Home
Elezar

Tabletop Exercise

Sample Tabletop Exercise: Operation Silent Reservoir

31 Aug 2026Elezar
Operation Silent Reservoir tabletop exercise cover

Most water utilities have an incident response plan. Far fewer have ever put their general manager, general counsel and communications lead in the same room as the SCADA administrator, the plant supervisor and the I&C technician, and forced all of them to make the calls that plan assumes somebody will make. That gap is where tabletop exercises earn their keep.

Below is a complete one, written to be run rather than admired. Operation Silent Reservoir puts a leadership team inside a two-actor intrusion of a municipal water system: a Chinese state-sponsored group quietly pre-positioning for months, then an Iranian-affiliated group that walks through the same exposed door and makes noise on purpose. Every inject, decision point and escalation is grounded in documented activity against real utilities.

It is deliberately generic. Change the utility name, drop in your own customer count and service area, and it is your exercise. The download on this page is the same exercise as a PowerPoint deck, ready to project.

Exercise overview

Duration

3 to 4 hours

Format

Facilitated discussion, four injects

Audience

Executive, OT and IT: 11 core roles

Sector

Water and wastewater utilities

Scenario. A Chinese state-sponsored threat group has maintained covert access inside your utility's IT network for months, quietly mapping pathways toward your operational technology, the systems that control water treatment and distribution. A second, more disruptive Iranian-affiliated group then exploits the same exposed remote-access systems to manipulate control equipment and issue a public extortion demand, triggering a full crisis. Leadership must navigate simultaneous operational, regulatory, legal and communications pressures in real time.

Objectives. Practice crisis decision-making under incomplete information. Exercise regulatory notification obligations across EPA, CISA and the state primacy agency. Test communications decision authority. Evaluate operational continuity and public health protocols. Surface gaps in cross-functional authority and escalation.

No technical solutions are required. Decisions and rationale are what matter.

Participants and roles

The scenario turns on the boundary between corporate IT and the control systems that move and treat water, so the roster has to span both. The roles below are named the way water utilities actually name them.

Role Participant title Exercise responsibility
Executive Sponsor
Executive
General Manager / CEOStrategic decisions, board and council communication, ultimate authority
Asset Owner
OT
COO / Director of Water OperationsAccountable for the water system itself. Authorizes changes to treatment and distribution, and owns the decision to accept or refuse operational risk
Plant and Site Operations
OT
Treatment Plant Supervisor / Shift Operations SupervisorManual control handover, on-site verification and sampling, operator safety, and what the control room can and cannot actually see
Control Systems Engineer
OT
SCADA Administrator / ICS EngineerHMI, PLC and historian integrity, setpoint verification, controller logic and configuration backups, engineering workstation control
Instrumentation and Controls
OT
I&C Technician / Maintenance SupervisorField device checks against the readings on screen, physical access to stations, vendor escort and remote-access approval
OT Security Lead
OT
OT / ICS Security ManagerControl-system risk assessment, segmentation and isolation decisions, OT-aware incident response and forensics
IT Security Lead
IT
CISO / IT Security ManagerEnterprise investigation, identity and credential response, MSSP and IR firm coordination, evidence collection
IT Infrastructure
IT
IT Manager / Network AdministratorEdge appliances, VPN and firewall changes, and the IT-to-OT path that both actors used
Legal and Compliance
Corporate
General Counsel / Regulatory AffairsEPA, CISA and state primacy notification obligations, liability, evidence preservation
Communications
Corporate
VP Communications / Public Information OfficerMedia response, customer and public notification, elected official coordination
Finance
Corporate
CFO / Finance DirectorFinancial impact, cyber insurance activation, emergency procurement
Systems Integrator (optional)
External
SCADA Integrator / OEM Support RepresentativeThird-party remote access into OT, patch and firmware realities, what vendor support can and cannot do mid-incident
Regulator Liaison (optional)
External
State Primacy Agency RepresentativeDrinking water primacy obligations, public health threshold decisions

Eleven core roles plus two on call is the full roster. At a small utility one person often holds several of them, and that is worth naming out loud at the start: if the same person is the SCADA administrator, the IT manager and the security lead, the exercise will surface a single point of failure that no org chart shows. The roles most often missing from a cyber tabletop are the OT ones, and they are the roles that determine whether the water keeps moving.

Threat landscape briefing

Presented to participants before the exercise begins.

