DEF CON hackers add new muscle to water utility protection
DEF CON's Franklin project, alongside the National Rural Water Association (NRWA), has launched the Water Watch Center, a scheme to expand free cyber-defences for small US water utilities beyond volunteer efforts. The initiative will fund managed detection and response providers, digital twins and AI agents to help utilities serving fewer than 10,000 people detect and mitigate cyberattacks, addressing the lack of a scalable national delivery mechanism for cybersecurity across an industry of roughly 150,000 mostly small operators.
The programme initially funds five security providers—Defendify, Legato Security, L1 Secure, Rapid7 and Sentinel Technologies—which will share threat intelligence with the NRWA and eventually expand to ten firms aligned with CISA's regional structure. Franklin co-founder Jake Braun said the model functions as a pyramid, with providers' sensors hunting for vulnerabilities and volunteers fixing issues or connecting utilities to support. The launch follows recent attacks by suspected Iranian hackers on small water systems that left industrial controllers exposed online with weak passwords; the project has also partnered with Vanderbilt University to build digital twins of water system environments under a DARPA-backed research programme, anticipating future AI-assisted attacks.
- DEF CON's Franklin project launches Water Watch Center for rural water cybersecurity
- Five security firms will provide detection and response services to small utilities
- Move follows suspected Iranian attacks exploiting weak water system security
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Supporters argue that inviting DEF CON-calibre security researchers to stress-test water utilities brings genuinely adversarial, real-world thinking that in-house teams often lack, and that digital twins let defenders simulate attacks without risking live systems. They see crowdsourcing scrutiny from skilled outsiders, combined with AI-assisted monitoring, as a pragmatic way to close gaps quickly in chronically underfunded, ageing infrastructure before malicious actors exploit them. For them, transparency and community involvement build public trust and resilience faster than closed, purely internal processes.
The case against
Sceptics caution that granting external hackers, however well-intentioned, deeper access to critical infrastructure creates new risks around vetting, accountability and unintended exposure of vulnerabilities before fixes are ready. They worry that leaning on AI and digital twins may create a false sense of security if these models fail to capture the messy realities of legacy operational technology, and that oversight of who controls or interprets these tools matters as much as the tools themselves. For them, security of essential services like water should rest primarily with accountable, professionally vetted personnel operating under strict governance rather than informal or loosely coordinated volunteer efforts.