Funding Cybersecurity Vendors to Secure Rural Water Systems

0
3

Key Takeaways

  • The DEF CON Franklin project is funding free managed detection and response (MDR) services for U.S. water utilities serving fewer than 10,000 people, which represent over 90 % of the nation’s 50,000 community water systems.
  • Five MDR vendors—Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies—will deploy their tools and feed threat data into a new Water Watch Center run by the National Rural Water Association (NRWA).
  • Volunteer experts will help utilities interpret alerts, fix vulnerabilities, or request hands‑on assistance, addressing the chronic lack of IT staff at small utilities.
  • The program is currently seeded by grants from Craig Newmark, but scaling to “tens of thousands” of utilities will require substantial federal investment, potentially through amendments to the Farm Bill’s NRWA contract.
  • Without government support, organizers warn that many small water systems will remain highly vulnerable to cyberattacks, including recent Iran‑linked intrusions.

Background on Water Utility Cyber Risks
Small water utilities are among the most digitally exposed critical‑infrastructure entities in the United States. Serving populations under 10,000, they often lack dedicated cybersecurity staff, outdated assets, and limited budgets for sophisticated defenses. Recent incidents linked to Iranian threat actors have demonstrated how attackers can manipulate treatment processes, jeopardize public health, and erode confidence in essential services. These events underscore a systemic gap: while larger utilities can afford dedicated security operations centers, the majority of community water systems operate with minimal or no continuous monitoring, leaving them ripe for exploitation.

Launch of the DEF CON Franklin MDR Initiative
At the DEF CON cybersecurity conference in Las Vegas, the volunteer‑driven Franklin project announced a new effort to subsidize MDR services for small water utilities. By paying commercial security firms to provide monitoring, detection, and response tools at no cost, Franklin aims to close the visibility gap that has left many utilities blind to intrusions. The initiative marks a shift from advisory volunteer work to direct funding of professional cybersecurity capabilities, reflecting the organizers’ belief that scale can only be achieved through sustained, resourced support.

Participating MDR Vendors
The initial cohort comprises five established MDR providers: Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies. Each company brings a distinct approach to threat hunting, endpoint protection, and incident response, allowing Franklin to evaluate which models work best in the water sector’s unique environment. Their prior experience serving water utilities gave them insight into sector‑specific protocols, such as SCADA‑related traffic patterns and regulatory reporting requirements, facilitating a smoother onboarding process for participating systems.

Function of the Water Watch Center
All MDR data will be aggregated in a new Water Watch Center operated by the National Rural Water Association. The center will normalize, anonymize, and analyze threat intelligence collected from the participating utilities’ networks. By centralizing this information, Franklin hopes to create a shared situational awareness picture that can reveal emerging tactics, techniques, and procedures (TTPs) targeting water infrastructure. The center will also serve as a conduit for disseminating actionable insights back to utilities and to broader information‑sharing bodies like WaterISAC.

Operational Flow from Detection to Remediation
When an MDR agent on a utility’s network detects anomalous behavior—such as unauthorized login attempts, malware signatures, or unusual SCADA commands—the vendor issues an immediate alert accompanied by a detailed report. The utility’s personnel can then attempt remediation using the report’s guidance. If the internal team lacks expertise or bandwidth, they may escalate the case to Franklin’s volunteer roster, which includes cybersecurity professionals willing to provide hands‑on assistance, configuration tweaks, or forensic analysis at no charge. This tiered response model is designed to maximize utility autonomy while ensuring expert help is available when needed.

Scale Challenge and Jake Braun’s Perspective
Jake Braun, executive director of the University of Chicago’s Cyber Policy Initiative and a lead organizer of Franklin, emphasized that the core obstacle is scaling delivery of cybersecurity services. “Scaling delivery of cyber is where all the challenges fall,” he noted during a Friday interview at DEF CON. While volunteer efforts can address isolated gaps, achieving nationwide coverage requires a systematic, funded approach that can consistently provision monitoring tools, threat intelligence, and expert support to thousands of disparate systems.

Evolution of Franklin’s Work
Before the MDR announcement, Franklin focused on deploying volunteers to help utilities implement basic hygiene measures: password policies, network segmentation, asset inventories, and incident‑response planning. Those activities laid groundwork but were limited by the volunteers’ availability and the utilities’ capacity to act on recommendations. The new funding model represents a logical progression—shifting from advisory assistance to sustained, paid protection that can operate continuously, independent of volunteer schedules.