Who is targeting organizations like ours

  • A Chinese state-sponsored group known as VOLTZITE (also tracked as Volt Typhoon by Microsoft and Dragos) has been confirmed compromising U.S. water and electric utilities since at least 2023. Their documented goal is pre-positioning: gaining persistent, undetected access to operational technology networks so they can be activated during a future geopolitical crisis.
  • An Iranian government-affiliated group known as BAUXITE (publicly operating as "CyberAv3ngers") has demonstrated the ability to physically interact with and manipulate programmable logic controllers (PLCs) used in water and wastewater treatment, including causing real-world process disruptions.

Why our sector and technology stack are at risk

  • Water utilities are specifically named in U.S. government advisories as priority targets.
  • Internet-exposed remote access systems, legacy VPN appliances, and control systems with default or weak credentials are the primary attack vectors used by both groups.
  • Small and mid-sized utilities are disproportionately targeted because they lack the security monitoring of larger organizations.
  • Operational technology systems, the computers that control pumps, valves, chemical dosing and treatment processes, are increasingly reachable from IT networks.

Recent real-world incidents

  • In early 2023, VOLTZITE compromised a small U.S. public water and electric utility (Littleton Electric Light and Water Departments, Massachusetts), exfiltrating sensitive OT configuration data, SCADA system configurations, GIS data, and lists of critical customers. The attacker was undetected for an extended period.
  • In late 2023, CyberAv3ngers compromised the Municipal Water Authority of Aliquippa, Pennsylvania, gaining control of a Unitronics PLC at a booster station and displaying a political message on the operator screen.

Phase 1  /  35 minutes

Silent foothold

Months -6 to Day 0

Managed Security Service Provider, Threat Monitoring Escalation 7:42 AM, Tuesday

We've flagged anomalous activity that we want to walk you through before escalating. Over the past 48 hours, our monitoring detected unusual administrative account activity on your VPN gateway appliance. Specifically, account enumeration queries that match a behavioral pattern we've seen associated with nation-state reconnaissance. The queries appear to use legitimate built-in tools, so no malware was flagged. We've traced the apparent source to residential IP addresses in your service territory, though our analysts believe this is likely proxied traffic. No data exfiltration has been confirmed, and we don't yet know if your operational technology systems have been accessed. We recommend an urgent call with your incident response team.

At stake

If the attacker has been inside for months and has already mapped OT pathways, the organization is in a pre-crisis window: the threat is real but not yet kinetic. Early action can prevent escalation. Delay may hand the adversary more time.

Time pressure

The MSSP has 24 hours of log retention beyond what they've already reviewed. Extended forensics will take days. Leadership must decide now how aggressively to pursue this.

Complication

The anomalous activity uses only legitimate tools: standard Windows administrative utilities. There is no malware signature to point to. IT staff believe this could be a misconfigured internal process. Your OT team says they have not seen anything unusual.

Decision points

Scope of response

Engage a specialized OT incident response firm immediately, which will require disclosing the event externally and could cost $50K to $200K, or direct your internal IT and MSSP to investigate for 72 hours first before deciding?

OT notification

Proactively brief your water operations supervisors and shift operators that there may be unauthorized access near their control systems, potentially causing concern and operational disruption, or hold back pending investigation to avoid unnecessary alarm?

Regulatory posture

Your General Counsel notes there is no confirmed breach yet, so no mandatory reporting clock has started. Do you proactively contact CISA's Water Sector coordination team now as a courtesy, or wait until the picture is clearer?

Escalation

The IR firm confirms 6 months of persistent access. The attacker has mapped your IT-to-OT boundary and accessed file shares containing SCADA system configurations and your critical customer list. No control systems have been manipulated. Yet.

Phase 2  /  45 minutes

The second actor arrives

Day 1, 2:17 AM

Night Shift Operations Supervisor Urgent 2:17 AM

Something is very wrong. We just lost visibility on the SCADA display for Pump Station 4. The screen is showing a message that says 'CyberAv3ngers was here, your water systems belong to us.' The pump station automation appears to be running, but we can't confirm setpoints from the control room. I've switched to manual monitoring at the site. We also got a call from a night operator who says the chemical dosing system at the treatment plant is showing readings that don't match our manual checks. I need direction. Do I shut down the automated systems and go fully manual, or do I hold and wait for IT?

At stake

Public health is the immediate concern. If chemical dosing is wrong, water leaving the plant could be unsafe for consumption. Approximately [X,000] customers are served from this system. The earliest a boil-water advisory could reach customers is 4 hours. The health department cannot be reached until 6 AM.

Time pressure

Water already in the distribution system cannot be recalled. If unsafe water has been flowing for hours, customers may already be consuming it. Every minute of uncertainty increases legal and public health exposure.

Complication

Two separate things are happening simultaneously: a suspected nation-state that has been quietly inside for months, and a second, more aggressive actor that just announced itself. Your IR firm says these are likely two different groups. The second group has publicly posted a screenshot of your HMI to a Telegram channel claiming credit.

