Skip to content
Epic IT Support

Local Government

Separating a control network from the business network

Network assessment, managed firewall, and SCADA DMZ segmentation for a municipal water utility — isolating OT without disrupting service delivery.

Client
A municipal water utility
Services
Cybersecurity, Managed IT, Project Engineering
Control network separated from corporate IT
Isolated Control network separated from corporate IT
Assessment findings with prioritized remediation
Documented Assessment findings with prioritized remediation
Ongoing firewall administration and support capacity
Retained Ongoing firewall administration and support capacity

The situation

A municipal water utility ran its operational technology — the control systems behind water treatment and distribution — on a network that had grown organically alongside its corporate IT. The boundary between them had never been deliberately designed. It had simply accumulated.

That is a common finding in utilities, and an uncomfortable one, because operational technology cannot be patched, rebooted, or tested the way business systems can. The systems that most need isolation are the ones you can least afford to disturb while isolating them.

What we did

Assessment first, with findings written down. A network assessment established what actually existed: the topology, the paths between control and corporate networks, remote access arrangements, and the firewall policy that had accumulated over years of individual changes. The deliverable was a prioritized remediation list separating what was urgent from what was budgetable.

A designed DMZ, not a firewall rule. Segmentation between the SCADA environment and the business network was designed as an architecture — what may cross the boundary, in which direction, initiated by whom — rather than implemented as a set of permit statements. The design was reviewed before anything was enforced.

Deliberate conservatism on the OT side. Our position on operational technology is that the priority is isolation, architecture review, and change discipline — not active testing against live control systems. A water utility is not an environment in which to discover that a control system responds badly to an unexpected packet.

Firewall and network taken under management. Ongoing firewall administration, policy lifecycle, and network support followed, giving a small municipal IT team specialist depth and after-hours coverage they could not staff internally.

The outcome

The utility gained a documented, intentional boundary between its control and business networks, replacing one that had never been designed. It also gained something a small public-sector IT department frequently lacks: an accurate written record of its own network, which made the subsequent budget requests defensible to a council that had to approve them.

The relationship continued into ongoing managed firewall and network support across several further projects.

Recognize the situation?

If this looks like the problem in front of you, describe it and we will tell you honestly what it would take.