Successful water treatment automation is not a project to add more sensors or make a more attractive dashboard. It is the engineering of a system that moves pumps, blowers, dosing equipment and valves to a safe state when influent changes, an instrument fails or communications are lost—while still allowing operators to intervene and later reconstruct why each action occurred. This guide is written for industrial wastewater facilities in Thailand. It covers PLC–SCADA boundaries, pump, aeration and chemical dosing control, alarms, fail-safe design, OT security, RFP requirements, FAT/SAT and a practical 90-day implementation. It deliberately avoids duplicating our existing discussion of statutory limits and monitoring points; the question here is how a measured value becomes a safe physical action.
The first water treatment automation decision is the control boundary
The first deliverable should be neither a product list nor a SCADA screen. It should be a control-boundary schedule: which signals are read, which outputs may be written, what causes automatic control to revert to manual, and what must stop or continue after each failure.
| Layer | Primary role | Typical assets | What the RFP must define |
|---|---|---|---|
| Field instrumentation | Measure process condition | DO, pH, flow, level, pressure, current | Range, accuracy, calibration and failure output |
| PLC and motor control | Move equipment on a sub-second-to-second basis | Pumps, blowers, dosing skids, valves, VFDs | Interlocks, priorities and safe state |
| SCADA | Present status, history, alarms and authorised commands | HMI, historian, reports and audit trail | Write authority, alarm response and retention |
| Business and reporting | Support daily decisions and external reporting | Maintenance, laboratory, ERP and reports | System of record, approval and accountability |
Critical local control normally remains close to the process in the PLC. A SCADA server or corporate-network outage must not make basic treatment impossible. The plant should continue within a tested operating envelope or transition to a defined safe condition. A design in which a cloud connection is required to start a pump adds an operational dependency that must be justified, not hidden.
Why September 2026 matters—and why AI is not the safety authority
In a 15 September 2026 announcement for WEFTEC 2026, Rockwell Automation said it would showcase AI, visualisation, control and cybersecurity technologies for water and wastewater operations. The announcement names several products as exhibits. These are vendor claims and exhibition examples, not independent performance evidence, mandatory requirements for Thai factories, or a guarantee of local availability and support.
The useful procurement signal is therefore not “specify that product.” It is that future RFPs should evaluate analytics, deterministic control, cybersecurity and lifecycle support as distinct capabilities. An AI layer may propose an aeration or chemical-dose setpoint, but deterministic limits, rate-of-change constraints, equipment interlocks and manual recovery remain authoritative. Adoption should require a tested fallback to conventional control when the model is unavailable and change control for every model update.
Do not confuse reporting with wastewater treatment automation
Thailand’s Department of Industrial Works (DIW) has described the use of WPMS measurements and POMS for continuous wastewater monitoring and alerts. That reporting and oversight path has a different purpose from the loop that changes blower speed or stops a dosing pump. A regulatory or reporting value is not automatically suitable for closed-loop control: calibration, response time, missing-data treatment, network path and maintenance responsibility may differ.
| Point of comparison | Monitoring and reporting | Control | Risk if they are confused |
|---|---|---|---|
| Purpose | Evidence, visibility and submission | Safe physical action | Reporting latency becomes control latency |
| Time scale | Minutes or longer may be acceptable | Seconds to minutes may matter | A slow signal causes oscillation |
| Missing data | Record and investigate the gap | Use a fallback or safe state | Last value drives indefinite output |
| Authority | Reporting owner or administrator | Authorised operations and maintenance | A data user can move equipment |
| Verification | Data, timestamps and auditability | Interlocks, stop and recovery | A healthy screen masks unsafe motion |
DIW’s factory-environment law index lists notifications covering wastewater, equipment, reporting and environmental personnel and includes 2026 updates. Applicability is not uniform. It depends on factory type, size, process, licence conditions, location and discharge route. This article is not legal advice. Before design approval, check the current Thai text, the factory’s licence conditions and instructions from DIW or the competent authority, and involve qualified environmental and legal specialists where appropriate.

Dividing responsibility among PLC, SCADA and VFD
The PLC owns safe sequence and constraints
PLC logic should implement start and stop sequences, minimum run and rest times, duty/standby rotation, standby changeover and level-, pressure- or motor-based interlocks. Before starting a transfer pump, for example, it should check suction level, discharge-valve state, downstream capacity, motor fault and emergency-stop status. A low DO value must not translate directly into an unrestricted blower command; surge limits, VFD range, valve position and minimum air flow still apply.
