The gap between contamination and awareness
Drinking water networks are verified by sampling. A sample is collected, transported, cultured, analysed, interpreted and reported. The regulatory value of this process is high and it is not in question. Its operational limitation is structural: the result describes the water at the moment the sample was taken, and it arrives days later.
Two documented events show what happens inside that gap.
In Brixham, England, in 2024, water quality in the Littlehempston supply zone was compromised between 31 March and 1 JuneE. Investigation later established that a damaged air valve on adjacent farmland had allowed contaminated surface water into the distribution main, and that a soil sample beside the valve tested positiveE. Before the cause was identified, residents had been reporting illness for several days and were advised to continue using the supply as normalE. Around 16,000 properties were subsequently placed under boil-water advice, and for some that advice remained in force for 54 daysE. The response cost the operator £16.3 million, followed by a £1.93 million prosecution outcome in 2026E.
In Östersund, Sweden, in November 2010, approximately 27,000 people, close to 45 per cent of the city, were affected following inadequate treatment barrier performance at the municipal worksE. The event continues to shape Swedish investment behaviour more than a decade laterE.
Neither event was caused by an absence of testing. Both operators sampled to regulatory requirement. Both events developed and propagated in the interval between samples.
This interval is the addressable problem. It is not solved by testing more often, because the constraint is analytical turnaround rather than sampling frequency, and it is not solved by adding more instruments, because most network instrumentation reports physical and chemical conditions rather than water quality change.
Evidence capture at the point of change
Aqua Insights places a continuous water quality measurement at the asset and pairs it with automatic physical sample collection triggered by that measurement.
The measurement is optical. It responds to fluorescence associated with organic material of biological origin, at a resolution of approximately 86,400 readings per day per pointE. It is reagent-free, which removes consumable logistics and the maintenance burden that limits where continuous instrumentation can realistically be sited.
The measurement is not specific. It identifies that conditions have changed. It does not identify what changed them, and it does not detect individual pathogens. Protozoan parasites including Cryptosporidium are not detectable by this method at the concentrations at which they cause harmE.
This is the reason the sampler exists.
When the signal deviates from the established behaviour of the asset, the system collects and preserves a physical sample from the water that produced that deviation. That sample goes to the laboratory under the operator's existing accredited process. The laboratory result is definitive, and it is now attached to a specific moment, a specific asset, and a specific measured signal rather than to a routine sampling slot.
Under conventional sampling, the water that carried an event is gone before anyone knows an event occurred. Every laboratory result describes a moment that was selected by the calendar. Aqua Insights selects the moment by evidence.
In the Brixham case, the ingress pathway was surface water of agricultural origin entering a distribution main through a damaged valve. Water of that origin carries organic and biological load that this measurement responds to.
The claim being made here is narrow, and it is worth stating what it is not. It is not that the parasite would have been identified. It is not that the people who fell ill in the first days would have been protected: they had already drunk the water, and no monitoring system detects contamination before it exists.
The claim is that the fault was persistent, and that a preserved sample tied to a specific asset and a specific moment would have shortened the interval in which the valve remained broken and unfoundA. The event ran from 31 March to 1 June. Boil-water advice remained in force at some properties for 54 days. The people this argument concerns are not those exposed on the first day. They are those exposed on the twentieth.
Detection and sampling produce evidence. They do not produce a decision. A deviation at a single point, considered alone, is not yet actionable: a utility that responded to every deviation would spend its resources investigating normal operational variation.
What converts evidence into decision is context.
Knowing that something changed
A continuous water quality measurement produces a stream of values. What that stream is worth depends entirely on what is done with it, and the most common analytical mistake in this field is to evaluate continuous monitoring as though it were an alarm system.
What a single continuous signal already delivers
Consider an ingress event of the kind that occurred at Brixham: surface water of agricultural origin entering a distribution main through a damaged valve. A continuous measurement at that asset records that the character of the water changed, when it changed, how steeply, for how long, and when it returned to baseline. It cannot identify the organism. It does not need to in order to be operationally significant.
Four distinct classes of value follow from this, and none of them require the signal to be specific.
A physical sample is preserved from the water that produced the change. This is the primary function. The deviation triggers collection, and the laboratory then applies definitive identification to water that actually carried the event. Under scheduled sampling that water is gone before anyone knows to look for it. The laboratory does not become less accurate; it becomes correctly targeted.
