US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
US Senate bill and Water Watch Center aim to boost cyber defenses for water infrastructure.
Summary
US lawmakers have introduced the Water Cyber Shield Act to enhance federal oversight and funding for water infrastructure cybersecurity, authorizing $300 million annually and mandating risk assessments and incident reporting. Concurrently, the Water Watch Center, launched at DEF CON, provides cybersecurity support and threat intelligence to under-resourced small water utilities, leveraging partnerships with cybersecurity firms and academic research for AI-driven defenses.
Full text
Federal lawmakers and cybersecurity leaders have launched parallel initiatives to protect US water infrastructure from growing cyber threats, combining new federal legislation with a grassroots defense project for local utilities. Senators Adam Schiff (D-Calif.) and Amy Klobuchar (D-Minn.) introduced the Water Cyber Shield Act to expand federal oversight and funding for water security. The bill would grant the Environmental Protection Agency (EPA) explicit authority to perform cybersecurity assessments, enforce corrective measures, and establish security standards alongside CISA and NIST. To help utilities fund these upgrades, the legislation authorizes $300 million annually for the Drinking Water and Clean Water State Revolving Funds. It also mandates risk assessments for large systems, expands mandatory cyber incident reporting to state and locally owned facilities, and protects sensitive utility data from public disclosure. The legislative push follows recent coordinated cyberattacks targeting dozens of community water systems across at least 12 US states, including Minnesota, Michigan, Georgia, South Dakota, New Jersey and Alabama. Simultaneously, DEF CON Franklin and the National Rural Water Association (NRWA) launched the Water Watch Center (WWC) at the DEF CON conference in Las Vegas. The program targets small, under-resourced utilities serving fewer than 10,000 people, which represent 91% of the nation’s roughly 50,000 community water systems. Through the WWC, five cybersecurity firms — Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies — will deliver managed detection and response services directly to small utilities while sharing threat intelligence through the NRWA. Seed funding for the initiative was provided by Craigslist founder Craig Newmark.Advertisement. Scroll to continue reading. The launch builds on a two-year pilot program that paired nearly 450 volunteer cyber experts with utilities across seven states. The WWC is now expanding into Maryland to protect civilian water systems supporting critical national security and military assets. To develop future defenses, the WWC is partnering with Vanderbilt University to use research from DARPA’s CASTLE program. The plan is to construct digital twins of water environments to test and ultimately implement AI-driven defensive agents capable of automatically detecting and stopping cyber intrusions. Related: Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data Related: White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative Related: Linux Foundation Unveils New Open Source Security Project Akrites Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack ConcernsNew Jersey, Alabama Join States Targeted in Water CyberattacksNovel Private APN Pivot Let Hackers Sabotage Second Polish Energy FacilityCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataTruck Brake Controller’s Safety Recall Doubled as Hidden Security FixSnowflake Hacker Pleads Guilty in US CourtZero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts Latest News Zoom Patches Zero-Click Code Execution VulnerabilityThe AI Governance Gap Is a Leadership Problem: Waiting Won’t Close ItSAP Patches Critical Code Injection, Memory Corruption VulnerabilitiesCorma Raises $60 Million for Defensive Cybersecurity AI ModelExtension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious ActivitiesHacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to RedemptionOpenAI Unveils New Cybersecurity Model GPT-5.6-CyberMozilla Issues New Firefox GPG Key Following Exposure Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move1Kosmos has named Frank Cohen Chief Revenue Officer.ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email