Water Security: Mission Domain Intelligence Guide
You can watch a diplomatic crisis fill up. Reservoir altimetry showed the impoundment rate months before the downstream government said a word about it.
You can watch a diplomatic crisis fill up. Reservoir altimetry showed the impoundment rate months before the downstream government said a word about it.
What Water Security covers as a mission domain
Water security intelligence covers the availability, allocation and protection of freshwater, and the conflict and stability consequences when any of the three fail. Practitioners monitor surface storage and river flow, groundwater depletion, transboundary basin politics, irrigation and municipal supply reliability, and the physical and cyber security of dams, canals, pumping stations and treatment works. The domain sits at the junction of hydrology and politics: the measurable part is storage and flow, but the decisive part is who controls release timing, who is metered, and which agreements are being quietly reinterpreted.
Sub-areas include transboundary basin monitoring, urban water stress and tanker-market analysis, agricultural abstraction and aquifer decline, and water infrastructure protection covering both physical attack and control system intrusion. Actors include upstream states using impoundment as leverage, utilities and irrigation authorities whose allocation decisions drive local grievance, armed groups that seize or damage water infrastructure to control populations, and criminal networks that profit from tanker supply when reticulated systems fail.
Why it matters
Water failure escalates faster than almost any other resource shock because there is no substitute and very little consumer storage. Urban supply interruptions produce protest within days, and irrigation shortfalls translate into rural displacement within one season. Weaponisation of water infrastructure is recurrent in modern conflict, and control system intrusions at small utilities have already been documented in several countries. Analysts serve utilities, humanitarian responders, agricultural risk teams and mediators who need to know when leverage is being applied.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Reservoir surface area and satellite altimetry heights diverging from the seasonal norm, indicating unusual impoundment or unusual drawdown behind a dam.
- GRACE-FO terrestrial water storage anomalies showing sustained multi-year decline, the strongest open indicator of aquifer overdraft.
- Downstream river gauge readings falling while upstream precipitation stays normal, which points to retention rather than drought.
- Tanker water prices in a city rising sharply while piped supply hours shorten, a reliable precursor to service protest.
- Irrigation abandonment visible as fallowed command-area pixels inside a scheme that was fully cropped in prior seasons.
- Salinity intrusion indicators in coastal aquifers and delta agriculture, including crop switching away from salt-intolerant staples.
- Unplanned treatment plant outages or boil-water notices clustering in one utility, sometimes an early sign of operational technology compromise.
- Diplomatic language shifting from technical committee statements to sovereignty framing over dam filling schedules or allocation shares.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- NASA GRACE-FO — Monthly terrestrial water storage change, the standard open proxy for regional groundwater depletion trends.
- USDA G-REALM and Hydroweb — Satellite radar altimetry of reservoir and lake heights for large water bodies worldwide, updated regularly.
- FAO AQUASTAT — National water withdrawal, irrigation area, dependency ratio and infrastructure statistics for comparative baselines.
- Copernicus Sentinel-2 and Global Land Service — Surface water extent, water bodies product and vegetation indices for command-area and reservoir monitoring.
- Global Reservoir and Dam Database (GRanD) and GDW — Georeferenced dam locations, capacities, purposes and commissioning dates for infrastructure inventory.
- WHO/UNICEF Joint Monitoring Programme — Household access to drinking water and sanitation by country and settlement type over time.
- UNECE Water Convention and treaty databases — Text and status of transboundary agreements, notification obligations and dispute mechanisms.
- Pacific Institute Water Conflict Chronology — Curated historical record of water-related violence, useful for base rates and precedent.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Delimit the basin or service area — Define the hydrological unit and the administrative units that actually make allocation decisions, since they rarely share the same boundaries.
- Build a storage and flow baseline — Assemble multi-year altimetry, gauge and storage records, and reconcile satellite estimates against any available ground measurement.
- Separate drought from decision — Compare upstream precipitation and snowpack against downstream flow to determine whether a shortfall is meteorological or operational.
- Map the infrastructure and its control — Inventory dams, canals, pumping and treatment assets, their operators, redundancy and exposure to physical or network compromise.
- Read the political layer — Track treaty status, notification compliance, ministerial statements and technical committee meeting outcomes for shifts in negotiating posture.
- Model the consumption impact — Translate the shortfall into irrigated area lost, supply hours reduced and population affected, which is the form decision makers can use.
