Beta
Podcast cover art for: The hackers fighting to keep our water safe
Science Quickly
Scientific American·02/09/2026

The hackers fighting to keep our water safe

This is a episode from podcasts.apple.com.
To find out more about the podcast go to The hackers fighting to keep our water safe.

Below is a short summary and detailed review of this podcast written by FutureFactual:

Defcon Franklin and Volunteer Hackers Protect United States Water Utilities from Cyber Attacks

Overview

In this Science Quickly episode, Rachel Feltman speaks with Eric Geller about the vulnerability of municipal water utilities to cyber threats and the emergence of DEFCON Franklin, a volunteer-driven effort to bolster security in water systems and other critical infrastructure.

Key insights

  • Water systems face unique cybersecurity challenges due to aging, bespoke hardware and limited staff capacity in rural and small utilities.
  • DEFCON Franklin connects volunteers with infrastructure operators to implement basic protections like multi factor authentication and network inventory, illustrating grassroots resilience.
  • There is a consensus that volunteer efforts cannot replace federal and state funding for sustained cybersecurity investments.
  • The initiative highlights trust-building between utilities and volunteers through a Rural Water Systems association and careful vetting.

Introduction and context

The podcast features a discussion with Eric Geller, a senior reporter focusing on federal cybersecurity policy and critical infrastructure protection, about why municipal water utilities are attractive targets for cyber attackers and how a grassroots model is attempting to close security gaps. The conversation begins with a broad definition of cyber threats, spanning social engineering to exploiting software vulnerabilities and the interdependencies of the supply chain. The guest explains that water utilities are often small, underfunded, and operating antiquated technology that cannot be easily upgraded. Bespoke, non off the shelf devices with login systems that rely on default passwords create fertile ground for breaches. The risk is not just technical but organizational, requiring both secure systems and informed operators who understand cyber risk.

Why water utilities are vulnerable

The core reasons include limited staff for security, old technology, and bespoke software that is hard to harden or upgrade. Rural and small urban systems struggle with security budgets, leaving devices exposed to the internet and easy-to-guess login credentials. The discussion emphasizes how even basic protections—like changing default passwords and implementing multi factor authentication—can significantly raise the barrier to intrusion, yet many facilities lack the resources or expertise to implement them widely. Geller underscores that the vulnerability is a systems problem, not a single failing device, involving a patchwork of hardware, software, and human factors.

DEFCON Franklin: origin, purpose and approach

Defcon Franklin grew out of the DEF CON hacker conference in 2024 as a spinoff designed to pair cybersecurity experts with infrastructure operators who lack cybersecurity expertise or money for upgrades. The initiative focuses on targeted improvements such as understanding devices on networks, implementing multi factor authentication, and discovering all devices on the network. The program is not a substitute for government funding but a bridge toward stronger practices while advocates call for federal and possibly state support for sustained cybersecurity funding. The host notes that the project mirrors a Cold War era notion of cyber civil defense, with universities, philanthropists, and student volunteers contributing to community resilience.

Community voices: success stories from the field

The guest highlights a rural Idaho example Wilder, where a public works director engaged with a volunteer from Defcon Franklin. The director describes how initial uncertainty about cybersecurity transformed into concrete changes and a culture of knowledge sharing. By learning about network topology, login security, and basic protections, the town gained peace of mind. The director then shared what she learned with other rural communities, illustrating how knowledge diffusion can occur through local networks. This story demonstrates how even basic measures can raise the town’s resilience and that community-level learning can propagate protective practices beyond a single installation.

Trust, expectations, and program design

A central challenge for the program is aligning the volunteers’ ambitious goals with utilities’ practical constraints. Defcon Franklin vets participants through a Rural Water Systems association to establish trust and legitimacy. Utilities are often understandably wary about who has access to their systems; the association acts as an intermediary to vet volunteers and advocate for the program. The volunteers’ approach emphasizes collaboration and learning rather than imposing sweeping changes, thereby increasing acceptance and effectiveness. The piece also notes a tension between demonstrations and real-world operations, suggesting that some utilities want to see tests show them already secure, while volunteers propose implementing foundational security improvements first to enable meaningful testing.

Lessons about technology offers and funding

The podcast discusses how offers from large technology vendors to provide free security products often overlook ongoing costs such as monitoring, interpretation of data, and staff time needed to manage and respond to security signals. Franklin researchers found that many small systems cannot capitalize on these offers due to staffing and the hidden expenditures required to keep devices functional and secure in the long term. This nuance challenges the notion that technology freebies alone can solve the problem and underscores the need for sustained funding and support from federal and state sources to institutionalize cybersecurity across water utilities.

Motivation, relationships, and future outlook

Jake Braun, who leads DEFCON Franklin, emphasizes the volunteers’ commitment, many of whom grew up in rural areas and understand the budgetary constraints faced by small utilities. The initiative’s success hinges on building trust, arranging clear expectations, and facilitating consistent, repeatable improvements across multiple facilities. Looking forward, organizers insist that volunteer efforts must be complemented by government funding and supportive policies to expand cyber civil defense for critical infrastructure. The engagement model also points toward broader support systems where universities run clinics and philanthropic groups subsidize efforts to bring cybersecurity to water systems and hospitals that otherwise cannot afford it.

Concluding reflections

The program embodies a civic participation ethos, drawing on Benjamin Franklin’s spirit of mutual aid while acknowledging the need for public funding. It presents a pragmatic, community-centered path to resilience that buys time for ordinary utilities while policy makers and funders address long-term structural investment in cybersecurity. The podcast closes with a sense of momentum, driven by volunteers who see tangible benefits in their communities and a growing recognition that protecting potable water requires both grassroots action and sustained public support.