Skip to main content
CybersecurityInfrastructure

Water Utilities Fortify Defenses Against Rising Cyber Threats

Control room of a water treatment plant with computer workstations and industrial equipment.

“These leading cyber firms and NRWA are architecting a scalable cyber delivery model that has eluded water industry and national security officials to date,” Jake Braun said.

The Water Watch Center: a targeted delivery model for small systems

Launched at this year’s DEF CON hacker convention, the Water Watch Center is a partnership between the National Rural Water Association (NRWA) and DEF CON Franklin, a project of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy. The center’s stated mission is to provide cyber mitigation support to community water systems that serve fewer than 10,000 people — a category that covers most of the nation’s community water systems. An initial group of five cybersecurity firms will help deliver services under the program.

What the recent incidents look like: Minnesota and a dozen states

State officials reported that more than 30 community water systems in Minnesota were targeted late last month. Around 12 states have reported similar activity in recent days, though officials in those states said systems continued to operate safely and there were no known effects on public health. Federal partners including the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) are working on incident response.

Programmable logic controllers and the technical exposure

Former U.S. Cyber Command and National Security Agency leader Paul Nakasone, speaking at DEF CON, pointed to a specific technical risk: programmable logic controllers (PLCs), the small computers used to operate pumps, valves and other equipment inside water facilities. “These [programmable logic controllers] should not be exposed to the internet,” Nakasone told reporters, framing a practical control that defenders say increases risk when left reachable from public networks.

Attribution posture: measured, public uncertainty remains

Some U.S. officials believe Iran may be responsible for the wave of intrusions, the public reporting indicates, but there has been no definitive public confirmation. Nakasone described the government’s approach as deliberate: “I think [the government] is taking a very measured approach to make sure that they have the right actor that’s doing this.” He added that he personally considers intent, capability and history when evaluating potential actors but is not the official decision-maker on attribution. “I’m not the person that’s making the call on the attribution,” he said. “I look at intent. I look at capability. I look at history. I’m not the person that’s making the call on the attribution, but I see an actor here that has certainly shown a history of being able to do this,” Nakasone said, noting capability and an environment he described as “we’re in conflict with Iran.”

What this means for technologists, policymakers, and community water systems

  • Technologists and security teams: The Water Watch Center will be a delivery channel for hands-on mitigation support, backed by five cybersecurity firms; the focus on PLC exposure underscores a concrete remediation priority — reducing or eliminating public network access to critical control systems.
  • Policymakers and federal responders: The FBI and CISA are already engaged in incident response, and government officials are publicly emphasizing careful attribution. That posture shapes how information and countermeasures will be shared with state and local partners.
  • Community water systems and operators: The initiative targets systems serving fewer than 10,000 people, offering a replicable package intended to raise defenses for the small utilities that make up most community systems and that may lack in-house cyber capability.

The effort combines a recognized membership organization for small utilities, NRWA, with a university-linked policy and hacker-conference ecosystem in DEF CON Franklin, and it will be tested quickly: dozens of systems have been targeted and federal responders are already engaged. Whether the Water Watch Center’s model — described by Jake Braun as scalable and newly architected — can be deployed fast enough and broadly enough to blunt the current wave of intrusions is the question at hand. The immediate next steps named in public reporting are delivery of mitigation services by the initial five firms and continued FBI and CISA incident response.

Original story