The asset acquires a characterised baseline. Every asset has a normal range and a normal pattern of variation, shaped by source, season, hydraulic behaviour and treatment. That behaviour is not currently recorded anywhere at sub-daily resolution. Establishing it is a precondition for recognising departure from it, and it has independent value: an operator who knows what a service reservoir normally does is better placed to judge what it is doing now.
Retrospective reconstruction becomes possible. When a laboratory result, a consumer contact or a downstream failure raises a concern, the signal record for the preceding days and weeks already exists. In the Brixham case, illness was reported for several days before the cause was identified, and during that period the public were advised to continue using the supply as normal. A continuous record does not by itself resolve that situation. It does mean that the question of when the water changed has a recorded answer rather than requiring inference.
Propagation can be tracked. Where measurement points are placed at inlet and outlet, or along a distribution path, the arrival and progression of a change through the network is observable. Extent, direction and timing are operationally decisive in an event, and they are precisely what grab sampling cannot provide.
None of this depends on knowing what caused the change. Water quality change due to an ingress, even where that is the entire content of the observation, is information a utility does not currently hold and can act on.
The objection this has to survive
An operator will reasonably ask what any of this is worth when the signal returns to baseline on its own. The water recovered. Nobody was protected who would otherwise have been harmed. If no illness follows, the argument runs, nothing was lost by not knowing.
Part of this is correct and should be conceded. Detection does not protect the people already exposed. A sample preserved during an ingress is forensic rather than protective, and a document that implies otherwise is overclaiming.
The rest of the objection contains an error worth naming, because it is the error the entire product exists to correct.
The statement that water quality recovered and stayed recovered is a finding, and it requires a record. Without one, an event that resolved and an event that is recurring undetected produce identical evidence, which is no evidence. The reassuring interpretation and the dangerous one are indistinguishable from the outcome alone.
A damaged valve does not repair itself when the water clears. It waits for the next rainfall. The event is transient; the defect that produced it is not. An operator who learns of a fault only when people become ill is finding faults at the slowest rate the network permits, and is finding them by a method that requires harm to occur first.
A noise from a vehicle that stops after ten seconds is not evidence that the vehicle is sound. It is evidence about the state of the vehicle, and the absence of a subsequent crash does not retire it. Applied to a network, this reasoning means that any event without a recorded illness is dismissed, which selects precisely for the faults that have not yet caused harm and are therefore still fixable.
Most ingress events carry nothing harmful. That is the argument for recording them rather than against it. Ten benign deviations at one location establish that the location is compromised, and they establish it before the eleventh deviation carries something that is not benign. This pattern is unavailable to an operator whose detection method is consumer illness, because the first ten events are invisible by construction.
There is a class of event for which the objection holds completely: a genuinely isolated ingress, from a cause that will not recur, carrying nothing harmful, at a location requiring no repair. Recording it returns nothing. No operator can identify which events these are in advance, and neither can we. Determining which category a network is in is the substance of what is being purchased.
Where precision starts to matter
Precision becomes the governing constraint at one specific point: when a deviation is used to demand an expensive human response.
Operationally relevant water quality events at a single asset occur perhaps two to twelve times a yearA. In a one-hour decision window that is a prevalence of roughly one in 1,500. At that prevalence, a single-point deviation flagged at 90 per cent sensitivity and a one per cent false positive rate carries a positive predictive value of approximately six per cent.
This is a property of low-prevalence detection. It applies to any single-signal instrument regardless of its quality, and no setting of a single threshold escapes it, because the information required to escape it is not present in the signal.
But the consequence of that six per cent depends on the response it triggers, and this is the distinction that is usually collapsed.
At six per cent positive predictive value, automatic sampling remains entirely economic. Ninety-four samples in a hundred will show nothing, and the six that do will be attached to the moment that produced them. The cost of being wrong is a laboratory test. Dispatching staff on the same signal is not economic, and a system that did so would be switched off within a season.
The conclusion is not that an unconditioned signal is worthless. It is that an unconditioned signal supports evidence capture and supports it well, and does not support dispatch.
Two routes to precision
Spatial conditioning compares measurement points against each other. A change observed at the outlet of an asset that is not explained by its inlet is a different observation from a change observed at a single point, because the two locations share the sources of variation that generate most false positives. Paired differential detection raises positive predictive value from approximately six per cent to the order of sixty-five per centA.