Vendor Selection Criteria
Franklin chose the five initial MDR partners because each already serves a subset of water utilities, giving them familiarity with sector‑specific constraints such as limited bandwidth, legacy OT systems, and regulatory compliance demands. This existing foothold reduces the learning curve for both vendors and utilities, accelerates deployment, and improves the likelihood that the services will be well‑tuned to the operational realities of small water plants.

Recruitment Strategy and Vendor Incentives
Franklin volunteers will manage the logistics of connecting utilities to their chosen MDR provider, a step Braun identified as one of the most expensive and time‑intensive parts of the process. By handling outreach, contract negotiation, and initial configuration, volunteers lower the barrier for utilities that might otherwise shy away from complex procurement. Vendors, in turn, gain a financial incentive to recruit additional utilities: each new customer expands their market footprint within a sector that is poised for growth as federal cybersecurity mandates tighten.

Partnership with Maryland Cybersecurity Program
As an early proof‑of‑concept, Franklin has partnered with Maryland’s statewide cybersecurity program to onboard rural utilities in that state. This collaboration demonstrates how state‑level resources can complement federal initiatives, providing a template for replication elsewhere. Maryland’s involvement also helps validate the MDR workflow, from alert generation to volunteer escalation, before a national rollout.

Threat Intelligence Sharing with WaterISAC
The Water Watch Center intends to feed anonymized threat data into WaterISAC, the water sector’s information‑sharing and analysis center. Braun explained that the team is working on techniques to strip personally identifiable or operationally sensitive details while preserving the tactical value of the indicators. This approach balances the need for collective defense with utilities’ concerns about exposing configuration specifics that could be leveraged by adversaries.

Limitations of Guidance Implementation
Even when federal agencies like CISA and WaterISAC publish best‑practice guidance, many small utilities struggle to put it into practice. Braun recounted a recent encounter with a utility staffed by just two employees—one of whom also organized the town’s Fourth of July parade. “We can send them alerts all day and do all the assessments we want, but there’s nobody to go do anything with it,” he said. This stark reality underscores why merely distributing information is insufficient; utilities need concrete support to act on alerts and implement remediation steps.

Funding Model and Seed Money
Initial seed money for the MDR program and Water Watch Center came from Craig Newmark, the founder of Craigslist and a noted cybersecurity philanthropist. Braun noted that the current funding sustains the pilot phase but will be inadequate for scaling to the tens of thousands of utilities Franklin hopes to reach. To achieve that ambition, the project is awaiting word on two additional “massive grants” that could substantially expand its financial runway.

Call for Federal Government Support
Braun argued that eventual federal involvement is inevitable and essential. He pointed out that Congress already channels funds to rural water systems through the NRWA under the Farm Bill. “They can just change the number,” he said, suggesting that a modest amendment to existing legislation could earmark money specifically for cybersecurity services. Without such federal backing, Braun warned, the initiative’s impact would remain limited, leaving many small utilities exposed.

Franklin’s Advocacy Plans
In response, Franklin intends to intensify its outreach to congressional offices, educating lawmakers about the heightened risk posed by cyber threats to drinking‑water infrastructure. By highlighting real‑world incidents and the tangible benefits of continuous monitoring, the group hopes to build bipartisan support for a dedicated funding stream. Braun believes that framing water cybersecurity as a non‑partisan public‑safety issue will improve the odds of legislative action.

Warning of Inaction
Should the government fail to step in, Braun was blunt: “None of this is going to work, [and] these water utilities are going to be [screwed],” using a stronger term than “screwed” to convey the severity of the risk. His statement captures the urgency felt by many in the cybersecurity community: without sustained investment, the nation’s smallest water providers will remain attractive targets for nation‑state and criminal actors alike.

Conclusion and Outlook
The DEF CON Franklin MDR initiative represents a promising model for bridging the cybersecurity gap that plagues America’s small water utilities. By combining commercial MDR tools, centralized threat intelligence, and a volunteer‑based escalation path, the program addresses both detection and response challenges. Yet its long‑term viability hinges on securing reliable, scalable funding—most plausibly through federal action that leverages existing rural‑water financing mechanisms. If successful, the effort could set a precedent for how public‑private partnerships safeguard other critical‑infrastructure sectors facing similar resource constraints.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here