Water Utilities Group Partners With DEF CON Offshoot For Water Watch Center
- Reference: 0184894012
- News link: https://it.slashdot.org/story/26/08/07/2137206/water-utilities-group-partners-with-def-con-offshoot-for-water-watch-center
- Source link:
> The program will see five managed detection and response providers work with DEF CON Franklin and the NRWA to offer cyber services for water utilities serving fewer than 10,000 people. There are over 50,000 community water systems across the U.S. and 91% of them serve fewer than 10,000 people. "These leading cyber firms and NRWA are architecting a scalable cyber delivery model that has eluded water industry and national security officials to date," said Jake Braun, the co-founder of DEF CON Franklin and former cyber official in the Biden administration.
>
> "Our incredible Franklin volunteers will support the effort to keep costs down for cash-strapped utilities fending off adversaries like the Iranian Red Guard or Chinese Military," Braun said. "To further accelerate the effort, we hand-picked cyber providers who already support water utilities. These folks walk in the door knowing the intricacies of cybersecurity in a water utility environment." The providers include Rapid7, Defendify, Legato Security, L1 Secure and Sentinel Technologies. The companies will share threat information and data on vulnerability patches with the NRWA, which will operate as a hub.
[1] https://www.prnewswire.com/news-releases/hunting-viruses-in-your-water-system-302846163.html
[2] https://therecord.media/water-watch-center-utilities-def-con-franklin-nrwa
[3] https://news.slashdot.org/story/26/07/31/209200/hackers-targeted-municipal-water-systems-in-7-states-this-week-fbi-says
Re:Working with "DEF CON" (Score:4, Informative)
The white hats understand the problem much better than most government employees. Who better to do a penetration test on poorly designed government systems?
Re: Working with "DEF CON" (Score:1)
If the DOGE children can get access, anyone can.
Re:Working with "DEF CON" (Score:4, Interesting)
Hello,
They likely already have them.
My local DEF CON group is composed mostly of active-duty military and defense contractors, many of whom have jobs that require TS/SCI and polygraph. Unsurprisingly, a lot of the discussions in the group revolve around getting CPEs and maintaining certifications.
This was a surprise to me when I started going to monthly meetings a couple of years ago, but in retrospect is probably more of the norm than an outlier: Hacking has gone from a niche subculture into a multi-billion dollar computer security industry, not just having to deal with 1980's cyberpunk threats like corporate espionage but a part of military doctrine for nation-states. It makes sense that the jobs, and the people who do them, followed those paths as well.
Regards,
Aryeh Goretsky
Regards,
Aryeh Goretsky
adversaries ...? (Score:2)
I was thinking of AI data centres as the adversaries when reading the article until I got the comical Iran part, then I stopped reading.
Or we could just stop hooking up (Score:2, Troll)
Critical infrastructure to the internet. But it's good for corporate profits when we do that because it means you can have remote monitoring on a dirt cheap Network. And corporate profits matter more than your water supply.
Comprehensive guide... (Score:1)
Comprehensive guide for internet-connected critical systems:
Don't