This requires no access to utility data systems. It is achieved with instrument placement alone, and it is available in a first deployment.
Operational conditioning introduces the context the utility already records: water age, chlorine residual, pressure transient history, recent maintenance, flow direction, source condition, weather. Considered together with the water quality signal, these distinguish a deviation with an operational explanation from one that warrants investigation. This supports positive predictive value above eighty per cent at around five flagged events a yearA. At that precision, field response becomes economically rational.
The trade, stated plainly
Conditioning costs sensitivity. A conditioned system detects fewer real events than an unconditioned one: on these figures, approximately 1.5 missed events per asset-year against 0.6.
This is why the two functions are not in competition and should not be traded against each other. Sampling should remain unconditioned or lightly conditioned, because the cost of a false positive is a laboratory test and the cost of a false negative is a lost event. Dispatch should be conditioned, because the cost of a false positive is a wasted day and the cost of a false negative is an event that was going to be missed by scheduled sampling in any case.
Capture broadly. Act selectively.
These require different thresholds on the same signal, and running them separately is only possible in a system that treats detection and response as distinct decisions.
This is why Aqua Alarm is not a sensor company. The measurement is one input. The system that determines what a measurement warrants is the product.
What we predict, and what would refute it
The above establishes why context is necessary. It does not establish that the specific causal hypotheses under development at Aqua Alarm are correct.
That work is at an early stage. It is not deployed, not validated, and makes no contribution to any capability described elsewhere in this paperE.
Its central prediction is stated here so that it can be tested rather than asserted: that water quality events produce characteristic signal patterns in combination with operational context, that these patterns recur, and that a pattern characterised at one asset can be recognised at a different asset in a different network.
- Event signatures characterised at one site fail to improve detection at another site above the rate achieved by site-specific calibration alone.
- The operational context required to condition a signal proves so site-specific that no transferable structure exists.
- Conditioned detection, evaluated against held-out data with predictions registered in advance, fails to outperform a tuned threshold on precision at equal sensitivity.
Aqua Alarm's position is that these are the right tests, and that they have not yet been run.
Enforcement exposure by jurisdiction
The financial consequence of a water quality failure varies substantially by jurisdiction. A utility in England and Wales faces four independent and additive mechanisms. A utility in Sweden or Denmark faces one.
| England & Wales | Sweden | Denmark | United States | |
|---|---|---|---|---|
| Quality regulator | Drinking Water Inspectorate | Livsmedelsverket and municipality | Miljøstyrelsen and municipality | EPA and state primacy agency |
| Economic regulator | Ofwat | None | None | None |
| Criminal prosecution | Active. £1.93m total: £1.853m fine, £75,000 costs, £2,000 surcharge, June 2026. Court cited systemic failure of governance. Source | Rare | Rare | SDWA administrative penalties |
| Regulated performance penalty | Compliance Risk Index. Score of 2 is the threshold from which financial consequence applies. England median 1.171 (2021), 1.365 (2022), 3.040 (2023), 1.741 (2024). Source | None | None | None |
| Customer-experience penalty | C-MeX. ±0.4% of return on regulated equity. One third operational contacts, one third billing, one third experience survey. Source | None | None | None |
| Direct incident cost | £16.3m, Brixham 2024 | Östersund 2010: ~27,000 affected, ~45% of city | Equivalent exposure | Highest. Uncapped civil litigation. |
| Political accountability | Moderate | Dominant. Municipal ownership. | Dominant. Municipal ownership. | Moderate |
| Sector-level scale | More than £700m returned to customers 2020–25; more than £260m in the final year. Source | 78 waterborne outbreaks 1992–2011, ~70,000 affected | — | — |
| Argument that applies | Regulated penalty and prosecution | Incident cost and capital deferral | Incident cost and political accountability | Litigation and compliance |
Three qualifications on the England and Wales column
CRI consequence is an outcome delivery incentive adjustment rather than a fineE. Underperformance payments reduce what customers are charged in the following billing year.
The CRI combines company performance with regulatory activity, since the issuing of notices deliberately augments the measureE. A rising median reflects both water quality and enforcement intensity, and should not be presented as a contamination trend.
Water companies have argued to Ofwat that C-MeX is substantially skewed towards penalty, noting that all companies fell short of proposed benchmarks in 2023/24E.
