NRWA Launches the Water Watch Center to Strengthen Cybersecurity for Rural Utilities In response to growing cyber threats targeting U.S. water infrastructure, the National Rural Water Association (NRWA) and DEF CON Franklin have launched the Water Watch Center (WWC), a new initiative designed to help small water and wastewater utilities defend against cyberattacks. The announcement was made at the DEF CON cybersecurity conference in Las Vegas on August 7. The Water Watch Center will provide direct cybersecurity support to utilities serving fewer than 10,000 people, which represent approximately 91% of the nation's community water systems. The program aims to strengthen cyber defenses, improve threat detection, and help utilities respond to security incidents before they impact operations and public health. Five cybersecurity firms have joined the effort, including Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies. These partners will collaborate by sharing threat intelligence, security updates, and best practices through a centralized network coordinated by NRWA. The initiative builds on a two-year project led by DEF CON Franklin that connected nearly 450 volunteer cybersecurity professionals with water and wastewater systems in several states. Lessons learned from those efforts highlighted the need for a scalable cybersecurity support model tailored to small and rural utilities. In addition to the Water Watch Center, NRWA continues to provide cybersecurity resources, training, advisories, and technical assistance through its National Rural Water Cybersecurity Center. The association is also advocating for a federal Cybersecurity Circuit Rider Program to bring on-the-ground cybersecurity expertise directly to rural utilities. As cyberattacks against critical infrastructure become more frequent and sophisticated, the Water Watch Center offers rural water systems access to specialized expertise and coordinated support to help protect essential water and wastewater services. Further Reading... Hunting Viruses in Your Water System | DEF CON Franklin DEF CON hackers launch Water Watch Center to defend small water utilities | SiliconANGLE Water Watch Center Launched to Defend Utilities Against Foreign Hacks | HSToday August 19, 2026 By Katelyn McLaughlin Emergency Response, Security cyberattacks, cybersecurity, cybersecurity support 0 0 Comment Read More »
Cybersecurity Threats: Lessons Learned from WaterISAC In July of 2024, WaterISAC sent out an advisory to its members advising them to take caution when opening emails from seemingly "trusted" sources. This was sent after WaterISAC was made aware of a second phishing attempt against Maine water operators and well drillers that was disguised as an information verification form from Maine.gov. A screenshot of the attempted phishing email is shown below: Now that phishing attempts are so common across the water sector, it is important to be vigilant when opening emails and clicking any links within. WaterISAC provided a list of lessons that can be learned from incidents like this, as well as resources to help water and wastewater systems get guidance on how to strengthen cybersecurity measures. These lessons and resources are shared below: Lessons Learned Share Information on Threats. In these cases, state agencies quickly sent out a broadcast alert to targeted audiences warning of the phishing attempt. Open-Source Intelligence (OSINT). There is a lot of information on the internet about our water systems. It is useful to know what public information is available. In some cases, detailed and sensitive information can be removed. In other cases, the information is intentionally part of the public record. Therefore, we need to be aware of this class of data so we are not fooled into trusting whoever has it because we believe only privileged sources have access to it. Practice Phishing Drills. Part of every utility’s cybersecurity awareness training should include regular phishing drills for staff. CISA has free resources to assist, such as, Teach Employees to Avoid Phishing. Not Sure, Call. If you are not sure that the source of an email is legitimate, call the supposed sender through previously established phone numbers to confirm the request’s validity. Fall for a Phish, Contact Your IT Department. If you realize after the fact that you fell for a phishing email, or you think you might have, call your information technology group to find out what to do. Everyone except the attacker, will be glad you did. Additional Water and Wastewater Systems Sector Guidance Resources: Recognize and Report Phishing | CISA Cybersecurity Fundamentals for Water and Wastewater Utilities | WaterISAC Top Cyber Actions for Securing Water Systems | CISA Water and Wastewater Sector - Incident Response Guide | CISA CISA's Free Cyber Vulnerability Scanning for Water Utilities | CISA Water and Wastewater Cybersecurity | CISA July 23, 2024 By Katelyn McLaughlin Emergency Response, Security cyber attacks, cyberattacks, cybersecurity, phishing attempts 0 0 Comment Read More »