Water infrastructure is becoming a bigger target for cybercriminals, and the United States is responding on two fronts. First, lawmakers are proposing expanded federal authority and funding to improve security across public water systems. Second, a grassroots-style initiative launched during DEF CON is giving smaller utilities hands-on help to detect and respond to threats.
Together, the Water Cyber Shield Act and the new Water Watch Center (WWC) are designed to reduce risk, increase visibility into incidents, and speed up upgrades—especially for water providers that often lack dedicated security teams.
What the new Senate bill would change
Senators Adam Schiff and Amy Klobuchar introduced the Water Cyber Shield Act to strengthen water cybersecurity with clearer federal oversight and additional resources. The proposal centers on giving the Environmental Protection Agency (EPA) explicit powers related to cybersecurity in the water sector.
Under the bill, the EPA would be able to perform cybersecurity assessments and require corrective actions where needed. The legislation also calls for security standards to be developed and aligned alongside existing frameworks and organizations, including CISA and NIST.
More funding for drinking and clean water upgrades
Security improvements cost money, and the bill reflects that reality. To help utilities pay for upgrades, it authorizes $300 million each year for the Drinking Water and Clean Water State Revolving Funds.
This funding is intended to support the kind of investments utilities typically need to harden systems—work that can include technology refreshes, security controls, and other mitigation steps following risk reviews.
Risk assessments and incident reporting requirements
Beyond funding, the legislation includes requirements that aim to make the sector more resilient over time. It would require risk assessments for large water systems, which are more likely to have extensive infrastructure and higher impact if compromised.
It also expands mandatory cyber incident reporting to additional facilities, including state-owned and locally owned organizations. The goal is to ensure that security events are reported consistently so that patterns and lessons can be shared more effectively.
Finally, the bill includes provisions designed to protect sensitive utility data from public disclosure, recognizing that utilities still need to manage transparency carefully while reporting incidents.
Why the timing matters: recent coordinated attacks
The legislative push comes after a wave of coordinated cyberattacks that targeted community water systems in multiple states. The report cites incidents affecting dozens of systems across at least 12 states, including Minnesota, Michigan, Georgia, South Dakota, New Jersey, and Alabama.
For many utilities, even one successful intrusion can disrupt operations, expose sensitive information, or force emergency recovery efforts. When attacks are coordinated across regions, they also raise the urgency for shared defenses and faster communication.
Water Watch Center: support for small utilities
While federal lawmakers move through the legislative process, a separate initiative is already deploying practical assistance in the field. At the DEF CON conference in Las Vegas, the DEF CON Franklin group and the National Rural Water Association (NRWA) launched the Water Watch Center (WWC).
WWC focuses on smaller utilities that often have limited cybersecurity staff and budgets. Specifically, it targets systems serving fewer than 10,000 people—utilities that represent 91% of the nation’s roughly 50,000 community water systems.
Managed detection and response, plus shared threat intelligence
Instead of asking small utilities to build security operations from scratch, the program provides a more direct service model. Five cybersecurity firms—Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies—deliver managed detection and response capabilities to participating utilities.
In addition to delivering monitoring and response support, the program uses a sharing mechanism for threat intelligence through the NRWA. That approach helps participants benefit from knowledge gained elsewhere, rather than relying solely on local visibility.
Funding to start the initiative was provided by Craig Newmark, the founder of Craigslist.
Built on a two-year pilot in multiple states
WWC is not starting from nothing. The launch expands a two-year pilot program that paired nearly 450 volunteer cyber experts with utilities across seven states.
By moving from a volunteer pilot into a broader program, WWC aims to make assistance more scalable while retaining the same core idea: connecting security expertise to water providers that need it most.
Expanding into additional regions
After the initial rollout, the WWC is expanding into Maryland. The stated focus includes protecting civilian water systems that support critical national security and military assets.
This expansion indicates that the program is looking beyond a narrow pilot scope and toward coverage that can align with broader national priorities.
Digital twins and AI-driven defenses
WWC also plans for the next generation of protection, not just day-to-day monitoring. The program is partnering with Vanderbilt University to use research drawn from DARPA’s CASTLE program.
The approach involves building digital twins of water environments—virtual models that can be used to test defenses in controlled scenarios. The long-term objective is to create AI-driven defensive agents that can automatically detect and stop cyber intrusions.
In other words, the initiative is aiming to blend immediate operational support with research-backed capabilities that could strengthen defenses over time.
How these efforts work together
The Senate bill and the Water Watch Center target different pieces of the puzzle, but they complement each other. The legislation is focused on setting clearer expectations for federal involvement—through EPA assessments, standards, funding, and expanded reporting. WWC, meanwhile, is focused on enabling smaller utilities to act now, even before large policy changes land.
At the same time, both efforts share a consistent theme: improve visibility, reduce uncertainty, and speed up response. Reporting requirements and assessment authority can help identify risk at a system level, while managed detection and response can help utilities handle threats in real time.
What utilities and stakeholders should watch next
For water operators, the next steps will depend on how the Water Cyber Shield Act progresses through the legislative process and how implementation guidance is developed. Meanwhile, WWC’s expansion and partnerships could influence how quickly smaller utilities gain security capabilities.
Stakeholders should also watch how incident reporting rules take shape and how standards are coordinated between federal bodies. Clear, consistent guidance can help reduce confusion and make it easier for utilities to prioritize improvements.
Conclusion
Cyberattacks against water systems have already shown that the threat is real and increasingly coordinated. With proposed federal authority and funding, the Water Cyber Shield Act aims to strengthen water cybersecurity through assessments, standards, and expanded reporting. At the same time, the Water Watch Center brings managed detection and response to smaller utilities—backed by threat intelligence sharing and plans for AI-enabled defenses through digital twins.
Together, these initiatives could help close the gap between large-sector security expectations and the resources available to the many small providers that keep communities running.
