Water Groups Push for Cybersecurity Rules

Water associations renewed calls for Washington to set minimum cybersecurity standards, arguing a string of disruptive attacks has exposed the limits of voluntary federal guidance.

The American Water Works Association, whose members supply roughly 80% of U.S. drinking water, urged congressional leaders last week to advance legislation creating an independent organization to develop cybersecurity requirements for water and wastewater systems.

The push follows cyberattacks across several states that federal authorities said disrupted operations, causing pressure loss and flooding in some cases. Officials in at least seven states confirmed attacks since July 27, with more reported over the past week.

"What's different here is that they turned the stuff off," said Kevin Morley, senior manager for federal relations at AWWA, contrasting the recent incidents with past passive intrusion campaigns that resulted in vandalism at U.S. water facilities.

Cyber experts have long been concerned that determined hackers could cause real damage by breaking into water systems, either depriving communities and nearby military bases of supply, or tinkering with the chemicals introduced into drinking water to unsafe levels.

In an Aug. 5 letter, AWWA urged congressional leaders to advance the Water Risk and Resilience Organization Establishment Act, sponsored by Rep. Rick Crawford (R., Ark.). The bill would create an independent, nongovernmental body to draft minimum cybersecurity requirements under Environmental Protection Agency oversight, and includes strict penalties for noncompliance.

The proposal mirrors the electricity sector, where industry experts develop mandatory cybersecurity standards through the North American Electric Reliability Corporation, subject to federal review.

The National Association of Water Companies, representing investor-owned utilities, also backs mandatory, risk-based standards under a NERC-like framework. Robert Powelson, NAWC's president and chief executive, said the absence of federal rules widens the gap between larger privately owned utilities and smaller municipal systems.

"We have no federal standards for cyber compliance for this industry, and it's now getting to a tipping point," Powelson said.

Privately owned utilities typically employ dedicated cybersecurity staff and incorporate upgrades into capital plans. Public systems must compete for limited municipal budgets alongside physical repairs like pipes and pumps.

That can turn cybersecurity into a political challenge as well as a financial one. Local officials often have to persuade residents to pay more for cyber defenses whose value is largely invisible when they work, particularly in smaller communities already reluctant to raise water bills.

About 84% of the 53,000 community water systems in the U.S., and 98% of roughly 16,000 wastewater systems, are government-owned.

Washington has tried mandates before. In 2023, the EPA directed states to evaluate cybersecurity during routine water sanitary inspections. The attorneys general of states including Iowa, Missouri and Arkansas sued the EPA, backed by AWWA and other groups, arguing the agency lacked legal authority to make such demands. A federal appeals court blocked the policy, and the EPA withdrew it seven months after issuing it.

Morley noted AWWA didn't object to cybersecurity mandates themselves, but to how the EPA attempted to impose them without statutory authority or industry input, using sanitary reviews as a vehicle.

"Part of it is that we don't want to have what happened to the pipeline guys with the TSA requirements," he said, referring to the Transportation Security Administration's imposition of emergency cybersecurity requirements on oil and gas pipeline operators in the wake of the 2021 Colonial Pipeline attack. Those rules became the subject of a protracted fight between regulators and operators, and eventually led to requirements around incident reporting and risk assessments being softened.

In the absence of a federal regime, some states have begun imposing requirements of their own. New York this year adopted minimum cybersecurity standards for many drinking-water and wastewater systems, including risk assessments, cybersecurity plans, training and incident reporting. Maryland also now requires its utilities to assess cyber risks and take steps to protect critical systems.

Mike Searight, chief information officer for Waco, Texas, until earlier this year, said he favors a state-level approach to regulation over a federal regime, which might seem remote to smaller and rural utilities.

" The utility departments in all the small cities, especially small or midsize, they need someone to call. They need a team that can come in and help support them," said Searight, now an adviser for cybersecurity company Elisity. Other efforts have also attempted to plug the cyber hole created by a lack of resources, including programs for free software launched by vendors and volunteer efforts organized by cybersecurity communities such as DEF CON Franklin, which provides utilities with free software and research.

Disagreement remains over the right model for regulation. While the water associations support the Crawford bill, some large systems such as the Metropolitan Water District of Southern California oppose it. Metropolitan argued in a letter to senior lawmakers last year that a new regulatory body duplicates existing efforts and warned that penalties of up to $25,000 a day for noncompliance could devastate small systems without federal funding. Metropolitan instead urged phased requirements backed by federal grants and closer coordination with the Cybersecurity and Infrastructure Security Agency.

Powelson at NAWC said that regardless of the form new standards take, baseline cyber protections must ultimately become as fundamental as physical safety infrastructure.

"We have to have a basic measure for cyber hygiene," he said. "Every drinking water system should have a cyber plan."