A water utility response plan is a useful classroom topic because it connects cybersecurity, public health, operational technology, and local services that students can recognize. For a lesson plan, the goal is not to train students to attack systems. The goal is to help them identify planning gaps, define response roles, and understand why water utilities need clear procedures before a cyber incident affects pumps, treatment controls, billing systems, or public communication channels.
Water Utility Response Plan Lesson Frame
Water Utility Response Plan Objectives
A strong lesson starts with a narrow scope. Students should produce a short planning document for a fictional community water system, not a live facility. The plan should show how the utility would prepare for a suspected cyber incident, who would make decisions, what systems would be checked, how evidence would be preserved, and how service continuity would be protected. This keeps the exercise defensive and avoids operational details that could be misused.
The water utility response plan can be introduced as a tabletop project. Students receive a scenario: a small utility notices unusual remote access activity, a workstation used for operations is behaving unexpectedly, and staff are unsure whether the issue is limited to office IT or could affect operational technology. The class then builds a response structure from supported components: risk assessment, incident response, access control, network separation, backups, reporting, training, and public communication.
Classroom Materials And Boundaries
For materials, students need a fictional utility profile, a simple network diagram, role cards, and a response worksheet. A diagram can show business systems, operator workstations, remote access paths, and control equipment as abstract blocks without vendor names or exploitable settings. Teachers who want adjacent hands-on STEM activities can direct students to resources at Camp Techwise for safe electronics and infrastructure learning. This ensures students stay focused on planning and analysis rather than intrusion techniques.
Boundaries matter. Students should not scan real networks, search for exposed devices, test credentials, or write attack steps. A cautious class design asks them to reason from symptoms and controls. This is closer to the work many utilities need: clear documentation, disciplined access management, recovery planning, and communication under uncertainty.
Risk And Resilience Assessment
Assets, Threats, And Service Impact
The first technical component is a risk and resilience assessment. In the United States, the Safe Drinking Water Act, as amended by America’s Water Infrastructure Act of 2018, requires community water systems serving more than 3,300 people to develop or update emergency response plans based on risk and resilience assessments, according to the EPA emergency response plan guidance. That requirement gives students a concrete policy anchor: this is not only an IT exercise; it is part of operational preparedness for water service.
In class, students can list assets in three categories. Physical assets include facilities, pumps, valves, and treatment areas. Cyber assets include workstations, remote access systems, servers, controllers, and monitoring tools. Human and procedural assets include trained operators, contact lists, vendor support agreements, and shift procedures. The point is to show that a cyber incident can create operational risk even if the first symptom appears on a standard office computer.
Prioritizing What Needs Protection
Students should then rank assets by consequence, not by technical novelty. A billing workstation may hold sensitive data, but a control workstation connected to treatment monitoring may require different response priorities. A remote access account may be convenient for maintenance, but it can increase exposure if permissions are broad or credentials are weak. A backup may exist, but it has limited value if no one knows how to restore it or whether it is isolated from the affected environment.
This section of the lesson works well as a small-group evidence exercise. Each group must explain why it placed an asset in a high, medium, or low priority category. The instructor can challenge claims that are too broad, such as “all systems are equally critical.” That claim may sound safe, but it does not help a utility allocate staff time during a real incident.
Incident Response Roles And Evidence
Detection, Triage, And Decision Points
An incident response plan should define how the utility detects, responds to, and recovers from cyber incidents. For the lesson, students can divide response into phases: initial report, triage, containment, operational decision-making, recovery, and review. Each phase should identify a role rather than a person’s real name. Useful roles include utility manager, operations lead, IT lead, communications lead, legal or administrative contact, and outside support contact.
The water utility response plan should also state what information must be collected early. Students can include time of discovery, affected systems, observed symptoms, recent account changes, whether operations appear affected, and whether manual procedures are available. This is evidence management at a basic level. It avoids technical forensics beyond the classroom while showing why vague reports slow response.
