TL;DR: On Friday at DEF CON 2026, DEF CON Franklin and the National Rural Water Association launched the Water Watch Center, a free managed security service for roughly 150,000 US water and wastewater utilities. The first five MSSPs are Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies, with a plan to expand to ten across the ten CISA regions. Suspected Iranian hackers have already hit small, community water systems whose programmable logic controllers sit directly on the internet behind default or weak passwords, and the country has a 500,000-person cybersecurity workforce shortfall. The center is the first time a DEF CON volunteer program has stood up a paid-MSSP delivery model at federal-scale reach.
What Just Launched
DEF CON Franklin and the National Rural Water Association launched the Water Watch Center at DEF CON 2026, The Register reported on August 10. The center will route CISA and ISAC alerts through five initial managed security service providers, with plans to scale to ten, one for each of the ten CISA regions, in the near term [1].
The five initial MSSPs: Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies. The first target population is utilities serving fewer than 10,000 people, which is most of them. Of the roughly 150,000 community water and wastewater systems in the United States, 98% are small businesses, Jake Braun, who co-founded the Franklin project at DEF CON in 2024, told The Register [1].
Braun described the structure as a pyramid. The National Rural Water Association sits at the top, providing technical assistance and operational support to small water and wastewater utilities in all 50 states. The five MSSPs form the middle layer, with sensors hunting for vulnerabilities across the utility networks. The Franklin volunteers are the base, fixing the issues the MSSPs flag or responding to the alerts the center pushes down [1].
The launch comes two years after Braun started Franklin at DEF CON 2024. That year, 350 volunteers signed up. The realization since: volunteer hours cannot scale to 150,000 utilities, but a small fleet of MSSPs can. "We groped around in the dark for what to do, and eventually realized we already know how to do security for small businesses. It's MSSPs," Braun told The Register. "So why don't we just do that?" [1]
Why Small Water Systems Are the Soft Spot
US critical infrastructure has a small-business problem. A municipal water utility serving 3,000 customers does not have a CISO. It does not have a 24x7 SOC. It often has a single IT generalist who is also doing billing, and it runs the same kind of programmable logic controllers a large utility runs, except the controllers are sitting on the public internet behind default or weak passwords [1][2].
Six federal agencies, the FBI, CISA, NSA, EPA, the Department of Energy, and Cyber Command's Cyber National Mission Force, warned in April 2026 that Iranian IRGC-linked hackers operating as CyberAv3ngers had been actively breaking into Rockwell Automation PLCs at US water plants, energy facilities, and government buildings since at least March 2026. The attackers were not exploiting exotic vulnerabilities. They were logging in [2].
The Register's reporting this week confirms the pattern is still active. Suspected Iranian hackers have recently hit "numerous" small, community water systems whose PLCs are exposed directly to the internet using default or weak passwords. The Register notes there is no indication AI was used in these attacks, but that cybersecurity experts it consulted said it is only a matter of time [1].
That is the operational gap the Water Watch Center is trying to close. Braun's framing in The Register: "There's just not a scalable delivery mechanism for cyber for these utilities when there's 150,000 of them, and 98 percent of them are small businesses." The center's value proposition is to be the delivery mechanism. It is also, by design, a national surveillance layer for the operational technology those utilities run, a fact Braun and the partners treat as a feature, not a bug, because the alternative is the attackers owning the layer instead [1].
The AI Layer: DARPA CASTLE, Vanderbilt, and Digital Twins
The Water Watch Center is not just MSSPs. It is also a research front. The center is partnering with Vanderbilt University to use research from DARPA's Cyber Agents for Security Testing and Learning Environment (CASTLE) program to build digital twins of water and wastewater environments, then run automated red-team attack agents against blue-team defenders in the simulated setting [1].
The training loop Braun described to The Register: "They let it fight each other a gazillion times, and then they figure out when does the blue team win." The goal is to produce AI agents trained on the digital twin simulations that can later be deployed against the 150,000 real utilities. The framing in the article is that this is how you scale cyber defense when there is no other way to scale it [1].
The 500,000-person shortfall Braun cites is the constraint. "There's already a 500,000-person shortage of cyber professionals. The idea that we're magically going to find 150,000 new people is a fantasy," he told The Register. The article frames the CASTLE-trained agents as filling the gap the workforce cannot, which is the same argument federal AI-in-cyber programs are now making at the CISA and DOD level. The surveillance-state shape of the answer is the same: when humans cannot watch the network, the AI watches the network [1].
Why This Is a Privacy Story, Not Just a Cyber One
Water utilities are not just operational technology. They are also holders of customer data. A compromised water utility is, among other things, a compromised customer database. The April federal advisory on the CyberAv3ngers intrusions flagged "operational disruptions and financial losses." The privacy dimension is the part that does not always make the CISA alert [2].
The Water Watch Center is also a new entry point into those networks. MSSPs at this scale will, by definition, sit inside the operational technology of tens of thousands of small utilities. The data they collect on customer and network behavior will be substantial. The Register does not detail what the center retains, who has access, or how the alerts route through CISA and the ISAC. Those are the next set of questions the program will face, and they are the same questions the federal government has had to answer for every other scaled cyber defense [1].
The civil-society framing of the program is the cleanest part. DEF CON's volunteers, the National Rural Water Association's existing operator relationships, and a fleet of named US MSSPs are pooling capacity to defend utilities the market and the federal government have both failed to defend. The April advisory identified the threat and named the victims. The Water Watch Center is the first nationally-scaled response the threat has received that is not another federal procurement. That, more than the AI or the MSSP names, is why this story matters [1][2].
What to Watch
Whether the MSSP count reaches ten by end of 2026. The plan is to align one MSSP per CISA region. The first five are named; the next five are not [1].
Whether the IRGC intrusions pause, escalate, or migrate to the defended systems. The Register's reporting is that Iran-aligned hackers are still active against the small water systems. The first defended utility to publicly disclose a blocked attack is the cleanest measure of program effectiveness [1].
What the CASTLE-trained agents actually look like in production. Digital twin training is one thing. Dropping AI agents into live operational technology networks is a different risk profile, especially at scale. Watch the first red-team debrief from a real utility [1].
Whether the federal advisory list grows beyond six agencies. The April advisory on CyberAv3ngers was the joint signature of FBI, CISA, NSA, EPA, DOE, and Cyber Command. A second advisory from a different set of attackers would force a reckoning on whether civil-society MSSPs are enough [2].
Sources
- The Register, Jessica Lyons: DEF CON hackers add new muscle to water-utility protection (August 10, 2026). https://www.theregister.com/security/2026/08/10/def-con-hackers-add-new-muscle-to-water-utility-protection/5285715
- State of Surveillance: Iran is already inside U.S. water and energy systems, the brief on the April 2026 six-agency advisory (AA26-097A) and the CyberAv3ngers intrusions. /news/iran-cyberav3ngers-plc-water-energy-infrastructure-attack-2026