- Set and monitor triggers — Define storage levels and flow rates that mark escalation states, and monitor them continuously rather than reporting on annual cycles.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Environmental Intelligence — Environmental Conditions, Damage, and Crime
- Meteorological Intelligence — Weather, Ocean, and Atmospheric Conditions
- Geospatial Intelligence — Intelligence Derived from Place
- Imagery Intelligence — Interpretation of Visual Imagery
- Risk Intelligence — Structured Assessment of Threat and Consequence
- Economic Intelligence — Economic Conditions, Trade, and Market Signals
Worked in these data points
- Facility / Site — A physical installation — plant, base, port, data centre — with a fixed footprint and function.
- Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
- Satellite Imagery — Overhead imagery of an area of interest, used for change detection and site analysis.
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
- GPS Coordinates — Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
Adjacent mission domains
- Environmental Crime
- Climate Security
- Food & Agricultural Security
- Critical Infrastructure
- Conflict & Humanitarian
Inside the platform: where Water Security lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
domain.php?d=water— Water Security dashboardtheater.php?d=water— Threat theater viewsearch.php— Advanced search, filter and pivotcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Delimit the basin or service area is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Separate drought from decision turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Set and monitor triggers feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Water Security
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence analysts treat water as both a dependency and a terrain variable. Installations and deployed forces need assured supply, so analysis covers source reliability, treatment capacity, single points of failure in pumping and distribution, and the resilience of host nation utilities. Operationally, dam release timing changes river crossing feasibility, wetland extent alters trafficability, and control of a treatment plant or canal gives an armed actor leverage over a civilian population. Products feed force protection, engineering planning and intelligence preparation of the environment. The constraint is legal: water installations serving civilians attract specific protection under international humanitarian law, and analysis should support that protection rather than anything else.
🕵 National intelligence
National intelligence interest centres on transboundary leverage and state capacity. Requirements typically cover impoundment behaviour at new upstream dams, treaty compliance and quiet reinterpretation, groundwater depletion that will force agricultural or migration change within a decade, and the stability consequences of urban supply failure. Fusion pairs open hydrology, which is unusually good and satellite-derived, with diplomatic and economic reporting that is not. Because the physical layer is open, maintain a shareable tearline for foreign ministries and basin organisations. Judgments should separate what the data shows about storage and flow from the political inference about intent, which is far weaker.
👮 Law enforcement
Law enforcement engagement covers illegal abstraction and well drilling, water theft from irrigation systems and municipal networks, contamination and pollution offences, fraud in water infrastructure procurement, and cyber intrusion into utility control systems. Evidence typically combines metering and telemetry records, imagery showing unpermitted irrigation or new wells, and permit registers, all requiring proper acquisition provenance. Lawful process is needed for utility records, financial material and any communications. Charging decisions often rest on regulatory offences, fraud and criminal damage rather than on water law itself, so investigators should map the offence set early with the regulator.
🔍 Private investigation and corporate security
Corporate security, insurers and due diligence teams assess water as an operational dependency and a licence-to-operate risk. Work covers basin-level supply reliability for a facility, competing abstraction by other users, the political risk of allocation decisions, and reputational exposure where an operation is perceived to take water from a stressed community. Private actors may not access utility control systems, may not gather intelligence on activists or community leaders, and should treat community grievance as a legitimate risk factor rather than a security target. Findings feed continuity planning, disclosure and community engagement, not enforcement.
📰 Journalism and OSINT media
Journalists have strong open evidence here: reservoir altimetry, satellite gravimetry and optical imagery let you show impoundment and depletion independently of official statements. Verification requires using more than one storage product, understanding their error characteristics, and separating drought from deliberate retention, which is the single most common reporting error in this domain. Sources inside utilities and ministries face dismissal or prosecution in many jurisdictions, so protect them accordingly. Give governments and utilities a right of reply and be careful with detail about infrastructure weaknesses, which can invite attack in conflict-affected basins.
🌍 NGO, humanitarian and human rights
Humanitarian and human rights organisations work water through service delivery, protection and accountability. Analysis supports pre-positioning of trucking and treatment capacity, identification of communities about to lose supply, and documentation of attacks on water infrastructure or deliberate deprivation, which can constitute serious violations. Practice should be community centred, with local water committees consulted rather than surveyed at. Do-no-harm applies to publishing well and borehole locations in contested areas. Documentation for accountability should follow evidentiary standards suitable for treaty bodies and courts. Duty of care includes disease exposure for staff operating in areas with degraded water and sanitation.
