As cybersecurity incidents continue to affect several water systems across the country, some advocates are now calling for new legislation, funding and federal direction.
The FBI and Environmental Protection Agency confirmed last week malicious cyber activity involving Internet-facing operational technology at water and wastewater systems in seven states. Although federal authorities have not identified the states, regional officials have separately confirmed cyber incidents affecting water systems in Minnesota, Michigan, Georgia, South Dakota and New Jersey.
While there is speculation about which malicious actors committed the intrusions, Michael Garcia, policy director for the Operational Technology Cybersecurity Coalition (OTCC), has identified immediate steps government bodies and water organizations can take to protect systems that don’t depend on attribution. Garcia’s group is an industry coalition that works with government to improve the cyber protection of the nation’s critical infrastructure.
“I’m always one to wait until you see official attribution from the federal government, which we haven’t seen quite yet,” Garcia said. “I like to try to put intent, motivation on one side, and outcome on the other. Because regardless of who did it, you had an outcome of Americans being scared, water systems being tampered with, and we need to do something. Put motivation aside — the solutions are going to be the same.”
Following the recent incidents, the OTCC issued a statement urging the federal government’s Cybersecurity and Infrastructure Security Agency (CISA) and Congress to take immediate steps to strengthen operational technology and water-sector cybersecurity. For one, the group has encouraged CISA to release a binding operational directive for operational technology, used throughout critical infrastructure sectors.
A binding operational directive is a cybersecurity requirement that federal civilian executive branch agencies must follow. Many of CISA’s directives have focused on IT, while OTCC is calling for one specifically addressing operational technology, which appears to be the target of the recent incidents. Such a directive would not directly apply to the state and local water systems affected by the recent attacks. Garcia, however, said that federal cybersecurity requirements can influence practices beyond the agencies required to follow them by setting expectations and sending a broader signal to other critical infrastructure operators.
The coalition also lists three concrete actions for Congress. These are reauthorizing the State and Local Cybersecurity Grant Program (SLCGP); supporting Andrew McClure as director of the Office of Cybersecurity, Energy Security and Emergency Response; and passing long-term authority for the Cybersecurity Information Sharing Act of 2015.
Without the SLCGP, the coalition argues that small towns are left to protect themselves against nation-state actors. Created by the Infrastructure Investment and Jobs Act in 2021 with $1 billion in grant funds to bolster cybersecurity at the state and local levels, the SLCGP is now authorized through the end of September, yet it remains unfunded. Two bills have been introduced to reauthorize and fund the program. One was received in the Senate, while the other was referred to committee.
The coalition also wants Congress to give McClure support in his new role as the head of the Office of Cybersecurity, Energy Security and Emergency Response, which works to strengthen and secure the nation’s energy infrastructure. McClure was appointed July 29. Like water infrastructure, the energy sector depends on operational technology to operate, and Garcia said supporting the leadership helps ensure sector cyber support.
Finally, the coalition wants Congress to pass long-term authority for the Cybersecurity Information Sharing Act. The law established a voluntary framework for private-sector organizations to share cyber threat information with the federal government and each other while receiving certain liability and disclosure protections. Garcia said that protection can encourage organizations to provide technical information to help CISA identify broader cyber campaigns and warn potential targets. Without it, organizations may not have the legal appetite to share.
“These are just immediate steps, easy steps that the government could do,” Garcia said. “But there are more things like [the Cyber Incident Reporting for Critical Infrastructure Act], intelligence authorities, and a couple of other things that folks are putting out there.”
The American Water Works Association is also calling for broader federal action. In a letter to Congress this week, the association pointed to pending legislation and other measures, as well as funding, cybersecurity training, information sharing and collaborative policy development. That association also supports the SLCGP and a 10-year Cybersecurity Information Sharing Act of 2015 reauthorization.
“Recent cybersecurity attacks on water utilities across multiple states underscore the need to further support drinking water and wastewater utilities as critical infrastructure,” the association wrote in its letter. “Water utilities are often out of sight and out of mind — historically under-resourced compared to other critical infrastructure sectors — despite their central role in daily life, the economy and public health.”
