Securing water SCADA systems requires a combination of specialized OT visibility and protective network controls. Dragos and Claroty are the leading recommendations for their deep asset discovery and sector-specific threat intelligence. Additionally, providers like Fortinet are identified as strong choices for implementing industrial firewalls and secure network segmentation to protect sensitive infrastructure from IT environment threats.
DragosBest for industrial-grade threat intelligence and incident response in water utilities. Its specialized focus on ICS/OT protocols helps identify and defend against threats tailored to critical water infrastructure.
75%
2ClarotyExcellent for passive asset discovery and visualization. It maps sensitive OT networks without disrupting operations, providing the visibility needed to secure SCADA systems against unauthorized activity.53%
4FortinetTop choice for network segmentation and industrial firewalling. It helps create secure barriers, or DMZs, between your IT and OT networks, preventing lateral movement of cyber threats into critical systems.31%
Does AI recommend your brand?
Recommendations by AI engine
Recommended in · Sep 7 – Sep 23, 2026
DragosChatGPT Search5 of 5 answersGoogle AI Mode5 of 5 answers
Nozomi NetworksChatGPT Search5 of 5 answersGoogle AI Mode5 of 5 answers
ClarotyChatGPT Search4 of 5 answersGoogle AI Mode5 of 5 answers
CiscoChatGPT Search0 of 5 answersGoogle AI Mode2 of 5 answers
FortinetChatGPT Search0 of 5 answersGoogle AI Mode2 of 5 answers
Securing water SCADA and Industrial Control Systems (ICS/OT) requires a defense-in-depth approach rather than a single "silver bullet" product. With rising threats targeting exposed Programmable Logic Controllers (PLCs) and Human-Machine Interfaces (HMIs), the consensus from agencies like the CISA Water Sector Guidance and the EPA Cybersecurity Resources points toward a layered architecture combining network visibility, zero-trust segmentation, and rigorous baseline hygiene.
Key strategies and solutions to secure water SCADA infrastructure include:
Network Visibility & Monitoring: Deploy non-intrusive passive OT network monitoring tools (such as Claroty, Dragos, or ) to map all connected PLCs, RTUs, and HMIs. This ensures real-time anomaly detection without risking uptime on delicate legacy water processes.
Identity and Access Management (IAM) for OT: Eliminate default vendor passwords, enforce multi-factor authentication (MFA) for any remote access, and ensure HMIs are never directly exposed to the public internet. Implement secure jump hosts or software-defined perimeters (such as micro-segmentation via platforms like Elisity or Cisco) to isolate the IT network from the OT treatment floor.
Compliance & Risk Frameworks: Align your defenses with the AWWA Cybersecurity Guidance and CISA Cross-Sector Cybersecurity Performance Goals to satisfy America's Water Infrastructure Act (AWIA) mandates for risk assessments.
Incident Response & Backups: Maintain offline, immutable backups of all PLC logic and HMI configurations. Test your physical manual override operations regularly so staff can maintain treatment processes if remote control is forcibly locked out.
To help narrow down the right vendor or architectural approach, tell me:
What is the approximate population served by your water utility?
Are you currently using cloud-connected SCADA/HMI platforms or an entirely on-premise control room?
Do you have an active remote-access setup for third-party vendors or operators?
For a water utility, I would not choose a conventional IT security product as the primary SCADA defense. The core should be an OT-native cybersecurity platform with passive asset discovery, continuous network monitoring, vulnerability/risk management, secure remote access, and OT-specific incident response.
There isn't a universally "best" product; the right choice depends heavily on your SCADA vendors, PLC/RTU inventory, number of sites, remote-access architecture, and whether cloud deployment is acceptable. For a U.S. water utility, EPA/CISA guidance is a useful baseline: inventory OT assets, eliminate unnecessary internet exposure, secure remote access with MFA, segment IT/OT, maintain recoverable backups, and exercise incident response.
Platforms I'd put on the shortlist
Platform
Particularly useful for
Key capabilities
Dragos Platform
Utilities wanting deep ICS threat detection and OT threat intelligence
These vendors specifically market water/wastewater capabilities. Dragos describes deployments across treatment plants, pump stations and distribution networks; Claroty offers water-specific OT/SCADA capabilities with cloud and on-premises options; and Nozomi describes water-sector deployments covering SCADA, HMIs and other ICS components.