Decision points

Operational decision

Take all automated treatment and distribution systems to full manual control immediately (requires calling in off-duty operators, will cost $30K to $80K in overtime, and creates operational risk from human error during handover), or maintain automation while operators verify individual setpoints manually at each site?

Public health decision

Issue a precautionary boil-water notice for the entire service area now, before lab confirmation, which will cause immediate panic, overwhelm your phones and potentially trigger media coverage, or wait 2 to 4 hours for lab results on water samples pulled tonight?

Disclosure decision

The Telegram post is already public. A local TV station has emailed your communications office asking for comment on "rumors of a cyberattack." Do you respond now with a brief acknowledgment, say nothing, or issue a proactive public statement?

Escalation

Lab results come back 3 hours later. Chlorine levels are within normal range. No contamination occurred. However, the Telegram post has been picked up by national news. Your state regulator is now calling.

Phase 3  /  40 minutes

Regulatory and legal crossfire

Day 1, 7:00 AM

General Counsel, Regulatory Notification Deadlines Urgent 7:03 AM

I've been on the phone since 5 AM. Here's where we stand legally. CISA expects notification of significant cyber incidents affecting critical infrastructure, with no specific statutory clock, but federal guidance says "as soon as reasonably practicable." EPA's Water Security reporting guidance recommends notification within 24 hours of a confirmed incident. Our state primacy agency is calling and wants a briefing before 9 AM. Our cyber insurance carrier has a 72-hour incident reporting clause, and we need to trigger that today. I also want to flag that evidence preservation needs to start now: if we start cleaning systems before forensics is complete, we may compromise our ability to pursue legal remedies or satisfy an SEC-equivalent disclosure requirement in the future. I need decisions on notification sequencing before I return those calls.

At stake

Failure to notify timely creates regulatory liability. Notifying with incomplete information could trigger enforcement scrutiny. The insurance window is non-negotiable: missing it could void coverage on a claim that may reach $2M to $10M.

Time pressure

State regulator wants a call in under 2 hours. Insurance clock is running. Forensics firm says full analysis will take 72 more hours.

Complication

Your communications team wants to announce that the water was never compromised and the situation is under control. Legal says you cannot make that statement yet. Forensics has not ruled out whether the first actor, the nation-state group, also touched OT systems. The story you tell publicly today must be consistent with what you tell regulators.

Decision points

Notification sequencing

Notify CISA, EPA and the state primacy agency simultaneously today with partial information, or brief the state first so they control the federal notification and you maintain a single point of coordination, at the cost of CISA learning from the state rather than directly?

Insurance activation

File the cyber insurance claim now, which opens your incident to an insurance investigation that may conflict with law enforcement forensics (the FBI has contacted you overnight), or delay the filing and risk the 72-hour clause?

The public statement

Your communications team has drafted a statement that says "the water supply was safe at all times." Legal says you cannot be certain of that. Do you issue a narrower statement acknowledging the cyber incident without public health claims, hold until forensics clears OT systems, or let the regulator speak first?

Escalation

The FBI Joint Cyber Defense Collaborative contacts your CISO directly. They have intelligence linking the first actor to a known nation-state campaign and request 48 hours before you make any public attribution. Your communications team is already being asked "was this China?" by two reporters.

Phase 4  /  30 minutes

Recovery and the harder question

Days 3 to 7

IR Firm Lead Analyst, Findings Briefing Summary Day 3, 4:00 PM

Here is our preliminary summary. The first actor has been present in your network for approximately 6 months. They accessed file shares containing OT asset inventories, SCADA configuration files, GIS mapping data, and your critical customer database. They did not touch control systems. Their apparent goal was intelligence collection and establishing persistent access for future use. We found no evidence they planned an imminent destructive attack. The second actor exploited the same internet-facing VPN appliance and reached the HMI for Pump Station 4 through a path that ran through your IT network. They manipulated display data but did not change operational setpoints. Water was never at risk. We can remediate both actors' access in 48 hours. However, until you address the IT-OT network architecture, specifically the lack of segmentation between your corporate network and control systems, you will remain vulnerable to this class of attack.

At stake

Remediation is not recovery. The architecture flaw that enabled both intrusions still exists. A third actor, or the same actors, could re-enter. The board and regulators will ask what you are doing to prevent recurrence. A capital project to segment IT from OT may cost $500K to $2M and take 18 months.

Time pressure

A CISA advisory is expected to be published within 30 days naming the attack vector your systems exposed. Media will connect the dots.

Complication

Your critical customer database, including the locations of hospitals, dialysis centers, schools and industrial facilities dependent on water, was exfiltrated by the first actor. That data is now in foreign government hands. There is no "undo." What are your obligations to those customers?

