Cybersecurity Roundup: Visa, BioCatch, Salam and DEF CON Confront Fraud, AI and Critical-Infrastructure Risk
Cybersecurity is moving deeper into the infrastructure that keeps economies and communities functioning.
Visa’s $2.4 billion BioCatch acquisition demonstrates the growing value of behavioural intelligence in fighting financial fraud. Saudi telecommunications provider Salam has secured regulatory approval to expand its managed-security operations, while the DEF CON Franklin initiative is helping resource-constrained rural water utilities address fundamental vulnerabilities.
At the same time, operational-technology specialists are calling for binding US cybersecurity requirements following disruptive attacks on water systems. The debate surrounding artificial intelligence is also becoming inseparable from geopolitical competition, as policymakers weigh safety, security and the consequences of falling behind China.
DEF CON Franklin brings volunteer cyber expertise to rural water utilities
A pioneering volunteer programme is helping small American water systems improve their cybersecurity without expecting them to deploy enterprise-scale technology or employ dedicated security teams.
Launched in late 2024, DEF CON Franklin connects volunteer cybersecurity professionals with rural water utilities through a partnership involving the DEF CON community, the University of Chicago’s Harris School of Public Policy and the National Rural Water Association.
The programme takes its name from Benjamin Franklin’s role in establishing the first volunteer fire company in the United States. Its cybersecurity model is similarly based on organised specialists providing practical assistance where permanent professional resources are unavailable.
According to an in-depth report from Cybersecurity Dive, Franklin has deployed 27 volunteers across 21 utilities in seven states. Six utilities remain actively engaged with the programme, including five that participated in its original pilot.
The work frequently starts with foundational controls rather than sophisticated threat-detection platforms. Volunteers help operators change default passwords, introduce multifactor authentication, document incident-response procedures and map networks containing equipment installed over many years.
Network documentation is particularly important in the water sector. External contractors may install operational equipment and depart without leaving a complete inventory of devices, connections and dependencies. Utility employees can consequently be responsible for systems whose configuration and exposure they do not fully understand.
Franklin has also revealed why apparently free cybersecurity products do not always help small operators. Some offers require utilities to purchase expensive hardware, hire consultants to interpret alerts or devote staff to maintaining systems they lack the capacity to operate. As Franklin founder Jake Braun observed, these services can be “free like a puppy”: the initial acquisition costs nothing, but ownership introduces substantial obligations.
The lesson is that cybersecurity support must be appropriate to the recipient’s budget, staffing and operational maturity. A rural utility with a handful of employees cannot adopt the same controls, reporting structures and procurement processes as a national energy company.
Volunteer support cannot replace sustainable public investment, managed services or enforceable standards. Franklin has reached only a fraction of the approximately 50,000 community water systems operating in the US. Nevertheless, it offers a model for converting specialist goodwill into measurable improvements.
The initiative’s importance is reinforced by the potentially physical consequences of compromised operational technology. HIPTHER previously examined similar risks in its analysis of evolving cybersecurity threats to hydropower dams, where outdated equipment, remote access and fragmented oversight can turn digital vulnerabilities into public-safety concerns.
Visa acquires BioCatch for $2.4 billion as fraud defence becomes behavioural
Visa has agreed to acquire fraud-intelligence provider BioCatch for $2.4 billion in cash from Permira and other investors.
As reported by AML Intelligence, the transaction represents another step in Visa’s expansion beyond transaction processing and into cybersecurity, fraud prevention and risk intelligence.
BioCatch specialises in behavioural biometrics. Its technology analyses how a person interacts with a device or digital service, including behavioural and device-related signals that may help distinguish a legitimate customer from a criminal using stolen credentials.
This approach addresses an important weakness in conventional authentication. A password, payment-card number or one-time code can be stolen and reused. Behaviour is more difficult to reproduce consistently, particularly when a criminal is manipulating an account remotely or coaching a victim through a fraudulent transaction.
Behavioural intelligence may therefore detect risks that traditional login controls miss, including:
- Account takeover using valid credentials.
- Remote-access scams in which criminals control a victim’s device.
- Social-engineering attacks that persuade customers to authorise payments.
- Automated account creation and credential-stuffing activity.
- Unusual changes in the way a trusted account is accessed or operated.
For Visa, BioCatch can add identity and behavioural context to the transactional information already moving through its network. That combination could allow financial institutions to evaluate not only whether a payment appears statistically unusual, but also whether the person initiating it appears to be interacting naturally with the account.
The transaction also illustrates how fraud prevention and cybersecurity are converging. Financial crime increasingly begins with phishing, malware, identity theft or social manipulation before producing a suspicious payment. Treating the cyber intrusion and the resulting transaction as unrelated events leaves institutions with an incomplete view of the attack.
Behavioural monitoring introduces its own governance requirements. Financial institutions must be transparent about the data they collect, restrict its use to legitimate purposes and test systems for disproportionate effects on customers with disabilities or atypical interaction patterns. Strong fraud detection must not become uncontrolled surveillance.
The deal’s price nevertheless shows how strategically important real-time fraud intelligence has become. Cybersecurity is no longer simply a protective layer surrounding the payment network; it is becoming part of the network’s core commercial value.
Salam receives Saudi approval for Tier 2 managed-security operations
Saudi telecommunications provider Salam has received a Tier 2 licence from the National Cybersecurity Authority to provide managed security operations centre services.
The approval allows the company to expand regulated cybersecurity services for organisations operating across the Kingdom. According to TechAfrica News, the licence reflects Salam’s compliance with the NCA’s operational, technical and governance requirements.
