Mon 10 Aug 2026 / 15:49 ET
Kernel
Security 3 min read

Water Cyber Shield Act would authorize $300 million a year for utility security

Senate Democrats’ proposal would pair annual water-system cybersecurity funding with new EPA assessment and reporting powers.

Dana Voss

By Dana Voss / Security Correspondent

Water Cyber Shield Act would authorize $300 million a year for utility security
img: The Record

Sens. Adam Schiff of California and Amy Klobuchar of Minnesota have introduced the Water Cyber Shield Act, a proposal to authorize $300 million a year for cybersecurity work at U.S. water and wastewater systems. The Water Cyber Shield Act $300 million authorization would draw on the Drinking Water and Clean Water State Revolving Funds, according to Recorded Future News. It is proposed legislation, not money that has been appropriated or distributed.

The bill would expand the Environmental Protection Agency’s role in a sector it manages but where, according to the reporting, it does not currently have authority to impose cybersecurity rules. The proposal would amend the Safe Drinking Water Act and Clean Water Act to let EPA conduct cybersecurity assessments and require corrective action when it identifies vulnerabilities.

What would the Water Cyber Shield Act require?

Water and wastewater utilities would have to evaluate cyber risk as part of resilience planning. They would also have to meet incident-reporting requirements set out in the forthcoming Cyber Incident Reporting for Critical Infrastructure Act framework, or CIRCIA, Recorded Future News reported.

The measure would not apply one uniform set of obligations to every utility. Its rules would vary by system size, with smaller systems receiving flexibility and priority for federal financial assistance. States could decide whether to administer the cybersecurity regulations themselves or ask EPA to help.

EPA would coordinate with the Cybersecurity and Infrastructure Security Agency on threat information and cybersecurity standards. A technical advisory committee would develop those standards. EPA would also create metrics to measure the sector’s cybersecurity progress and issue public reports, while cybersecurity information submitted by utilities would be shielded from public disclosure.

Why are senators seeking new water cybersecurity powers?

The proposal follows reported attacks on at least 30 water and wastewater systems in roughly 12 states. Experts cited by Recorded Future News believed groups tied to Iran’s military carried out those attacks. The reporting also said state-backed groups and ransomware operators have repeatedly targeted U.S. water systems, at times pushing utilities to disable certain tools or run operations manually.

The federal government has tried this route before and found the plumbing political. A Biden administration effort to add cybersecurity checks to annual water-system assessments was challenged in court by water-industry groups and several states, which argued that required improvements could raise customer costs. The administration later dropped the effort, according to Recorded Future News.

Schiff said the new bill would give EPA tools to protect critical infrastructure while supplying local systems with resources. Whether the authorization becomes law, and whether Congress provides the money, remain separate questions not answered by the proposal.

This story draws on original reporting from The Record.

More Security/

view all ↗