AutoTableTop
Water/Wastewater Utility
AutoTableTop™ served as the platform for a ransomware crisis management competition (at a water & wastewater industry conference in April 2026) in which 16 participating teams (composed of working water and wastewater plant operators, maintenance technicians, laboratory staff, and collection systems professionals) responded to a simulated ransomware attack on a water treatment facility's SCADA / HMI.

Summary
ThreatGEN AutoTableTop™ version 2.0 (since updated for version 2.1) served as the platform for a ransomware crisis management competition (at a water & wastewater industry conference in April 2026) in which 16 participating teams (composed of working water and wastewater plant operators, maintenance technicians, laboratory staff, and collection systems professionals) responded to a simulated ransomware attack on a water treatment facility's SCADA / HMI systems.
Why this scenario matters? Water and wastewater utilities are classified as 1 of 16 critical infrastructure sectors by CISA. Ransomware attacks on water systems like the 2023 Aliquippa, Pennsylvania attack (a built-in AutoTableTop scenario) demonstrate that these facilities are active targets. Yet operators who run these plants daily are rarely included in cybersecurity tabletop exercises because traditional exercises require technical cybersecurity knowledge to participate. AutoTableTop™ versio 2.0 changes that: this scenario proves that water operators can engage meaningfully in crisis management exercises at the beginner level, producing outcomes that match or exceed those of cybersecurity-aware participants.
What made this deployment unique was not just the exercise itself, but the depth of analysis it enabled. Before the competition, ThreatGEN support staff ran 20 exercises from the same scenario configuration to establish a baseline, then compared those results against the 16 live participating teams - producing what we believe is the first published study comparing tool-expert performance against domain-expert performance on the same AI-driven tabletop exercise. Every exercise, all 36 of them, generated a complete After-Action Report ('ARR') automatically, demonstrating how AutoTableTop™ version 2.0's built-in analysis replaces the manual post-exercise work that makes traditional tabletop programs so resource intensive.
Team names and identifying event details have been anonymized. All scores, transcripts, and ARR findings are presented exactly as generated by AutoTableTop™ version 2.0. Expert reviewers Randy Petersen (SJRA) and Doug Short (Trinity River Authority) appear with permission.
Scenario Files for AutoTableTop™ version 2.0
Download these files to run the Water & Wastewater Industry ransomware crisis management exercise in AutoTableTop™ 2.1 (updated from version 2.0 which was used within the original exercises), along with the complete baseline study, case study, and presentation materials:
Best Practices
Most tabletop exercise platforms treat each exercise as a standalone event. ThreatGEN believes the real power of AutoTableTop™ version 2.0 is that it makes exercises repeatable, measurable, and continuously improving without manual analysis:
- Create a scenario tailored to your organization. The settings define the parameters; the AI creates the experience.
- Store it. Version 2.1 introduces organization-level scenario storage - save, share, and reuse configurations without rebuilding.
- Exercise it (repeatedly). Run the same scenario with different teams or the same team over time. Because the AI generates a unique exercise every run, there is no answer key to study.
- Let the platform analyze. Every exercise automatically generates a comprehensive AAR including crisis response metrics, improvement areas, operational learnings, safety recommendations, and per-turn scoring.
Running a scenario multiple times reveals what a single exercise cannot: whether teams repeat mistakes or improve, which weaknesses are systemic (public communication was flagged in over half our AAR's), whether compound-action inputs consistently outscore single actions (they do, 7–8 vs. 5–6), and how different teams compare on the same scenario. For this study, we ran 36 exercises from one configuration. Despite sharing the same settings, no two played out identically. Every run produced a complete AAR automatically, and the entire comparative analysis was built from those platform-generated reports.
Create once. Store it. Exercise repeatedly. Let the platform analyze. Run the same scenario with different teams for cross-team benchmarking, or with the same team over time to measure improvement. The platform does the heavy lifting — no external analysts, manual scoring rubrics, or post-exercise interviews required.
.png)
INSIGHT - Tool Expertise vs. Domain Expertise
The central finding of this case study is that tool familiarity raises the floor, but domain expertise raises the ceiling. The pre-competition study team (Group A) achieved a higher mean average score (6.5 vs. 6.1) through optimized phrasing and turn-count management. But the event's top team produced the single highest-performing trial of either group - an 8.0 average from a team of water operators who had never seen AutoTableTop™ version 2.0.
Exercise Themes
- Ransomware discovery on SCADA / HMI systems during a routine shift change
- Transition from automated to manual plant operations under crisis conditions
- DFIR engagement and cybersecurity resource mobilization without in-house cyber staff
- Regulatory compliance maintenance (permit requirements, water quality standards) during degraded operations
- Public communication strategy including social media misinformation management
- Cross-facility and multi-agency coordination (law enforcement, regulatory bodies, neighboring utilities)
- Post-incident process verification, ensuring the attacker didn't alter treatment parameters
- Cyber insurance and legal stakeholder coordination
- Lessons learned documentation and prevention strategy development
- Incident command structure activation for non-traditional (cyber) emergencies
Water & Wastewater Cybersecurity Resources
The following resources informed the scenario development and provide additional context for water/wastewater cybersecurity preparedness:
- CISA — Water and Wastewater Systems Sector: cisa.gov/water-and-wastewater-systems-sector
- EPA — Cybersecurity for Water Utilities: epa.gov/waterriskassessment/epa-cybersecurity-water-sector
- WaterISAC — Water Information Sharing and Analysis Center: waterisac.org
- AWWA — Cybersecurity Guidance (ANSI/AWWA J100): awwa.org/cybersecurity-guidance
- NACWA — "10 Practical Steps to Reduce SCADA Cybersecurity Risk" by Randy Petersen (SJRA) — referenced in the expert review section of the pre-event study report
- SCADA User Group: scadausergroup.org — co-founded by Randy Petersen; ThreatGEN® is a Tier 1 Sponsor
- MITRE ATT&CK for ICS: attack.mitre.org/techniques/ics/
Copyright © 2026 by Derezzed Inc. D/B/A ThreatGEN, all rights reserved. AutoTableTop™ is a trademark of Derezzed Inc.
Many thanks to William (Randy) Peterson of SJRA and Doug Short of TRA for all of their time involved with the competition and our case studies.