SCADA supports operator decisions
SCADA should present the overall process, trends, alarms, command history and controlled changes to recipes or setpoints. Every writable parameter needs a range, role permission and, where risk requires it, a reason and second confirmation. A green “AUTO” label is not enough. Operators need to see which loop is automatic, which unit is in local manual, and which constraint is limiting control.
Our guide to SCADA platform selection and lifecycle cost explains tag models and acceptance evidence. For segmentation and remote-maintenance controls, also see the OT Security for Manufacturing in Thailand guide. A separate factory wastewater monitoring guide covers the monitoring side; this article concentrates on control.
A VFD does not create efficiency by itself
Energy performance depends on the control around the VFD: flow, pressure or DO target; minimum speed; cooling; resonance bands; valve coordination; and restart conditions. The failure action must also be specified. On loss of communications, does the drive hold its last frequency, move to a validated fixed value, or stop? The answer depends on the process hazard.
Pump control must consider the whole transfer path
A level-on/level-off scheme may be an acceptable starting point, but a production system commonly requires:
- two- or three-pump rotation and runtime balancing;
- automatic substitution after a duty-pump failure;
- dry-run, blockage, pressure and overcurrent detection;
- start inhibition when a downstream tank is high;
- staggered restart after power restoration; and
- retention of safety interlocks in manual mode.
Fail-safe does not always mean “stop everything.” If influent continues, stopping all transfer pumps can create an overflow hazard. Conversely, retaining the last chemical-dose output after flow falls can cause overdosing. For every asset, define the safe response to communications loss, sensor failure, PLC fault, power loss and loss of instrument air through a process-risk review.
Aeration control: never wire a DO number straight to a blower
The US EPA’s design material discusses aeration energy conservation and control using dissolved oxygen measurements. It is valuable engineering context, but its numerical examples are not a design basis for every Thai industrial effluent. Oxygen demand depends on influent load, temperature, basin volume, biomass condition, diffuser performance and treatment objective. Setpoints require local data and process responsibility.
| Control level | Inputs | Outputs | Benefit | Precondition |
|---|---|---|---|---|
| Fixed operation | Schedule and run command | Blower on/off | Simple and transparent | Confirm load margin and over-aeration risk |
| DO feedback | DO | VFD frequency or unit count | Responds to changing load | Sensor fouling, delay and minimum airflow handled |
| Cascade | DO plus header pressure/flow | Pressure target, blower and valves | Coordinates multiple basins | Surge, valve priority and loop interaction tested |
| Predictive assistance | Above plus influent/history | Candidate target | May act earlier | Fallback, model monitoring and approval defined |
The design must carry the DO instrument’s quality flag, implausible rate-of-change and calibration status. If the sensor is bad, the loop must not trust the last value indefinitely. It should move to a validated fixed or conservative regime. FAT and SAT should establish how much load remaining equipment can carry after one blower fails and what happens when minimum air flow cannot be maintained.
Chemical dosing: separate feedforward flow from quality correction
A practical candidate architecture uses flow-proportional feedforward with a bounded pH or quality correction. Aggressive feedback around a slow pH probe and mixing delay can make acid and alkali doses chase each other. Measure residence time between dosing and sensing, verify mixing, then specify deadband, maximum rate of change and absolute dose limits.
Interlocks should cover zero process flow, low chemical-tank level, leak detection, pump fault, valve position and local-manual status. A concentration or reagent change is a controlled process change—not merely a new screen setting—and should update the calculation, labels, approval and test record.
Alarm design: more alarms do not mean more safety
An alarm is a timed request for operator action, not a list of every abnormal measurement. Adding High and Low to every tag creates floods that hide the critical event. Priority should be based on consequence and available response time. The message should state the condition, first check and prohibited action, not just an instrument code.
| Example priority | Consequence | Response window | Notification | Evidence retained |
|---|---|---|---|---|
| P1 | Safety, overflow or major treatment loss | Immediate | Audible, distinct and continuously staffed path | Occurrence, acknowledgement, action and recovery |
| P2 | Reduced capacity or loss of standby | Short | SCADA and duty person | Cause, owner and temporary measure |
| P3 | Maintenance need or degradation | Within shift | List and work-management link | Work order, due date and completion |
| Event | Command or mode change | No operator response required | History only | User, before/after value and reason |
Shelving, suppression and disablement require an owner, reason and expiry. FAT should verify not only that an alarm appears, but also duplicate suppression, acknowledgement, recovery, time ordering and behaviour after power restoration.