Consequence for procurement. Where regulated financial mechanisms exist, monitoring investment can be justified against a quantified penalty. Where they do not, it must be justified against incident cost and capital deferral. The operational case is identical in both. The financial argument is not.
Incident cost and the investment threshold
What a water quality failure costs
The Brixham event of 2024 is the most completely documented contamination incident in recent European water supply, and the figures are public.
Direct response cost the operator £16.3 million, covering customer compensation, eight weeks of bottled water supply, and extensive network cleaning and filtering interventionE. Prosecution followed in June 2026, adding £1.93 million. A further £1.2 million fund was committed over three years to support local tourism recoveryE. Combined direct and legal exposure is approximately €21.3 million.
International comparators establish that this is not an outlier. A 2007 outbreak in Ireland with 242 confirmed cases carried an economic cost above €19 million; Milwaukee, affecting more than 400,000 people, was estimated at over $96.2 millionE. The Irish figure is the more instructive of the two: 242 confirmed cases produced €19 million of cost, which demonstrates that incident cost is driven by response, disruption and duration rather than by case count.
The threshold this establishes
The relevant question for an operator is not whether the technology returns a saving. It is how often an event of this scale would need to be avoided for the investment to be justified.
The second cost, which is incurred continuously
Incident cost is episodic. Investigative cost is not.
As set out in section 3, the cost of imprecision depends on what a deviation is used to trigger. A utility that responds to unconditioned deviations with field investigation incurs approximately €79,000 per asset per year in investigative effort, the large majority of it spent on normal operational variation. Operational conditioning reduces the same figure to approximately €4,600.
The difference is of the order of €74,000 per asset per year. Across a fleet it is the largest single recurring item in the business case, and unlike incident avoidance it does not depend on an event occurring.
Commercial structure
| Tier | Scope | Price |
|---|---|---|
| Visibility | Storage, distribution hubs, simpler assets | €15,000–25,000 / asset / yr |
| Insight | Treatment works and complex assets | €45,000–65,000 / asset / yr |
| Network | Ten or more assets, priced per network | €250,000–400,000 / yr |
Deployment carries no customer capital expenditure. Hardware is included in the subscription. Installation is within 14 days of orderE. At Insight pricing this represents approximately three to four per cent of the annual operating cost of a treatment works of typical scaleA, which places the decision within operational budget authority rather than capital programme review.
Deployment and integration
The principal constraint on adopting new monitoring is rarely the monitoring itself. It is the integration burden, the procurement route and the engineering backlog. Aqua Insights is structured to minimise all three.
Physical deployment. Installation requires power and a plumbed connection at the monitoring point. It is completed within 14 days of order. The measurement is reagent-free, which removes consumable supply, storage and disposal from the operational burden and makes remote and unstaffed sites viable monitoring locations.
Commercial route. Hardware is included in the subscription. There is no customer capital expenditure. This is deliberate: capital procurement in a regulated utility runs on a multi-year programme cycle, and a monitoring decision that enters that cycle is a monitoring decision deferred. At the pricing set out in section 5, the decision sits within operational budget authority.
Data integration. Aqua Insights operates as an additional layer above existing systems. It does not replace SCADA, LIMS, historians or laboratory workflow, and it does not require them to be modified. It reads approved data from those sources and combines it with the water quality signal and sample record.
This matters beyond convenience. Section 3 established that operational conditioning is what makes a deviation precise enough to justify dispatching staff. That context already exists in the utility's systems. A deployment that cannot reach SCADA, flow, pressure and maintenance records retains full evidence-capture capability and does not support conditioned field response.
What the utility retains. Interpretation is presented to the operator with the evidence that produced it. Decision authority, professional judgement and the record of what was decided and why remain with the utility. The system produces a traceable sequence from signal to sample to laboratory result to decision to outcome, which is the record required for management and compliance review.
Scope of a first deployment. A first deployment is a visibility deployment. Continuous measurement, event-triggered sampling, and paired inlet and outlet monitoring where differential detection is relevant. Operational conditioning follows once sufficient site data exists to characterise normal behaviour and once data access is established. The causal work described in section 3 forms no part of a first deployment.
Evidence appendix
Claims are classified as evidence where the figure derives from a published source or from Aqua Alarm's own instrumented data, and ambition where it derives from a model whose parameters are stated below and which has not yet been tested against observation.
