The Drinking Water Department of a key municipality in Québec engaged CIMA+ to carry out a cybersecurity risk assessment for its water treatment plant and several related critical infrastructure assets. This initiative is part of a three-year framework agreement for advanced information technology (IT) and operational technology (OT) services aimed at modernizing the city’s water infrastructure. The primary objective is to assess cybersecurity risks, along with general risks of operational downtime, using the IEC 62443-3 standard.
CIMA+ assembled a multidisciplinary team, including a cybersecurity solutions architect and OT specialists, to lead the assessment in close collaboration with the city’s cybersecurity teams and water department staff. This collaborative approach facilitates knowledge transfer and trains city employees in applying the IEC 62443-3-2 methodology, which involves advanced study of the IEC 62332 series, comprehensive risk analysis, and conceptualizing infrastructure into defined security zones and conduits.
Key challenges include the need for specialized expertise in drinking water infrastructure and the application of a methodology that demands a deep understanding of operational technology environments. Deliverables for the project include a detailed risk assessment report, a segment and conduit architecture aligned with IEC 62443-3, and a final presentation. The project is currently in progress, advancing toward enhanced cybersecurity resilience for critical municipal water assets of this major municipality.