OT Secure Remote Access for Water & Wastewater Utilities

Vendors, operators, and remote employees across IT and OT connect through one platform, closing internet exposure and replacing a patchwork of VPNs with a single security baseline.

For Water & Wastewater IT/OT Teams

OT Secure Remote Access for Water & Wastewater Utilities

Vendors, operators, and remote employees across IT and OT connect through one platform, closing internet exposure and replacing a patchwork of VPNs with a single security baseline.

For Water & Wastewater IT/OT Teams

Why Distributed Water Infrastructure Is Hard to Secure

Water and wastewater utilities run some of the most distributed OT environments in critical infrastructure. Treatment plants, lift stations, and remote wellheads connect through cellular modems and legacy PLCs, often supported by a vendor working elsewhere entirely.

Since late July 2026, utilities across a dozen states have confirmed OT attacks, nearly all through the same pattern: an internet-exposed PLC and a default password, no malware required. When proper access isn't there, people find a way around it. The workaround becomes the risk.

70% of inspected water systems were found in violation of basic cybersecurity requirements — failure to change default passwords, shared logins, no incident response plan.
EPA enforcement alert, 2024

Where Water Utility Access Breaks Down — and How Dispel Fixes It

When a line breaks at 2 a.m. and help is 400 miles away, the workaround becomes the risk. Make the secure path, the fastest path.

Where Water Utility Access Breaks Down — and How Dispel Fixes It

When a line breaks at 2 a.m. and help is 400 miles away, the workaround becomes the risk. Make the secure path, the fastest path.

The Challenge

Another Vendor, Another Workaround

Every new tool is another gap.

A vendor VPN here, a personal laptop there, a cellular router IT never knew about. Remote access wasn't designed, it accumulated, and each new tool is untracked attack surface.

Dispel's Solution

One Platform, Every Vendor

One system replaces every ad hoc fix.

Vendors and OT operators connect through one Dispel access layer, standardized and policy-enforced, still segmented between IT and OT.

The Challenge

Internet-Exposed PLCs Are an Open Front Door

A default password was all it took.

Attackers reached 30+ utilities in one weekend by logging into exposed PLCs with default credentials. No malware required. 86% shared a single cellular carrier network.Forescout

Dispel's Solution

Zero Trust Access: No Standing Pathway to Find

There's nothing left standing to exploit.

Dispel brokers every session through a secure gateway. No PLC, RTU, or HMI is ever directly reachable, the pattern NIST SP 1800-45 validates. Session Forensics records every action for full attribution.

The Challenge

After-Hours Access Slows Down an Already Lean Team

A 2 a.m. alarm shouldn't wait on an IT ticket.

Most water systems run lean, on-call staff, often one IT person covering security, billing, and the website. A VPN login and an IT ticket are real delay at 2 a.m.

Dispel's Solution

Enterprise Oversight, Without Enterprise Headcount

The platform does the watching, so your team doesn't have to.

Self-service onboarding, automatic session logging, and built-in compliance reporting do the work a dedicated security team would otherwise have to do. A lean staff gets enterprise-grade oversight without the enterprise headcount.

The Challenge

Another Vendor, Another Workaround

Every new tool is another gap.

A vendor VPN here, a personal laptop there, a cellular router IT never knew about. Remote access wasn't designed, it accumulated, and each new tool is untracked attack surface.

Dispel's Solution

One Platform, Every Vendor

One system replaces every ad hoc fix.

Vendors and OT operators connect through one Dispel access layer, standardized and policy-enforced, still segmented between IT and OT.

The Challenge

Internet-Exposed PLCs Are an Open Front Door

A default password was all it took.

Attackers reached 30+ utilities in one weekend by logging into exposed PLCs with default credentials. No malware required. 86% shared a single cellular carrier network.Forescout

Dispel's Solution

Zero Trust Access: No Standing Pathway to Find

There's nothing left standing to exploit.

Dispel brokers every session through a secure gateway. No PLC, RTU, or HMI is ever directly reachable, the pattern NIST SP 1800-45 validates. Session Forensics records every action for full attribution.

The Challenge

After-Hours Access Slows Down an Already Lean Team

A 2 a.m. alarm shouldn't wait on an IT ticket.

Most water systems run lean, on-call staff, often one IT person covering security, billing, and the website. A VPN login and an IT ticket are real delay at 2 a.m.

Dispel's Solution

Enterprise Oversight, Without Enterprise Headcount

The platform does the watching, so your team doesn't have to.