🎓 University and research
Research strength here comes from the depth of open hydrological and remote sensing data, and the main methodological risk is over-reading coarse products. Gravimetry resolves large basins, not districts; altimetry covers a subset of reservoirs; and reanalysis precipitation carries substantial regional bias. State resolution and error explicitly, validate against gauge data where it exists, and document how you separated climate variability from management decisions. Ethics review applies to fieldwork in water-scarce communities. Publish code, cite dataset versions since reprocessing changes long-term trends, and honour restrictions on national hydrological data that is often treated as security sensitive.
Playbook: working Water Security end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Define the basin and the question
Fix the hydrological unit and the decision it serves: upstream impoundment behaviour, urban supply reliability, aquifer trajectory or infrastructure protection. Basins cross borders and administrative units, so state which sub-basins, reaches and abstraction points are in scope and which country holds each gauge. A good output is a basin schematic with storage nodes, diversion points, major users and the data owner for each. Stop when every significant storage and abstraction point on the reach is named, even where no data exists for it.
Phase 2 — Build the storage and flow baseline
Assemble multi-year reservoir levels from altimetry, gauge records where published, snowpack and precipitation series, and terrestrial water storage anomaly. Establish the seasonal shape and the historical range for each week of the year, because a level that looks alarming in absolute terms may be normal for the season. Note the error bars for each product. A good output is a per-reservoir baseline with percentile framing. Stop when today's storage can be expressed as a percentile of the historical record for that date.
Phase 3 — Separate drought from management
Test whether observed downstream shortfall is explained by upstream precipitation and snowmelt deficits, or by retention decisions. Compare upstream inflow proxies against downstream flow and reservoir level change, and look for filling that continues while inflows fall. This single distinction drives the political interpretation of the whole assessment, and getting it wrong is the classic failure in this domain. A good output is an attribution statement with the water balance shown. Stop when the balance either closes or the residual is quantified and explained.
Phase 4 — Map demand and allocation
Establish who uses the water: irrigated area by crop and season, municipal supply populations, industrial and thermal power abstraction, and environmental flow requirements. Identify who is metered, who is not, and how allocation decisions are made and by whom. Unmetered agricultural abstraction is usually the largest and least visible term. A good output is a demand picture with an explicit statement of which components are measured and which are estimated. Stop when the largest uncertainty in the balance is identified by name.
Phase 5 — Assess groundwater trajectory
Use gravimetry, well level records where available and irrigated area expansion to establish whether the aquifer is being depleted and at what rate. Convert the trend into a timeframe a decision maker understands: years of pumping at current rates before specific wells or well fields fail. Note that gravimetry is coarse and cannot resolve local wells, so state the spatial limit clearly. A good output is a depletion trajectory with a stated confidence and resolution. Stop when the trajectory has a date attached to a consequence.
Phase 6 — Analyse the treaty and institutional layer
Read the applicable agreements, allocation formulas, notification requirements and dispute mechanisms, and establish which are being observed, which are contested and which have quietly lapsed. Identify the basin organisation, its actual authority and its data-sharing practice. Institutional weakness, not scarcity, is the usual proximate cause of escalation. A good output is a compliance assessment naming specific obligations and their observed status. Stop when each obligation is marked observed, contested or unobservable with the evidence given.
Phase 7 — Assess infrastructure exposure defensively
Review dams, canals, pumping stations and treatment works for physical and control system exposure at a protective level: dependency on single feeds, remote access governance for supervisory systems, chlorine and chemical handling, and restoration time after loss. The purpose is prioritising protective investment and identifying what an operator should fix. Any specific weakness found goes to the operator and national CERT through coordinated disclosure. A good output is a prioritised protection gap list. Stop before probing or documenting exploitable detail in a distributable product.
Phase 8 — Model the consequence chain
Trace what supply failure actually does: crop loss and rural income collapse, urban rationing and tanker market price spikes, hospital and sanitation failure, disease risk, and the protest and displacement patterns each produces. Use local historical precedent for the chain rather than generic assumptions, because responses differ sharply by governance context. A good output is a consequence chain with observable indicators at each link. Stop when each link has a precedent or a documented mechanism rather than an assumption.
