Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Tools topic

No spam. Unsubscribe anytime.

Open-source Malcolm urged as a low-cost way for water systems to detect OT cyber threats

Massachusetts Department of Environmental Protection — Drinking Water Program · March 17, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Presenters at a MassDEP webinar highlighted recent ransomware and counterfeit-PLC incidents and recommended Malcolm, a free open-source network traffic analysis suite, for asset inventories, secure logging, and OT anomaly detection; hardware costs for typical systems were estimated under $5,000.

Seth Grover, a software engineer at Idaho National Laboratory and lead developer of the Malcolm network-traffic analysis suite, urged water-system operators to deploy network logging and asset inventories to detect intrusions and rogue devices. "We want this to be something that people can install in their networks... to have network logging, to have some visibility into OT traffic," Grover said during a Massachusetts Department of Environmental Protection webinar.

The recommendation followed two recent examples discussed by Christopher Van, a cyber security technical assistance provider with MassDEP's drinking water program: a Massachusetts public water system that recovered from ransomware on a SCADA server after operators clicked a phishing link, and a New Hampshire alert about counterfeit programmable logic controllers (PLCs) that can mimic legitimate devices but may contain backdoors or fail unexpectedly. "If you buy equipment from unauthorized sources you risk devices that look like the real deal but won't have manufacturer support," Van said.

Malcolm, Grover said, is an open-source suite designed to be comparatively easy to deploy in small utilities. It can run on a single server or be paired with small sensors that capture and forward network traffic for analysis. Key uses include autopopulating an asset inventory (via NetBox integration), collecting secure OT logs for incident response, and surfacing anomalies through dashboards and visualizations. Grover noted Malcolm can be installed in air-gapped environments and that the software itself is free; he estimated that the additional hardware for a typical small system is likely to cost under $5,000.

Andrew Hildick Smith, a principal at OTSE LLC who helped introduce the tool on the call, said two priorities for utilities are maintaining an accurate OT asset list and protecting operational logs so responders can reconstruct attacks. "The first thing they're going to ask you is, 'Do you have logs?'" he said, describing how ready logs assist incident response.

Grover addressed audience questions on safe handling of suspicious emails (verify senders and headers or confirm by phone), dashboard customization (Malcolm includes numerous prebuilt dashboards and supports drag-and-drop custom views), and software provenance (the project maintains component inventories and typically issues monthly releases, with faster patches for urgent vulnerabilities). He pointed attendees to GitHub, documentation, YouTube tutorials, and a community discussion forum for installation steps and ongoing support.

The presenters framed Malcolm not as a cure-all but as one practical, low-cost tool to improve visibility into OT networks and to reduce recovery time after incidents. MassDEP staff encouraged utilities to consider assessments, training, and grants to fund hardware and implementation work.

The webinar materials include links to Malcolm documentation, installation videos, and community discussion forums; organizers said those links were posted in the event materials and chat.