Water Watch Center opens for small utilities amid Iran-linked intrusions
The program targets the sector's structural problem (small systems with PLCs still exposed online and no budget to fix them) while attribution remains unconfirmed.
TL;DR
The National Rural Water Association and DEF CON Franklin launched the Water Watch Center at DEF CON, backed by five cybersecurity firms, to deliver direct mitigation support to water utilities serving fewer than 10,000 people. The initiative arrives as at least 12 states report intrusions against water infrastructure (more than 30 Minnesota systems were hit late last month) with U.S. officials weighing but not yet confirming Iranian responsibility. Acting CISA Director Nick Andersen told NextGov/FCW that PLCs with default or no passwords remain a live problem, and the agency's guidance hasn't changed: get operational technology off the internet and set a password.
The Water Watch Center is an attempt to solve a problem that federal agencies have been naming for years but can't fix on their own. The Water and Wastewater Sector's roughly 50,000 community water systems are overwhelmingly small (most serve under 10,000 people) and cybersecurity budgets are functionally nonexistent. CISA, the FBI, and the EPA co-authored a 2024 incident response guide for the sector that laid out the barriers plainly: governance split across federal, state, and local authorities; "disparate" maturity levels; and universal solutions that are, in the guide's own words, "unfeasible."
So the work falls to a hybrid model: a trade association, a university policy initiative, and five private security firms building what Jake Braun called "a scalable cyber delivery model that has eluded water industry and national security officials to date." That's a big claim, and it'll be tested the first time a small utility in rural Minnesota has to get an incident responder on the phone at 2 a.m.
The intrusions that prompted the launch haven't stopped. Acting CISA Director Nick Andersen, speaking at Black Hat the day before DEF CON opened, said the agency is still finding PLCs accessible on the public internet with default passwords or none at all. "We're not making ourselves hardened targets," he said. Retired Gen. Paul Nakasone, who led USCYBERCOM and NSA through 2024, pushed the same line at DEF CON: controllers shouldn't be exposed. On attribution, he was careful (the government hasn't named Iran) but he noted the history, the capability, and the intent. "We're in conflict with Iran," he said. That's not attribution. It's context that makes the unconfirmed link harder to dismiss.
Published ·Updated ·Deep Fathom