As digital threats loom over crucial sectors like water, food, healthcare, and other vital services in the US, a new initiative called UnDisruptable27 is set to address cybersecurity vulnerabilities where previous efforts have faltered. The frequent occurrences of data breaches, disruptive ransomware attacks, and debilitating IT outages have become alarmingly commonplace globally. Despite these escalating threats to critical infrastructure and daily life, progress has been sporadic and often short-lived. To address this, a veteran critical-infrastructure security researcher is launching a new project at the BSides Las Vegas security conference. This project aims to engage utility operators, municipalities, and the general public in innovative ways to highlight both the urgency and potential solutions for protecting critical infrastructure.
Named UnDisruptable27, the project will begin as a pilot funded by a $700,000 grant for its first year from Craig Newmark Philanthropies’ Cyber Civil Defense coalition. Led by Josh Corman, former chief strategist for the US Cybersecurity and Infrastructure Security Agency’s Covid Task Force, in partnership with the Institute for Security and Technology (IST), the initiative will focus on the interconnected nature of water, food, emergency medical care, and power as the foundation of public safety. Corman emphasizes that the primary objective is to spark new conversations about these challenges, guided by the disaster management principles of “inform, influence, inspire.” Essentially, people need to understand the risks and feel empowered to take action.
“We are overdependent on undependable things. No one should feel comfortable with the potential for harm given our current state of defense,” Corman told WIRED. “Our reliance on connected technology has outpaced our ability to secure it. People have been making positive efforts, but public policy moves slowly. This year, we need to heighten the sense of urgency.”
One of Corman’s motivations for swiftly launching the project stemmed from statements made during a January congressional hearing about the cybersecurity threat China poses to the US. During this hearing, top officials including then Cyber Command head and NSA director Paul Nakasone, Cybersecurity and Infrastructure Security Agency director Jen Easterly, FBI director Christopher Wray, and National Cyber Director Harry Coker Jr. highlighted specific campaigns by the Chinese hacking group Volt Typhoon targeting US water infrastructure. This targeting aims to create leverage and a credible threat as part of China’s plans to invade Taiwan, potentially by 2027.
“The budgets currently being discussed will determine the resources available in 2027, a year that the CCP has marked on its calendar,” Wray informed the US House of Representatives committee in January. “That year will arrive sooner than we think. While we can protect ourselves, we cannot afford to ignore this danger.”
Corman, having extensive experience in embedded device security and critical infrastructure defense, including his grassroots initiative I Am the Cavalry, found it significant that top intelligence officials were warning Congress about specific threats to US infrastructure in an unclassified setting.
“It’s not just about the water going out; when the sole wastewater facility in your community fails, really bad things happen. For instance, no water means no hospital,” he explains. “During my leadership of the Covid Task Force, I saw how interdependent the basic functions of society are.”
UnDisruptable27 will focus on engaging with communities that aren’t typically involved in Washington, DC-based policy discussions or Information Sharing and Analysis Centers (ISACs), which represent various US infrastructure sectors. The project aims to directly communicate with those working on the ground in critical infrastructure, addressing the reality that cybersecurity-related disasters could disrupt their daily operations.
“There’s a perception that after a data breach, life just goes on without long-term impacts,” says Megan Stifel, IST’s chief strategy officer. “We’re keen on tackling critical infrastructure security with perhaps a new approach.”
Corman notes that despite the common occurrence of cybersecurity incidents, business owners and infrastructure operators are often surprised when directly affected. Meanwhile, government efforts to impose cybersecurity standards are frequently met with resistance. For instance, the US Environmental Protection Agency had to rescind new cybersecurity guidelines for water systems after facing legal challenges from water companies and Congressional Republicans.
“Repeatedly, trade associations, lobbyists, and operators resist oversight, preferring voluntary measures, claiming they’re managing fine on their own,” Corman says. “Yet, time and again, people are blindsided by disruptions. This shows that those most affected are not included in the conversation. They need to understand the risks of our connectivity. We’ve tried many approaches, but we haven’t tried just being straightforward with people.”
UnDisruptable27 is launching this week for visibility at BSides and other conferences like Black Hat and Defcon in Las Vegas. Corman aims to combine the hacker mentality with a call for volunteers, working with creative collaborators to produce engaging content that drives understanding and discourse. Information campaigns using memes, social media, narrative podcasts, and even reality TV are all potential strategies.
“We must prioritize the security, safety, and resilience of critical infrastructure—including water, healthcare facilities, and utilities,” says Craig Newmark, the Craigslist founder funding UnDisruptable27. “The urgency of this issue requires influencing human behavior through storytelling.”



