Key Takeaways
- Recent malicious cyber activity targeting Internet‑facing operational technology (OT) has been confirmed in water and wastewater systems across at least seven states, with public reports from Minnesota, Michigan, Georgia, South Dakota, and New Jersey.
- The Operational Technology Cybersecurity Coalition (OTCC) urges the federal government to issue a binding operational directive for OT, reauthorize the State and Local Cybersecurity Grant Program (SLCGP), support the appointment of Andrew McClure as director of the Office of Cybersecurity, Energy Security and Emergency Response, and pass long‑term authority for the Cybersecurity Information Sharing Act of 2015 (CISA).
- The American Water Works Association (AWWA) echoes these calls, emphasizing that water utilities are historically under‑resourced despite their vital role in public health, the economy, and daily life.
- Immediate, attribution‑agnostic steps—such as setting federal OT standards, expanding grant funding, and strengthening information‑sharing protections—can raise the baseline security posture for small and municipal water systems without waiting for attacker identification.
Overview of the Recent Cyber Incidents
Federal authorities, specifically the FBI and the Environmental Protection Agency (EPA), disclosed last week that malicious cyber activity has been detected against Internet‑facing operational technology components of water and wastewater facilities in seven states. While the exact states have not been named by the agencies, regional officials have publicly confirmed incidents in Minnesota, Michigan, Georgia, South Dakota, and New Jersey. The intrusions involved attempts to manipulate or monitor OT systems that control pumps, treatment processes, and distribution networks, raising concerns about the safety and reliability of drinking‑water supplies.
OTCC’s Stance on Attribution Versus Outcome
Michael Garcia, policy director for the Operational Technology Cybersecurity Coalition (OTCC), emphasized that while identifying the threat actors is useful, the coalition prefers to focus on the tangible outcomes of the attacks rather than their motivations. He argued that regardless of who carried out the intrusions, the result—public alarm, potential tampering with essential services, and heightened risk to communities—demands immediate remedial action. By separating intent from impact, Garcia believes policymakers can devise solutions that are effective irrespective of the attacker’s identity.
Call for a Binding Operational Directive on OT
One of the OTCC’s primary recommendations is for the Cybersecurity and Infrastructure Security Agency (CISA) to issue a binding operational directive (BOD) that specifically addresses operational technology used across critical‑infrastructure sectors. Unlike many existing CISA directives that concentrate on traditional information technology (IT), a BOD for OT would set mandatory security standards for federal civilian executive branch agencies. Although the directive would not directly govern state‑ or locally‑owned water systems, Garcia noted that federal requirements often create a de facto benchmark that influences practices throughout the broader critical‑infrastructure community, encouraging utilities to adopt stronger OT defenses.
Reauthorizing the State and Local Cybersecurity Grant Program
The OTCC also urges Congress to reauthorize and fund the State and Local Cybersecurity Grant Program (SLCGP). Established by the Infrastructure Investment and Jobs Act of 2021 with an initial $1 billion allocation, the SLCGP aims to bolster cybersecurity capabilities at state and local levels. Its current authorization expires at the end of September, yet the program remains unfunded. Two legislative proposals—one received in the Senate and another referred to committee—seek to revive the initiative. Without renewed funding, smaller municipalities may lack the resources to defend against sophisticated nation‑state cyber threats targeting water infrastructure.
Supporting Leadership at the Office of Cybersecurity, Energy Security and Emergency Response
Another concrete action advocated by the OTCC is to provide congressional backing for Andrew McClure, who was appointed on July 29 as director of the Office of Cybersecurity, Energy Security and Emergency Response (CESER). This office works to strengthen the security of the nation’s energy infrastructure, which, like water systems, relies heavily on operational technology. Garcia argued that endorsing McClure’s leadership ensures that the expertise and policy direction needed to protect OT environments are present at the highest levels of federal coordination, benefitting sectors that share similar technological dependencies.
Securing Long‑Term Authority for the Cybersecurity Information Sharing Act
The coalition further recommends that Congress enact long‑term authority for the Cybersecurity Information Sharing Act of 2015 (CISA). This law creates a voluntary framework enabling private‑sector entities to share cyber threat information with the federal government and each other while receiving certain liability and disclosure protections. Garcia highlighted that these protections are crucial for encouraging organizations to divulge technical details that can help CISA identify broader attack campaigns and issue timely warnings to potential victims. Without a durable legislative foundation, many firms may hesitate to share valuable intelligence due to legal uncertainty.
American Water Works Association’s Broader Federal Appeal
Echoing the OTCC’s stance, the American Water Works Association (AWWA) sent a letter to Congress this week urging broader federal action on water‑sector cybersecurity. The association pointed to pending legislation, additional funding mechanisms, cybersecurity training initiatives, and collaborative policy development as necessary steps. AWWA expressly endorsed the reauthorization of the SLCGP and a ten‑year extension of the Cybersecurity Information Sharing Act, stressing that water utilities—often “out of sight and out of mind”—have historically received fewer resources than other critical‑infrastructure sectors despite their indispensable role in public health, economic activity, and daily life.
Immediate, Attribution‑Agnostic Steps for Water Systems
Garcia characterized the OTCC’s recommendations as “immediate steps, easy steps that the government could do,” while acknowledging that additional measures—such as the Cyber Incident Reporting for Critical Infrastructure Act, expanded intelligence authorities, and further legislative proposals—are also under discussion. By focusing on actions that do not require definitive attribution of the attacks, federal and municipal entities can begin strengthening defenses right away, reducing the window of exposure for water and wastewater systems nationwide.
Conclusion: Building Resilience Through Coordinated Federal Action
The recent cyber incidents targeting water and wastewater operational technology underscore a pressing need for coordinated federal intervention. Through a combination of binding OT directives, reinvigorated grant programs, steadfast support for key cybersecurity leadership, and durable information‑sharing authorities, the government can raise the baseline security posture for utilities of all sizes. Coupled with advocacy from organizations like the OTCC and AWWA, these measures offer a pragmatic pathway to safeguard essential water services against evolving cyber threats while awaiting deeper investigations into the actors behind the attacks.