Make water-treatment OT security a functional requirement
NIST IR 8183 Rev. 2, the Cybersecurity Framework 2.0 Manufacturing Profile, was published on 29 September 2025 as an Initial Public Draft. Its public-comment period is closed, but it is not a final publication at the time of writing. Use it only as voluntary, risk-based input to a manufacturing cybersecurity assessment—not as a legal duty, certification criterion or final normative requirement. ISA/IEC 62443 addresses industrial automation and control systems across asset-owner, service-provider, system and component lifecycles. Neither is a one-product compliance list. They help an owner translate assets, risk and accountability into design, procurement and operations.
CISA, EPA and FBI’s practical actions for water systems include reducing public-internet exposure, maintaining asset inventories, changing default passwords, assessing risk, backing up and restoring systems, planning incident response and training personnel. They are not automatically Thai legal requirements, but they are useful RFP checks.
A minimum zone-and-communications model
- Identify field devices, PLCs and VFDs as a control zone.
- Separate SCADA and historian services into a server zone.
- Put a controlled boundary between OT and business/cloud services.
- Permit only required source, destination, port and direction.
- Require named accounts, MFA, approval, time limits and recording for vendor remote access.
Security controls themselves must be tested for operational failure. What happens to local control when a firewall fails, time synchronisation is lost, the authentication service is unavailable or the log destination is full? Do not run unplanned active scans or office-IT patch routines against live equipment; use a test environment and approved outage window.
RFP deliverables that make bids comparable
“PLC package” and “SCADA package” are not comparable line items. Specify deliverables and acceptance evidence.
| Deliverable | Minimum content | FAT evidence | SAT evidence |
|---|---|---|---|
| Control narrative and cause/effect | Modes, start/stop, fault and recovery | Simulation record | Physical action and operator confirmation |
| I/O and tag list | Unit, range, quality, owner and write permission | Point-by-point check | Loop-check record |
| Alarm register | Priority, response and suppression | Trigger, acknowledge and clear | Validation in shift operation |
| Network diagram and flow table | Zones, paths, ports and remote access | Allow/deny tests | Site configuration match |
| Backup and restore procedure | PLC, HMI, SCADA, VFD and setpoints | Restore into clean environment | Restore on designated equipment |
| Maintenance handover | Source, licences, spares and training | Receipt register | Owner performs an approved change |
If a brand is named because it must integrate with an installed standard, explain the reason and equivalent criteria. Do not turn a WEFTEC exhibit into a mandatory requirement. Write performance requirements for I/O, cycle time, redundancy, environment, maintainability and cybersecurity. Evaluate spare-part lead time in Thailand, support languages, licence renewal and source-code handover.
Ten questions for bidders
- How do you distinguish a process upset from equipment failure?
- What is the fallback when an instrument quality flag is bad?
- Which controls continue after a SCADA outage?
- Which interlocks remain in manual mode?
- Who can restore the system, from what backup, within what demonstrated time?
- Who approves remote support and who closes the session?
- Who owns PLC, HMI and SCADA source and credentials?
- Which failures can the FAT simulator reproduce?
- How will SAT cover conditions that cannot safely be produced with real effluent?
- Where are post-handover changes recorded?
Twelve checks before a brownfield modification
In a live water-treatment plant, the as-built drawing and the installed system may not match. A spare terminal shown on paper may already serve another function. Instruments with the same name may use different signal, power, isolation or fault conventions. The survey must therefore establish evidence for design, FAT, SAT, cutover and recovery—not merely confirm that an asset exists.
