U.S. water industry groups are renewing calls for mandatory federal cybersecurity standards after a series of attacks disrupted water systems across several states, in some cases causing pressure loss and flooding.
Among them is the American Water Works Association, whose members supply about 80% of U.S. drinking water. It urged congressional leaders last week to advance legislation that would create an independent organization responsible for developing minimum cybersecurity requirements for water and wastewater systems under Environmental Protection Agency oversight, according to The Wall Street Journal.
Officials in at least seven states have confirmed attacks since July 27, with additional incidents reported over the past week. Unlike some previous intrusions into water systems, the latest attacks disrupted physical operations.
“What’s different here is that they turned the stuff off,” Kevin Morley, AWWA’s senior manager for federal relations, told the Journal.
The proposed Water Risk and Resilience Organization Establishment Act would establish an independent, nongovernmental body to develop mandatory cybersecurity requirements and impose penalties for noncompliance. The approach resembles the electricity industry’s system, where cybersecurity standards are developed through the North American Electric Reliability Corporation and subject to federal oversight.
The National Association of Water Companies, which represents investor-owned utilities, also supports mandatory risk-based standards. The groups argue that voluntary federal guidance has left thousands of smaller municipal systems particularly vulnerable because they often lack dedicated cybersecurity staff and must compete for funding with basic infrastructure needs.
About 84% of the nation’s 53,000 community water systems and 98% of roughly 16,000 wastewater systems are government-owned, according to the Journal.
Washington previously tried to impose cybersecurity requirements on water systems. In 2023, the EPA directed states to evaluate cybersecurity during routine inspections, but several states sued, arguing the agency lacked authority to impose the requirements. A federal appeals court blocked the policy and the EPA subsequently withdrew it.
Some states have since acted independently. New York has adopted minimum cybersecurity standards covering many water and wastewater systems, while Maryland requires utilities to assess cyber risks and protect critical systems.
There is still disagreement over whether a new federal regulatory organization is the answer. The Metropolitan Water District of Southern California has argued that another regulatory body could duplicate existing efforts and that penalties could overwhelm smaller utilities without accompanying federal funding