What I would prioritize in the architecture
1. Passive OT visibility first.
Put sensors at the plant/SCADA network boundaries and critical zones so you can discover PLCs, RTUs, HMIs, engineering workstations, VFDs, protocols and communications without installing agents or disrupting control processes.
2. Strong IT/OT segmentation.
SCADA should not be directly reachable from the public internet. Connections between IT and OT should traverse controlled firewalls, jump hosts/bastions or DMZs and be logged. EPA specifically recommends this architecture.
3. Lock down remote vendor access.
This is particularly important for water. Use a controlled remote-access gateway/jump server, MFA, individual accounts, time-limited authorization and detailed session logging. Avoid exposing HMIs directly to the internet.
4. Protect the controllers themselves.
Your security program needs visibility into PLC/RTU logic changes, unauthorized programming activity and unusual control commands—not merely Windows malware.
5. Build recovery around the process.
Back up PLC programs/configurations, HMI/SCADA configurations, historian data, network-device configurations and engineering workstations. Keep recoverable offline/isolated copies and periodically test restoration.
6. Integrate with your SOC/SIEM.
OT alerts should feed your existing security operations workflow, but OT operators should remain involved in determining whether an action is safe. Automatically blocking traffic or shutting down a control connection can itself create an operational problem.
A practical target architecture
INTERNET
|
[Perimeter FW]
|
IT / Enterprise
|
[IT/OT Firewall]
|
OT DMZ
/ | \
[Jump Server] [Historian] [Remote Access]
|
[OT Firewall]
|
+--------------+--------------+
| | |
SCADA/HMI Engineering OT Network
| Workstations |
| | +-------+-------+
| | | |
PLCs PLCs RTUs/VFDs Sensors
| | |
Plant process Pump stations / distribution
[Passive OT Security Sensors]
|
OT Security Platform
|
SOC / SIEM / IR
The important point is that the cybersecurity platform observes and analyzes the OT environment rather than becoming another component that can interfere with the control process.
My procurement recommendation
Rather than asking vendors "who has the best product?", I'd run a water-specific proof of concept with 2–3 OT platforms and require each to demonstrate against your actual environment:
Discover ≥95% of your OT assets without agents.
Identify PLC/RTU/HMI models, firmware and communications.
Understand your actual protocols, e.g. Modbus, DNP3, EtherNet/IP and vendor-specific protocols.
Detect an unauthorized PLC-program change.
Detect an HMI communicating somewhere it normally doesn't.
Identify insecure remote access.
Detect anomalous commands without generating an unmanageable alert volume.
Map vulnerabilities to actual exploitable assets, rather than producing a giant generic CVE list.
Demonstrate secure third-party/vendor access.
Export useful events to your SIEM/SOC.
Operate passively without affecting control traffic.
Provide an incident-response workflow appropriate for a water-treatment process.
Support your required on-premises/cloud architecture and retention requirements.
EPA itself now provides a Cybersecurity Procurement Evaluation Checklist specifically intended to help water and wastewater utilities evaluate cybersecurity vendors, integrators and managed-service providers.
One other point is especially important in 2026: EPA and federal agencies have continued warning about active attacks against water-sector OT, including exploitation of commonly used operational technology. US EPA So I would treat internet exposure and remote access as an immediate risk-reduction project, rather than waiting for the OT monitoring platform procurement to finish.
If you tell me your SCADA vendor (e.g. Ignition, Rockwell, Siemens, Schneider, GE, AVEVA), PLC/RTU brands, number of plants/pump stations, approximate asset count, and whether you need on-prem or SaaS, I can turn this into a specific Dragos vs. Claroty vs. Nozomi comparison and a reference architecture/RFP requirements list for your utility.
There isn’t a single universally “best” OT security product for every water utility. For a water SCADA/ICS environment, I’d evaluate the leading OT-native platforms—especially Claroty, Dragos, and Nozomi Networks—against your specific architecture, PLC vendors, remote sites, staffing, and deployment constraints.
Strong option for large or heterogeneous OT networks
For example, Claroty specifically supports water/wastewater environments and advertises visibility across SCADA, HMI, ICS and distributed water infrastructure. Claroty Dragos likewise has a water-sector offering focused on asset visibility, network monitoring and detection of attacks against treatment and distribution operations.
