New ‘Water Watch Center’ launched to help small utilities stop cyberattacks

Seth McConnell/The Denver Post via Getty Images

The initiative comes as multiple states grapple with intrusions into their water systems that some officials suspect could be tied to Iran.

LAS VEGAS — A new program is seeking to assist water providers around the country as multiple states grapple with possible Iran-linked cyber intrusions against water infrastructure.

The Water Watch Center provides direct cyber mitigation support to utilities serving fewer than 10,000 people, which represents most of the nation’s community water systems. Launched at this year’s DEF CON hacker convention, the initiative is a joint effort between the National Rural Water Association and DEF CON Franklin, a project of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy.

More than 30 community water systems in Minnesota were targeted late last month, according to state officials. Around 12 states have reported similar activity in recent days, though state officials said they continued operating safely and experienced no known effects on public health. The FBI and Cybersecurity and Infrastructure Security Agency are working on incident response.

An initial group of five cybersecurity firms will help deliver services to water utilities as part of the initiative. 

“These leading cyber firms and NRWA are architecting a scalable cyber delivery model that has eluded water industry and national security officials to date,” Jake Braun, the co-founder of DEF CON Franklin and a former White House acting principal deputy national cyber director, said in a statement.

Retired Gen. Paul Nakasone, who led U.S. Cyber Command and the NSA from 2018 to 2024, said at DEF CON this year that water utilities around the country are highly exposed, and he pushed for higher defense standards in the sector.

“These [programmable logic controllers] should not be exposed to the internet,” he told reporters in a briefing on Friday, referring to the small computers used to operate pumps, valves and other equipment inside water facilities.

Some U.S. officials believe Iran may be responsible, though there has been no definitive public confirmation.

“I think [the government] is taking a very measured approach to make sure that they have the right actor that’s doing this,” Nakasone said when asked about why Iran hasn’t publicly been linked to the hacks

“I look at intent. I look at capability. I look at history. I’m not the person that’s making the call on the attribution, but I see an actor here that has certainly shown a history of being able to do this,” he said. “They certainly have the capability, and I think there’s an intent right now — we’re in conflict with Iran.”