Vignette 01
Regional Water Utility
11 days lead time
Confirmed before asset impact
Vendor compromise detected before asset impact.
- Situation
- A regional water utility had integrated several industrial-automation vendors into its OT environment, including remote-management tools used by engineering contractors. The utility's internal SOC could see anomalous vendor-vpn sessions but could not determine whether they were benign or part of a larger campaign.
- Challenge
- Determine whether the anomalous sessions were isolated operator error, credential compromise, or part of a sector-wide campaign — and act before a safety-system or process-control event.
- Approach
- The Sovereignty Infinium was deployed to monitor surface, deep, and dark-web sources for vendor-name mentions, credential dumps, and threat-actor infrastructure associated with industrial-automation vendors. The vendor's software-update channel was monitored for integrity anomalies. ATT&CK-for-ICS mapping was applied to observed behaviors.