Bridging the Gap: Revealing Water Utility Cybersecurity Vulnerabilities

0
2

Key Takeaways

  • The Water Watch Center, launched at DEF CON Franklin with the National Rural Water Association, provides managed detection and response (MDR) services to water utilities serving fewer than 10,000 people—representing 91 % of the ~50,000 community water systems in the U.S.
  • MDR fills a critical visibility gap for utilities that lack dedicated cybersecurity staff, delivering alerts but not the full response actions required during an incident.
  • Effective response still depends on human processes (contacting operators, assembling teams, switching to manual control, reporting to state and federal agencies) that function independently of the detection system.
  • CISA’s CI Fortify guidance stresses the need to isolate vital operational technology (OT) and recover from known‑good sources while isolated, highlighting a tension: MDR services are delivered over the internet, which may be severed during an isolation event.
  • Utilities must ask vendors what their detection capability does when the internet connection is lost and which deployment model (on‑premises, hybrid, or hosted‑only) ensures continued alerting and accountability.
  • Legislative momentum is building: the Water Cyber Shield Act would grant the EPA authority to conduct cybersecurity assessments and set standards, authorizing $300 million annually through state revolving funds, offering a potential funding stream for utilities.
  • The next investment priority should extend beyond detection to reliable mass alerting, verified personnel accountability, and coordination channels that remain operational even when the enterprise network is suspect.
  • Capabilities that utilities own, operate, and exercise regularly outlast grant cycles; associations and state primacy agencies should guide members on what to fund second and why.

Launch of the Water Watch Center
On August 7, DEF CON Franklin partnered with the National Rural Water Association (NWRA) to unveil the Water Watch Center at DEF CON in Las Vegas. The initiative supplies managed detection and response (MDR) services directly to water and wastewater utilities that serve populations under 10,000. These small systems constitute roughly 91 percent of the nation’s approximately 50,000 community water utilities, a segment that has historically struggled to access cybersecurity expertise and guidance.


From Volunteer Effort to Scalable Service Model
The Water Watch Center emerged after two years of field work in which DEF CON Franklin recruited nearly 450 volunteer cyber‑security professionals to aid utilities across seven states. As the volunteer model proved unable to scale to the size of the sector, the effort transitioned into a formal service model. This shift marks the first credible attempt to deliver cybersecurity capability at scale to utilities that possess minimal staff and limited financial resources.


What Detection Provides—and What It Does Not
MDR solutions principally close a visibility gap: for a utility that has never had anyone monitoring its IT/OT environment, receiving an alert is a substantial gain. However, the output of MDR is merely a notification—a signal that something anomalous has occurred. Turning that notification into an effective response requires a series of human‑driven steps that occur well after the alert is generated. At 2 a.m., for example, a utility must: locate an off‑shift operator, reach an operations lead who often doubles as the IT department, gather enough personnel to make a containment decision, coordinate a shift to manual control across plant and distribution systems, determine who is on site and who can be contacted, and continuously report status to the state primacy agency and CISA throughout the incident. None of these actions constitute detection, and all depend on communication channels that may be compromised when the enterprise network is under suspicion.


The Dependency Question Raised by CI Fortify
In May, CISA released CI Fortify: Advice for Isolating Vital Systems, jointly developed with the Australian Signals Directorate, the UK’s National Cyber Security Centre, and Canada’s Centre for Cyber Security. The guidance imposes two structural requirements: (1) Isolation—the ability to proactively disconnect vital OT and enabling systems from third‑party dependencies such as telecom, internet, and vendor links; and (2) Recovery—the capacity to rebuild from known‑good sources while remaining isolated, sustaining essential services for up to three months. When read alongside the Water Watch Center’s MDR offering, a design tension appears: MDR is delivered as a third‑party service over the internet, placing it on the far side of the boundary that CI Fortify instructs operators to be able to draw. Any service that relies on external connectivity faces the same challenge—its usefulness must be evaluated before an isolation event, not during it. Operators who understand that detection may go quiet when the internet is severed can plan accordingly; those who never consider the scenario will discover the gap at the worst possible moment.


Asking the Right Question of Vendors
Because many security platforms, including BlackBerry® AtHoc®, default to a cloud‑first deployment, the survival of alerting and accountability during a network outage hinges on the chosen deployment model. On‑premises or hybrid architectures can preserve functionality when the internet is severed, whereas a hosted‑only configuration cannot. Consequently, a critical question must be posed to every provider in the response chain: What does this capability do when the internet connection is gone, and which deployment model makes that answer true? Vendors asserting continuity through isolation should be required to disclose the underlying deployment model that supports their claim.


Funding Developments and Legislative Prospects
The same week as the Water Watch Center launch, two U.S. Senators introduced the Water Cyber Shield Act. The bill would grant the EPA explicit authority to conduct cybersecurity assessments and set standards in collaboration with CISA and NIST, and it would authorize $300 million annually via the Drinking Water and Clean Water State Revolving Funds. Although the legislation is still in the introduction stage and authorization does not yet equal appropriation, it offers a plausible, no‑cost funding mechanism for a sector that has long endured unfunded mandates. The availability of a free detection service now creates a clear sequencing question: if the first increment of capability (detection) arrives at no cost, the logical second increment should fund what detection hands off to—reliable mass alerting, verified personnel accountability, and coordination channels that remain operational even when the primary network is suspect.


What the Next Dollar Should Buy
For utilities whose entire response capacity may consist of only four people, any breakdown in coordination translates directly into response failure; there is simply no bench depth to absorb gaps. Therefore, the next investment should focus on delivering a coordination layer that does not rely on the potentially compromised enterprise network. This could involve dedicated radio systems, satellite links, or hardened mesh networks capable of transmitting alerts and confirming receipt by personnel. Additionally, the system must provide verified accountability—knowing who received the alert, who acknowledged it, and who is executing each response step—so that incident commanders can maintain situational awareness even under degraded communications.


Durability and Ownership Over Grant Cycles
Philanthropic seed funding and the original volunteer effort built the Water Watch Center, a capability that neither the federal government nor any single grant program had previously managed to assemble at scale. Because the resulting service is owned, operated, and exercised regularly by the utilities themselves, it possesses a durability that outlives any specific grant cycle. Associations and state primacy agencies should leverage the current wave of attention to guide members on what to fund second—namely, the alerting and coordination infrastructure that bridges detection to effective response—and explain why sustaining those capabilities is essential for long‑term resilience.


Closing the Gap and Looking Ahead
The Water Watch Center has successfully addressed the sector’s widest gap: the lack of basic cybersecurity visibility for the majority of small water utilities. The next, equally critical gap lies between detection and actionable response. By answering the deployment‑model question, investing in resilient alerting and coordination pathways, and grounding capabilities in utility ownership, the water sector can move from merely seeing threats to effectively containing and recovering from them—even when the internet is down. This progression will transform the Water Watch Center from a valuable first step into a cornerstone of enduring cyber‑resilience for America’s community water systems.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here