The works nobody sees,until it stops.
Water is the most distributed critical infrastructure there is: intakes, treatment works, pumping stations and reservoirs across a city or a district, built by one contractor, run by another, and watched from a control room that may belong to neither. ASTRICS gives the utility one operational understanding of all of it — every PLC, every dosing pump, every remote site — ranked by what the public would lose.
Jal Jeevan Mission has connected more than 15 crore rural households to tap water, with IoT-based monitoring across the schemes, and AMRUT 2.0 is funding 24×7 supply with SCADA in every one of the 500 AMRUT cities.
Sources: Ministry of Jal Shakti; Ministry of Housing and Urban Affairs, AMRUT 2.0
The water estate,as ASTRICS reads it.
Intake, treatment, storage and distribution assets land in one register with their process, their owner — often a contractor — and their consequence to supply and public health.
Intake and pumping stations
Pumps, valves and level control at the edge of the network, usually on a cellular link. The first thing to stop and the last thing to be visited.
Treatment control
Chemical dosing, filtration and disinfection. The PLCs whose set-points decide whether the water is safe — critical by definition.
Clarifiers, aeration and sludge
The slow processes of a treatment works, each with its own drives, sensors and small controllers.
Distribution SCADA and district metering
Pressure, flow and quality across the network; the 24×7 supply schemes now being built on it.
Telemetry and time
Level, flow and quality sensors reporting over cellular and radio. If the reading is wrong, the decision is wrong.
Contractor control rooms
EPC and O&M contractors operate the works. Every session, every remote login, observed and attributed.
Why water utilitiesare the soft target.
The water sector has been the target of choice for hacktivists and state-aligned groups because its controllers are small, exposed and rarely watched — and because the consequence is public.
Built by a contractor, run by a contractor
The asset register, if it exists, belongs to whoever built the works. The utility that carries the consequence often cannot answer what is connected.
Cellular PLCs at the end of a lane
Small controllers with default credentials on internet-facing links. The pattern behind the attacks on US water systems since 2023 is the pattern of a district pumping station anywhere.
A public-safety consequence
A dosing set-point is a safety parameter. Ranking risk by consequence means the chlorination PLC outranks the billing server every time.
On the record
No cyber incident at an Indian water utility has been made public. The controllers, links and contracting model are the same ones attacked elsewhere.
- 2023
A group calling itself CyberAv3ngers defaced a Unitronics PLC at a booster station of the Municipal Water Authority of Aliquippa, Pennsylvania, forcing manual operation. Similar devices were hit at other utilities.
WaterISAC; US CISA advisory, November 2023
- 2026
The FBI warned that malicious actors were targeting internet-facing programmable logic controllers in the water and wastewater sector and causing operational disruption.
FBI cyber alert, 2026
- 2021
An intrusion at a Florida water treatment plant briefly changed the sodium hydroxide set-point through remote-access software, according to the county sheriff. Later reporting questioned the account, which is why the record matters.
Pinellas County Sheriff's Office, February 2021 — as reported
What the rules askof a water utility.
Summaries of the notified text as we read it in September 2026. Orientation, not legal advice — check the Gazette before you rely on a clause.
CERT-In, six hours
IT Act s.70B(6) DirectionsThe CERT-In Directions of 28 April 2022 apply to every body corporate and government organisation: covered incidents reported within six hours of noticing, 180 days of ICT logs kept in India, clocks synchronised to NIC or NPL time.
Protected systems, where notified
IT Act ss.70, 70AWhere NCIIPC identifies a utility's control system as critical information infrastructure, it can be notified as a protected system under section 70 of the IT Act.
No water-specific OT rule — yet
Ministry of Jal Shakti; MoHUAAs of September 2026 India has no sector-specific OT cyber security regulation for water, so the obligations come from the IT Act, from state water boards and urban local bodies, and from the contracts under which schemes are built and run.
IEC 62443 as the Indian standard
BIS / IEC 62443The Bureau of Indian Standards has adopted the IEC 62443 series as Indian Standards. It is the framework a utility can hold its contractors to now, ahead of a sector mandate.
to report a covered cyber incident to CERT-In after noticing it — for every body corporate, whatever the sector.
of ICT system logs to be kept, inside India, and produced to CERT-In on request.
How ASTRICS mapsto a water utility.
One platform, one language, one source of truth. Understand, Govern, Protect, Orchestrate and Assure travel together, so every capability below reads the same record.
A register the utility owns
Asset Inventory discovers what the contractors connected and holds it with an accountable owner and a criticality — so the utility, not the EPC, holds the record.
Many small sites, one view
Fleet Command shows readiness per works, per pumping station and per obligation, so the weakest site in a district is obvious.
Dosing ranked first
The Risk Queue orders vulnerability data by consequence to supply and public health. The chlorination PLC ranks above the office file server.
Plain answers for thin teams
The on-premises Operational Assistant answers in plain language and cites the record behind every claim — for the engineer who runs six works with a phone.
Asset Inventory
The Chapter III register as a living object. Accountable owner and criticality are first-class columns because the regulation asks for them — and completeness against each field is tracked, since an incomplete register is a failed control.

Fleet Command
One posture number per obligation, across every site — built to answer “are we defensible today, and where are we not” in seconds, not in a reporting cycle.

Operational Assistant
An on-premises assistant that cites the record behind every claim and shows the context it read. Writes to control devices are not a permission it can be granted — that path does not exist in the product.

What operators askbefore they buy.
Straight answers, in the terms the regulation and the plant already use. Bring the rest to a walkthrough.
Our SCADA is run by the O&M contractor. Who is responsible for cyber security?
The consequence sits with the utility, whatever the contract says, and the CERT-In directions apply to the body corporate that operates the system. ASTRICS gives the utility its own record — assets, owners, findings and remote sessions — independent of the contractor's, so accountability can be assigned and evidenced.
Do the CEA power-sector regulations apply to water?
Not directly. The CEA regulation covers entities that own or operate OT connected to the interconnected power system. A water utility's own captive generation at 50 MW or more would be in scope, but the treatment works are governed by the IT Act, the CERT-In directions and the utility's own contracts.
Can ASTRICS see PLCs on cellular links?
ASTRICS builds the record from the traffic and sources the utility already has — the SCADA servers, historians and syslog at the control room, and passive observation where a collector is deployed. Distributed multi-site deployment, centrally managed, is a supported model.
What happens on the day something goes wrong?
The statutory incident workflow assembles the six-hour CERT-In notification from context already held — the asset, its consequence, the events around it — and keeps the clock, the workflow and the submission in one place.
See ASTRICS against your own environment.
Book a walkthrough with the ASTRICS team and bring one site's worth of questions.