Phase 9 — Set thresholds and warning triggers
Define numeric triggers on named products: reservoir storage below a percentile on a date, groundwater trend crossing a rate, tanker prices above a multiple of baseline, or a treaty notification missed. Attach an action and an owner. Water crises are slow and highly predictable, which means the failure is nearly always institutional rather than analytic. A good output is a trigger table wired to specific decisions. Stop when every trigger has a named person who acts and a data source with a known update cadence.
Phase 10 — Publish with attribution discipline and review
Report storage, flow and demand separately from intent. State plainly what the physical data shows, what it cannot show, and which political inference is yours. Route any infrastructure weakness through the operator and regulator rather than into the product. Schedule review at seasonal boundaries because the whole picture resets with each wet season. A good output is a versioned assessment with an attribution statement and a review date. Stop when a reader can distinguish measurement from inference without asking.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| NASA GRACE-FO | Open | Satellite gravimetry measuring terrestrial water storage anomaly including groundwater, at basin scale with monthly resolution. | Establishes multi-year aquifer and total storage trajectories that no national dataset will publish openly. |
| USDA Global Reservoir and Lake Monitor | Open | Satellite radar altimetry time series of surface height for a global set of large reservoirs and lakes. | Detects impoundment and drawdown at upstream dams independently of any national announcement. |
| Copernicus Global Land Service and Sentinel-2 | Registration | Water body extent products and free optical imagery at ten metre resolution with revisit measured in days. | Measures reservoir surface area change and irrigated area expansion that indicates unpermitted abstraction. |
| FAO AQUASTAT | Open | Country-level water resources, withdrawal by sector, irrigation infrastructure and dam statistics with methodological notes. | Provides the demand-side denominator for any stress assessment and the baseline for sectoral withdrawal shares. |
| WHO and UNICEF Joint Monitoring Programme | Open | National and sub-national estimates of drinking water and sanitation service levels with time series back two decades. | Establishes population exposure to supply failure and the baseline service level a crisis degrades from. |
| Global Reservoir and Dam database and Global Dam Watch | Open | Georeferenced inventory of dams and reservoirs with capacity, purpose, height and year of completion attributes. | Builds the storage node inventory for a basin and identifies newly constructed impoundments to monitor. |
| UNECE Water Convention materials | Open | Treaty text, guidance and national reporting on transboundary water cooperation, notification and joint bodies. | Frames the obligation set against which upstream and downstream behaviour is assessed for compliance. |
| Pacific Institute Water Conflict Chronology | Open | Curated chronology of water-related violence and disputes with categorisation by trigger, weapon and casualty type. | Supplies precedent for consequence chains and benchmarks how water disputes have historically escalated. |
| Copernicus Emergency Management Service drought and flood monitoring | Open | Combined drought indicators, soil moisture anomaly and flood awareness forecasts at continental and global scale. | Establishes whether deficits are meteorological, agricultural or hydrological, which drives the attribution argument. |
| FEWS NET | Open | Integrated rainfall, vegetation, market and livelihood monitoring with forward outlooks for food insecure regions. | Connects water deficit to livelihood and food security consequences with region-specific mechanisms. |
| CISA advisories on water and wastewater systems | Open | Advisories and guidance on control system vulnerabilities and threat activity affecting water utilities. | Maps known threat activity to utility control system estates for defensive prioritisation. |
| ACLED conflict event data | Registration | Geolocated political violence and protest events with actor coding, including incidents at infrastructure sites. | Detects protest and violence associated with allocation decisions, rationing and infrastructure seizure. |
| World Bank water sector data and diagnostics | Open | Country and utility level indicators on water supply, non-revenue water, tariffs and institutional capacity. | Assesses utility capacity, which determines whether a hydrological shortfall becomes a service failure. |
| NASA Earthdata hydrology products | Registration | Precipitation, soil moisture, snow cover and evapotranspiration products from multiple satellite missions. | Builds the inflow side of the water balance used to separate drought from deliberate retention. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Water Security. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- QGIS — Basin mapping, reservoir extent digitisation and overlay of abstraction points. Strong spatial capability, but hydrological modelling requires additional plugins and care.
- Google Earth Engine — Long time series of water extent and irrigated area over large areas without local downloads. Excellent scale, though results need validation against independent products.
- Python with xarray — Handles gravimetry, precipitation and soil moisture grids and computes anomalies. Reproducibility depends on pinning product versions, which are reprocessed regularly.
- Sentinel Hub EO Browser — Rapid visual comparison of reservoir extent across dates. Good for triage, insufficient for measurement without proper area computation.
