This methodology resonates strongly with me after having dedicated a portion of calendar year 2024 and almost all of 2025 while utilizing the AWWA J100-21 standard to construct a brand new RRA (and ERP) that works for my utility.

Representative
from Water Utility
Serving Population
of 500,000

Outstanding security analysis tool! I look forward to working with your team and exploring ways we can collaborate further with your guidance and support.

National Consultant
and Utility Supplier

A very poignant example of why more work needs to be done, and physical security needs to be elevated to a level that is at least comparable to the attention that cyber has received.

Inner-City Water Utility
Half-Million Population

UtilitySTAT

Measure What You Know

Stop Guessing at
Threat Likelihood.

Traditional risk assessment methods frequently ask, “How likely is this threat to occur?”
But how accurately can anyone know that?

The Department of Homeland Security Lexicon states that determining likelihood for malevolent threats is generally not possible. There is simply not enough data in the dataset to establish probability.

The EPA Baseline Information on Malevolent Acts V3.0 states that “No comprehensive database exists to provide an authoritative basis to estimate the probability of a water system being victimized by a malevolent act.” Yet it describes default threat-likelihood values so fractionally insignificant that meaningful investment is not prioritized for security improvements.

We can do better.

Subjective risk assessments ask what is unmeasurable

Which adversary threat types should I prepare for?

What are the motives and objectives of the potential adversary?

What tactics will the adversary use to compromise my facility?

What is the attractiveness value of my facility as a target?

Is there available intel that suggests imminent threat?

Attempting to predict adversarial threat pairings is a failed method for security improvement.

Objective security answers what is measurable.

Where are the gaps in my existing security architecture?

Hardening remains consistent whether malevolent or accidental.

Attack vectors and path are mapped against the security architecture.

Does your security have measurable resilience to match the consequence?

Does budget, time, and resource suddenly appear based on imminent threat?

Measure the probability of success of a threat against a known security architecture.

Sun Tsu, 5th Century BC

Sun Tzu bust
  • The art of war teaches us not to rely on the likelihood of the enemy’s not coming,
  • but on our own readiness to receive him;
  • not on the chance of his not attacking, but rather on the fact that we have
  • made our position unassailable.

Categories are
not measurements.

  • Low. Medium. High.
  • Small. Medium. Large.
  • Slow. Variable. Fast.
  • Possible. Probable. Certain.
  • Limited. Strong. Very Strong.

Cumulative Defense Strategy: sequential defense layers 2+3+4+5+6+7 = 27 countermeasures, the Foster-Wallace formula, and a defense dome over a water facility

Security Gaps Are Revealed ThroughMeasurement

Measure the probability of success of a threat against a known security architecture.

Because when it comes to categories, how much better is “High” than “Medium”?  Which mitigation caused the improvement? How much resilience was gained?

Ask:

How much better is “High” than “Medium”?

Which mitigation caused the improvement?

How much resilience was actually gained?

UtilitySTAT Security Assessment
From estimated risk to measurable resilience.

How does UtilitySTAT compare to other assessment tools?

CDS, J100, and VSAT aren’t exactly equivalent methodologies. CDS is an assessment methodology that measures the probability of success of a threat against known security defenses. The J100 is an AWWA all hazards risk assessment standard based on DBT and VSAT is an EPA all hazards vulnerability self-assessment tool. The AWWA describes J100-21 as its current Risk and Resilience Management of Water and Wastewater Systems standard, aimed at helping utilities make sound resource-allocation decisions.

UtilitySTAT
ASCE 78-24
AWWA
J100-21
EPA
VSAT
Adversary-Agnostic Security Assessment Core methodology Speculative Probabilty/Likelihood Scenarios Speculative Threat Likelihood Categories
Degree of Difficulty to Compromise Quantitatively & Qualitatively Evaluated Not a core measurement Not a core measurement
Cumulative Defensive Difficulty Measured across layers No equivalent metric No equivalent metric
Measures Improvement as Threat Advances Toward Asset Yes No cumulative measurement No cumulative measurement
Identifies Weak or Non-Contributing Security Layers Directly exposed by CDS analysis Indirect through vulnerability analysis Indirect through vulnerability analysis
Requires Malevolent Threat Probability to Measure Security Does not rely on Probability Estimations Attempts to Measure Likelihood Without Sufficient Data User Default/User-Adjusted Ranges
Countermeasure-Specific Difficulty Values Mathematically and Objective Scored Vulnerability based on Estimated Likelihood Vulnerability based on Estimated Likelihood
Ordered Defense Layers Core methodology Not a core requirement Not a core requirement
Physical-Security Countermeasure Design Guidance Primary Purpose for Risk Mitigation Only within low measurements of estimated likelihood Only within low measurements of estimated likelihood
Security Architecture / Retrofit Application Explicitly addressed Only within low measurements of estimated likelihood Only within low measurements of estimated likelihood
Physical Security Measurement Basis Measurement of Difficulty based on Known Countermeasures Traditional based on Threat Likelihood Estimated Values Traditional based on Threat Likelihood Estimated Values

Satisfy AWIA Physical Security
Risk & Resilience Requirements
Three Assessment Options

The EPA states that the Safe Drinking Water Act (SDWA) §1433 identifies what the Risk & Resilience Assessment (RRA) must address but does not require a particular assessment methodology. EPA recommends a variety of methodologies including the ASCE 78-24 rooted in Cumulative Defense Strategy, to which UtilitySTAT is aligned.

UtilitySTAT™

UtilitySTAT™ – Essentials
Self-Guided with the UtilitySTAT Tool

Utility personnel complete the assessment directly within UtilitySTAT.

UtilitySTAT™ – Guided
Self-Guided + Professional Services

Your team owns the assessment with expert assistance where needed.

UtilitySTAT™ – Expert
Consultant Platform

Qualified consultants use UtilitySTAT to conduct, document, and deliver assessments for their clients.

Security
Requirements
are Dynamic

Your
Assessment
Should Be Too

Update the known inputs and see how the security posture changes.

Improve your security posture from an AWIA compliance product every five years into a security-management platform with real time value.

Get a Quote

Get a Quote