Tabletop Exercises for Water Utility Incident Response: What Actually Works

Published May 8, 2026

A regional water utility in the Southeast ran its first cyber-focused tabletop exercise last year. The Emergency Response Plan, updated on schedule for AWIA compliance, sat on the shared drive looking thorough. Twelve utility staff and three people from the supporting engineering firm gathered around a conference table for a three-hour session. The facilitator read out a scenario: a ransomware note discovered on the SCADA historian at 6 a.m. on a Saturday.

By minute 40, the exercise had surfaced five specific gaps nobody had flagged before. The operations team did not know who had authority to decide whether to disconnect the SCADA network from the internet. The IT contact listed in the ERP had left the utility six months earlier. Nobody was sure which state agency to notify, or whether CISA wanted to hear about it, or in what order. The public communications plan assumed someone was available who was, it turned out, on a cruise with limited phone coverage.

None of these gaps were knowable from reading the ERP. They only became visible when real people had to work a realistic scenario in real time.

The America’s Water Infrastructure Act (AWIA) requires community water systems to maintain Emergency Response Plans. It does not mandate exercises. But the EPA’s AWIA implementation materials make clear that an untested ERP is not actually a plan. Tabletop exercises are the standard tool for closing the gap between what the plan says and what the team can actually do.

The Problem: Written Plans Develop Fiction

ERPs get written, reviewed, and filed. Over time, drift happens:

  • Staff turnover changes the humans in named roles
  • Vendor relationships change, so the IT contact is someone who no longer works for the utility
  • Communication channels change, as tools are replaced or reorganizations rearrange reporting lines
  • New systems come online that the ERP never addresses (new SCADA platforms, cloud services, new cyber threats)
  • Regulations and guidance evolve, so the notification steps in the plan may now be incomplete or wrong

A plan that has not been exercised in two years is probably a plan full of quiet inaccuracies. The first time the team finds those inaccuracies should not be during a real incident.

Why It Matters to You Specifically

For a utility manager or the engineering firm supporting the utility, regular tabletop exercises serve several concrete purposes:

They Make the ERP Real for the Team

Staff who have walked through a scenario know the plan. Staff who have only been handed a binder do not. The difference shows up in how calmly and quickly the actual incident gets managed.

They Surface Planning Gaps Before They Hurt

The gaps the tabletop finds (missing contacts, ambiguous authority, missing procedures) are fixable before a real event. A utility that runs two tabletops per year is iteratively improving its ERP. A utility that runs none is quietly accumulating gaps.

They Build Cross-Function Relationships

Operations, IT, management, legal counsel, the engineering firm, and external partners meet each other and work together on a low-stakes scenario. When a real event happens, those people already know each other and have built a baseline of trust.

They Support AWIA Compliance Documentation

Exercise documentation (date, scenario, participants, findings, corrective actions) becomes evidence that the utility’s ERP is a living document. In an AWIA audit or a state primacy review, “we exercised this scenario in March and updated the plan based on findings” is a much stronger answer than “the ERP is in the binder.”

They Prepare the Utility for State and Federal Support

In a real cyber incident, the utility will likely need to engage state primacy agencies, state fusion centers, EPA regional offices, CISA, and potentially the FBI. Tabletops that include those external relationships (either with real participants or with role-players standing in) prepare the team for what coordination looks like.

What Good Looks Like

Effective tabletop exercises for water utility cyber incident response share several characteristics.

Realistic, Utility-Specific Scenarios

Generic scenarios produce generic findings. Tailor each scenario to your utility’s actual systems, vendors, and risk profile. Examples that produce productive exercises:

  • Ransomware on the historian server during a weekend, with SCADA still operational but operators blind to historical data
  • Unauthorized remote access detected on a pump station RTU, with uncertainty about whether the attacker made changes
  • A compromised vendor laptop with active SCADA access, detected by the vendor and reported to the utility
  • Public release of sensitive utility data on a dark web forum, after a suspected breach
  • A sophisticated phishing attack targeting the general manager’s email, resulting in wire fraud that also suggests broader email compromise

The CISA Tabletop Exercise Packages (CTEPs) include water sector scenarios that are useful as a starting point. Customize before running.

The Right Participants

The people who would actually need to act in a real incident should be at the table. For a water utility, that typically means:

  • General manager or operations director
  • Water or wastewater operations supervisor
  • IT lead (internal or contracted)
  • The supporting engineering firm’s project manager and cybersecurity lead
  • A representative from legal counsel (for larger utilities)
  • Communications or public information officer
  • Board chair or elected official (for the more serious scenario exercises)

External partners can sometimes be invited or simulated. State primacy agencies and CISA regional coordinators are often willing to participate in exercises if asked.

A Prepared Facilitator

The facilitator leads the scenario, injects realistic developments as time passes, and keeps the discussion moving. A good facilitator has both cybersecurity expertise and familiarity with water utility operations. Hiring an outside facilitator (or asking the supporting engineering firm to bring one) is often worth it for serious exercises.

Ground Rules That Encourage Honesty

The point of the exercise is to find gaps, not to demonstrate competence. Participants should be encouraged to say “I don’t know who to call” or “I don’t think we have a procedure for this” out loud. A facilitator who signals that admissions of uncertainty are valuable gets more productive results than one who lets the exercise turn into a display of confidence.

Documented Findings and Corrective Actions

Every exercise produces an After-Action Report (AAR) listing:

  • What scenario was run and who participated
  • Strengths observed (not just gaps)
  • Specific gaps identified
  • Corrective actions assigned, with owners and deadlines
  • Follow-up verification that corrective actions closed the gaps

The AAR is the evidence of the exercise’s value. It is also what you show an auditor or regulator.

Regular Cadence

A single tabletop does not make a utility ready. A cadence of at least one cyber-focused tabletop per year, and ideally two, is what sustains readiness. New scenarios each time cover different aspects of the ERP.

Practical Takeaways

  1. Schedule a tabletop exercise in the next 90 days. Not “sometime this year.” A specific date on the calendar.
  2. Pick a scenario relevant to your utility. Ransomware on SCADA, compromised vendor access, or a regional cyberattack affecting multiple utilities are all good starting points.
  3. Invite the right people. If the general manager is not at the table, the authority gaps will not get found. If IT is not at the table, the technical gaps will not get found.
  4. Write the After-Action Report. An exercise without documentation leaves no trail. Documentation is what turns exercises into sustained improvement.
  5. Update the ERP based on findings. The ERP as written at the start of the exercise should not be the same ERP three weeks later. Exercises generate specific changes.

Utilities that exercise their plans regularly have measurably better outcomes when real events occur. The WaterISAC’s members-only resources and CISA’s public materials both emphasize exercising as foundational to incident response maturity.

If you want a conversation about running a cyber-focused tabletop for your utility or utility client, the HVR Cloud team works with utilities and supporting engineering firms on exactly this. Get in touch and we can walk through what an exercise program looks like.