- HEC-RAS and open hydraulic models — Channel and inundation modelling where terrain and cross section data exist. Data hungry, and elevation model quality usually limits the result.
- Water balance spreadsheets with documented assumptions — The most underrated tool in the domain, forcing every term to be stated. Only as good as the honesty of the estimated terms.
- OpenStreetMap and canal network layers — Community mapping of canals, wells and treatment works, often the only public infrastructure geometry available. Coverage and currency vary enormously by country.
- Grafana or similar threshold dashboards — Monitors storage percentiles and flow triggers with alerting. Requires seasonal recalibration or it produces constant nuisance alerts.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Always express storage as a percentile for that calendar date rather than an absolute volume or a percentage of capacity. Reservoirs are supposed to be low at the end of the dry season, and absolute figures generate false alarms.
- The decisive analytic move is separating drought from retention. Close the water balance between upstream inflow proxies and downstream flow before you write a single sentence about upstream intent.
- Gravimetry resolves basins, not districts. Publishing a district-level groundwater claim from a coarse product is the most common technical error in this field and it is easy for a hydrologist to demolish.
- The largest term in most basin balances is unmetered agricultural abstraction, which is precisely the term nobody measures. Say so explicitly rather than letting it hide inside a residual.
- Institutional capacity determines whether hydrological shortfall becomes a service crisis. A utility with high non-revenue water and no maintenance budget fails at a deficit another utility absorbs without notice.
- Water infrastructure serving civilians has specific protection under international humanitarian law, so document attacks on it to an evidentiary standard rather than treating them as generic infrastructure incidents.
- Water crises are slow and highly predictable, which means a missed warning is nearly always an institutional failure. Build the trigger, the action and the named owner before refining the hydrology.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Water Security is producing anything, and they are worth baselining before you change process or tooling.
- Lead time between a storage percentile trigger firing and the rationing or trucking decision it was designed to inform.
- Proportion of shortfall assessments carrying an explicit drought versus retention attribution with the water balance shown.
- Share of monitored reservoirs with a maintained baseline expressed in percentiles rather than absolute volume.
- Number of infrastructure weaknesses routed to operators and CERTs through coordinated disclosure with acknowledgement recorded.
- Accuracy of seasonal supply adequacy calls scored against outturn at the end of each dry season.
- Percentage of published claims about groundwater that state the spatial resolution and error of the underlying product.
- Time from a treaty notification obligation being missed to the finding reaching the relevant foreign ministry or basin body.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Satellite altimetry only covers large water bodies; small reservoirs and canal systems need imagery or ground data and are frequently missed.
- Groundwater is invisible in most national statistics, so surface-only analysis systematically underestimates real stress in irrigated basins.
- Attributing low downstream flow to upstream retention without checking precipitation and snowpack is the most common error in basin reporting.
- State hydrological data is often classified, delayed or politically adjusted, particularly during active negotiations.
- Water conflict is usually local and sub-national rather than interstate; scanning only for war between states misses the actual violence.
- Utility outage notices under-report cause, and cyber-related incidents are frequently described as maintenance for months afterwards.
Legal and ethical considerations
Hydrological data can be treated as a national security matter, and publishing dam operating detail or utility control system findings can create both diplomatic friction and physical risk. Report infrastructure vulnerability through coordinated disclosure to the operator and national authority rather than in open products. Transboundary assessments carry legal weight in ongoing disputes, so separate measurement from interpretation and state uncertainty in satellite-derived volumes. Community-level supply data should be aggregated to avoid identifying vulnerable households.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Water Security, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 6 intelligence disciplines, 5 data points, 5 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
How do I tell deliberate retention from drought?
Close the water balance. Assemble upstream precipitation and snowmelt proxies, inflow estimates, reservoir level change and downstream flow for the same period, and ask whether the downstream shortfall is accounted for by reduced inflow. Retention shows as reservoir level rising or holding while inflows fall and downstream flow drops faster than the inflow deficit explains. Drought shows as a consistent deficit through the whole chain. State the residual explicitly, since evaporation, unmetered abstraction and measurement error are all real. This distinction determines whether the story is hydrological or diplomatic, so never assert it casually.
Can satellite data really measure groundwater?
Gravimetry measures total terrestrial water storage anomaly, which includes soil moisture, surface water, snow and groundwater together, at a spatial scale of hundreds of kilometres and a monthly cadence. With careful removal of the other components it gives a defensible multi-year groundwater trend for a large aquifer. It cannot tell you about an individual well field, a district or a single season, and claims at that resolution will be dismissed by hydrologists. Report it as a basin-scale trajectory with stated resolution and error, and validate against well level records where any are published.
