one exhausting all day event. Ninety minutes, one scenario thread, six people who matter, and a written list of gaps is enough to move a program forward. Rotate the requirement you stress so that over a few cycles you have covered remote access, supply chain, dosing manipulation, and telemetry loss.

Where ThreatSpire fits

Intelligence-driven exercises depend on having evidence to draw from. ThreatSpire honeypot sensors covering ICS protocols give water utilities their own observations of scanning and interaction attempts, and CTILedger keeps requirements, collection sources, and evidence linked so exercise gaps become tracked work rather than a slide from last spring.

Run the exercise from your own intelligence. It is the fastest way to find out whether your program produces decisions or just documents.

Share this post

See it in action

Want intelligence that drives decisions, not noise?