Third Level IT

HomeIndustriesMunicipal & Utilities

The plant was never designed to be on a network. Now it is.

OT security for water and wastewater utilities and municipal environments: segmentation between business and control networks, locked-down remote access, and monitoring that doesn't interfere with operations.

  • OT / SCADA
  • AWIA risk assessments
  • Fortinet OT
  • Purdue model segmentation
  • EPA cybersecurity guidance
The situation

Small utilities are getting attention they never asked for.

Attacks on water systems stopped being hypothetical. Regulators noticed, insurers noticed, and the questions coming from your board and your state primacy agency got specific: How is the SCADA network separated from the office network? Who can reach the HMIs remotely? Would you know if someone did?

Meanwhile the reality on the ground is a control network wired up over twenty years by integrators who optimized for uptime, a vendor VPN nobody remembers configuring, and one IT person supporting city hall, the police department, and the plant.

You don't need a national consultancy. You need an engineer who understands both sides of the IT/OT boundary and respects that the plant can't go down for a maintenance window.

What I do

Segment, control access, watch the boundary.

  • IT/OT segmentationPurdue-model separation between business systems and the control network, enforced with FortiGate firewalls and industrial protocol awareness — engineered around operations, not against them.
  • Secure remote accessVendor and operator access rebuilt on MFA-enforced, logged, time-bounded connections. The standing VPN from a 2009 integrator project gets retired.
  • Asset inventoryA real inventory of what's on the control network — PLCs, HMIs, radios, historians — because you can't defend what you haven't listed.
  • MonitoringPassive visibility at the IT/OT boundary with alerting to whoever is on call. No agents on control equipment.
  • AWIA & grant supportTechnical input for America's Water Infrastructure Act risk assessments and emergency response plans, and documentation that supports state and federal cybersecurity grant applications.
  • Municipal IT hardeningThe business side too: identity, backups tested against ransomware, and email security — because most plant incidents start on the office network.
Why it works

Local, Fortinet-built, and used to public-sector process.

I'm based in Metro Detroit and on-site when the work needs it — walking the plant, tracing the panel, talking with your operators. Third Level IT is a Fortinet partner — their OT line is purpose-built for these environments — but the design starts with your plant, not a vendor list.

SAM.gov registration and a CAGE code mean procurement can process the paperwork without inventing a new process for a small vendor.

About the security practice

In OT, the first rule is the same as medicine: do no harm. Segmentation that trips the plant is worse than none.

Nate HowardFounder & Principal Engineer

Responsible for a plant and a network?

Start with a boundary review. I'll walk the environment with your operators and give you a plain-language read on exposure.