Case Study
Water

SCADA Upgrade Catches Critical Failover Defect Before It Reaches Production

A like-for-like platform and OPC driver upgrade at GWW Sunbury — engineered to bring the site into line with GWW's other Western sites, and rigorously tested to uncover a latent tag-activation defect in the server redundancy layer before it could affect a live failover.

Project Reference
GWW / J13643
Handover Date
August 2026
11,423
SCADA Tags Migrated
7,925
Tags Saved from Dark Failover
2018 R2 U32
Target Platform
Server 2022
Operating System

Project Overview

Greater Western Water (GWW) engaged Parasyn to upgrade the SCADA platform at its Sunbury site. The site's existing Citect SCADA servers were running an older operating system and software version than the rest of GWW's Western site portfolio, creating an inconsistency in platform baseline, support posture, and long-term maintainability.

The engagement scope was to upgrade the Sunbury Citect machines to Windows Server 2022 and AVEVA Plant SCADA (Citect) 2018 R2, Update 32 — bringing the site's software stack into alignment with GWW's other Western sites — and to replace the site's legacy KEPServerEX OPC driver with a direct GE driver, migrating all 11,423 existing SCADA tags onto the new driver.

Technical Scope & Requirements

The scope combined platform standardisation with an OPC driver replacement — two changes that interact at the server redundancy layer and required careful sequencing to avoid compounding risk.

Platform Standardisation
Two new GWW-supplied servers imaged with Windows Server 2022 and AVEVA Plant SCADA (Citect) 2018 R2, Update 32 — configured with the same image, policies and permissions used on previous GWW Western site upgrades.
OPC Driver Replacement
Replacement of the legacy KEPServerEX OPC driver with a direct GE driver, including migration and validation of all 11,423 existing SCADA tags onto the new driver.
Offline Development & FAT
Stand-up of an offline development server matching the target production OS and SCADA versions, used for configuration, tag conversion and Factory Acceptance Testing ahead of site cutover.
Run Sheet & Site Cutover
Development of a detailed GWW Run Sheet governing each step of installation, parallel-running and Site Acceptance Testing, executed on-site with defined rollback provisions.

The Challenge — A Hidden Failover Defect

Because the OPC driver replacement touched the mechanism by which the primary and standby Citect servers exchange live tag data, Parasyn treated it as a contractual Hold Point — meaning full development work would not proceed until a proof-of-concept confirmed the new driver behaved correctly under redundancy, not just in normal single-server operation.

Tag Activation on Failover
Structured testing across three failover states — normal dual-server operation, primary-server failure with standby promotion, and standby-only cold start — found that on promotion, the standby server activated only 3,498 of 11,423 tags, leaving 7,925 tags inactive.
Root Cause in OPC Parameters
The behaviour was isolated through systematic testing of the OPC-layer redundancy parameters — LeaveTagsActive, FillCacheOnStartup and InhibitActivationOnStandby — across each server role and health state, to identify the configuration required for full, reliable tag activation.

The Parasyn Solution

Left unresolved, the defect meant that a real primary-server failure at Sunbury could leave close to two-thirds of SCADA tags dark on the promoted standby server — a significant loss of operator visibility during exactly the event that redundancy exists to protect against. Because the issue surfaced during Parasyn's own validation testing rather than in production, GWW raised it as a dedicated investigation and rectification work package, resolved ahead of final go-live.

Hold-Point Governance
The OPC driver replacement was gated behind a contractual Hold Point, requiring a proof-of-concept before committing to full detailed development — preventing an unproven driver change from being carried into production configuration.
Structured Failover Test Plan
A repeatable, multi-scenario test procedure — normal operation, primary failover, and standby cold start — reproduced and characterised the tag-activation defect under controlled conditions, rather than relying on assumed redundancy behaviour.
Root-Cause Isolation
Iterative testing of OPC server parameter combinations identified the configuration required to achieve full, consistent tag activation across every failover state, ahead of site cutover.
Transparent Escalation
Findings were documented and escalated to GWW as an additional, scoped and quoted work package — keeping the discovery contained, budgeted and schedule-visible rather than an undisclosed risk carried into go-live.

Implementation & Cutover Methodology

  1. Preparation
    Requirements finalisation, collection of comms drivers and data files, and stand-up of an offline development environment matching the target GWW server build.
  2. Development
    Software and licence installation, comms driver configuration, GE OPC driver installation and tag conversion, and development of the GWW Run Sheet and test documentation.
  3. Testing — FAT
    Offline testing of the upgraded project on the development server, comms driver testing, and configuration/tag health checks on the two new GWW-supplied servers ahead of shipment to site.
  4. Cutover — SAT
    Site-specific induction, installation and data copy to the new servers, parallel running of old and new servers, and Run Sheet-governed Site Acceptance Testing.
  5. Completion
    Resolution of remaining defects, completion of the testing Run Sheet, and formal project sign-off — with an allowance retained for post-implementation support.

Project Outcomes

As at the August 2026 reporting period, the Sunbury upgrade is in its final stages of issue resolution.

Platform Standardised
Sunbury aligned to Windows Server 2022 and AVEVA Plant SCADA (Citect) 2018 R2, Update 32 — matching the baseline used across GWW's other Western sites.
Failover Defect Resolved
A latent tag-activation issue in the primary/standby OPC redundancy layer was identified and root-caused through structured testing before it could affect a live failover event.
Run Sheet Delivered
Comprehensive, step-by-step site cutover and test documentation completed and issued to 100%.

Standards & Frameworks Applied

ISO 9001 / SEMP — Quality management: structured development, hold-point governance, FAT/SAT and change escalation applied throughout.
OPC / GE Driver — SCADA-to-PLC interface protocol: redundancy parameters validated across all failover states.

Lessons Learned & Future Recommendations

InsightImpact & ContextRecommendation
Test Every Failover State ExplicitlySteady-state operation testing alone does not prove redundancy.Include primary failure and standby cold-start scenarios as mandatory test cases in every SCADA SAT plan.
Treat Driver Replacements as Hold PointsGating the OPC driver swap behind a proof-of-concept caught the defect early enough to resolve it without derailing the schedule.Define OPC or comms driver replacements as contractual Hold Points in every project that touches the redundancy layer.
Document Validated OPC Parameters for ReuseThe validated OPC redundancy parameters are a reusable reference for future GWW Western site standardisation work.Maintain a validated OPC parameter library by site and driver type, updated at project close-out.
Budget for Out-of-Scope DiscoveryA defined discovery allowance kept the additional tag-discrepancy investigation contained and schedule-visible.Include a scoped discovery allowance with a timeout trigger in every upgrade engagement that touches a comms driver.

Site

Greater Western Water Sunbury site — SCADA upgrade and OPC driver replacement