Decision points

Capital prioritization

Request emergency board approval for IT-OT network segmentation now, competing with $3M in already-approved water main replacement projects, or address through interim compensating controls while staying on the capital plan?

Critical customer notification

Proactively notify hospitals, dialysis centers and schools that their location data and water dependency profiles were exfiltrated, triggering their own incident response plans and potential public disclosure, or treat this as operational security information that does not require customer notification?

Public accountability

Your board wants to release a "lessons learned" statement demonstrating transparency. Your legal team says a detailed public statement could be used in future litigation. Do you publish a transparent after-action report, a high-level summary, or nothing beyond mandatory regulatory filings?

Escalation

A second utility in your region reports an identical intrusion pattern 10 days later. You are now the only utility in the region that has publicly acknowledged the incident. The regional water authority is asking you to brief the sector.

Running the room

Facilitator guide

Total 3 hours, including debrief

Segment Duration
Phase 1: Silent foothold35 minutes
Phase 2: The second actor arrives45 minutes
Phase 3: Regulatory and legal crossfire40 minutes
Phase 4: Recovery and the harder question30 minutes
Debrief30 minutes

If discussion stalls

"Let's step back. Who in this room has the authority to make this call? If it is not clear, that is itself a finding."

"What's the worst-case outcome if we do nothing for 24 hours? Who does that harm?"

"Your shift operator at Pump Station 4 is on the phone right now. What do you tell them?"

If resolved too quickly, add pressure injects

  • Phase 2. A local elected official has just posted on social media that the water supply may be unsafe. Your phones are lighting up.
  • Phase 3. A class action law firm has sent a preservation letter. They represent 14 customers who say they consumed water during the window in question.
  • Phase 4. A national investigative journalist is filing a FOIA request for all communications between your organization and CISA during the incident window.

Key pitfall to watch for

Leadership teams consistently underestimate the IT-OT boundary problem. They assume their operational technology is "air-gapped" or "separate" when in practice it has been reachable from the IT network for years. Watch for participants dismissing OT risk as "the operators' problem". The scenario is designed to make that assumption fail.

Debrief  /  30 minutes

Debrief discussion

The part that produces the findings

Authority gaps

At what decision point did we discover we lacked a clear process or designated decision-maker? What was the consequence of that gap in this scenario?

Escalation timing

When did we escalate to the board, to external counsel, and to regulators? In hindsight, was it too early, too late, or to the wrong parties first?

Tension resolution

Where did technical response, legal obligations and communications strategy directly conflict, for example the FBI attribution request versus public statement timing? How did we resolve it, and what would we do differently?

OT understanding

Did leadership have a clear enough understanding of what "operational technology" is and what it controls to make sound decisions under pressure? If not, what would close that gap?

Pre-existing vulnerabilities

The scenario was enabled by architecture decisions made years ago. How do we resource and prioritize security improvements that compete with visible operational needs?

Tomorrow test

If this incident began at 2 AM tonight, what is the single most important thing we would do differently?

Action items

Fill the owner and target date columns live, in the room, before anyone leaves. An action item without a name against it is a note, not a commitment.

Gap identified Owner Action Target date
No clear decision authority matrix for OT-impacting cyber incidentsGeneral Manager + LegalDraft and approve incident decision authority matrix with OT-specific escalation thresholds
Boil-water advisory process not rehearsed under cyber incident conditionsAsset Owner + Plant OperationsTabletop the boil-water advisory process as a standalone drill, including 2 AM contact chains
IT-OT network segmentation absent or insufficientOT Security Lead + IT InfrastructureCommission OT network architecture assessment and develop capital funding request
Regulatory notification sequence undocumentedLegal + CommunicationsDocument EPA, CISA, state primacy and insurance notification sequence and timing triggers
No pre-negotiated OT incident response retainerOT Security Lead + IT Security LeadEvaluate and contract an OT-specialized IR firm with water sector experience
Critical customer dependency data protectionLegal + Asset OwnerReview data classification and access controls for critical customer infrastructure data
Board-level OT security fluencyGeneral Manager + OT Security LeadSchedule annual board briefing on OT threat landscape and capital investment needs

Appendix: source evidence

Every claim in the threat briefing traces back to published reporting. These are the source reports behind this scenario.

Take the facilitator copy

The same exercise as an unstyled PowerPoint deck, one inject per slide. Brand it, cut it down, and run it with your own team.

Download Table-Top

Want a scenario built from your own threat picture in minutes?

Give Sol your sector, technology, region and scenario outline, and it writes the exercise using evidence-backed scenarios in minutes.

Talk to us