DEF CON Franklin, NRWA Launch Water Watch Center for Rural Utilities
The National Rural Water Association (NRWA) has launched a new partnership with DEF CON Franklin to establish the Water Watch Center (WWC), a program aimed at delivering threat intelligence and managed cybersecurity services to underfunded water and wastewater utilities across the United States. The initiative responds to a growing wave of cyberattacks on operational technology (OT) environments at water systems in at least 12 states, with recent incidents reported in Minnesota, Michigan, Georgia, South Dakota, and two New Jersey towns. Given that 91% of the country's 50,000 community water systems serve fewer than 10,000 people, the program targets the most vulnerable segment of the U.S. water infrastructure, where dedicated IT and security staff are often nonexistent.
Under the program, five managed detection and response providers—Rapid7, Defendify, Legato Security, L1 Secure, and Sentinel Technologies—will collaborate with DEF CON Franklin and NRWA to deliver incident response support, vulnerability patching data, and shared threat intelligence to small utilities. NRWA will operate as the central hub aggregating this information. "These leading cyber firms and NRWA are architecting a scalable cyber delivery model that has eluded water industry and national security officials to date," said Jake Braun, co-founder of DEF CON Franklin and former Biden administration cyber official. The center has already begun work in Maryland to identify rural systems in need, with priority given to facilities supporting military installations. Operators concerned about their own exposure can run a port scanner to identify open services that may be visible to adversaries.
DEF CON Franklin, launched two years ago by veterans of the DEF CON security conference, has recruited roughly 450 volunteer cybersecurity experts and previously paired them with utilities in Arizona, Indiana, Oregon, Utah, Vermont, Washington, and Wyoming. The campaign currently linked to Iranian state-sponsored actors—referenced by Braun as the "Iranian Red Guard" and "Chinese Military"—continues to expose how easily under-resourced utilities can be compromised through exposed OT interfaces and unpatched remote access tools. For security teams tracking related infrastructure exposures, an SSL/TLS checker can help verify whether web-facing utility management portals have properly configured encryption.
Scaling cybersecurity to the nation's estimated 150,000 water and wastewater systems—including 100,000 public systems serving schools, hospitals, factories, and campgrounds—remains the central challenge. By combining volunteer expertise with commercial MDR capacity, the WWC represents one of the first structured attempts to address that gap at a national level. Utilities and supply-chain partners can also use a email breach checker to assess whether credentials tied to administrative accounts have appeared in known compromise datasets, a common initial access vector in the recent OT intrusions.