Key Takeaways
- Illinois currently has no state‑ or federal‑mandated requirement for water utilities to report cyber incidents.
- State Rep. Dagmara Alevar (D‑Romeoville) has introduced House Bill 3576 to compel the state’s ~1,700 community water systems to notify emergency agencies of any attack.
- Recent cyber intrusions on water‑treatment computers in Minnesota, Michigan, Wisconsin and other Midwestern states show Iranian‑linked fingerprints.
- The University of Chicago’s Franklin Project, partnered with DEF CON volunteers, is providing free cybersecurity assessments and hardening help to small utilities nationwide.
- Federal legislation by Senators Amy Klobuchar (D‑MN) and Adam Schiff (D‑CA) would place water‑plant cybersecurity oversight under the Environmental Protection Agency, but faces opposition from many Republicans and some industry groups.
Introduction: The Stakes of Water System Cybersecurity in Illinois
The safety of drinking water is a fundamental public‑health concern, yet Illinois residents have little assurance that their tap water is protected from cyber threats. Unlike many other states, Illinois currently has no law that forces municipal or private water systems to disclose a hacking incident to state emergency managers or federal agencies. This regulatory gap means that a successful cyber intrusion could go unnoticed, potentially allowing attackers to manipulate treatment processes, disrupt service, or erode public trust without any official oversight. The issue gained national attention after NBC 5 Investigates highlighted the problem, prompting lawmakers to examine how Illinois can shore up its defenses before a malicious actor exploits the vulnerability.
Recent Cyberattacks Across the Midwest and Their Origins
In the past month, a series of cyberattacks struck water‑processing computers in Minnesota, Michigan, Wisconsin and several other Midwestern states. Security analysts have traced the intrusion patterns to Iranian‑linked threat actors, noting the use of known malware signatures and tactics consistent with state‑sponsored cyber espionage. Although the attackers did not appear to contaminate the water directly, experts warn that even the perception of compromised water can cause panic, economic disruption, and a loss of confidence in essential services. These incidents transformed what was once a hypothetical risk into a demonstrable threat, underscoring the urgency for states like Illinois to adopt preventive measures before similar breaches occur on their own infrastructure.
State Representative Dagmara Alevar’s Response and Legislative Proposal
State Representative Dagmara Alevar, a Democrat representing the southwest suburban district of Romeoville, has emerged as a leading voice calling for stronger water‑system cybersecurity safeguards. In a recent interview with NBC Chicago, she emphasized that protecting water supplies is a non‑partisan responsibility, whether the hacker originates overseas or from a neighboring town. Alevar expressed concern that Illinois is currently “fighting with one hand tied behind its back” because there is no mandatory reporting requirement for cyber incidents. Her immediate reaction to the recent Midwest attacks was to push for legislative action that would compel utilities to notify state emergency agencies whenever a breach is detected.
House Bill 3576: Mandatory Reporting and Scope
To address the reporting gap, Representative Alevar introduced House Bill 3576, which would require all of Illinois’ approximately 1,700 community water systems to report any cyberattack to the Illinois Emergency Management Agency (IEMA) and, where appropriate, to federal partners such as the Cybersecurity and Infrastructure Security Agency (CISA). The bill defines a reportable incident as any unauthorized access, disruption, or attempted manipulation of water‑treatment control systems, regardless of whether the attack succeeds in altering water quality. By mandating timely disclosure, the legislation aims to create a statewide situational awareness picture that enables rapid response, coordinated mitigation, and the sharing of lessons learned across utilities.
The Franklin Project: University of Chicago and DEF CON Volunteer Aid
While legislative solutions work their way through the statehouse, technical assistance is already arriving from an unexpected quarter. The Franklin Project, a collaboration between the University of Chicago’s Cyber Policy Initiative and the volunteer hacker collective DEF CON, has been deploying cybersecurity specialists to small water utilities across the nation. Over the past two years, dozens of assessments have been conducted, helping operators identify vulnerable legacy hardware, weak password practices, and insufficient network segmentation. The project’s goal is not only to diagnose weaknesses but also to provide practical, low‑cost remediation steps that cash‑strapped municipalities can implement without waiting for federal grants or lengthy procurement cycles.
Expert Perspective: Jake Braun on Volunteer Cyber Assistance
Jake Braun, a former deputy national cyber director in the Biden White House and now a senior cyber expert at the University of Chicago, leads the Franklin Project’s volunteer effort. He notes that many small water systems lack dedicated IT staff and rely on outdated supervisory control and data acquisition (SCADA) platforms that were never designed with modern threats in mind. Braun emphasizes that the project’s approach is deliberately hands‑on: volunteers conduct on‑site penetration tests, recommend configuration changes, and help utilities develop incident‑response plans. “We’ve had dozens of them deployed to water utilities over the last two years,” he said, “and many of the utilities have been able to shore up their own security.” This model demonstrates how public‑private partnerships can fill gaps left by slow‑moving regulation.
Federal Legislative Effort: Klobuchar‑Schiff Bill and EPA Oversight
At the federal level, the recent spate of attacks prompted Senators Amy Klobuchar (D‑MN) and Adam Schiff (D‑CA) to introduce legislation that would assign the Environmental Protection Agency (EPA) primary authority over cybersecurity for the nation’s drinking‑water and wastewater infrastructure. The bill would require the EPA to develop mandatory cybersecurity standards, conduct regular audits, and provide funding for upgrades to high‑risk facilities. Proponents argue that centralizing oversight under an agency already charged with water quality ensures consistency and leverages existing regulatory frameworks. The proposal also seeks to close the reporting loophole that currently leaves many states, including Illinois, without a clear federal mandate to disclose cyber incidents.
Political and Industry Resistance to Federal Water‑Cyber Rules
Not everyone welcomes the EPA‑centric approach. Numerous Republican lawmakers contend that expanding the EPA’s remit into cybersecurity oversteps its traditional environmental mandate and could create bureaucratic duplication with existing agencies such as CISA and the Department of Homeland Security. Some water‑industry groups, while supportive of improved security, warn that prescriptive federal standards might increase compliance costs for small utilities that already operate on tight budgets. They advocate instead for a voluntary, incentive‑based model that builds on initiatives like the Franklin Project and allows utilities to adopt best practices at their own pace, arguing that flexibility is essential to accommodate the diverse technical capabilities of the nation’s 150,000+ water systems.
Conclusion: Toward a Proactive Cyber‑Resilient Water Supply in Illinois
In summary, Illinois finds itself at a crossroads where the threat of cyberterrorism targeting water supplies is no longer abstract but evidenced by recent attacks in neighboring states. Representative Alevar’s House Bill 3576 seeks to close the immediate reporting gap, while the Franklin Project offers tangible, on‑the‑ground assistance to harden vulnerable systems. Federal proposals to empower the EPA reflect a broader push for national standards, yet they face political and industry resistance that underscores the need for balanced solutions. Moving forward, a combination of mandatory reporting, targeted technical aid, and flexible federal guidelines could help ensure that the water flowing from Illinois taps remains safe, reliable, and resilient against cyber threats.

