The Water Watch Center, a program delivering managed cybersecurity services to small water utilities, was launched on Aug. 7 at the DEF CON hacker conference in Las Vegas. This launch came after more than 30 Minnesota water systems were hit by intrusions in late July, with roughly 12 states reporting similar activity since then. The U.S. Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency are running incident response, with officials suspecting Iranian involvement, though it has not been confirmed.
Small water utilities, which serve fewer than 10,000 people, make up 91% of the roughly 50,000 community water systems in the country. Most of these utilities have no chief information security officer, no security operations center, and no budget to hire either, making them highly vulnerable to cyber threats.
Five managed detection and response providers have signed on to serve these systems, including Rapid7 Inc., Defendify Inc., Legato Security LLC, L1 Secure, and Sentinel Technologies Inc. These providers will exchange threat information and patches through a dedicated collaboration mechanism, then pass what they find to the National Rural Water Association, which acts as the national hub.
The program is the result of a two-year field effort by DEF CON Franklin, a joint project of DEF CON and the University of Chicago Harris School of Public Policy’s Cyber Policy Initiative. Nearly 450 volunteer cyber experts were recruited and paired with water and wastewater utilities in several states, hardening individual plants and exposing the limits of volunteer labor against the large number of water and wastewater systems.
“These leading cyber firms and the National Rural Water Association are architecting a scalable cyber delivery model that has eluded water industry and national security officials to date,” said Jake Braun, co-founder of DEF CON Franklin and a former White House acting principal deputy national cyber director. The mix of volunteers and hand-picked providers is intended to hold costs down for cash-strapped utilities, with seed money provided by Craig Newmark, the craigslist Inc. founder and a longtime backer of what he calls cyber civil defense.
Related: AI gains fail to lift Qualcomm and Arm shares
Vanderbilt University is applying research from the Defense Advanced Research Projects Agency’s CASTLE program to build digital twins of water systems, which will be used to test automated defenses. Work is already under way in Maryland to identify vulnerable rural systems, which tend to run legacy operational technology with exposed programmable logic controllers and weak credentials, making them susceptible to fairly basic attack techniques.
Matt Hartman, chief strategy officer at Merlin Group LLC, noted that managed detection and response can provide significant value for utilities without dedicated cybersecurity staff, but only if it has visibility into the operational environment. He also noted that the reliance on philanthropic funding to stand the capability up highlights the significant resource gap that remains.
Kevin E. Greene, chief cybersecurity technologist for the public sector at BeyondTrust Corp., said many small water systems are still operating below the cyber poverty line. The operating model has to “meet these municipalities where they are,” Greene said, adding that philanthropy helps in the short run but municipalities should not have to rely on it for baseline cyber resilience on infrastructure communities use every day.
As the Water Watch Center begins its work, it’s clear that the challenge of securing small water utilities is complex, requiring a regulatory framework that can keep pace with evolving threats, such as those related to data center emission concerns. With the help of managed detection and response providers and research institutions, these utilities may finally have a chance to defend themselves against cyber threats.
The Water Watch Center’s efforts are part of a larger trend of increased focus on cybersecurity in the water industry.
