For MSSPs
Scale threat-led services across your customers
For Internal SOCs
Run threat-led operations in your own environment
Integrations
Connect Sol to your security stack
Blog
Latest articles and insights
About Us
Meet the people and purpose behind Elezar
Account
Login
Create Account
Support
Help Centre
Legal
Terms & Conditions
Privacy Policy
Tabletop Exercise
Most water utilities have an incident response plan. Far fewer have ever put their general manager, general counsel and communications lead in the same room as the SCADA administrator, the plant supervisor and the I&C technician, and forced all of them to make the calls that plan assumes somebody will make. That gap is where tabletop exercises earn their keep.
Below is a complete one, written to be run rather than admired. Operation Silent Reservoir puts a leadership team inside a two-actor intrusion of a municipal water system: a Chinese state-sponsored group quietly pre-positioning for months, then an Iranian-affiliated group that walks through the same exposed door and makes noise on purpose. Every inject, decision point and escalation is grounded in documented activity against real utilities.
It is deliberately generic. Change the utility name, drop in your own customer count and service area, and it is your exercise. The download on this page is the same exercise as a PowerPoint deck, ready to project.
Duration
3 to 4 hours
Format
Facilitated discussion, four injects
Audience
Executive, OT and IT: 11 core roles
Sector
Water and wastewater utilities
Scenario. A Chinese state-sponsored threat group has maintained covert access inside your utility's IT network for months, quietly mapping pathways toward your operational technology, the systems that control water treatment and distribution. A second, more disruptive Iranian-affiliated group then exploits the same exposed remote-access systems to manipulate control equipment and issue a public extortion demand, triggering a full crisis. Leadership must navigate simultaneous operational, regulatory, legal and communications pressures in real time.
Objectives. Practice crisis decision-making under incomplete information. Exercise regulatory notification obligations across EPA, CISA and the state primacy agency. Test communications decision authority. Evaluate operational continuity and public health protocols. Surface gaps in cross-functional authority and escalation.
No technical solutions are required. Decisions and rationale are what matter.
The scenario turns on the boundary between corporate IT and the control systems that move and treat water, so the roster has to span both. The roles below are named the way water utilities actually name them.
Eleven core roles plus two on call is the full roster. At a small utility one person often holds several of them, and that is worth naming out loud at the start: if the same person is the SCADA administrator, the IT manager and the security lead, the exercise will surface a single point of failure that no org chart shows. The roles most often missing from a cyber tabletop are the OT ones, and they are the roles that determine whether the water keeps moving.
Presented to participants before the exercise begins.
Phase 1 / 35 minutes
Months -6 to Day 0
We've flagged anomalous activity that we want to walk you through before escalating. Over the past 48 hours, our monitoring detected unusual administrative account activity on your VPN gateway appliance. Specifically, account enumeration queries that match a behavioral pattern we've seen associated with nation-state reconnaissance. The queries appear to use legitimate built-in tools, so no malware was flagged. We've traced the apparent source to residential IP addresses in your service territory, though our analysts believe this is likely proxied traffic. No data exfiltration has been confirmed, and we don't yet know if your operational technology systems have been accessed. We recommend an urgent call with your incident response team.
At stake
If the attacker has been inside for months and has already mapped OT pathways, the organization is in a pre-crisis window: the threat is real but not yet kinetic. Early action can prevent escalation. Delay may hand the adversary more time.
Time pressure
The MSSP has 24 hours of log retention beyond what they've already reviewed. Extended forensics will take days. Leadership must decide now how aggressively to pursue this.
Complication
The anomalous activity uses only legitimate tools: standard Windows administrative utilities. There is no malware signature to point to. IT staff believe this could be a misconfigured internal process. Your OT team says they have not seen anything unusual.
Engage a specialized OT incident response firm immediately, which will require disclosing the event externally and could cost $50K to $200K, or direct your internal IT and MSSP to investigate for 72 hours first before deciding?
Proactively brief your water operations supervisors and shift operators that there may be unauthorized access near their control systems, potentially causing concern and operational disruption, or hold back pending investigation to avoid unnecessary alarm?