| Check | Site fact to establish | RFP/design consequence | FAT/SAT evidence |
|---|---|---|---|
| 1. Spare I/O | Actual use of racks, cards, channels, terminals and cable routes | State required cards, panel work and actual points | I/O reconciliation, terminal photo and loop check |
| 2. Signal type | 4–20 mA, contact, pulse, communications and NO/NC convention | Specify input, isolation, scaling and line-fault detection | Inject low/mid/high and broken-line states |
| 3. Calibration and quality | History, drift, noise, grounding and response delay | Define quality flag, calibration due and filter ownership | Reference comparison, trend and bad-quality test |
| 4. Control power and UPS | Circuits, hold-up, load and battery condition | Define which PLC, network and instruments remain powered | Power-loss/recovery timeline and restart result |
| 5. MCC and VFD | Circuit, protection, local panel, communications and parameters | Define start/stop, speed reference and fault-reset boundary | Rotation, frequency range and fault/reset tests |
| 6. Local/Remote and manual | Selectors, buttons, keys and current procedure | Define mode priority and interlocks retained in each mode | Cause/effect and command record for every mode |
| 7. Safe state on control loss | Continued inflow, tank margin and equipment response | Define safe state separately for PLC, SCADA and network loss | Fault injection and approved recovery |
| 8. Time synchronisation | Time source and drift for PLC, SCADA, analyser and network | Define NTP, timezone and loss-of-time-source action | Cross-system event comparison and resync record |
| 9. Historian and retention | Tags, period, compression, capacity, retention and export | Set periods from required evidence | Gap, resend, capacity, search and export tests |
| 10. Backup and restore | Source, version, password, licence and replacement hardware | Specify scope, owner, frequency, storage and restore environment | Restore from a clean copy and compare settings |
| 11. Maintenance access | Vendor VPN, modem, shared ID, service PC and persistent paths | Require named ID, MFA, approval, expiry, record and kill switch | Allow/deny, expired access and session log |
| 12. Cutover and rollback | Available outage, temporary operation, decision and contacts | Define hold points, go/no-go and preservation of old system | Rehearsal, rollback demonstration and sign-off |
Verify spare I/O at the terminal, not on the drawing
An allowance such as “20% spare” is not enough to make a decision. Allocate every added DO, pH, flow, level, motor-status and command signal, and verify the card type, channel, terminal, cable route, panel space, heat load and power capacity against the installed system. If the existing PLC cannot be expanded, decide whether to add remote I/O, install a separate PLC, or link another controller to the existing control system. That choice changes the failure boundary and maintenance accountability, so it cannot be made on purchase price alone.
For a 4–20 mA signal, confirm the lower and upper scaling limits, whether an open circuit drives the value low, whether a bad value is held, and whether a signal isolator or splitter exists. For a digital point, confirm Normally Open/Closed convention, wet or dry contact, voltage and pulse width. For a communicating device, the tag list must include not only the protocol name but the register to read or write, update period, quality state, communications timeout and behaviour after reconnection.
Make the control-power and MCC/VFD boundary explicit
A UPS does not establish continuity if it keeps only the PLC alive while the network switch or instrument power fails. Conversely, if the PLC and SCADA remain available while the MCC main circuit is de-energised, a command may remain visible without any physical response. Reconcile the single-line diagram with installed wiring, then define which components survive each power loss, which restart automatically after restoration, and which require an operator confirmation.
Before overwriting an existing VFD, upload and preserve its parameters, motor nameplate data, minimum and maximum frequency, acceleration and deceleration, prohibited frequencies and fault history. Even when the new PLC supplies the speed reference, do not inadvertently defeat local emergency operation, hardwired interlocks or machine protection. FAT should verify the logic with simulated signals; SAT should verify it against actual motor rotation, current, vibration and valve state.
Define Local/Remote priority in operator language
In an installed plant, Local at the panel, Hand at the field station, PLC Auto and SCADA Remote may coexist under inconsistent names. Harmonising the labels is not enough: it remains unsafe if nobody knows which mode has priority, who may change it, or whether the output bumps during transfer. For every mode, document the permitted commands, interlocks that remain active, alarm destination and return condition, and connect them to procedures for normal operation, cleaning, calibration, maintenance and emergency response.
If manual operation is the fallback, demonstrate what the field operator will observe, in what order actions are taken, and how far equipment may be operated after SCADA loss. Hand over local indications, a concise procedure, contact path and decision criteria. Do not make the memory of one experienced operator the recovery system.
Time, history and backup underpin acceptance evidence
If the PLC, SCADA, analyser and network devices disagree on time, the sequence among low DO, blower command, motor fault and operator action cannot be reconstructed. Define the NTP source, timezone, daylight-saving treatment and behaviour when the source is lost, then compare timestamps for the same event across systems during SAT.
“Save everything” is not a historian requirement. Select tags, collection period, compression and retention from the evidence needed for causal analysis and reporting. A fast control variable and a daily reporting value do not need the same period. Also verify what happens when storage reaches capacity: whether old data is overwritten, acquisition stops, or an alarm is raised.
