By EJN Labs · 7 Aug 2026 · 8 min read
SEMD penetration testing is how UK water undertakers evidence that the security measures in their SEMD plans actually hold up. The Security and Emergency Measures Direction, issued by DEFRA and the Welsh Government, is mandatory for water undertakers in scope and expects testing and exercises under each company’s plan. Typical engagements run 4 to 9 days, around £4,400 to £12,600 at UK day rates of £1,100 to £1,400.
Where SEMD penetration testing fits for water companies
SEMD penetration testing sits in an unusual position. The Security and Emergency Measures Direction for water does not hand you a checklist item that says “commission a penetration test”. It places mandatory security and resilience duties on water undertakers in scope, backed by assurance: testing and exercises carried out under the company’s own plan. A penetration test is the most direct way to show the technical measures in that plan survive contact with a real attacker.
This post is for OT security leads, engineering directors, CISOs and asset managers who need to turn “we have measures” into “we have tested the measures”.
Why security assurance matters for water companies
Security assurance matters because water is critical national infrastructure, and a successful attack on treatment, distribution or wastewater systems is a public health and continuity-of-supply event, not just a data breach. Utilities worldwide have been probed and disrupted through exactly these weaknesses.
The routes are well documented: exposed remote access, weak IT to OT segmentation, and unpatched SCADA components never designed to face a hostile network.
The estates themselves make assurance harder. A typical UK undertaker runs decades-old telemetry alongside modern cloud analytics, hundreds of unmanned remote sites, third-party remote maintenance connections, and a corporate network that usually touches the operational one somewhere. Every seam is an attack path, and none is proven safe by a policy document. That is the gap testing closes.
What SEMD actually requires
SEMD requires water undertakers in scope to maintain security and emergency measures so that water and sewerage services continue to function during emergencies and deliberate attack, and to plan for how those measures are kept effective. It is mandatory, a direction rather than guidance you can politely decline.
The Security and Emergency Measures Direction is issued by DEFRA, and by the Welsh Government for undertakers wholly or mainly in Wales.
On penetration testing specifically, honesty matters: SEMD does not name a specific test type or frequency. Its position is that security and resilience measures are assured through testing and exercises carried out under the company’s plan. That makes SEMD a strong technical-testing trigger. If your plan claims IT to OT segmentation, hardened remote access to outstations, or resilient telemetry, the credible way to evidence those claims is to have someone competent attempt to break them under controlled conditions. The wider UK NIS regime for essential services pulls in the same direction: demonstrate, do not assert.
The scope logic extends beyond the undertaker to the suppliers around it: SCADA suppliers, OT integrators, remote maintenance providers and equipment vendors whose connections land inside the operational estate. If you sell into this sector, expect your customers’ SEMD and procurement teams to ask what testing sits behind your product or remote access.
What to test in a water company estate
External infrastructure and remote access
The internet-facing perimeter is where most real intrusions start: VPN concentrators, engineer remote access, vendor support gateways, exposed telemetry management interfaces. An external infrastructure penetration test attacks this surface first, because one weak remote access path can put an attacker a hop from the control network.
IT to OT segmentation
The most important claim in most SEMD plans is that a compromise of the corporate network cannot reach process control. Testing this means starting from an assumed-breach position on the IT side and attempting to pivot: through historians, jump servers, shared Active Directory, dual-homed engineering workstations and misconfigured firewall rules. If that path exists, you want it found before an adversary finds it.
SCADA, telemetry and outstations
Control system components are assessed carefully rather than aggressively: configuration and architecture review, credential and protocol weaknesses, and safe verification of what an attacker could reach. Unmanned remote sites deserve attention because they combine physical exposure with network trust back to the core.
Cloud platforms and data APIs
Modern water estates push telemetry into cloud analytics and smart metering back ends. Cloud penetration testing and API testing cover the identity, storage and interface layer that carries operational data out of, and commands back into, the estate.
How a SEMD-driven engagement runs
Testing live water infrastructure is not like testing a web app. The sequence reflects that:
- Scoping against your SEMD plan. We start from the security measures your plan claims, then agree which claims each phase of testing will evidence and which systems are observe-only.
- Safety and change control. Testing windows, named engineering contacts, and hard rules for anything that touches process control. Active exploitation stays on IT and perimeter layers; OT verification is passive or performed on reference and standby systems.
