Breaking Into a Water Utility, Safely
How BayaniCyber developed and delivered a complete OT/ICS attack scenario into Red Knight’s Cyber Colosseum cyber range — and built a next-generation plant simulator for what’s next.
You can’t hand a class a real water plant
A lecture can describe a cyberattack. It can’t let a student feel one. The most durable lessons in incident response come from doing the work — pulling the logs, reconstructing the timeline, and figuring out what actually happened and in what order.
The problem is that “doing the work” requires a convincing target: the computers, the network, the control systems, and a believable attack to investigate. Operational technology (OT) and industrial control systems (ICS) — the equipment that runs water treatment, energy, and manufacturing — make it harder still, because the environments are specialized and the real-world consequences are physical. That is exactly the gap Red Knight’s Cyber Colosseum closes, and exactly where BayaniCyber contributed.
From the open internet to the water supply
Red Knight’s WaterWerks environment is a simulated small rural water utility — the kind common across Texas — running inside the Cyber Colosseum cyber range. Red Knight owns and operates it: the range infrastructure, the network and systems engineering, the day-to-day operations, and the plant simulator at its core — a SCADA server and terminal client that models the utility’s water-treatment controls. BayaniCyber’s job was to develop a new attack scenario on top of that environment — Module 2: External Compromise — and deliver it to Red Knight’s standards.
We designed the scenario around a threat every defender should understand: Log4Shell (CVE-2021-44228), the Log4j vulnerability that shook the internet in late 2021 and remains a textbook example of how one internet-facing flaw becomes a doorway. It connects well-understood enterprise attack tradecraft to critical-infrastructure targeting — the precise intersection where cyber operations meet cybersecurity.
The scenario tells a complete story. An outside attacker exploits the utility’s public-facing web portal, gains a foothold, performs reconnaissance to understand the internal network, and pivots across it toward the control systems — a segmented network with no direct path to the plant, which forces a realistic multi-stage route. The attack ends where it hurts: the water-treatment control system, with the chlorine setpoint forced far past the safe limit and a critical alarm firing at the operator’s screen. Students don’t watch this happen — they walk into the aftermath and work backward from the alarm, through control-system logs, authentication records, and web-server evidence, to reconstruct the whole chain.
To make it a finished teaching product, BayaniCyber delivered the full package: the scenario objectives, the threat logic and attack-chain design, a student guide, and an instructor guide with the setup, expected outcomes, and reset procedures needed to run it repeatedly. We integrated Module 2 with Red Knight’s earlier scenario so the range gained a richer, more varied exercise library. Then we finished it: the scenario was developed, tested in the live environment, demonstrated to Red Knight, and accepted into the WaterWerks baseline scenario library and merged into production. It is a deployable deliverable, not a prototype.
Disciplined, AI-accelerated delivery
The engagement ran on Bayani Forge, our structured framework for AI-assisted engineering. Forge sets up each project with defined roles, review gates, and after-action capture from day one, and pairs human architects with AI agents that carry deep working knowledge of the technology stack — ICS/SCADA design, automation, infrastructure-as-code, and CI/CD pipelines.
Humans stay focused on architecture and scenario-design judgment; AI agents handle the breadth — configuration, scripting, and boilerplate — under a review-until-correct loop that keeps quality high. And because Forge learns as it goes, each project leaves the framework stronger for the next, compounding our OT/ICS capability with every engagement.
A next-generation plant simulator
Alongside the scenario work, BayaniCyber invested in the road ahead by building ICS Water Sim — a more advanced, software-only water-treatment plant simulator designed to support richer, more demanding WaterWerks scenarios in the future.
The current WaterWerks environment runs on Red Knight’s existing simulator, a SCADA server and terminal client. ICS Water Sim extends that concept into a fuller platform with four components: an authoritative plant server and simulator, a terminal client, a network gateway that exposes a safe remote-facing surface, and a web-based Human-Machine Interface (HMI) dashboard that stands in for the operator’s screen. It models the parameters a real plant lives and dies by — chlorine and fluoride levels, pH, turbidity, alkalinity, tank level, pressure, and flow — with the pumps, valves, and dosing controls to match.
Status: a forward investment
ICS Water Sim is not deployed in the range today — current scenarios run on Red Knight’s simulator. It is a more capable foundation, ready to underpin the next generation of WaterWerks scenarios as the training program grows.
What we delivered
- A complete, tested, and accepted WaterWerks Module 2 scenario — attack-chain design, student guide, and instructor guide — demonstrated live to Red Knight and merged into the production range library.
- A realistic multi-stage OT/ICS scenario connecting a real-world initial-access technique to genuine control-system impact, built to develop real defender judgment.
- A reusable scenario-development approach — threat-logic design, artifact packaging, partner coordination, and after-action capture — now applied to further Cyber Colosseum work.
- A next-generation plant simulator (ICS Water Sim) built and ready to support more advanced future scenarios — an additional, forward-looking deliverable beyond the engagement itself.
- A clean teaming model: BayaniCyber develops the adversary-side scenario content; Red Knight operates and supports the range.
BayaniCyber develops its scenario content under partner authorization and controlled disclosure. Sensitive implementation details — exploit specifics, infrastructure configuration, credentials, and instructor-only materials — are deliberately kept out of public materials like this one.
Interested in the cyber range? Talk to Red Knight.
The Cyber Colosseum — the realistic, hands-on cyber range where scenarios like this come to life — is Red Knight’s platform. If you want to put your team through immersive OT/ICS and enterprise attack simulations, or you’re an institution looking to stand up hands-on cyber training, reach out to Red Knight.