Tim Pappa on Water’s Exposed Frontline
Tim Pappa spent years profiling threat actors for the FBI’s Behavioral Analysis Unit before turning to cyber deception in the private sector. He volunteers with rural water utilities through DEF CON Franklin to change how an overworked operator thinks about the odd request that comes in at 2 a.m. His message: the biggest risk to water isn’t the attacker nobody can name. It’s the vulnerability nobody’s gotten around to fixing.
“The biggest risk to water isn't the attacker nobody can name. It's the vulnerability nobody's gotten around to fixing.”
When you think about who’s attacking vital services—water, schools, hospitals—what does that adversary really look like?
There’s no prototypical threat actor. What I keep coming back to, from profiling work at the FBI, is that it’s less about who they are and more about the vulnerabilities in the organization. Groups that sound fearsome like Scattered Spider and ShinyHunters usually succeed because they have stolen credentials and a script they follow, not because the technical bar is especially high. The obstacle to unauthorized access often isn’t that big. The question I’d rather organizations ask isn’t “who’s coming for us,” it’s “what on our network would let them in.”
What makes water utilities an attractive target?
A lot of water utilities have a single public IP address, which makes them easy to find even for someone who’s just scanning out of curiosity. I use an availability, desirability, vulnerability framework to think about why an attacker picks a target. It won’t always tell you who they are, but it tells you why them. A defaced small-town library site with an extremist flag probably isn’t really about that library; it’s about what was available and undefended, not what was most desired. Apply that to water: it’s not that anyone particularly wants to hit a rural utility. It’s that they can.
What follows if someone gets in and compromises a water system?
There are several scenarios. In some operational technology environments, an attacker who gains unauthorized access could directly modify the chemical composition of the water supply in that town. There are controls and alerting, but that water supply could be tainted, harming people and, at a minimum, temporarily disrupting access to clean water. In many situations, we are talking about inconvenience and perception of an attacker’s reach, not persistent damage. Most of these water systems are in rural areas, serving smaller numbers of people.
Most attacks on critical systems happen far from public view, but the damage can reach everyone. How do we reconcile the banality of an attack with large-scale impacts like the Colonial Pipeline? Why did that one break through?
Because people didn’t realize how ordinary the failure was. That wasn’t even an operational technology compromise—it was an IT breach that led a company to voluntarily shut off fuel transport, and that decision moved prices and availability overnight. It showed people how easily disruption spreads from something mundane. That’s the pattern with critical services generally: it doesn’t take a nation-state’s full capability to cause a nation-sized headache.
“It doesn't take a nation-state’s full capability to cause a nation-sized headache.”
Water operators are engineers, not cybersecurity professionals—their job is keeping the water clean. How do you explain that the cyber threat to their networks is real?
You start with what’s already unusual to them, not with abstract threats. If a request hits their system at 2 a.m. three nights running, what do they do? Who do they call? Most don’t have a process, and that gap—not technical sophistication—is the real obstacle. We walk through it together: how to document what they’re seeing, when something crosses a threshold, who to loop in. It has to be concrete enough to fit into a day that’s already full. It’s less me as a volunteer and more them as water operators starting to model these behaviors with their peers.
You work with water operators who are already stretched thin. Is that a training gap, or is it a staffing and funding issue dressed up as a training problem?
Most operators have had to adjust to managing cybersecurity risks in addition to their own roles, and that shift has been manageable as long as security incidents or attacks remain infrequent. I have seen earnest attempts to provide more comprehensive training in cybersecurity to water operators, but when their background is not technical and they are not hired specifically for that role, it is difficult to shape a community of water operators into network defenders.
Was there a moment that felt genuinely rewarding to you?
It was not one incident—it was a slow change. I’ve worked with one water operator for about a year, and I’ve watched how differently he thinks about strange network activity now compared to when we started. He got a spear-phishing attempt spoofing someone else in his own town, and he handled it—called the right people, didn’t panic. He’s since started passing that same thinking on to others. That’s the real mechanism of change: not funding or programs alone, but one person modeling better judgment for their peers.
“That’s the real mechanism of change: not funding or programs alone, but one person modeling better judgment for their peers.”
Is that pattern—peer storytelling changing behavior—true across sectors, or is rural water different from schools or hospitals?
It holds across sectors. What doesn’t land is an outside organization telling a small hospital or school district to worry about a distant nation-state. What does land is hearing that something happened to a similar place an hour away. Schools have their own version of this: threat actors are getting younger, often starting on their own school’s network. The fix there isn’t a lecture—it’s finding an older student or young defender they’d look up to, someone with a similar skill set who can model a different direction.
If you could change one practical thing to help water operators, what would it be?
Free or low-cost Managed Service Provider support would be a game changer. We’ve already seen that shift in support in some pilot programs, where operators have an extra set of eyes and hands to guide them through incidents or events and ask questions. That kind of support can compound network defense response and management much faster than trying to train water operators to the level of seasoned network defenders.
What would be your message to help defenders secure vital services?
People stay fixated on the unknown attacker—who’s out there, how capable are they—when the more useful question is always what’s vulnerable on our own network and how we fix it. Fear of the adversary is a much less productive place to spend your attention than the work of protecting what you control.
“Fear of the adversary is a much less productive place to spend your attention than the work of protecting what you control.”