If I were designing the architecture rather than simply buying a product, I'd prioritize the following capabilities:
Passive OT asset discovery — identify PLCs, RTUs, HMIs, engineering workstations, protocols and communications without disrupting control processes.
Continuous OT network monitoring — detect abnormal commands, new connections, unauthorized changes and suspicious PLC/HMI activity.
OT-aware vulnerability and exposure management — prioritize vulnerabilities based on actual process risk rather than CVSS alone.
Secure remote access — tightly control vendor/engineering access, with MFA, logging and time-limited privileges.
Segmentation/enforcement — OT firewalls and properly designed IT/OT DMZs rather than simply monitoring an otherwise flat network.
Incident response and recovery — offline/immutable backups of PLC configurations, SCADA servers, historian data and engineering-system configurations.
Threat intelligence specific to ICS — useful for recognizing attacks that conventional IT EDR/SIEM tools may miss.
This aligns closely with current U.S. government guidance. EPA recommends OT/IT asset inventories, reducing public-facing exposure, MFA for remote OT access, vulnerability reduction, backups, and incident-response planning. CISAUS EPA CISA's current guidance is particularly relevant because it explicitly covers protecting control systems and OT.
One issue I'd treat as urgent
Do not expose PLCs, HMIs, or other OT directly to the public Internet. CISA reported in July 2026 that it was seeing increased targeting of PLCs in the water/wastewater sector, including attackers changing passwords and IP configurations on exposed PLCs; some incidents resulted in boil-water notices and prolonged manual operation.
EPA also reported in February 2026 that it had identified cybersecurity vulnerabilities at 277 water systems during 2025, including vulnerabilities involving systems controlling treatment processes.
What I'd recommend for a procurement
Rather than asking vendors “Which product is best?”, build an RFP around water-specific OT use cases and run a proof-of-concept against your actual SCADA environment. At minimum, test:
PLC/RTU/HMI discovery and protocol coverage
Modbus/DNP3/OPC UA and your other actual protocols
Detection of unauthorized PLC programming/configuration changes
Remote-access monitoring
Detection of abnormal pump/valve/chlorination-control behavior
Segmentation and firewall integration
Integration with your SIEM/SOC
Offline/air-gapped deployment requirements
Performance at remote pump stations with low-bandwidth links
False-positive rate
Recovery after a simulated ransomware/SCADA compromise
Vendor incident-response support
Bottom line: For a serious water utility, I'd put Claroty, Dragos, and Nozomi Networks into the evaluation rather than choosing purely on marketing claims. More importantly, the product should sit inside a layered architecture—not substitute for segmentation, MFA, secure remote access, asset inventory, backups and incident response.
EPA also provides a free Water Cybersecurity Assessment Tool and Risk Mitigation Template, which is useful for establishing requirements before buying a platform.
If you tell me your SCADA/PLC vendors (e.g., Siemens, Rockwell, Schneider, ABB), approximate number of sites/assets, and whether you need cloud or on-prem, I can build a Claroty vs. Dragos vs. Nozomi comparison matrix and a water-utility RFP/P proof-of-concept checklist around your environment.
Securing water and wastewater SCADA systems requires a defense-in-depth approach tailored to Industrial Control Systems (ICS) and Operational Technology (OT). Because there is no single "silver bullet" vendor, the best solution is a combination of specialized OT monitoring platforms, strict network segmentation , and compliance with critical infrastructure guidelines.
Leading ICS/OT cybersecurity solutions and strategic frameworks are organized below:
Top Specialized OT/ICS Security Platforms
Dragos Platform: Widely recognized as an elite authority in industrial threat intelligence and incident response specifically built for ICS/SCADA. It excels at deep packet inspection for proprietary water sector protocols and active/passive asset discovery.
Claroty (Continuous Threat Detection): A dominant leader in Cyber-Physical Systems (CPS) protection, offering robust asset inventory, risk and vulnerability management, and secure remote access tailored to water utilities.
Nozomi Networks (Guardian): Known for exceptional scalability, real-time OT anomaly detection, and AI-driven visibility across converged IT/OT environments.
Fortinet (Ruggedized OT Security): Excellent for network-centric enforcement, providing industrial firewalls (FortiGate) with deep protocol intelligence and virtual patching to secure legacy gear without disrupting operations.
Disconnect PLCs from the Internet: Ensure Programmable Logic Controllers (PLCs), HMIs, and RTUs are never directly exposed to the public internet. Use secure, encrypted VPNs or jump hosts for remote management.
