Breaching a Water Treatment Facility: A Physical Security Test
Most water utilities invest heavily in network penetration testing and web application security, and rightly so. Far fewer test whether someone can simply walk onto the property, badge their way past staff, or climb a fence after dark and reach the equipment that keeps water flowing to a community. This case study walks through a real-world physical security penetration test performed against a municipal water treatment facility, combining social engineering and covert entry testing to answer one question: what would a motivated adversary actually be able to do?
The Challenge: Testing Critical Infrastructure Physical Security
Our client operates a water treatment facility serving a municipal population of roughly 50,000 residents. Leadership wanted to know what would happen if a malicious actor targeted the facility in person, not just online.
We proposed two complementary approaches:
-
Social engineering assessment — testing whether employees recognize, understand, and follow security policies and training when interacting with an unfamiliar visitor.
-
Covert entry testing — testing physical controls such as locks, alarms, and sensors, with minimal or no employee interaction.
The client asked for both.
Why Physical Security Matters for Water Utilities
Water treatment facilities are high-value targets for nation-state actors and criminal groups alike. A successful physical breach could shut off water to a city for days, allow contaminants into the supply, or destroy pumping infrastructure that takes months to replace. Many facilities also store residents' personal and payment information, adding a data-breach dimension to the risk. These were the questions our physical penetration test set out to answer.
Phase 1: Remote Reconnaissance (OSINT)
Every engagement starts with open-source intelligence (OSINT) gathering. Using LinkedIn, Facebook, and the client's own website and press releases, we identified employee names, job titles, photos, badge designs, and even how staff wore their lanyards — details that make an on-site pretext credible. We also learned the facility had just renewed its contract with its internet service provider (ISP), information that would later shape our approach.
Google Maps and satellite imagery mapped the facility layout: gate locations, fencing, nearby buildings, and hangout spots such as a coffee shop frequented by badge-wearing employees. Google Street View let us study the facility's approach and appearance without ever setting foot on site.
.webp?width=600&height=451&name=Picture1%20(1).webp)
These images were created with AI to set the scene, but the breach itself was very real.
Phase 2: On-Site Reconnaissance
With our OSINT complete, we visited the area to validate what we had found: were the gates and fences still as expected? Did employees really visit that coffee shop? We flew a drone for aerial reconnaissance and watched from a distance to identify guard patrol patterns, camera locations and blind spots, nighttime lighting gaps, and traffic patterns.
When possible, we also perform embedded reconnaissance — sending a tester inside as a simple observer with no intent to compromise anything. This person learns how visitor badges are issued, whether tailgating is possible, how closely the receptionist screens visitors, where badge readers and alarms are located, and, critically, where the sensitive areas are. That last point matters: once inside with limited time, testers cannot afford to search for the server room or the control room. This tester is typically not reused later in the engagement, since their face may already be familiar to staff.
Building the Pretext
With enough intelligence gathered, we built our pretext, or cover story, for the social engineering test. Covert entry, by contrast, needed no pretext: we planned that portion for the middle of the night, when there was no legitimate reason to be on site.
We chose to impersonate the ISP. Using our OSINT, we identified how the ISP's field technicians typically dress and purchased similar clothing. We created a fake ID badge bearing the ISP's logo, our tester's photo, and a fabricated name. Our story: we were there to investigate slow internet speeds. Two testers approached together, one carrying a laptop with an external antenna, playing the part of a technician actively testing the network.
Execution: Daytime Social Engineering
The two testers arrived at the sprawling, multi-building campus typical of water treatment facilities and found employees working in a garage. While one tester wandered nearby with the laptop and antenna, the other struck up a conversation and explained the ISP pretext. The employee mentioned an internet outage the previous day, a stroke of luck that made the pretext instantly credible. He directed the testers to the office building, adding, “Mary is in there,” and gave his own name: Bob.
