Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Critical Infrastructure Security - US Rural Water Systems and Wastewater Utilities Seek Cybersecurity Boost
Critical Infrastructure Security Latest News News & Analysis Security

US Rural Water Systems and Wastewater Utilities Seek Cybersecurity Boost

Adam ParlettBy Adam ParlettMarch 20, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
US
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Two bipartisan Senate bills reintroduced by US Senators last week aim to boost the cybersecurity defenses of small water and wastewater utilities. 

Any move to enhance cybersecurity in the water sector is welcome and overdue following calls last year from the Environmental Protection Agency (EPA) and the Cybersecurity and Infrastructure Security Agency (CISA) for the industry to secure remote access to Human Machine Interfaces (HMIs) following an attack by pro-Russia hacktivists. 

Time to Act 

The Senators introducing the bills assert that only 20% of water and wastewater systems across the U.S. do not even have even basic levels of cyber protection. They are looking to address the situation through the Rural Water System Disaster Preparedness and Assistance Act and The Cybersecurity for Rural Water Systems Act. 

The Rural Water System Disaster Preparedness and Assistance Act would help rural water and wastewater utilities prepare for and become more resilient to natural disasters and other extreme weather events. 

The Cybersecurity for Rural Water Systems Act would update technical assistance opportunities for cyber defense to address vulnerabilities in rural water systems. 

Modernizing the Program 

Both bills would modernize and increase the scope of the Department of Agriculture’s Circuit Rider Program. The program provides technical assistance to rural water systems experiencing daily financial, managerial, or operational problems. The amendments seek to improve the sector’s cybersecurity through protocols for protection and prevention and the hiring of cybersecurity experts, referred to as ‘circuit riders.’ 

Mike Rounds, the Republican Senator from South Dakota who co-led the Cybersecurity for Rural Water Systems Act, underlined the need for the amendments. “As our near-peer adversaries continue to utilize cyberattacks, we must have cybersecurity safeguards in place to protect our critical infrastructure, such as water systems. Our legislation would modernize and expand the Circuit Rider Program, providing cybersecurity-related technical assistance to rural water and wastewater systems.” 

2024 Was a Tough Year 

Ensuring the safety and security of water resources is critical for public health, agriculture, and industrial processes. Unfortunately, 2024 saw a concerning rise in cyberattacks targeting water systems. Some of the notable attacks were: 

  • American Water—The biggest water and wastewater utility in the United States, serving approximately 14 million people, experienced a cybersecurity incident in October 2024. The attack resulted in the shutdown of its call center and the disconnection of its customer portal and billing platform. 
  • Arkansas City Water Treatment Facility – The City’s Water Treatment Facility had to switch to manual operations while a cyberattack, which occurred in September 2024, was being resolved. The incident was investigated by the FBI and the U.S. Department of Homeland Security. 

These attacks were accompanied by apologies and assurances but without detailed public disclosures. Any disruption to the digital ecosystem of a drinking water or wastewater system could significantly impact the community it serves and other critical infrastructure. It seems as though 2024 acted as a wake-up call in terms of governance. Recommendations and then urges from authorities have proved insufficient, and now legislation is being proposed, so organizations are forced to act. 

Expert Analysis 

Evan Dornbush, a former NSA cybersecurity expert, has provided his expert analysis of the current situation, as well as his view on the proposed bills.  

“We’ve already seen multiple examples of foreign actors attempting to, and successfully breach the technology utilized by water systems using zero-day exploits and remaining undetected for extended time periods. Building a consolidated program for operators to cost-share on monitoring, remediation, and information-distribution efforts sounds like a national imperative at this point in history.”  

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    New Lazarus Group Scam Targets Crypto Jobseekers

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The evolution of cyber risk: Addressing geopolitical threats

May 13, 20265 Mins Read

“Recovery Is the New Prevention”: a Q&A with CSO of Health-ISAC, Errol Weiss

May 7, 20266 Mins Read

Pro-Russian threat actors target Swedish heat and power plant in failed cyberattack

April 20, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}