A backup is a recovery capability, not the existence of a file. Align the versions of PLC, HMI, SCADA, VFD, network and analyser configurations, then restore them from a clean copy with the necessary licence, password, firmware and engineering-tool version. After restoration, compare I/O, tags, alarms, permissions, communications and time settings and retain the comparison as acceptance evidence.
Every cutover plan needs rollback criteria
Cutover is not the calendar time at which the new system is switched on. It is one continuous sequence covering backup of the old system, temporary operating arrangements, equipment isolation, I/O transfer order, loop checks, initial filling or real-load validation, go/no-go decision and operating approval. At every hold point, define who reviews which evidence and who has authority to permit continuation.
“Roll back if there is a problem” is not a usable criterion. Define project-specific, observable triggers such as inability to maintain safe treatment, failure to establish critical-signal quality, alarm load beyond operator capacity, or a restore procedure that does not work. Approve removal of the old panel, program and wiring only after stable operation and completion of restore testing. This is how RFP accountability, FAT simulation and SAT verification move a brownfield modification from merely “connected” to genuinely ready for operational handover.
FAT and SAT serve different purposes
FAT is the safe place to expose logic, screen, alarm and fault-sequence defects before shipment. Simulate instrument failure, loss of communications, pump fault, downstream high level and power restoration. SAT verifies field wiring, rotation, valve position, actual communications, operating procedure and interfaces with safety equipment. Passing FAT neither eliminates SAT nor makes SAT a mechanical repeat.
| Test | Normal case | Fault case | Acceptance evidence |
|---|---|---|---|
| Instrument loop | Sensor to display and history | Open circuit, out of range, bad quality | Calibration value reconciled to screen |
| Pump | Start, stop and rotation | Overcurrent, dry run and standby changeover | Time-series log and witnessed action |
| Aeration | DO tracking and staging | Bad DO, blower fault and network loss | Target/output/response trend |
| Dosing | Flow ratio and maximum limit | Zero flow, low level and sensor delay | Dose stop and alarm history |
| Security | Approved flow and login | Blocked flow and expired user | Firewall, identity and audit logs |
| Recovery | Backup creation | Simulated PLC/server replacement | Post-restore comparison |
An acceptance case must include input, expected action, tolerance, evidence and approver. Where variable real wastewater cannot be represented during FAT, record the simulation boundary and close the gap through a defined performance-verification period after SAT.
A 90-day plan: 15 + 15 + 30 + 30 = 90 days
Ninety days is suitable for one representative train or basin, not an uncontrolled plant-wide conversion. The arithmetic is explicit: Days 1–15 are 15 days; 16–30 are 15; 31–60 are 30; and 61–90 are 30, totalling 90.
| Period | Principal work | Gate deliverable | Stop or redesign condition |
|---|---|---|---|
| Days 1–15 | Survey, P&ID, I/O, operator interviews and applicability check | Boundary, baseline and risk register | Asset responsibility or permit basis unknown |
| Days 16–30 | Basic design, cause/effect, alarms, zones and test plan | Approved design and RFP delta | Safe state or manual operation undefined |
| Days 31–60 | Panel/software build, simulation, FAT and training preparation | FAT pass, restore test and SAT plan | Major fault sequence untested |
| Days 61–90 | Installation, loop check, SAT, staged operation and handover | SAT, operating approval and source/procedures | Quality deterioration, alarm flood or failed recovery |
Take a baseline from Day 1. Candidate metrics include blower and pump energy, chemical use, alarm count, manual interventions, equipment downtime and process variation in DO and pH. These are examples, not universal guarantees. Normalise for production, flow, temperature and load where possible, and disclose when pre/post conditions differ.
Do not jump directly to full automatic operation on Day 61. Progress from monitoring, to recommendations, to operator-approved moves, to bounded automatic control. Define the rollback trigger and accountable person at every step.

Build the business case from the loss structure, not a promised percentage
Aeration may be a major electricity load, but no supplier should promise one universal saving percentage before measuring the existing plant. EPA material provides useful efficiency concepts, while the outcome still depends on present control, load, blower curves, diffuser condition and operations.
An example calculation structure is:
Annual benefit = energy reduction + chemical reduction + avoided outage loss + avoided emergency maintenance − annual support and licence cost.
