Local Public Administration · Municipal services and water

Water continuity requires protection of IT, OT, people and suppliers.

In water and sanitation services, cybersecurity work must respect availability, operational safety and service quality. The objective is to understand, segment, control, recover and demonstrate without creating new risk.

Essential service and operational technology

The service depends on a complete cyber-physical chain.

Administrative systems, telecommunications, supervision, controllers, remote stations, sensors, energy, suppliers and manual procedures may all support the same service. The framework should consider the entity, activity and applicable criteria without presuming an official qualification.

  • Services, processes and operational impact identified
  • IT and OT assets connected without treating them as identical environments
  • Remote access and third-party dependencies made visible
  • Recovery prepared for configurations, systems and operations

Govern before delegating

Clear responsibility, specialist support and effective reporting.

Governance connects decisions, risk, resources and oversight. It must not exist only in an organization chart or an isolated document.

Multidisciplinary decisions

Management, operations, maintenance, technology, quality and security should participate in decisions that may affect availability, the process or recovery.

Operational responsibilities

Owners of services, systems and access, internal and external contacts, escalation criteria and authority to act during an incident should be defined.

Roles where applicable

Where required by the confirmed framework, the Cybersecurity Officer (RCS) and Permanent Contact Point (PCP) should coordinate with those who understand and operate the process while maintaining effective reporting and communication.

Services and dependencies

Protect the complete service cycle, from the field to the central system.

Abstraction, treatment, pumping, storage, distribution and sanitation may depend on networks, automation, communications, energy and external teams.

Process and operations

  • Abstraction, treatment and storage
  • Pumping, distribution and pressure
  • Wastewater collection and treatment
  • Local operation and manual procedures

IT, OT and communications

  • SCADA, HMI, PLC and remote stations
  • Servers, endpoints and management applications
  • Networks, radio, mobile and dedicated connections
  • Segmentation and authorized flows

Access and suppliers

  • Remote maintenance and assistance
  • Individual accounts, MFA and temporary authorization
  • Session recording and review
  • Contracts, contacts and alternatives

Recovery and continuity

  • Configuration and software backups
  • Replacement equipment and components
  • Safe restoration tests
  • Energy, communications and degraded modes

Municipal implementation

From the initial assessment to continuous improvement.

Each stage should produce a decision, verifiable implementation or evidence that allows progress to be monitored.

  1. 01

    Map the service

    Connect processes, facilities, assets, networks, data, energy, communications, people and suppliers.

  2. 02

    Separate and control

    Define zones, flows, interconnection points, privileges and remote access according to operational need.

  3. 03

    Reduce exposure

    Address configurations, accounts, updates, vulnerabilities and third parties with technical and operational validation.

  4. 04

    Prepare response and recovery

    Define safe containment, communication, alternatives, backups, restoration and controlled return to operations.

  5. 05

    Test and improve

    Conduct proportionate exercises and tests, retain evidence and update risk, architecture and procedures.

Usable outcomes

Deliverables that support decision-making and implementation.

Deliverables should support secure operations, recovery and decision-making without unduly affecting process availability or physical safety.

  1. 01Map of the service, facilities, assets and IT/OT dependencies
  2. 02Architecture of zones, interconnections and authorized flows
  3. 03Remote-access, supplier and responsibility matrix
  4. 04Prioritized plan of measures with operational validation
  5. 05Configuration, software backup and restoration strategy
  6. 06Incident, degraded-mode, recovery and continuity procedures

Technical and operational evidence

Three perspectives that corroborate one another.

Architecture and configuration

Inventories, diagrams, zones, flows, versions, approved configurations, backups and restoration results.

Access and maintenance

Authorizations, identities, sessions, interventions, changes, suppliers and validation of completed work.

Operations and continuity

Alarms, events, incidents, decisions, exercises, degraded modes, recovery and implemented improvements.

First steps

Begin with enough information to make better decisions.

The initial assessment should involve operations, maintenance and technology teams while respecting safety, availability and intervention windows.

Open the RJCS Checker
  1. 01Identify facilities and processes whose unavailability would have the greatest impact
  2. 02Locate interconnections between IT, OT, remote stations and suppliers
  3. 03Review all remote access, shared accounts and authorization mechanisms
  4. 04Confirm configuration backups and actual restoration capability
  5. 05Organize the framework and uncertainties in the RJCS Checker

Frequently asked questions

Provide guidance without anticipating official decisions.

Do all municipal water services automatically have the same qualification?

An outcome should not be presumed from the service designation alone. The entity, activity, size, services and applicable criteria must be confirmed. Official qualification belongs to the competent authority.

Should IT and OT receive exactly the same measures?

No. They share risk and governance objectives, but operational technology may require different procedures, compatibility, windows, testing and containment to protect process availability and safety.

Can suppliers retain permanent remote access?

Access should be justified, controlled and reviewed. Wherever technically possible, it should use individual identities, time-limited authorization, MFA, session recording and subsequent validation of the intervention.

Is a server backup sufficient to recover the service?

It may not be. Recovery can depend on PLC, HMI and network-equipment configurations, communications, licenses, replacement components and tested operational procedures.

Primary sources

Always confirm against the official source.

Information published on . Content and references reviewed on . This information supports initial guidance and should be confirmed against the applicable framework and official instructions for each entity.

Next step

Understand dependencies before changing operations.

Confirm the framework and organize IT, OT, suppliers, recovery and continuity through a technically safe pathway.