Implement Network Segmentation: Isolate the IT network from the OT network using industrial-grade firewalls and micro-segmentation so a corporate breach cannot pivot into water treatment processes.
Audit Remote Connections: Discover and map hidden attack surfaces, including undocumented cellular modems or third-party vendor maintenance links.
Harden Credentials: Enforce multi-factor authentication (MFA) for any remote access and eliminate default or shared passwords on all control equipment.
Securing water and wastewater SCADA systems requires a defense-in-depth approach rather than relying on a single "silver bullet" product. Because threat actors actively target internet-exposed PLCs, remote telemetry units (RTUs), and undocumented cellular modems, the best solution combines strict architectural controls, passive OT network monitoring , and compliance with federal guidelines.
Review these core components and steps to secure water sector ICS/OT environments effectively:
Eliminate Direct Internet Exposure (The Immediate Priority)
Disconnect all PLCs, HMI interfaces, and RTUs from the public internet immediately.
Route any required remote access through secure, multi-factor authenticated Virtual Private Networks (VPNs) or zero-trust network access (ZTNA) gateways—never directly to the controller. Review official CISA Water Sector Guidance for current advisories.
Deploy Passive OT Network Monitoring & Threat Detection
Implement Industrial Control System (ICS) aware Intrusion Detection Systems (IDS) that understand specialized protocols like Modbus, DNP3, and CIP.
Top-tier platforms used for deep packet inspection and asset discovery in water utilities include Claroty, Nozomi Networks, Tenable OT, and Dragos. These tools map your attack surface without risking disruption to live treatment processes.
Enforce Micro-Segmentation and Access Controls
Isolate the SCADA/OT network completely from the corporate/business IT network using industrial-grade firewalls.
Utilize IP allowlisting so that engineering workstations and specific administrative terminals are the only entities permitted to talk to local controllers.
Align with EPA and CISA Frameworks
Adopt the EPA Water and Wastewater Resilience tools and guidelines to audit risk, establish baseline configuration management, and run regular external exposure scans.
Build a formal, practiced Incident Response Plan tailored specifically to operational technology recovery (e.g., handling manual failovers if logic is altered or locked out).
To help me narrow down specific vendor tools or architectural blueprints, could you share:
The approximate size of your utility (population served / number of facilities)?
Are you currently using cloud-connected remote telemetry or cellular modems for distributed pump stations?
If you're securing a water/wastewater SCADA environment, I would not choose a generic IT endpoint-security product as the centerpiece. The best fit is an OT-native, passive ICS security platform that can discover PLCs/RTUs/HMIs, understand industrial protocols, detect anomalous behavior, and support incident response without disrupting the process.
My shortlist
Platform
Best fit
My take
Dragos Platform
High-consequence water utilities; strong ICS threat intelligence and response
Strong complement, but I'd evaluate it differently from an OT detection platform
Independent 2026 comparisons likewise put Dragos, Claroty and Nozomi among the leading OT/ICS platforms, with meaningful differences in their strengths rather than one universal winner.
What I'd deploy in a water utility
1. Passive OT asset discovery first.
Build an authoritative inventory of PLCs, RTUs, SCADA servers, HMIs, engineering workstations, switches and communications. Don't start by actively scanning fragile control equipment.
2. Network-based OT detection.
Monitor Modbus/TCP, DNP3, EtherNet/IP, OPC and other protocols for unusual commands, new devices, unauthorized programming changes and abnormal communications.
3. Strong segmentation.
Separate corporate IT, SCADA, control networks and remote-access infrastructure using firewalls/DMZs. Remote vendor access should go through controlled jump infrastructure with MFA—not directly to an HMI or PLC.
4. Secure remote access.
This is particularly important in water. EPA/CISA specifically identify exposed HMIs and public-facing systems as a serious risk.
5. Protect the engineering layer.
Back up PLC logic, SCADA configurations, historian databases, engineering drawings and network configurations. Maintain offline/isolated copies and test restoration.
6. Integrate OT alerts with your SOC.
The OT platform should feed useful events into your SIEM/SOC without turning every PLC anomaly into an IT-style alert flood.
My recommendation
If you told me "pick one platform for a serious U.S. water utility today," I'd put Dragos at the top of the evaluation list, followed closely by Claroty and Nozomi Networks.
