Key Takeaways
- U.S. Rep. Josh Gottheimer unveiled a bipartisan Critical Infrastructure Security Plan to shield water, electric, and other essential services from cyberattacks.
- The plan centers on two new bills: the AI Cyber Defense Act (providing free AI‑based cybersecurity tools) and the Securing Our Critical Infrastructure Act (creating a rapid‑response hub within CISA for small and medium utilities).
- Gottheimer is urging CISA, the EPA, and the FBI to boost incident‑response teams, technical assistance, and long‑term guidance for water and wastewater systems, especially small and rural utilities.
- Recent attacks—linked to Iranian‑affiliated actors—have forced several municipal water systems in New Jersey and at least a dozen other states to revert to manual operations, highlighting the sector’s exposure.
- Because 97 % of the nation’s ~150,000 public water systems serve small communities and often lack dedicated cybersecurity staff, the proposals aim to level the playing field by delivering federal resources and expertise.
Overview of the Announcement
On Wednesday, Congressman Josh Gottheimer (D‑NJ‑5) stood in Park Ridge, New Jersey, to announce a comprehensive package of bipartisan federal initiatives designed to fortify the nation’s critical infrastructure against cyber threats. Speaking before local residents and officials, Gottheimer emphasized the everyday reliance on safe drinking water and reliable electricity, arguing that no American should have to worry about the safety of these essential services. The announcement followed a surge of cyber intrusions targeting municipal water systems across multiple states, prompting immediate concern among policymakers, utility operators, and federal agencies. By framing the issue as a matter of public safety and national resilience, Gottheimer sought to build cross‑party support for concrete legislative and administrative actions that could be deployed swiftly to protect vulnerable communities.
Recent Cyberattacks on Water Systems
According to Gottheimer’s office, hackers have struck water utilities in New Jersey and at least a dozen other states over the past two weeks. Two municipal systems in Cape May County were specifically cited as victims; after losing access to their digital control panels, operators were forced to manually operate valves and pumps to maintain service. The Federal Bureau of Investigation is now investigating incidents in at least seven states, while the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), and the FBI have issued a joint advisory urging water providers to strengthen their cybersecurity defenses. Early investigations suggest Iranian‑affiliated actors may be behind the campaign, although investigators are also examining whether other threat groups are employing similar tactics. The attacks underscore how quickly a cyber intrusion can degrade essential services, compelling utilities to revert to labor‑intensive, manual processes that increase the risk of human error and service disruption.
Vulnerabilities of Small Utilities
Gottheimer highlighted that smaller water and wastewater utilities are particularly exposed to cyber threats. Nationwide, there are roughly 150,000 public water systems, and an overwhelming 97 % serve small communities. Many of these utilities operate with limited staffing, aging infrastructure, and no full‑time cybersecurity personnel, leaving them ill‑equipped to detect, prevent, or respond to sophisticated intrusions. Unlike larger municipal or private utilities that can afford dedicated security teams and advanced threat‑intelligence platforms, small systems often rely on outdated software, minimal network segmentation, and ad‑hoc IT support. This resource gap creates a disproportionate risk profile: while large utilities may absorb an attack with limited impact, a successful breach of a small system can quickly jeopardize public health, disrupt daily life, and erode community trust. Gottheimer’s plan directly addresses this imbalance by seeking to extend federal cybersecurity capabilities to those utilities that lack the means to acquire them independently.
Details of the AI Cyber Defense Act
A cornerstone of Gottheimer’s proposal is the bipartisan AI Cyber Defense Act, co‑sponsored by Representatives Don Bacon (R‑NE), Zach Nunn (R‑IA), Hilary Scholten (D‑MI), and Greg Landsman (D‑OH). The legislation would grant critical infrastructure operators—particularly water and electric utilities—free access to cutting‑edge artificial intelligence models equipped with cybersecurity analytics. These AI tools would be capable of continuously monitoring network traffic, identifying anomalous behavior, flagging unpatched vulnerabilities, and recommending remedial actions before attackers can exploit weaknesses. By democratizing access to advanced AI‑driven defenses, the act aims to narrow the technological divide between well‑funded utilities and those operating on shoestring budgets. Supporters argue that AI can automate threat detection at scale, reduce reliance on scarce human expertise, and provide real‑time insights that enable faster, more effective mitigation. The bill also includes provisions for training and technical support to ensure that utility staff can effectively interpret and act upon AI‑generated alerts.
