>samit_hota
Back to security news

Security News · SN-2026-343

MEDIUMOPEN

Water Utilities Partner with DEF CON Franklin to Launch Water Watch Center

Affected: US Rural Water Utilities · Community Water Systems

Samit Hota·
#news#vulnerability-disclosure#nrwa

In response to a escalating wave of cyberattacks against municipal infrastructure, the National Rural Water Association (NRWA) has partnered with volunteer security group DEF CON Franklin to launch the Water Watch Center (WWC). The new initiative aims to provide threat intelligence, incident response assistance, and managed cybersecurity services to cash-strapped water and wastewater utilities across the United States.

The program directly addresses the operational vulnerabilities of smaller utilities, specifically those serving populations under 10,000 residents. While major metropolitan water authorities often possess dedicated security operations teams, rural facilities operate on thin margins, frequently relying on a single plant operator who manages both physical operations and basic IT infrastructure.

Operational Technology Vulnerabilities and Iranian Targeting

The launch of the Water Watch Center comes as nation-state adversaries and affiliated hacktivist groups intensify targeting of critical infrastructure operational technology (OT). Recent incidents across at least 12 states—including newly reported breaches in New Jersey, Minnesota, Michigan, Georgia, and South Dakota—highlight a systemic vulnerability pattern in the sector.

Many of these attacks, attributed to Iranian Islamic Revolutionary Guard Corps (IRGC)-affiliated threat groups such as CyberAv3ngers, do not rely on complex zero-day exploits. Instead, adversaries routinely scan public IP spaces via platforms like Shodan and Censys to discover exposed Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), and remote terminal units (RTUs). Common vectors include:

  • Internet-Exposed Control Systems: PLCs and HMIs directly connected to cellular modems or public WAN connections without VPN encapsulation or network firewalls.
  • Default Credentials: Unchanged administrative passwords on OT hardware, such as factory-default access codes on Unitronics Vision-series controllers and similar industrial devices.
  • Unauthenticated Insecure Protocols: Legacy industrial protocols (such as Modbus TCP or Ethernet/IP) exposed to public networks, allowing remote attackers to send unauthenticated control commands or write directly to memory registers.

When attackers gain access to an HMI or controller, their actions typically involve defacing digital screens, altering setpoints, or shutting down pumps to disrupt operations and create public alarm.

How the Water Watch Center Operates

To counter these intrusions without imposing prohibitive costs on small facilities, the Water Watch Center pairs technical volunteers with established commercial vendors. Five managed detection and response (MDR) providers have joined the initiative: Rapid7, Defendify, Legato Security, L1 Secure, and Sentinel Technologies.

Under the architecture of the WWC, these private security firms will deliver specialized monitoring and vulnerability data to the NRWA, which will serve as a centralized hub for rural systems:

  1. Centralized Threat Hub: The NRWA aggregates indicators of compromise (IOCs), vulnerability disclosures, and patch guidance tailored to industrial control systems, redistributing actionable intelligence to local utility managers.
  2. Volunteer Support & Field Engagement: Building on DEF CON Franklin’s pilot network of 450 volunteer security professionals, field experts will assist operators in conducting architecture reviews, closing remote access vectors, and removing internet-facing OT interfaces.
  3. Digital Twin Modeling: In collaboration with Vanderbilt University and the U.S. military, the initiative is building digital replicas of water treatment environments. These digital twins allow researchers to safely simulate cyberattacks and refine automated defensive playbooks without risking physical disruptions to live drinking water systems.

Initial rollout efforts are already underway in Maryland, focusing on rural utilities that support surrounding military installations and critical federal supply chains.

Realistic Blast Radius and Industry Impact

The United States houses approximately 150,000 public water and wastewater systems, including 50,000 community systems. Crucially, 91 percent of these community water systems serve populations of fewer than 10,000 people.

For these smaller entities, the practical blast radius of a cyber intrusion rarely involves immediate public health hazards like chemical poisoning. Industrial water treatment plants rely on secondary physical safety controls, manual pressure relief valves, and mechanical interlocks that operate independently of digital networks. However, an attack can readily cause localized operational downtime, operational technology bricking, loss of automated monitoring capabilities, and forced reversion to manual operations. Manual overrides require 24/7 physical staffing, rapidly draining the financial and labor resources of small utility districts.

Historically, organizations like the NRWA have resisted federal mandates for mandatory cybersecurity controls, pointing out that unfunded regulatory requirements force small utilities to raise water tariffs on low-income residents. The creation of the Water Watch Center represents a shift toward subsidized, vendor-backed defensive frameworks, allowing small-scale operators to implement network segmentation, multi-factor authentication for remote access, and log monitoring without bearing the full capital burden.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call