Managed security operations can provide organisations with continuous monitoring, threat detection and incident-response support without requiring every customer to establish a complete in-house security operations centre.
This is particularly valuable for mid-sized businesses and public-sector bodies. Advanced security technology produces alerts around the clock, but those alerts deliver little value when an organisation lacks analysts capable of investigating them. A managed provider can centralise expertise, tooling and threat intelligence across multiple customers.
Salam’s telecommunications position may also provide useful visibility across connectivity, cloud infrastructure and enterprise services. Effective integration could help customers identify malicious activity earlier and coordinate containment across network and security environments.
The licence is significant beyond one company. Saudi Arabia’s digital transformation depends on organisations being able to procure cybersecurity services from providers operating under clear national requirements. Formal licensing can establish minimum expectations for personnel, processes, data handling and service continuity.
However, outsourcing monitoring does not outsource accountability. Customers remain responsible for defining which systems are covered, maintaining accurate asset inventories and deciding how quickly critical alerts must be escalated. Contracts must clearly address data residency, incident notification, evidence preservation and responsibilities during a breach.
The development reflects a broader shift towards regulated cyber-resilience ecosystems, in which governments define expectations while licensed providers supply capabilities that many organisations cannot build independently. HIPTHER’s overview of cyber resilience as a strategic leadership priority similarly emphasises that security depends on governance, operational preparation and collaboration—not technology alone.
OT coalition calls for binding CISA action after water-system attacks
The Operational Technology Cyber Coalition is urging the US Cybersecurity and Infrastructure Security Agency to issue a binding operational directive addressing vulnerabilities in internet-connected industrial systems.
The demand follows cyberattacks that disrupted water utilities and renewed concern about exposed programmable logic controllers, human-machine interfaces and remote-access equipment.
According to Industrial Cyber, the coalition wants CISA and lawmakers to move from voluntary recommendations towards requirements capable of producing consistent action.
Basic weaknesses continue to recur across critical infrastructure: devices exposed directly to the internet, default or weak passwords, undocumented connections, insecure remote access and insufficient separation between business and operational networks.
These problems are well understood, but fragmented ownership makes them difficult to resolve. Thousands of water providers operate with different budgets, technologies and regulatory arrangements. Smaller utilities may understand what should be done but lack the personnel or funding to implement it.
A binding directive could establish a common baseline around controls such as:
- Identifying and removing unnecessary internet exposure.
- Replacing default credentials and enforcing stronger authentication.
- Documenting every external connection to operational equipment.
- Segmenting operational networks from corporate IT.
- Maintaining recoverable configurations and tested backups.
- Preparing manual operating procedures for cyber disruption.
- Reporting serious incidents through consistent channels.
Requirements alone will not solve the resource problem. If mandates arrive without technical assistance, procurement support and funding, small utilities could become formally non-compliant while remaining practically vulnerable.
The strongest model would therefore combine enforceable minimum controls with programmes such as DEF CON Franklin. Regulation can define the destination, while trusted specialists and public funding help smaller operators reach it.
Chris Kelly warns that AI safety is becoming a cybersecurity contest
The cybersecurity implications of artificial intelligence are also becoming entangled with the strategic competition between the United States and China.
In a CNBC discussion, investor and technology executive Chris Kelly addressed the future of AI safety, associated cybersecurity concerns and the competitive pressure created by China’s rapidly developing technology sector.
AI introduces risk on both sides of the security equation. Defenders can use models to analyse alerts, identify vulnerabilities and automate investigations. Attackers can use similar capabilities to produce convincing phishing campaigns, search for weaknesses and scale operations across more targets.
This creates a difficult policy balance. Excessively permissive development could allow unsafe systems to reach critical environments without adequate testing. Excessively restrictive rules could slow legitimate innovation, concentrate capability in a few companies and weaken the position of democratic countries in global technology markets.
Treating AI safety and national competitiveness as opposing goals is therefore misleading. Secure development can itself become a competitive advantage. Models that are resistant to manipulation, transparent about their limitations and controllable within enterprise environments will be more useful for governments, infrastructure operators and regulated industries.
The US-China competition also raises supply-chain questions. Organisations must understand where models were developed, how training and user data are handled, what external services they contact and whether their behaviour can be independently evaluated.
The challenge is to prevent geopolitical urgency from becoming an excuse to abandon safeguards. A race conducted without security testing, access controls or incident-disclosure mechanisms could produce powerful systems that neither side can reliably govern.
The bigger picture: cybersecurity must meet organisations where they operate
These developments span rural utilities, payment networks, Saudi managed-security services, federal regulation and global AI competition. Yet they expose the same underlying problem: cybersecurity expectations often exceed the capacity of the organisations expected to meet them.
DEF CON Franklin demonstrates the value of practical assistance grounded in local realities. Visa’s BioCatch acquisition shows that cyber and fraud intelligence are becoming core financial infrastructure. Salam’s licence highlights the importance of regulated service providers, while the OT coalition’s proposal argues that voluntary guidance is no longer sufficient for essential systems.
AI adds urgency because it can accelerate both attack and defence.
Effective cyber resilience will require three elements working together: enforceable minimum standards, accessible professional support and technology that produces outcomes organisations can understand and maintain.
The most sophisticated platform cannot compensate for an unknown internet connection, a default password or the absence of an incident plan. Cybersecurity becomes meaningful only when it fits the systems, people and budgets responsible for keeping essential services running.








Got a Questions?
Find us on Socials or Contact us and we’ll get back to you as soon as possible.