Your General Counsel notes there is no confirmed breach yet, so no mandatory reporting clock has started. Do you proactively contact CISA's Water Sector coordination team now as a courtesy, or wait until the picture is clearer?
Escalation
The IR firm confirms 6 months of persistent access. The attacker has mapped your IT-to-OT boundary and accessed file shares containing SCADA system configurations and your critical customer list. No control systems have been manipulated. Yet.
Phase 2 / 45 minutes
Day 1, 2:17 AM
Something is very wrong. We just lost visibility on the SCADA display for Pump Station 4. The screen is showing a message that says 'CyberAv3ngers was here, your water systems belong to us.' The pump station automation appears to be running, but we can't confirm setpoints from the control room. I've switched to manual monitoring at the site. We also got a call from a night operator who says the chemical dosing system at the treatment plant is showing readings that don't match our manual checks. I need direction. Do I shut down the automated systems and go fully manual, or do I hold and wait for IT?
Public health is the immediate concern. If chemical dosing is wrong, water leaving the plant could be unsafe for consumption. Approximately [X,000] customers are served from this system. The earliest a boil-water advisory could reach customers is 4 hours. The health department cannot be reached until 6 AM.
Water already in the distribution system cannot be recalled. If unsafe water has been flowing for hours, customers may already be consuming it. Every minute of uncertainty increases legal and public health exposure.
Two separate things are happening simultaneously: a suspected nation-state that has been quietly inside for months, and a second, more aggressive actor that just announced itself. Your IR firm says these are likely two different groups. The second group has publicly posted a screenshot of your HMI to a Telegram channel claiming credit.
Take all automated treatment and distribution systems to full manual control immediately (requires calling in off-duty operators, will cost $30K to $80K in overtime, and creates operational risk from human error during handover), or maintain automation while operators verify individual setpoints manually at each site?
Issue a precautionary boil-water notice for the entire service area now, before lab confirmation, which will cause immediate panic, overwhelm your phones and potentially trigger media coverage, or wait 2 to 4 hours for lab results on water samples pulled tonight?
The Telegram post is already public. A local TV station has emailed your communications office asking for comment on "rumors of a cyberattack." Do you respond now with a brief acknowledgment, say nothing, or issue a proactive public statement?
Lab results come back 3 hours later. Chlorine levels are within normal range. No contamination occurred. However, the Telegram post has been picked up by national news. Your state regulator is now calling.
Phase 3 / 40 minutes
Day 1, 7:00 AM
I've been on the phone since 5 AM. Here's where we stand legally. CISA expects notification of significant cyber incidents affecting critical infrastructure, with no specific statutory clock, but federal guidance says "as soon as reasonably practicable." EPA's Water Security reporting guidance recommends notification within 24 hours of a confirmed incident. Our state primacy agency is calling and wants a briefing before 9 AM. Our cyber insurance carrier has a 72-hour incident reporting clause, and we need to trigger that today. I also want to flag that evidence preservation needs to start now: if we start cleaning systems before forensics is complete, we may compromise our ability to pursue legal remedies or satisfy an SEC-equivalent disclosure requirement in the future. I need decisions on notification sequencing before I return those calls.
Failure to notify timely creates regulatory liability. Notifying with incomplete information could trigger enforcement scrutiny. The insurance window is non-negotiable: missing it could void coverage on a claim that may reach $2M to $10M.
State regulator wants a call in under 2 hours. Insurance clock is running. Forensics firm says full analysis will take 72 more hours.
Your communications team wants to announce that the water was never compromised and the situation is under control. Legal says you cannot make that statement yet. Forensics has not ruled out whether the first actor, the nation-state group, also touched OT systems. The story you tell publicly today must be consistent with what you tell regulators.
Notify CISA, EPA and the state primacy agency simultaneously today with partial information, or brief the state first so they control the federal notification and you maintain a single point of coordination, at the cost of CISA learning from the state rather than directly?
File the cyber insurance claim now, which opens your incident to an insurance investigation that may conflict with law enforcement forensics (the FBI has contacted you overnight), or delay the filing and risk the 72-hour clause?
Your communications team has drafted a statement that says "the water supply was safe at all times." Legal says you cannot be certain of that. Do you issue a narrower statement acknowledging the cyber incident without public health claims, hold until forensics clears OT systems, or let the regulator speak first?