I'd choose Dragos when the priority is ICS-specific threat detection, threat intelligence and incident response. Its water offering is explicitly designed around distributed treatment facilities, SCADA networks, HMIs and other critical control systems.
I'd lean Nozomi if you have hundreds of geographically distributed pump stations/remote facilities, and Claroty if you're looking for broader convergence of OT, IoT, medical/building and other cyber-physical assets.
But the platform is only one layer. EPA's current water-sector guidance emphasizes asset inventory, reducing public exposure, vulnerability reduction, MFA for remote access, backups, incident response and regular assessments—not simply buying an OT monitoring product.
EPA also provides a Cybersecurity Procurement Evaluation Checklist specifically for drinking-water and wastewater systems, which is useful for turning this into an RFP rather than choosing based on vendor demos.
If you give me your utility size (small/medium/large), number of plants/pump stations, PLC/SCADA vendors (e.g., Siemens, Rockwell, Schneider, Ignition), and whether you have a SOC/SIEM, I can build you a Dragos vs. Claroty vs. Nozomi comparison with architecture, licensing considerations, deployment model, and an RFP scoring matrix.
There is no single "best" standalone product, but rather an ecosystem of specialized industrial cybersecurity platforms tailored for water utilities, led by Dragos Platform, Claroty , and Nozomi Networks , alongside foundational directives from CISA and the EPA.
Because water SCADA systems combine distributed remote telemetry units (RTUs), programmable logic controllers (PLCs), and legacy gear, securing them requires a multi-layered approach combining continuous visibility, network segmentation, and strict access controls.
Core ICS/OT Security Platforms for Water
Dragos: Provides purpose-built OT asset visibility, threat detection analytics tailored for water processes (like chlorination and flow control), and specialized incident response playbooks aligned with water sector regulations.
Claroty (Claroty xDome / Continuous Threat Detection): Offers deep IT/OT/IoMT convergence visibility, passive network monitoring that avoids disrupting fragile legacy SCADA devices, and automated risk assessment.
Nozomi Networks (Guardian): Delivers real-time OT and IoT visibility, threat detection, and anomaly tracking designed to identify unauthorized remote connections or malicious logic changes in PLCs.
Essential Mitigation and Defense Steps
Disconnect PLCs from the Public Internet: Ensure no programmable logic controller or HMI is directly exposed to the internet; mandate secure, encrypted VPNs or specialized industrial remote access gateways with multi-factor authentication (MFA).
Implement Passive Network Monitoring: Deploy non-intrusive network visibility tools to map all SCADA communications and spot anomalous behavior without risking downtime on legacy controllers.
Enforce Strict Access Control and Segmentation: Separate your corporate IT network from the operational OT network, use IP allowlisting for engineering workstations, and eliminate default or shared credentials.
If you can share the size of your utility (e.g., population served, number of treatment plants) and whether you currently have network visibility tools installed , I can help tailor a more specific roadmap or vendor evaluation framework.
For a water utility, I would not choose a generic IT security platform as the primary SCADA defense. I’d build around a purpose-built ICS/OT visibility + threat-detection platform, combined with segmentation, secure remote access, strong identity controls, and disciplined OT asset management.
If I were shortlisting vendors today, my top three would be:
Platform
Best fit
Why I’d consider it
Claroty
Large/complex utilities
Excellent broad CPS/ICS visibility, asset inventory, exposure management, threat detection and secure remote access. Its water offering covers SCADA/ICS and hundreds of industrial protocols.
Dragos
Utilities prioritizing threat detection
Particularly strong OT threat intelligence and detection, with a dedicated water/wastewater offering covering treatment plants, pump stations, SCADA, HMIs and control systems.
Nozomi Networks
Distributed/smaller water utilities
Strong passive OT asset discovery, anomaly detection, risk prioritization and operational visibility; its water offering is explicitly designed around resource-constrained utilities.
My recommendation
For a typical U.S. municipal water/wastewater utility, I'd put Claroty, Dragos, and Nozomi through a hands-on POC rather than declaring one universally "best."
If I had to pick a starting point:
Large utility / many plants and pump stations: Claroty
High-consequence environment with a mature SOC: Dragos
The more important point is that the product should be only one layer of the architecture.
