Environment
A regional water and wastewater utility operated treatment and pumping stations across multiple sites, supervised through a central SCADA system. Several PLCs at older sites were reachable from the same network segment used by engineering support laptops and a third-party integrator's remote access tooling.
Challenge
The utility's risk register had flagged "unauthorized access to control systems" for years without a concrete remediation path, largely because no one had mapped exactly which systems could reach which others, or why. Support contracts also required the integrator to retain some form of remote access for legitimate maintenance, so the fix could not simply be "remove all outside access."
Approach
The team began with an asset and communication-path inventory: what talks to what, over which protocol, and for what operational reason. This produced a realistic zone model -- treatment process control, pumping station control, and a supervisory/historian zone -- with the vendor's remote access explicitly modeled as its own conduit rather than an ambient trust relationship. Vendor access was moved behind a jump host with session recording and time-boxed access requests tied to specific maintenance tickets, replacing standing VPN credentials. Firmware and configuration change control was tightened so that any PLC logic change required a documented request, not direct field-side edits.
Outcome
The utility could demonstrate, for the first time, exactly which external parties could reach control systems, when, and why -- turning a vague audit finding into a controlled, auditable process. The jump-host model also gave operations visibility into vendor activity that had previously been invisible.