Table A · Evidence
| Figure | Value | Source |
|---|---|---|
| Brixham direct incident cost | £16.3m | Pennon Group H1 results |
| Brixham prosecution | £1.853m + £75,000 + £2,000 | Exeter Magistrates' Court, June 2026 |
| Brixham tourism recovery fund | £1.2m / 3 yrs | ITV News West Country |
| Pennon total incident-related cost | ~£36m | BBC News |
| Properties under boil-water advice | ~16,000 · 54 days max | Contemporaneous reporting |
| Illness reported before cause identified | Several days | Court testimony, June 2026 |
| Ingress pathway | Damaged air valve | Court testimony, June 2026 |
| CRI penalty threshold | Score of 2 | DWI CRI definition |
| CRI industry median, England | 1.171 / 1.365 / 3.040 / 1.741 | DWI Chief Inspector's Report 2024 |
| CRI consequence mechanism | ODI payment, not fine | Ofwat |
| C-MeX incentive strength | ±0.4% of RoRE | Ofwat PR24 final determinations |
| C-MeX composition | 33.3 / 33.3 / 33.3 | Ofwat C-MeX PC definition |
| Sector underperformance payments | >£700m 2020–25 | Ofwat WCPR 2024-25 |
| Östersund outbreak | ~27,000 · ~45% of city | Widerström et al., Emerg Infect Dis 20(4), 2014 |
| Swedish outbreak frequency | 78 outbreaks 1992–2011 | Primary source required |
| Ireland 2007 outbreak cost | >€19m · 242 cases | Chyzheuskaya et al., 2017 |
| Milwaukee 1993 outbreak cost | >$96.2m · >400,000 | Corso et al., 2003 |
| PR24 total expenditure allowance | £104bn (£60bn base) | Ofwat PR24 final determinations |
| Ofwat catch-up cost gaps | 2%–17% | Ofwat PR24 redeterminations |
| Measurement resolution | ~86,400 readings/day/point | Aqua Alarm instrumentation |
| Installation lead time | 14 days from order | Aqua Alarm |
| TLF and protozoan detection | Not detectable at harm-relevant conc. | Citation required |
Table B · Ambition — modelled parameters, pre-registered
Every value below is fixed before test data exists. Confirming or refuting them against first-deployment data is the point of stating them.
| Parameter | Value used | Basis | How it will be tested |
|---|---|---|---|
| Event prevalence | 6 /asset/yr (2–12) | Estimate | Event log, first full deployment year |
| Decision window | 1 hour | Modelling choice | Sensitivity analysis at 15 min and 4 hr |
| Unconditioned sensitivity / FPR | 90% / 1% | Estimate | Held-out data, predictions pre-registered |
| Spatial conditioning FPR | 0.03% | Modelled, 3× penalty for correlated noise | Paired inlet/outlet deployment |
| Operational conditioning sens / FPR | 75% / 0.01% | Estimate | Held-out data, predictions pre-registered |
| Sample + laboratory cost | €60 | Estimate | Customer invoice data |
| Operator review cost | €25 | Estimate | Time-and-motion at pilot site |
| Field investigation cost | €850 | 2 staff, half day, travel, sampling, lab | Customer callout records |
| Treatment OPEX, 40,000-pop asset | £0.86m (£0.52–1.36m) | PR24 base £12bn/yr × water 35–45% × opex 50–65% × treatment 35–55% ÷ 1,424 works | Customer-supplied site baseline |
| Works count, England & Wales | 1,424 | Scaled from DWI registers: 386 works / 15.4m population, six companies | — |
| Scaling exponent, works size | 0.7 | Standard sub-linear assumption | Multi-site data |
| Reactive share of treatment OPEX | 15–30% | Anchored to Ofwat catch-up gaps | Customer baseline |
| Addressable share of reactive spend | 10–20% | Estimate | Pilot measurement |
| Currency conversion | £1 = €1.17 | — | — |
Table C · Stated refutation conditions
- Event signatures characterised at one site fail to improve detection at another site above the rate achieved by site-specific calibration alone.
- The operational context required to condition a signal proves so site-specific that no transferable structure exists.
- Conditioned detection, evaluated against held-out data with predictions registered in advance, fails to outperform a tuned threshold on precision at equal sensitivity.