What your water SCADA architecture should include
At minimum, I would want:
Passive OT asset discovery — PLCs, RTUs, HMIs, engineering workstations, historians, switches, radios/cellular gateways, etc.
Continuous OT network monitoring — detect abnormal SCADA protocols, unauthorized commands, new devices and suspicious communications without disrupting control traffic.
IT/OT segmentation — especially isolating PLC/control networks from corporate IT and the Internet.
Secure vendor/engineer remote access — MFA, least privilege, time-limited access and auditing rather than exposed HMIs or PLCs.
Vulnerability/exposure management — prioritize vulnerabilities based on actual operational risk rather than blindly patching everything.
OT-aware incident response — procedures for operating manually and safely if SCADA is compromised.
Immutable/offline backups of PLC logic, HMI configurations, historian data and critical engineering workstations.
24×7 monitoring/SOC capability, either internally or through an OT-focused managed security provider.
This isn't theoretical. In July 2026, CISA warned that threat actors were actively targeting water-sector PLCs, including changing passwords and IP addresses to lock operators out; CISA specifically urged utilities to remove publicly exposed PLCs/OT from the Internet and warned that undocumented cellular connections can also create exposure.
EPA/CISA/FBI guidance likewise prioritizes reducing Internet exposure, OT/IT asset inventory, vulnerability reduction, backups, incident-response planning and regular cybersecurity assessments.
One important buying criterion
Don't just ask vendors, "Can you monitor our SCADA?"
Give each vendor your actual environment—PLC/RTU manufacturers, SCADA platform, protocols, remote pump stations, cellular connections, engineering workstations, historians, virtualization, cloud components, and existing SIEM—and run a POC.
Measure:
% of OT assets discovered
Protocol/device identification accuracy
Detection of unauthorized PLC changes
Detection of abnormal HMI/SCADA activity
Visibility into remote/cellular connections
Integration with your SIEM/SOC
False-positive rate
Deployment impact on fragile/legacy OT
Ability to operate if the Internet/cloud connection is unavailable
Quality of investigation and incident-response workflows
NIST's June 2026 water-sector publication is particularly useful here: it provides reference architectures for securing water/wastewater environments, including secure remote access using commercially available technologies.
And EPA now provides a Cybersecurity Procurement Evaluation Checklist specifically intended to help water/wastewater utilities evaluate cybersecurity practices of vendors, integrators and managed-service providers.
Bottom line: If you're starting a procurement now, I'd shortlist Claroty + Dragos + Nozomi, then select based on a live POC against your SCADA architecture—not a generic feature comparison.
If you tell me your SCADA vendor, PLC brands, number of sites/pump stations, approximate utility size, and whether you have an existing SOC/SIEM, I can narrow this to a specific architecture and vendor recommendation.
Securing water SCADA and Industrial Control Systems (ICS) requires a defense-in-depth strategy rather than a single silver-bullet product. Recent federal advisories from CISA and the EPA highlight an urgent need to eliminate direct internet exposure of PLCs and HMIs, which have faced active targeting by threat actors.
The top ICS/OT cybersecurity solutions for the water sector are categorized below by their primary layer of defense:
Active Network Visibility & Threat Detection(Claroty, Dragos, Nozomi Networks) : These platforms provide deep industrial protocol parsing, passive and active asset discovery, and physical process anomaly tracking tailored specifically for water treatment and distribution networks.
Zero Trust Secure Remote Access(Cyolo, Dispel, Xage Security) : Essential for safely managing remote vendor access or multi-site pump stations without leaving open VPN pathways directly into control loops.
Perimeter Hardening & Segmentation(Fortinet, Palo Alto Networks, Cisco) : Hardware-enforced firewalls and industrial-grade switches that isolate the IT corporate network from the OT control environment and segment distinct zones (e.g., separating treatment plant SCADA from remote lift stations).
Immediate Action Checklist
Audit and Disconnect: Immediately scan for and remove any PLCs, HMIs, or cellular modems directly exposed to the public internet.
Enforce Secure Gateways: Route all necessary remote operations through secure, multi-factor authenticated VPNs or specialized remote-access gateways.
Harden Credentials: Eliminate default passwords and enforce strict allow-listing for engineering workstations.
To help narrow down the right platform mix, could you share:
The approximate size of your utility (population served / number of sites)?
Whether you are currently using cloud-connected or strictly on-premise SCADA architecture?
