Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Senate Democrats Introduce Water Cyber Shield Act to Fund $300M Annual Water System Cybersecurity
Senate Democrats Introduce Water Cyber Shield Act to Fund $300M Annual Water System Cybersecurity
NEWS

Senate Democrats Introduce Water Cyber Shield Act to Fund $300M Annual Water System Cybersecurity

Senators Schiff and Klobuchar introduce legislation directing $300 million per year to secure U.S. water and wastewater infrastructure following coordinated Iranian-linked attacks on municipal systems across 12 states.

Dylan H.

News Desk

August 10, 2026
5 min read

Senators Adam Schiff (D-California) and Amy Klobuchar (D-Minnesota) introduced the Water Cyber Shield Act on August 10, 2026, proposing $300 million in annual federal funding to strengthen cybersecurity defenses across U.S. drinking water and wastewater systems. The legislation arrives in direct response to a coordinated cyberattack that disrupted more than 30 municipal water systems across approximately 12 states — with U.S. officials attributing the attacks to groups connected to Iran's military.

Background: The Attacks That Prompted the Bill

The immediate catalyst for the legislation was a coordinated campaign that struck municipal water and wastewater operational technology (OT) systems across multiple states. Minnesota was among the hardest hit, with cities including Plymouth, South St. Paul, Maple Plain, and Braham all reporting disruptions that caused brief automated shutdowns, pressure loss, or forced switches from automated to manual operations.

The attacks highlighted a chronic vulnerability in U.S. water infrastructure: thousands of small and mid-sized water utilities operate with minimal cybersecurity budgets, aging OT equipment, and limited technical staff — making them attractive targets for adversarial nations seeking to probe critical infrastructure without triggering a full escalatory response.

This is the second major legislative attempt to address the issue. The Biden administration's 2023 effort to mandate cybersecurity assessments for water utilities was blocked by Republican state opposition and industry groups citing regulatory overreach.

Key Provisions of the Water Cyber Shield Act

Funding Mechanism

The bill allocates $300 million per year channeled through two existing EPA grant programs:

  • Drinking Water State Revolving Fund — funds improvements to drinking water systems
  • Clean Water State Revolving Fund — funds wastewater and stormwater infrastructure

Smaller water systems with limited internal resources are prioritized as funding recipients, acknowledging that large utilities have more capacity to self-fund cybersecurity improvements.

EPA Assessment Authority

The legislation amends the Safe Drinking Water Act and Clean Water Act to give the EPA authority to:

  • Conduct formal cybersecurity assessments of water and wastewater systems
  • Require corrective actions where vulnerabilities are identified
  • Develop minimum cybersecurity standards in collaboration with CISA and NIST

CIRCIA Compliance Mandate

Water and wastewater utilities would be required to comply with the incident reporting requirements under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) — bringing the sector into alignment with the broader mandatory reporting framework already applying to most other critical infrastructure sectors.

State Primacy Option

States with sufficient enforcement capacity may elect to hold primary enforcement responsibility rather than defaulting to federal EPA oversight — a concession designed to attract bipartisan support by preserving state-level authority.

Other Provisions

ProvisionDetail
Technical advisory committeeSector-specific cybersecurity standards development
Information protectionAssessment data shielded from public disclosure to prevent adversaries from learning of specific vulnerabilities
Progress reportingEPA required to develop success metrics and publish public progress reports
Risk assessmentsUtilities must assess cybersecurity risk as part of resilience planning

Sponsor Statements

Senator Klobuchar: "The recent cybersecurity attacks on Minnesota have highlighted the urgent need to improve the security of our water systems and critical infrastructure. Our legislation will direct the EPA to assess water infrastructure cybersecurity and identify vulnerabilities, and help municipal water systems defend against cyber threats."

Senator Schiff: "Every American depends on safe, reliable drinking water, yet recent events have exposed just how vulnerable our water systems remain to cyberattacks by foreign adversaries and criminal entities. These threats are not hypothetical — they are happening right now. This legislation gives EPA the tools it needs to protect this critical infrastructure while providing resources that local water and wastewater systems need to strengthen their cybersecurity without passing the cost on to ratepayers."

Industry Reaction

The American Water Works Association (AWWA), the primary trade group for U.S. drinking water utilities, has been publicly encouraging Congress to act in response to recent attacks, signaling sector-level support for federal investment. The Water Cyber Shield Act's funding-forward approach — leading with resources rather than mandates — appears designed to avoid the regulatory backlash that derailed the 2023 effort.

Legislative Outlook

Introduced as S.5368 in the 119th Congress, the bill has not yet been assigned to committee for a vote. Senator Schiff's office has indicated he may seek to attach the legislation to a larger legislative package before year's end but has not identified a specific vehicle.

Passage faces the structural challenge that affected previous water cybersecurity legislation: smaller utilities and some state governments worry that federal mandates will impose compliance costs that outpace any funding benefit. The bill's state primacy option and explicit prioritization of smaller systems appear designed to address those objections.

Why Water Systems Are a Persistent Target

Water infrastructure presents a compelling target for adversarial nation-states for several reasons:

  • Direct public health impact: Compromising water treatment or distribution threatens the health of entire communities
  • Psychological effect: Public anxiety about water safety is disproportionate to the actual disruption caused by brief OT outages
  • Weak defenses: Thousands of small utilities run legacy SCADA systems with minimal cybersecurity staffing or budget
  • Limited federal oversight: Until now, no federal agency has had clear authority to assess or mandate cybersecurity standards for water systems

The Water Cyber Shield Act would address the last two points directly — if it passes.

References

  • The Record — Water Cyber Shield Act Coverage
  • Congress.gov — S.5368
  • AWWA Water Security Resources
  • CISA Water and Wastewater Systems Sector
#Water Security#Critical Infrastructure#US Senate#Legislation#Iran#CISA#OT Security

Related Articles

Iran, Russia, and China Target Water Systems for Sabotage

Nation-state attackers from Iran, Russia, and China are breaching water utility systems through weak passwords, exposed PLCs, and poor network...

5 min read

Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack

California Water Service has confirmed that Iranian hacker group Handala's cyberattack was limited to IT systems, with Mandiant's investigation finding no...

6 min read

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

A CISA/FBI joint advisory warns that Gunra ransomware — a Conti-derived RaaS — has claimed 51+ victims by exploiting critical Fortinet FortiOS authentication bypass flaws, deploying double extortion across healthcare, government, and critical infrastructure sectors.

4 min read
Back to all News