Is water scarcity a driver of war between states?
Interstate water wars are rare; the historical record is dominated by cooperation, negotiated agreements and localised violence rather than state-on-state conflict. What water does reliably produce is subnational violence over allocation, coercive leverage between riparians, protest against utilities and governments, and displacement. The analytically useful framing is leverage and legitimacy rather than war: who controls release timing, who is metered, who bears the shortfall, and whether the institutional mechanism for dispute is functioning. Assess those and you will explain far more of the observed behaviour than a scarcity-to-conflict model does.
What matters most in urban water crisis warning?
Utility capacity and distribution losses, not raw availability. Cities have failed with adequate reservoirs and survived severe deficits with well-run systems. Watch non-revenue water, pump and treatment plant availability, energy supply to the utility since pumping is electricity dependent, tanker market prices as a real-time scarcity signal, and rationing schedule changes. Add the storage percentile as the slow variable underneath. Warning products should name the specific system component expected to fail and the date, because a general scarcity warning does not tell a city manager what to procure.
What can be published about water infrastructure vulnerabilities?
Very little in a distributable product. Water treatment and distribution systems have been targeted for both physical attack and control system intrusion, and in conflict-affected basins publishing a weakness invites its exploitation against a civilian population. The professional route is coordinated disclosure to the utility and the national CERT or sector regulator, with a documented timeline. Public products can discuss categories of exposure and the need for investment without identifying specific assets or specific weaknesses. If you cannot make the point without naming the vulnerability, the point belongs in the private channel.
Which treaty obligations actually bite?
Notification and data-sharing obligations bite most often, because they are concrete, observable and frequently breached quietly. Allocation formulas matter but are often written with enough ambiguity to permit reinterpretation, and dispute mechanisms are frequently unused. Assess each obligation individually: read the text, establish what observable behaviour would constitute compliance, and mark it observed, contested or unobservable. That produces a compliance picture that a foreign ministry can act on, rather than a general statement that a treaty is under strain, which tells a diplomat nothing they can raise.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- UNECE Convention on the Protection and Use of Transboundary Watercourses and International Lakes, which sets cooperation, notification and joint body obligations.
- UN Watercourses Convention principles of equitable and reasonable utilisation and the obligation not to cause significant harm, which frame most basin disputes.
- Additional Protocols to the Geneva Conventions protecting objects indispensable to civilian survival, which cover drinking water installations and irrigation works.
- WHO Guidelines for Drinking-water Quality, which define the safety standards a degraded supply is assessed against.
- Sphere Handbook minimum standards for water supply and sanitation in humanitarian response, which set service level benchmarks for programming.
- ISO 24500 series and equivalent water utility service standards, which govern utility performance measurement and continuity planning.
- Coordinated vulnerability disclosure under ISO 29147 and ISO 30111, which governs how utility control system findings are reported.
- Sendai Framework for Disaster Risk Reduction, which frames drought and flood risk reduction targets national systems report against.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- GRACE and GRACE-FO mission data — NASA Jet Propulsion Laboratory. Satellite gravimetry of terrestrial water storage change
- AQUASTAT global water information system — Food and Agriculture Organization. Country water resources and withdrawal statistics by sector
- Joint Monitoring Programme for Water Supply, Sanitation and Hygiene — WHO and UNICEF. Global service level estimates for drinking water and sanitation
- Water Conflict Chronology — Pacific Institute. Curated dataset of water-related violence and disputes with categorisation
- Convention on the Protection and Use of Transboundary Watercourses — UN Economic Commission for Europe. Treaty framework for transboundary water cooperation and notification
- Global Dam Watch dam and reservoir inventories — Global Dam Watch consortium. Georeferenced global inventory of dams and reservoir attributes
- Global Reservoir and Lake Monitor — USDA Foreign Agricultural Service. Radar altimetry time series of reservoir and lake surface height
- Water and wastewater sector guidance and advisories — US Cybersecurity and Infrastructure Security Agency. Defensive guidance for water utility control system security
- Copernicus Emergency Management Service drought monitoring — European Commission. Drought indicators and flood awareness forecasting at continental scale
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: basin storage baselines, retention versus drought attribution and infrastructure exposure monitoring across the systems you depend on. Explore the platform, or browse the rest of the library by following any tag above.