Self-service onboarding, automatic session logging, and built-in compliance reporting do the work a dedicated security team would otherwise have to do. A lean staff gets enterprise-grade oversight without the enterprise headcount.

The Dispel Zero Trust Engine

Built for Water and Wastewater OT

Secure by design. Runs anywhere. Operations simplified.

The Dispel Zero Trust Engine

Built for Water and Wastewater OT

Secure by design. Runs anywhere. Operations simplified.

Proven Impact with Dispel

The Security, Consolidation, and Efficient Operations Outcomes Water Utilities Achieve

54,000,000

People worldwide protected by utilities running Dispel

2 min

Cut SCADA response time from 2 hours to 2 minutes with Dispel

90%

Recurring IT support burden eliminated

30%

Reduction in OT cyber risk

Proven Impact with Dispel

The Security, Consolidation, and Efficient Operations Outcomes Water Utilities Achieve

54,000,000

People worldwide protected by utilities running Dispel

2 min

Cut SCADA response time from 2 hours to 2 minutes with Dispel

90%

Recurring IT support burden eliminated

30%

Reduction in OT cyber risk

Dispel Community Power & Water Program

Community Power & Water Program

Security assistance for utilities facing nation-state threats, MFA and Zero Trust access layer.

Dispel Community Power & Water Program

Community Power & Water Program

Security assistance for utilities facing nation-state threats, MFA and Zero Trust access layer.

A Critical Control for Modern Risk

Secure Remote Access delivers 12%+ risk reduction and closes one of OT's top three attack vectors.

Verified by Teams Protecting the Water Supply

“The Dispel team has done an amazing job of being proactive and doing their due diligence to identify the challenges and pain points that an organization has with securely providing remote access to their employees and third parties.”
Information Security Analyst
Critical Infrastructure

Frequently Asked Questions

Water Utility OT Remote Access, Answered

Frequently Asked Questions

Water Utility OT Remote Access, Answered

The strongest fit removes direct internet exposure entirely, rotates infrastructure so there's no static pathway to exploit, and generates compliance evidence automatically rather than requiring a dedicated program. Dispel combines all three: brokered Zero Trust access, Moving Target Defense, and continuous evidence mapped to NIST SP 1800-45 and IEC 62443.

Brokered remote access. Dispel routes every session through a secure gateway, so no PLC, RTU, or HMI is ever directly reachable from the internet, the exact exposure CISA's advisory AA26-097A warned adversaries were targeting, and the same exposure investigators confirmed in the 2026 water sector attacks. Because investigators found no malware in that campaign, only default or exposed credentials, Dispel also enforces just-in-time access and eliminates standing credentials entirely, so there's no static login path left to exploit even if a password were compromised elsewhere.

Yes. NIST SP 1800-45, “Cybersecurity for the Water and Wastewater Sector: Build Architecture,” is a sector-specific guide from NIST's National Cybersecurity Center of Excellence addressing exactly what keeps water safe to drink: secure remote access to OT. It demonstrates reference architectures for interactive access (operators, vendors) and system-to-system access (PLCs communicating across sites), the same brokered, Zero Trust pattern Dispel implements.

Cellular modems are often the least monitored part of a water utility's network, whether at a pump station, a lift station, or a remote wellhead. Dispel isolates field connectivity behind Zero Trust network access with strong authentication and logging on the modems themselves, covering every distributed asset the same way, not just the ones with a wired connection back to the plant.

Yes. Self-service onboarding and pre-approved access profiles remove the dedicated security headcount most enterprise-grade tools assume you have, so a small operations team gets the same Zero Trust protection larger utilities run. The Dispel Community Power & Water Program also provides free security assistance, including MFA support and a standardized access layer, specifically for water co-ops facing nation-state threats.

The same way you'd scope any vendor: just-in-time, asset-specific, and time-bound, rather than a standing VPN connection into the broader network. Dispel grants a SCADA integrator access to only the specific PLC or HMI their work requires, records the full session through Session Forensics, and automatically revokes the connection at disconnect, so an integrator never holds a persistent pathway into the treatment network at large.

Give Your Team One System, Not Five Workarounds

See how the Dispel Zero Trust Engine closes the exposure gaps behind the 2026 attacks, without adding headcount your utility doesn't have.

Give Your Team One System, Not Five Workarounds

See how the Dispel Zero Trust Engine closes the exposure gaps behind the 2026 attacks, without adding headcount your utility doesn't have.