Same principles. Different consequences.
These synthetic U.S. utility exercises use general OT guidance; electricity and water subsectors have different legal requirements and operating procedures.
Physical processes keep running
Water treatment and electricity operations can depend on digital controls that affect physical outcomes. A security action that is routine on an office laptop may disrupt monitoring or control here, so operators and safety procedures must shape the response.
Equipment has different lifecycles
A supported engineering workstation and a long-lived field controller may have very different maintenance options. Inventory should capture function, owner, dependencies, and approved maintenance windows so a vulnerability response reflects operational consequence as well as technical severity.
Utilities are not one regulatory category
Electricity generation, transmission, distribution, drinking water, and wastewater have different responsibilities and oversight. Identify the specific service and applicable authority before claiming a standard is mandatory; a water-sector resource does not define requirements for an electricity network.
How to use this path
Read each situation, inspect the synthetic evidence, and choose a response. Every answer explains its tradeoffs. Follow the linked foundation lessons when you need a concept explained, then mark the decision practiced when you are ready.
All organizations, people, events, and evidence in these exercises are fictional. The controls stay in the browser.
APPLIED LESSON 1 / 7 MIN
Approve a bounded maintenance session
Make remote maintenance accountable to an operational owner.
A synthetic electricity utility receives a request for remote vendor access to investigate intermittent telemetry. The vendor asks for broad access until the issue is resolved. The operator needs visibility without introducing an uncontrolled path into sensitive systems. Before approving anything, the team identifies the affected asset, the requested diagnostic activity, the responsible operator, and the approved maintenance conditions. Urgency does not make unrestricted access safer.
The operator selects the approved remote-access route, authorizes a limited window, and ensures activity can be attributed to a named person. The vendor’s task is constrained to agreed diagnostics, with changes requiring separate approval. If a session behaves unexpectedly, the operator follows the site’s safe response procedure. The analyst should not independently scan, reboot, or isolate running equipment merely because those actions work on office endpoints.
Which access decision best supports the maintenance task?
CONNECT TO THE FUNDAMENTALS
APPLIED LESSON 2 / 7 MIN
Check the trustworthiness of operational evidence
Corroborate a suspicious change without changing the process.
In a synthetic water-utility exercise, a dashboard value changes abruptly while a configuration audit reports a recent edit. The correlation deserves attention, but it does not prove the edit caused a physical change. Telemetry can be stale, delayed, mis-scaled, or incorrectly displayed. The analyst separates observed data from interpretation and brings the timeline to the operator responsible for understanding the process and its safe operating limits.
The operator compares approved independent observations and maintenance records, while the analyst preserves available audit events and configuration version identifiers. They check clock differences before ordering events and verify whether an authorized work order explains the edit. Any operational adjustment follows the site procedure and appropriate authority. The learning objective is disciplined corroboration: technical evidence should inform the operator’s decision without substituting an analyst’s guess for process knowledge.
What is the most useful first analytical response?
CONNECT TO THE FUNDAMENTALS
APPLIED LESSON 3 / 7 MIN
Rehearse recovery with the operational owner
Verify that recovered systems support safe, observable operation.
A synthetic utility has copies of engineering configurations, but its most recent recovery exercise restored only an office server. An operational recovery plan also needs compatible software, approved configuration versions, access credentials, dependencies, and people who understand startup conditions. A backup file alone cannot demonstrate that the service can return safely. The team begins with an offline rehearsal using representative assets and documented assumptions.
During the rehearsal, the operator checks the selected baseline against approved changes, and the technical team verifies restoration steps and monitoring. Together they record decision points for stopping or escalating if the recovered state differs from expectations. Any eventual production work requires the site’s approved maintenance and safety process. Success means the operator can explain the recovered state and its limits, not simply that a restoration utility completed.
What should the team do before relying on this recovery plan?
CONNECT TO THE FUNDAMENTALS
Standards & scope
These are signposts for further study. The examples use U.S. regulatory context where noted; applicability depends on your organization, jurisdiction, services, and data.
NIST SP 800-82 Rev. 3 ↗
OT security guidance considers performance, reliability, and safety; adapt it to the actual system and approved operational procedures.
EPA water-sector cybersecurity resources ↗
Resources support cybersecurity planning and response for drinking water and wastewater systems; the resource collection is not itself a new universal legal requirement.