Details of the Securing Our Critical Infrastructure Act
The second legislative component, the bipartisan Securing Our Critical Infrastructure Act, is being introduced by the same group of lawmakers. This bill would establish a dedicated rapid‑response and threat‑notification service within CISA tailored specifically for small and medium‑sized water and electric utilities. Under the proposed framework, participating utilities would gain a single federal point of contact during cybersecurity incidents, streamlining communication and coordination amid crises. The service would deliver real‑time threat intelligence, incident‑response guidance, and direct access to federal cybersecurity experts who could assist with containment, eradication, and recovery efforts. Importantly, the act emphasizes utilities that lack the resources of larger operators, ensuring that assistance is proportionate to need. By institutionalizing a rapid‑response mechanism, the legislation seeks to reduce the time between detection and remediation—a critical factor in limiting the potential damage of cyberattacks on essential services.
Request for Federal Agency Action
Beyond legislation, Gottheimer is sending a formal letter to CISA, the EPA, and the FBI requesting immediate enhancements to incident‑response capabilities and technical assistance for water and wastewater utilities affected by the recent cyberattack campaign. The letter stresses the urgency of deploying additional incident‑response teams to the most impacted regions, expanding on‑site technical support, and providing actionable guidance tailored to the unique operational technology environments of water systems. It also calls for the agencies to develop longer‑term protections, including sector‑specific cybersecurity guidance and a permanent rapid‑response framework that can be activated for future threats. By focusing on small and rural utilities—those most likely to lack internal cybersecurity capacity—the request aims to ensure that federal assistance reaches the communities where it is needed most, thereby strengthening the overall resilience of the nation’s water infrastructure.
Implications for National Infrastructure Security
If enacted, Gottheimer’s proposals could represent a significant shift in how the United States safeguards its critical infrastructure against cyber threats. The AI Cyber Defense Act would introduce advanced, automated detection capabilities to a broad swath of utilities that currently rely on manual monitoring and periodic audits. Simultaneously, the Securing Our Critical Infrastructure Act would institutionalize a federal safety net, ensuring that even the most under‑resourced systems have access to expert assistance during emergencies. Together, these measures address both the preventive and responsive dimensions of cybersecurity: reducing the likelihood of successful intrusions and minimizing the consequences when they do occur. Moreover, by elevating the water sector’s cybersecurity posture, the plan indirectly protects interconnected systems such as energy, transportation, and public health, which depend on reliable water supplies for cooling, sanitation, and other essential functions. The initiative also sets a precedent for sector‑specific federal support that could be replicated in other critical infrastructure domains facing similar resource constraints.
Conclusion and Next Steps
Congressman Josh Gottheimer’s Critical Infrastructure Security Plan emerges at a moment of heightened awareness about the fragility of essential services in the face of increasingly sophisticated cyber adversaries. By combining legislative innovation—through the AI Cyber Defense Act and the Securing Our Critical Infrastructure Act—with direct appeals to federal agencies for augmented response capabilities, Gottheimer aims to create a layered defense strategy that protects both large and small utilities. The success of this effort will hinge on congressional approval of the proposed bills, the willingness of agencies to allocate additional resources, and the ability of local utilities to integrate new tools and guidance into their existing operations. If implemented effectively, the plan could markedly reduce the risk of cyber‑induced disruptions to water and electric services, safeguarding public health, economic stability, and community confidence across the nation. As the legislation moves forward, stakeholders from utilities, cybersecurity experts, and public officials will need to collaborate closely to translate these federal initiatives into tangible, on‑the‑ground protections.

