Key Takeaways
- Sens. Adam Schiff (D‑Calif.) and Amy Klobuchar (D‑Minn.) introduced the Water Cyber Shield Act, allocating $300 million annually from Drinking Water and Clean Water State Revolving Funds to bolster cybersecurity in the water and wastewater sector.
- The bill amends the Safe Drinking Water Act and Clean Water Act, granting the Environmental Protection Agency (EPA) authority to conduct cybersecurity assessments, mandate corrective actions, and enforce incident‑reporting requirements aligned with the forthcoming Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA).
- Utilities must integrate cybersecurity risk assessments into resilience planning; smaller systems receive flexibility and priority for federal assistance, while submitted cybersecurity data is protected from public disclosure.
- The EPA will coordinate with the Cybersecurity and Infrastructure Security Agency (CISA), establish a technical advisory committee to develop standards, and publish metrics and progress reports on the sector’s cybersecurity posture.
- The legislation responds to a series of cyberattacks linked to Iranian‑affiliated groups that have disrupted water systems in over a dozen states, aiming to protect critical infrastructure without shifting costs to ratepayers.
Legislation Overview
On Monday, Senators Adam Schiff of California and Amy Klobuchar of Minnesota unveiled the Water Cyber Shield Act, a bipartisan‑leaning measure designed to fortify the nation’s water and wastewater infrastructure against cyber threats. The act proposes a steady stream of federal funding—$300 million each year—drawn from the existing Drinking Water and Clean Water State Revolving Funds. By earmarking these resources specifically for cybersecurity upgrades, the bill seeks to close a long‑standing gap in protection for essential water services that serve millions of Americans daily.
Funding Mechanism and Financial Safeguards
The $300 million annual allocation would be administered through the Environmental Protection Agency, which would distribute grants and low‑interest loans to utilities seeking to improve their cyber defenses. Importantly, the legislation stipulates that these funds cannot be passed on to consumers as higher water rates, addressing a primary concern raised by industry groups during previous EPA attempts to impose cybersecurity checks. This financial shield aims to ensure that cash‑strapped municipalities, especially smaller systems, can afford necessary upgrades without burdening ratepayers.
Legal Amendments and EPA Authority
To enable the EPA to act, the Water Cyber Shield Act amends two cornerstone statutes: the Safe Drinking Water Act and the Clean Water Act. The amendments give the agency explicit authority to conduct cybersecurity assessments of water and wastewater facilities, identify vulnerabilities, and require corrective actions when deficiencies are found. By embedding cybersecurity responsibilities into existing environmental law, the bill leverages the EPA’s regulatory expertise while avoiding the creation of a wholly new oversight body.
Utility Responsibilities: Risk Assessment and Incident Reporting
Under the proposed law, all water and wastewater systems must incorporate cybersecurity risk assessments into their broader resilience planning processes. This requirement mirrors the approach taken for natural‑disaster preparedness, ensuring that cyber threats are treated as a routine component of operational safety. Additionally, utilities would be compelled to report cyber incidents in accordance with the forthcoming Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), facilitating timely information sharing and coordinated response efforts across federal, state, and local partners.
Size‑Based Rules and State Flexibility
Recognizing the vast disparity in resources among water utilities, the act outlines differentiated requirements based on system size. Larger utilities would face stricter assessment and reporting standards, while smaller systems would receive procedural flexibility—such as simplified reporting formats and extended compliance timelines—to accommodate limited staff and expertise. Moreover, states would have the option to either administer the cybersecurity regulations independently or request EPA assistance, allowing a tailored approach that respects regional capabilities while maintaining a national baseline of protection.
Coordination with CISA and Advisory Committee
The legislation mandates close collaboration between the EPA and the Cybersecurity and Infrastructure Security Agency (CISA) to share threat intelligence, develop unified cybersecurity standards, and align incident‑response protocols. To inform these standards, a technical advisory committee would be established, comprising experts from the water sector, cybersecurity professionals, state regulators, and federal agencies. This committee would translate emerging threats into actionable guidelines, ensuring that regulatory measures remain relevant and effective against evolving adversarial tactics.