Using Scenarios Without Creating Attack Instructions
A good scenario gives students enough detail to make decisions but not enough detail to reproduce harm. For example, a prompt can say that an operator sees unexpected interface behavior and that a remote login occurred outside normal hours. Students then decide who should be notified, whether remote access should be reviewed, and whether operational staff should verify process readings through approved procedures.
Teachers can connect this exercise to a related classroom resource on critical infrastructure risks when students need more practice comparing cyber risk across sectors. The comparison helps them see that water utilities have distinct constraints: safety, continuity, public trust, and limited tolerance for confusion during an outage or contamination concern.
Technical Controls For Water Systems

Access Control, Segmentation, And Backups
Technical controls should be described in plain language. Access control limits who can use systems and what each user can do. Multi-factor authentication can reduce the risk that a password alone provides access. Network segmentation separates operational technology from ordinary business IT so a problem in one area is less likely to spread without resistance. Current backups support recovery if systems or data are damaged. These practices are commonly discussed for SCADA cybersecurity in water utilities, including SCADA access, segmentation, and backup controls.
Students should not treat these controls as magic fixes. A water utility response plan should ask configuration questions. Who approves new users? How often are permissions reviewed? Are remote access accounts removed when staff or vendors leave? Are backups tested? Is the operational network truly separated, or is it only separated on a diagram? These questions help students move from slogans to verifiable planning.
Maintenance And Cost Constraints
Water utilities may face staffing, budget, and maintenance constraints. A classroom plan should recognize that controls require ongoing work. Multi-factor authentication needs user enrollment and support. Segmentation requires network knowledge and change management. Backups require storage, retention decisions, and restore testing. Training requires time away from routine duties. A plan that ignores maintenance is unlikely to hold up during stress.
- Students should define at least three access control rules for the fictional utility.
- Students should identify which systems belong in operational technology and which belong in business IT.
- Students should specify what data or system images must be backed up for recovery.
- Students should describe how staff will confirm that a backup can be restored.
- Students should identify one control that may be difficult for a small utility to maintain.
Communication, Reporting, And Recovery
Internal Communication Before Public Messaging
During an incident, utilities need internal communication before they can communicate well with the public. The plan should state who receives the first alert, who decides whether operations are affected, and who approves external messages. In a classroom exercise, students can draft a short internal notification that reports facts without guessing: what was observed, when it was observed, which systems may be affected, and what decisions are pending.
Public communication is also part of emergency planning. Students should prepare a plain-language holding statement for a fictional incident. It should avoid unsupported claims, explain that the utility is investigating, and state where customers would receive verified updates. This teaches a key response habit: communicate what is known, what is being checked, and what the public should do, without creating false certainty.
Reporting Paths And Outside Support
Incident reporting procedures should identify relevant authorities and support contacts before an incident occurs. Research on water-sector planning points to reporting protocols involving agencies such as EPA and CISA, and coordination with federal partners can help utilities access support resources. In class, students can create a contact matrix using role names and agency categories rather than personal contact details.
A recovery section should cover how the utility returns to normal operations. Students can include steps such as confirming which systems are affected, restoring from known-good backups, validating operational readings, reviewing account permissions, and documenting lessons learned. They should also state what remains uncertain. For example, if a class scenario does not provide forensic evidence, the plan should not claim to know the root cause.
Teaching Water Utility Readiness
Assessment Criteria For Student Plans
Assessment should reward evidence-based reasoning. A high-quality student plan identifies assets, assigns response roles, includes access controls, separates IT and operational concerns, plans for backups, and explains communication steps. It also admits limits. If a fictional utility has no backup test record, the student should flag that gap rather than assume recovery will work.
The final deliverable can be a two-page water utility response plan plus a short presentation. Each team explains one risk, one control, one recovery step, and one communication decision. The instructor can ask how the plan would change if the utility served a larger population, depended on remote vendors, or lacked full-time IT staff. These prompts keep the lesson grounded in practical constraints.
For students who need a case-based extension, a related analysis of water system cyberattack risks and controls can support discussion without shifting into offensive techniques. The value of the lesson is disciplined preparation: students learn that cybersecurity for water utilities is not only about tools. It is also about roles, documentation, tested recovery paths, and accurate communication when public services may be affected.