A full real-project case study: hardening a municipal water utility's SCADA system against common attack vectors.
This second case study applies the vulnerability management approach from Module 9 and the risk assessment method from Module 4 to a municipal water utility's SCADA system — a category of critical infrastructure with unusually direct public-safety consequences if compromised. The project works through identifying the system's highest-risk vulnerabilities, deciding which can be patched versus which need a compensating control, and hardening the human-machine interface (HMI) and remote terminal unit (RTU) layer against the most common documented attack patterns against water utilities.
This project assumes the concepts from Modules 4, 6, and 9 and applies them together against a real, named category of critical infrastructure with real regulatory attention (in the U.S., EPA and CISA guidance both cover water-sector cybersecurity specifically).