Data Protection and Assistance for Small Systems
To encourage transparency without exposing sensitive information, the bill exempts cybersecurity data submitted by utilities from public disclosure under the Freedom of Information Act. This provision aims to alleviate concerns that revealing vulnerabilities could be exploited by malicious actors. Concurrently, smaller water systems are prioritized for federal financial assistance, receiving targeted grants and technical support to help them meet cybersecurity benchmarks despite limited budgets and staffing.
EPA Metrics, Reporting, and Accountability
The EPA would be required to develop a set of cybersecurity metrics to gauge the progress and effectiveness of improvements across the water sector. These metrics would track areas such as vulnerability remediation rates, incident response times, and adoption of recommended safeguards. The agency must publish regular reports detailing sector‑wide performance, trends, and emerging risks, thereby providing Congress, stakeholders, and the public with measurable accountability and a clear picture of the nation’s water‑system cybersecurity posture.
Senatorial Statements and Motivations
Senator Klobuchar emphasized that recent cyberattacks on Minnesota’s water infrastructure underscored the urgent need for stronger defenses, asserting that the legislation will empower the EPA to assess vulnerabilities and aid municipal systems in thwarting cyber threats. Senator Schiff echoed this sentiment, noting that every American relies on safe, reliable drinking water, and that the bill delivers the EPA the tools necessary to protect critical infrastructure while shielding ratepayers from cost increases. Both lawmakers framed the act as a proactive response to an evolving threat landscape rather than a reactive measure after damage has occurred.
Historical Context: EPA’s Prior Attempts and Industry Pushback
The Biden administration previously sought to integrate cybersecurity checks into routine water system assessments, but the initiative stalled after facing legal challenges from water industry groups and several states. Opponents argued that mandatory cybersecurity upgrades would force utilities to raise rates, placing an undue financial burden on consumers. Consequently, the administration withdrew the proposal, leaving a regulatory vacuum that malicious actors have since exploited. The Water Cyber Shield Act attempts to address those concerns by providing dedicated federal funding and explicit cost‑protection language, thereby preempting the rate‑increase objection that derailed earlier efforts.
Recent Attacks and Operational Impacts
Over the past year, Iranian‑affiliated cyber groups and ransomware gangs have launched a series of incursions against water and wastewater facilities in at least twelve states, disrupting treatment processes, forcing manual operation of critical equipment, and, in some cases, prompting temporary shutdowns of certain tools. These incidents have demonstrated the real‑world consequences of cyber vulnerabilities, including potential risks to public health and environmental safety. The frequency and sophistication of the attacks have heightened urgency among policymakers to establish robust, enforceable cybersecurity standards for the sector.
Consultation Process and Stakeholder Feedback
According to a spokesperson for Senator Schiff, the bill’s drafters engaged extensively with a broad array of stakeholders before introduction. Consultations included water industry associations, state regulatory bodies, cybersecurity experts, and federal agencies such as the EPA and CISA. Feedback from these groups helped shape provisions that balance security imperatives with practical considerations, aiming to mitigate potential objections and foster widespread support for the legislation’s adoption.
Conclusion and Significance
The Water Cyber Shield Act represents a consequential step toward safeguarding one of the nation’s most vital lifelines—its water and wastewater infrastructure—from increasingly sophisticated cyber threats. By coupling dedicated funding with clear regulatory authority, risk‑assessment mandates, incident‑reporting obligations, and targeted assistance for smaller utilities, the bill seeks to create a resilient, nationally coordinated defense posture. If enacted, it could substantially reduce the likelihood of disruptive cyber incidents, protect public health, and ensure that the essential service of clean water remains reliable in the face of evolving digital dangers.