The FBI Joint Cyber Defense Collaborative contacts your CISO directly. They have intelligence linking the first actor to a known nation-state campaign and request 48 hours before you make any public attribution. Your communications team is already being asked "was this China?" by two reporters.
Phase 4 / 30 minutes
Days 3 to 7
Here is our preliminary summary. The first actor has been present in your network for approximately 6 months. They accessed file shares containing OT asset inventories, SCADA configuration files, GIS mapping data, and your critical customer database. They did not touch control systems. Their apparent goal was intelligence collection and establishing persistent access for future use. We found no evidence they planned an imminent destructive attack. The second actor exploited the same internet-facing VPN appliance and reached the HMI for Pump Station 4 through a path that ran through your IT network. They manipulated display data but did not change operational setpoints. Water was never at risk. We can remediate both actors' access in 48 hours. However, until you address the IT-OT network architecture, specifically the lack of segmentation between your corporate network and control systems, you will remain vulnerable to this class of attack.
Remediation is not recovery. The architecture flaw that enabled both intrusions still exists. A third actor, or the same actors, could re-enter. The board and regulators will ask what you are doing to prevent recurrence. A capital project to segment IT from OT may cost $500K to $2M and take 18 months.
A CISA advisory is expected to be published within 30 days naming the attack vector your systems exposed. Media will connect the dots.
Your critical customer database, including the locations of hospitals, dialysis centers, schools and industrial facilities dependent on water, was exfiltrated by the first actor. That data is now in foreign government hands. There is no "undo." What are your obligations to those customers?
Request emergency board approval for IT-OT network segmentation now, competing with $3M in already-approved water main replacement projects, or address through interim compensating controls while staying on the capital plan?
Proactively notify hospitals, dialysis centers and schools that their location data and water dependency profiles were exfiltrated, triggering their own incident response plans and potential public disclosure, or treat this as operational security information that does not require customer notification?
Your board wants to release a "lessons learned" statement demonstrating transparency. Your legal team says a detailed public statement could be used in future litigation. Do you publish a transparent after-action report, a high-level summary, or nothing beyond mandatory regulatory filings?
A second utility in your region reports an identical intrusion pattern 10 days later. You are now the only utility in the region that has publicly acknowledged the incident. The regional water authority is asking you to brief the sector.
Running the room
Total 3 hours, including debrief
"Let's step back. Who in this room has the authority to make this call? If it is not clear, that is itself a finding."
"What's the worst-case outcome if we do nothing for 24 hours? Who does that harm?"
"Your shift operator at Pump Station 4 is on the phone right now. What do you tell them?"
Key pitfall to watch for
Leadership teams consistently underestimate the IT-OT boundary problem. They assume their operational technology is "air-gapped" or "separate" when in practice it has been reachable from the IT network for years. Watch for participants dismissing OT risk as "the operators' problem". The scenario is designed to make that assumption fail.
Debrief / 30 minutes
The part that produces the findings
At what decision point did we discover we lacked a clear process or designated decision-maker? What was the consequence of that gap in this scenario?
When did we escalate to the board, to external counsel, and to regulators? In hindsight, was it too early, too late, or to the wrong parties first?
Where did technical response, legal obligations and communications strategy directly conflict, for example the FBI attribution request versus public statement timing? How did we resolve it, and what would we do differently?
Did leadership have a clear enough understanding of what "operational technology" is and what it controls to make sound decisions under pressure? If not, what would close that gap?
The scenario was enabled by architecture decisions made years ago. How do we resource and prioritize security improvements that compete with visible operational needs?
If this incident began at 2 AM tonight, what is the single most important thing we would do differently?
Fill the owner and target date columns live, in the room, before anyone leaves. An action item without a name against it is a note, not a commitment.
Every claim in the threat briefing traces back to published reporting. These are the source reports behind this scenario.
Take the facilitator copy
The same exercise as an unstyled PowerPoint deck, one inject per slide. Brand it, cut it down, and run it with your own team.
Give Sol your sector, technology, region and scenario outline, and it writes the exercise using evidence-backed scenarios in minutes.