Section 01
The everyday situation
A SCADA system at a water treatment plant has a vendor maintenance account. The vendor visits twice a year for firmware updates and unplanned site calls. Between visits, the account is supposed to be disabled — and on the audit, the field shows it as disabled.
In practice, the field is often wrong. The vendor calls in for a small fix in March; the account is re-enabled to handle the request; the operator gets pulled into a different fire before the cleanup step; the account stays enabled for the next eleven months. The audit field says 'disabled' because nobody re-checked it.