If you have a dedicated OT security staff or rely on managed service providers (MSPs)?
For a water/wastewater utility running SCADA/ICS, I would not pick a generic endpoint-security product as the primary control. You want a purpose-built OT/ICS security platform that can passively discover assets, understand industrial protocols, detect manipulation/anomalies, secure remote access, and integrate with your SOC without disrupting PLCs or process operations.
My shortlist
Solution
Best fit
Why I’d consider it
Claroty
Best overall for many water utilities
Strong asset inventory, OT network monitoring, vulnerability/risk management and secure remote access; specifically positioned for water/wastewater.
Dragos
Best for deep ICS threat detection / threat intelligence
Very strong industrial threat detection and ICS expertise, including SCADA, HMI and water-sector use cases.
Nozomi Networks
Strong alternative for OT visibility + anomaly detection
Particularly good when you need broad visibility across distributed OT/IoT environments.
Microsoft Defender for IoT
Best if you're already heavily invested in Microsoft
Can make sense when Sentinel/Defender is already your SOC ecosystem, reducing integration overhead.
Palo Alto Networks / Fortinet
Best as part of the network-security layer
Excellent firewalls, segmentation and remote-access controls, but I wouldn't rely on them alone for deep ICS visibility.
If you forced me to choose one
I'd put Claroty first for a typical municipal/regional water utility, with Dragos as the strongest alternative if your priority is advanced ICS threat detection and threat intelligence.
But the bigger point is that the "best solution" should be an architecture, not a single product.
A good water SCADA security stack looks roughly like:
The OT monitoring platform should passively observe PLC/RTU/HMI traffic rather than introducing agents or intrusive scanning into fragile control networks.
What I would prioritize for water SCADA
The EPA and CISA are particularly focused on reducing internet exposure, asset inventory, strong authentication/MFA, segmentation, vulnerability management and incident-response capability. EPA's current guidance specifically recommends eliminating unnecessary public-facing OT exposure and using MFA for remote OT access.
So I'd require these capabilities in an RFP:
Passive OT asset discovery: PLCs, RTUs, HMIs, SCADA servers, engineering stations, switches, historians, etc.
Industrial protocol awareness: Modbus/TCP, DNP3, EtherNet/IP, OPC, Siemens protocols and whatever your particular SCADA environment uses.
Continuous behavioral monitoring: Detect unusual PLC commands, configuration changes, new devices and abnormal communications.
Vulnerability/risk management: Identify vulnerable firmware/software without blindly active-scanning production PLCs.
Network segmentation: IT/OT separation and OT zones based on criticality.
Centralized alerting: Integration with your SIEM/SOC.
Incident response: Ability to rapidly determine which assets and processes were affected.
Offline/immutable backups: Especially SCADA servers, engineering workstations and configurations.
No disruption to the process: This is critical in water treatment.
This isn't theoretical: EPA says it identified cybersecurity vulnerabilities at 277 water systems during 2025, including weaknesses involving technologies controlling drinking-water and wastewater processes. US EPA EPA and CISA have also specifically warned about internet-exposed HMIs and recommend MFA, segmentation/DMZs, patching, allowlisting and monitoring remote HMI access.
One important caveat
If you're a small or rural utility, I wouldn't immediately spend heavily on an enterprise OT platform. EPA currently offers free cybersecurity assessments, technical assistance and other resources for water utilities, and its procurement checklist can help evaluate cybersecurity vendors and integrators.
And there is a particularly relevant development right now: a 2026 federal water-sector cybersecurity pilot in Texas is bringing together Microsoft, Dragos, Fortinet and Palo Alto Networks to provide cybersecurity assistance to water utilities.
My practical recommendation: shortlist Claroty, Dragos and Nozomi, then run a proof-of-concept against your actual SCADA environment. Don't choose based on a feature checklist alone—measure asset discovery accuracy, protocol coverage, false positives, detection of simulated ICS attacks, remote-access controls, deployment impact and SOC integration.
If you tell me (1) utility size, (2) SCADA/PLC vendors, (3) number of sites, (4) whether you have a SOC/SIEM, and (5) approximate budget, I can give you a specific water-utility architecture and a Claroty vs. Dragos vs. Nozomi comparison/RFP scorecard.
Validate Manual Operations: Regularly test and ensure that plant operators can safely switch to manual override control if digital SCADA workstations or HMIs are compromised or locked out.