- Testing. External perimeter first, then assumed-breach internal work targeting the IT to OT boundary, then the agreed OT, telemetry, cloud and API scope.
- Reporting mapped to your plan. Findings are ranked by realistic impact on continuity of supply, and each states which security measure it undermines so the report drops straight into your SEMD assurance evidence.
- Retesting. Fixed findings are verified to close the evidence chain.
If you are preparing internally first, our penetration testing checklist covers the groundwork that makes the testing window far more productive.
What it costs and how scope drives the price
Penetration testing in the UK is priced by effort. Day rates for CREST-accredited work typically run £1,100 to £1,400, and days are set by scope: external ranges, internal segments, whether the IT to OT boundary is in play, and how much OT verification is agreed. Typical ranges for water company work:
| Engagement | Typical effort | Typical cost |
|---|---|---|
| External infrastructure and remote access | 4 to 6 days | £4,400 to £8,400 |
| Assumed-breach internal test with IT to OT boundary focus | 6 to 9 days | £6,600 to £12,600 |
| Cloud platform and telemetry API assessment | 5 to 8 days | £5,500 to £11,200 |
| Combined estate programme across a plan cycle | 10 to 15 days | £11,000 to £21,000 |
These are typical UK ranges, not quotes; an exact price follows a short scoping call. Our guide to penetration testing costs in the UK breaks down the drivers. For SEMD budget holders: spread testing across the plan cycle and prioritise the segments whose failure would actually interrupt supply.
How EJN Labs approaches testing for water companies
EJN Labs is a UK firm delivering CREST-accredited penetration testing with UK-based testers, and we hold Cyber Essentials Plus and ISO 27001 ourselves. When we assess a mixed IT and OT environment, we begin with a joint architecture walkthrough with your engineering team, agree a written rules-of-engagement document naming every system where active testing is permitted, and route anything process-critical to passive analysis or standby equipment. Our reports map each finding to the security measure it undermines, which is exactly the shape SEMD assurance evidence needs to take.
We work with undertakers and with the suppliers around them who need credible testing evidence to keep water sector contracts. If you are comparing firms, our guide to the best UK penetration testing provider sets out the questions worth asking any bidder.
Frequently Asked Questions
Does SEMD require penetration testing?
Not by name. SEMD requires security and resilience measures assured through testing and exercises under the company’s plan, but it does not prescribe a specific test type or frequency. Penetration testing is the accepted way to evidence that the technical measures in your plan work.
SEMD remains mandatory for water undertakers in scope, which is why independent testing is treated as a strong expectation rather than an optional extra.
What does SEMD-driven penetration testing cost?
Budget £4,800 to £21,000 depending on scope, at UK day rates of £1,100 to £1,400. An external infrastructure test typically runs 4 to 6 days, an assumed-breach internal test with IT to OT boundary focus 6 to 9 days, and a combined estate programme 10 to 15 days.
In money terms that is £4,400 to £8,400 for the external work, £6,600 to £12,600 for the assumed-breach internal test, and £11,000 to £21,000 for the combined programme. Scope drives the number, and an exact price follows a scoping call.
Is it safe to test live water treatment and SCADA systems?
Yes, when scoped properly. Active exploitation is confined to IT and perimeter layers under agreed windows and change control, while control system components are assessed through passive analysis, configuration review and testing on reference or standby equipment. The goal is evidence, never disruption.
Named engineering contacts and stop conditions are agreed in writing before anything starts.
Who enforces SEMD and who is in scope?
SEMD is issued by DEFRA, and by the Welsh Government for undertakers wholly or mainly in Wales, and it is mandatory for water undertakers in scope. The direction binds the undertakers themselves, but its risk picture reaches well beyond them into the supply chain.
OT integrators, SCADA suppliers, remote maintenance providers and equipment vendors are increasingly asked by undertakers to evidence testing of their own products and connections.
How often should a water company commission testing?
Align testing with your SEMD plan cycle rather than a fixed calendar habit. Most water companies test the external perimeter and remote access annually, exercise the IT to OT boundary at least once per plan cycle, and retest after significant changes.
Changes worth a retest include new telemetry platforms, new vendor remote access or major network redesigns.
Get a water sector testing quote
If you own the security measures in a SEMD plan and need testing evidence behind them, tell us about your estate through our quote form and we will come back with a scoped, day-rate priced proposal from a CREST-accredited firm with UK-based testers.




Leave a Reply