Use metered baselines and plant-specific outage cost rather than a supplier’s generic assumption. Environmental harm and non-compliance should not be reduced to an average expected-value calculation; treat them as constraints that the design must prevent.
Common failure patterns
Buying screens before behaviour
Approve the I/O list, cause/effect, modes and fault responses before screen design.
Giving AI final authority
Start with recommendations. Retain independent limits, rate constraints and interlocks, and record training-data period, gaps, seasonality and model version.
Allowing manual mode to bypass everything
Maintenance may need controlled overrides, but safety-critical interlocks should remain. Every override needs authority, expiry, reason, visibility and an audit log.
Keeping backups without proving restore
Test licences, keys and compatible replacement hardware. Include PLC, HMI, SCADA, VFD parameters, alarm registers and network devices.
Treating DIW reporting as the plant control loop
Separate reporting and control paths. Define conversion, timing, gaps, retransmission and ownership. DIW applicability still requires a factory-specific check.
FAQ
Where should wastewater treatment automation start?
Choose one train where loss is material, inputs and results are measurable, and rollback is possible. Pump rotation, DO-based aeration or flow-proportional dosing may be candidates. The correct scope is one that can complete FAT, SAT and operational handover within the pilot.
Can a wastewater PLC run when SCADA is down?
Important local control and interlocks should normally remain in the PLC so the process can continue within a tested envelope or stop safely. Test actual dependencies—including network, licence and time services—during FAT and SAT.
What energy saving should aeration control guarantee?
There is no universal percentage. Establish a baseline normalised for flow or load and measure the pilot. A fixed-speed, over-aerated basin has a different opportunity from a well-tuned existing DO loop.
Does a water treatment control system require AI?
No. Measurement quality, deterministic control, alarms, recovery and asset inventory come first. AI can be evaluated as an advisory layer with a tested fallback.
What is the first water-treatment OT security action?
Inventory assets and paths, reduce internet exposure, remove default passwords, test restoration and control remote support. Use ISA/IEC 62443 and the NIST profile to structure ownership and lifecycle controls.
Does DIW POMS/WPMS apply equally to every factory?
No. Confirm factory category, size, licence and discharge conditions against current DIW material and the Thai source text before each decision.
Summary
Water treatment automation converts measurements into safe, explainable physical action. Keep local control and interlocks in the PLC, use SCADA for operator awareness, history and governed commands, and engineer pumps, aeration and dosing around process delays and equipment constraints. Define RFP evidence, expose faults in FAT, verify the installed system in SAT, and complete a bounded pilot and handover in 90 days. AI and named products may be options; they are not substitutes for fail-safe behaviour, recovery or OT security.
If you are defining a Thai factory pilot, PLC/SCADA boundary, RFP or FAT/SAT evidence, you can contact TOMAS TECH during the planning stage. We can start from the installed equipment and control risk before selecting a product.
References
- Rockwell Automation, “Rockwell Automation Showcases AI-Driven Water Treatment Solutions at WEFTEC 2026” (15 September 2026): https://www.rockwellautomation.com/en-il/company/news/press-releases/rockwell-automation-showcases-ai-driven-water-treatment-solutions-at-weftec-2026.html
- Thailand DIW, factory-environment law index: https://www.diw.go.th/webdiw/law-fac-env/
- DIW, POMS/WPMS announcement: https://www.diw.go.th/webdiw/pr68-687/
- DIW, continuous WPMS/POMS monitoring announcement: https://www.diw.go.th/webdiw/pr64-215-2/
- NIST IR 8183 Rev. 2, Cybersecurity Framework 2.0 Manufacturing Profile (Initial Public Draft): https://csrc.nist.gov/pubs/ir/8183/r2/ipd
- ISA, ISA/IEC 62443 Series of Standards: https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards
- CISA, EPA and FBI, Top Cyber Actions for Securing Water Systems: https://www.cisa.gov/news-events/alerts/2024/02/21/cisa-epa-and-fbi-release-top-cyber-actions-securing-water-systems
- US EPA, Evaluation of Energy Conservation Measures for Wastewater Treatment Facilities (EPA 832-R-10-005, 2010), Chapter 4 “Design and Control of Aeration Systems”: https://www.epa.gov/sites/default/files/2016-01/documents/p1008sbm.pdf
- US EPA, Energy Efficiency for Water Utilities: https://www.epa.gov/sustainable-water-infrastructure/energy-efficiency-water-utilities