Critical Infrastructure Security

The Water Watch Center promises the cyber protection small water utilities need

Biological water treatment plant with a round settlers

COMMENTARY: The recent and alarming news that unspecified threat actors targeted water utilities in at least 12 states across the U.S. has driven an urgent renewed focus on safeguarding the critical water infrastructure millions of Americans rely on daily.

That effort must begin with fundamental cyber hygiene and the operational capacity to execute it consistently at scale.

However, achieving true long-term resilience across all tiers of public infrastructure, especially for small, rural, and under-resourced water facilities, requires significant changes, particularly in specialized training, real-time threat intelligence sharing, and sustainable funding.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

That’s precisely why the announcement at DEFCON last week regarding the launch of the Water Watch Center (WWC) by DEF CON Franklin and the National Rural Water Association (NRWA) stands as a great milestone.

The initiative directly targets the structural and operational gaps that have long left smaller utilities acutely vulnerable to both opportunistic threat actors and sophisticated nation-state campaigns.

Scale has become the most glaring challenge facing critical infrastructure security today. Roughly 91% of the approximately 50,000 community water systems operating in the U.S. serve populations under 10,000 residents.

These small systems frequently operate on razor-thin municipal budgets with virtually zero dedicated IT workers let alone high-priced cybersecurity personnel. While larger metropolitan water authorities can turn to in-house teams or commercial managed security service providers (MSSPs) to handle network defense, small rural districts simply lack the financial capital to do so.

Often there are no cybersecurity workers and no cybersecurity budget. The WWC directly solves this imbalance by aiming to function as a centralized operational hub, delivering specialized, enterprise-grade defenses straight to rural operators without requiring them to hire or maintain in-house security teams.

Furthermore, small water utilities represent uniquely delicate and unforgiving operational technology (OT) environments. Gaining deep visibility into industrial control systems (ICS) and legacy programmable logic controllers (PLCs) without causing unexpected service shutdowns remains one of critical infrastructure’s greatest technical hurdles. Legacy PLCs running water treatment processes are notoriously fragile. Running standard IT vulnerability scans—such as active Nmap port sweeps—can easily crash a controller, freeze serial communications, or trigger unintended valve actions that disrupt water flow.

The WWC addresses this environment by emphasizing actionable, non-disruptive threat monitoring and information sharing. Operating with the NRWA as its central national hub, the program facilitates threat-intelligence sharing across participating managed detection and response (MDR) providers and municipal utilities. As a result, an anomaly or malicious footprint detected at one facility immediately informs defenses across the entire national network.

This structure marks a decisive shift from traditional Information Sharing and Analysis Centers (ISACs), which primarily operate in advisory and high-level policy roles.

While ISACs produce vital sector-wide alerts, they rely on member organizations to digest the data and apply patches themselves. By pairing rapid threat intelligence with concrete, hands-on remediation plans, the WWC offers the operational execution layer that an ISAC was never meant to deliver. Without question, this direct operational approach can help blunt the impact of coordinated cyber campaigns and significantly accelerate recovery if an attack occurs.

The WWC also tackles the sector's financial barrier head-on through an innovative hybrid delivery model. By leveraging philanthropic seed funding and grants, participating MDR providers deliver commercial software and 24/7 security operations center (SOC) monitoring to small utilities at no direct cost.

When paired with nearly 450 DEF CON Franklin volunteer cyber experts who offer the human labor required to execute field assessments and remediation plans, the initiative drastically lowers the cost for small municipalities seeking cyber resilience.

Looking at long-term technological advancement, the WWC’s initiative around building "digital twins" promises immense strategic payoffs. To test aggressive threat detection techniques and automated AI responses without risking physical plant equipment, the WWC constructs virtual duplicates of utility control systems.

As emergency mitigation strategies increasingly lean on AI models to generate short-term virtual patches, the ability to safely evaluate these patches in a digital twin prior to live deployment has become vital for public safety. This sandbox environment lets red and blue AI defense agents interact dynamically, ensuring that only field-proven, zero-risk techniques are ever introduced into physical water treatment plants.

Nevertheless, the remaining challenges are significant: we need to understand that the WWC is mainly a pilot project meant to establish a scalable foundation.

Here are at least three challenges: First, while private philanthropy can launch a proof-of-concept, alternative and permanent funding mechanisms—such as dedicated federal or state appropriations—must be established to scale coverage across the nation's 50,000+ small water systems. Second, relying on volunteer labor inherently carries long-term limits regarding burnout and retention in a domain that demands continuous, 24/7 efforts. Finally, the WWC operates outside of mandatory regulatory frameworks. Unlike the bulk electric grid that’s strictly governed by mandatory NERC-CIP standards, the water sector continues to operate under voluntary guidelines that vary dramatically from town-to-town.

Despite these operational and regulatory headwinds, the WWC offers a compelling and urgently needed blueprint for public-interest cybersecurity. By bridging the gap between high-level threat intelligence and hands-on, ground-level operational support, the initiative demonstrates how vendor partnerships, philanthropic seed capital, and technical volunteer talent can effectively combine to shield the nation’s most vulnerable municipal assets.

Federal policymakers and industry leaders must now build upon the WWC’s momentum—securing sustainable funding streams and formalizing governance frameworks to ensure that every American community, regardless of size, benefits from a secure, resilient, and uncompromised water supply.

John Gallagher, vice president, Viakoo

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds