Key Takeaways
- The Water Watch Center offers direct cyber‑mitigation support to small‑scale water utilities (those serving fewer than 10,000 people), which make up the majority of the nation’s community water systems.
- Launched at DEF CON, the initiative is a partnership between the National Rural Water Association (NRWA) and DEF CON Franklin, a project of the University of Chicago Harris School of Public Policy.
- More than 30 Minnesota water systems were reportedly targeted last month, with activity noted in around 12 states; the FBI and CISA are coordinating incident response.
- An initial cohort of five cybersecurity firms will deliver services, aiming to create a scalable delivery model that has previously eluded the water sector and national‑security officials.
- Retired General Paul Nakasone warned that programmable logic controllers (PLCs) in water facilities should not be exposed to the internet and urged higher defense standards across the sector.
- While some U.S. officials suspect Iran may be behind the intrusions, officials stress a measured approach to attribution, weighing intent, capability, and historical behavior.
Overview of the Water Watch Center Initiative
The Water Watch Center is a newly established program designed to bolster the cyber resilience of small community water systems across the United States. By focusing on utilities that serve populations under 10,000, the center addresses a segment that constitutes the majority of the nation’s water infrastructure but often lacks the resources for sophisticated cyber defenses. The program provides direct mitigation assistance, including threat monitoring, incident response guidance, and remedial support, to help these utilities detect, contain, and recover from cyber threats. Its creation reflects growing recognition that water systems, despite their critical role in public health, are increasingly attractive targets for malicious actors seeking to disrupt essential services.
Launch at DEF CON and Partners Involved
The initiative was unveiled at this year’s DEF CON hacker convention, a venue known for bringing together cybersecurity experts, researchers, and policymakers. The Water Watch Center is a joint effort between the National Rural Water Association (NRWA), which represents rural and small‑town water providers, and DEF CON Franklin—a project housed within the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy. This collaboration merges the NRWA’s deep ties to the water‑utility community with DEF CON Franklin’s expertise in cyber policy and technical mitigation, aiming to translate hacker‑community insights into practical defenses for water infrastructure.
Target Audience and Scope
Specifically, the Water Watch Center serves community water systems that provide drinking water to fewer than 10,000 residents. According to industry data, such small systems account for roughly 80 % of all community water utilities in the United States, yet they frequently operate with limited IT budgets and specialized cybersecurity staff. By concentrating on this underserved segment, the program hopes to close a significant gap in national cyber‑defense posture, ensuring that a broad base of water providers can achieve a baseline level of protection against increasingly sophisticated threats.
Recent Cyber Intrusion Activity
State officials reported that more than 30 community water systems in Minnesota were targeted by cyber intrusions late last month. Similar suspicious activity has been observed in approximately 12 additional states over the past few days. Although officials emphasized that the affected systems continued to operate safely and that no known public‑health impacts have occurred, the incidents prompted a coordinated response from the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA). Both agencies are sharing threat intelligence, assisting with forensic analysis, and advising utilities on mitigation steps to prevent further compromise.
Role of Participating Cybersecurity Firms
To operationalize its support model, the Water Watch Center has enlisted an initial group of five leading cybersecurity firms. These partners are tasked with delivering services such as vulnerability assessments, intrusion detection, threat hunting, and remediation guidance directly to participating utilities. Jake Braun, co‑founder of DEF CON Franklin and a former White House acting principal deputy national cyber director, noted that these firms, together with the NRWA, are “architecting a scalable cyber delivery model that has eluded water industry and national‑security officials to date.” The goal is to create a repeatable framework that can be expanded as more utilities join the program and as the threat landscape evolves.
Statements from Jake Braun
Jake Braun emphasized the importance of leveraging private‑sector expertise to fill capability gaps that government agencies alone cannot address. Drawing on his experience in national cyber leadership, he argued that a collaborative model—where specialized firms provide technical water‑utility support while policy bodies like the NRWA handle outreach and coordination—offers the best chance to achieve rapid, effective defense. Braun also highlighted that the initiative’s design intentionally avoids creating a bureaucratic bottleneck, instead focusing on agile, on‑the‑ground assistance that can be deployed quickly when an incident is detected.
Insights from Retired Gen. Paul Nakasone
Retired General Paul Nakasone, who led U.S. Cyber Command and the National Security Agency from 2018 to 2024, spoke at DEF CON about the systemic exposure of water utilities. He warned that many facilities still link programmable logic controllers (PLCs)—the small computers that control pumps, valves, and other critical equipment—to the internet, creating unnecessary attack surfaces. Nakasone urged the adoption of higher defense standards, including network segmentation, strict access controls, and regular patching, to protect these vital components. His remarks underscored a broader concern: without elevated security practices, water infrastructure remains an attractive low‑hanging fruit for state‑sponsored and criminal actors alike.
Attribution Considerations and Iran Link
While some U.S. officials have raised the possibility that Iran may be behind the recent intrusions, no definitive public attribution has been made. Nakasone explained that the government is taking a measured approach, carefully evaluating intent, capability, and historical behavior before assigning blame. He noted that Iran possesses both the technical capability and a demonstrated interest in targeting critical infrastructure, and that the current geopolitical climate suggests a plausible motive. Nevertheless, officials stress that premature attribution could undermine diplomatic efforts and that the priority remains safeguarding systems and improving resilience rather than public naming‑and‑shaming.
Implications and Future Outlook
The emergence of the Water Watch Center signals a growing recognition that water utilities—especially small, rural systems—require dedicated cybersecurity support as part of national critical‑infrastructure protection. By marrying the technical prowess of private cyber firms with the community reach of the NRWA and the policy insight of DEF CON Franklin, the program aims to create a replicable model that could be adapted to other sectors facing similar resource constraints. Ongoing coordination with the FBI and CISA will be essential to track evolving threats, share indicators of compromise, and refine defensive practices. Ultimately, the initiative’s success will be measured by its ability to reduce the frequency and impact of cyber incidents on water services, thereby safeguarding public health and maintaining confidence in the nation’s essential water supply.