Unescorted, the testers walked to Mary's office, passing within feet of large, uncovered tanks of treated water along the way, with no other employees in sight.
.webp?width=600&height=451&name=Picture2%20(1).webp)
Once with Mary, one tester engaged her in conversation about the outage while the other quietly slipped into unattended offices nearby. There, the second tester found unlocked, logged-in computers, sensitive documents left on desks, and system logs, all photographed and recorded. Back in Mary's office, the first tester asked to verify her connection speed using a USB drive. Mary agreed and stepped away from her computer so the “technician” could plug in an inert USB stick that appeared to confirm a fast connection.
Before leaving, the testers asked Mary's permission to check other areas of the campus, and she agreed. They left her with a positive, unremarkable impression, exactly the goal. Continuing their walk, the testers located and documented additional sensitive assets, including programmable logic controllers (PLCs) and power station switches, none of which were secured or monitored.
Execution: Nighttime Covert Entry
The facility ran 24 hours a day but had no dedicated security guards. Its single main entrance was brightly lit and near occupied offices; any vehicle arriving at night would draw immediate attention from a small, tight-knit night staff who would recognize a stranger on sight.
Instead, the testers targeted a different perimeter: a section bounded by a stream and a chain-link fence. At 1:00 a.m., they waded across the stream, used a small stepladder to reach the top of the fence, and laid a welcome mat over the barbed wire to climb over safely.
.webp?width=600&height=328&name=Picture3%20(1).webp)
Armed with the layout knowledge from earlier reconnaissance, the testers moved directly to the PLCs and power supplies, unmonitored by cameras, alarms, or even a lock. They could have manipulated, disabled, or destroyed either system; the access itself was documented with photographs as proof for the client.
.webp?width=600&height=451&name=Picture4%20(1).webp)
Nearby, they also found a company vehicle with its windows down, containing a keychain with facility keys and company credit cards inside, which was likewise photographed and reported.
With their objectives complete, the testers exited the way they had entered, wading back through the stream. The next day, they delivered a full debrief to the client, walking through every phase of reconnaissance, the pretext, and the steps used to compromise the facility.
Recommendations for Critical Infrastructure Security
Based on the findings, we recommended the client:
-
Verify visitor identity before granting access. Anyone claiming to represent a vendor such as the ISP should have a confirmed appointment, and staff should call the vendor directly to confirm before allowing entry.
-
Escort all visitors at all times. Our use of two testers, one to distract and one to explore, is a common technique that a strict escort policy directly defeats.
-
Never allow outside devices to connect to company systems. Only trained IT staff should insert removable media, and only after validation.
-
Upgrade camera coverage and monitoring, adding motion-activated alerts and closing nighttime lighting gaps around the entire perimeter, not just the main entrance.
-
Physically secure critical assets such as PLCs and power switches behind locked enclosures.
.webp?width=600&height=329&name=Picture5%20(1).webp)
The Takeaway for Critical Infrastructure Operators
Attacks against water treatment facilities and other critical infrastructure come from both the internet and the front gate, or in this case, the back fence. Facilities routinely test their networks, web applications, and internal systems for cyber vulnerabilities but often overlook physical security testing. If a malicious actor can walk onto a campus and reach the equipment that controls the water supply, no firewall will stop them.
Concerned about your own facility's exposure? Our physical security penetration testing combines OSINT reconnaissance, social engineering, and covert entry testing to show you exactly how an adversary would get in, what they could reach, and how to close the gaps before a real attacker finds them. Contact us to schedule an assessment for your facility.
Contact Us
Share this
You May Also Like
These Related Stories

What the Minnesota Water Hack Reveals About OT Security Assessments

Penetration Testing: Understanding Red, Blue, & Purple Teams

.webp?width=2169&height=526&name=Compass%20white%20blue%20transparent%202%20website%20(1).webp)
-1.webp?width=2169&height=620&name=Compass%20regular%20transparent%20website%20smaller%20(1)-1.webp)
No Comments Yet
Let us know what you think