Showing posts with label Water Security. Show all posts
Showing posts with label Water Security. Show all posts

Monday, December 1, 2025

Review S 2388 Introduced – Cyber Circuit Rider Program

Back in March Sen Cortez-Masto (D,NV) introduced S 1018, the Cybersecurity for Rural Water Systems Act. The bill would require USDA to establish a rural water and wastewater cybersecurity circuit rider program” similar to the one established in 7 USC 1926(a)(22), but focused on cybersecurity. The bill would authorize $10-million per year through 2028 to support the program.

This bill is essentially the same as S 2388, the Cybersecurity for Rural Water Systems Act, that was introduced by Cortez Masto in July 2023. No action was taken on that bill in the 118th Congress.

Moving Forward

Neither Cortez-Masto nor her sole co-sponsor {Sen Rounds (R,ND)} are members of the Senate Agriculture, Nutrition, and Forestry Committee to which this bill was assigned for consideration. This means that it is unlikely that there is sufficient influence to see the bill considered in Committee. Adding $10-million dollars in spending is sure to draw opposition from many Republicans, but there may still be sufficient bipartisan support in the Committee to see the bill approved if it were considered.

As with most bills, there would not be sufficient interest in this legislation to see the Senate leadership tie up the Senate for the time that it would be necessary to consider this bill under regular order. Because of the added spending involved, it would not be possible to pass this bill under the Senate’s unanimous consent process; it would take just a single Senator to object to passage of the bill to kill consideration.

Commentary

The current circuit rider program has about 147 personnel periodically helping small water systems and small wastewater treatment systems. CISA reports about 153,000 water treatment facilities in the US with the vast majority (93 % by one estimate -pg 3) being small systems that would be covered by the circuit rider program. That means that each circuit rider would have to cover about 1,000 systems. They do not get around very often.

 

For more details about the provisions of this bill, including a brief look at the related NRWA actions, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2388-introduced-cyber-circuit-rider - subscription required.

Friday, March 24, 2023

S 660 Introduced – Water System Threats

Earlier this month, Sen Markey (D,MA) introduced S 660, the Water System Threat Preparedness and Resilience Act of 2023. This is a companion bill (identical wording) to HR 1367 that was introduced earlier this month in the House. The legislation would require the EPA to carry out a program to support, and encourage participation in, the Water Information Sharing and Analysis Center (W-ISAC). The legislation would authorize $10-million for FY 2024 and FY 2025 to support this initiative.

Moving Forward

Markey is a member of the Senate Environment and Public Works Committee to which this bill was assigned for consideration. This means that there should be sufficient influence to see the bill considered in committee. I see nothing in this bill that would engender any organized opposition, and the spending issue is less of a problem in the Senate than in the House. At this point, this bill is more likely to move forward in committee than is the House bill.

Commentary

While the undefined term ‘malevolent acts’ used in §2(b)(4)(B) would certainly seem to include cyber incursions or attacks, I would prefer to see cybersecurity specifically addressed. To that end, I would suggest changing subparagraph (B) to read:

“(B) enhancing the preparedness of community water systems and publicly owned treatment works to identify, protect against, detect, respond to, and recover from cybersecurity threats (as defined in 6 USC 1501), malevolent acts (within the meaning of section 1433 of the Safe Drinking Water Act (42 U.S.C. 300i–2)) or natural hazards.”

 

For more information about the provisions of this bill, see my article on HR 1367 at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-1367-introduced - subscription required.


Wednesday, March 22, 2023

Review - HR 1367 Introduced – Water System Threats

Earlier this month, Rep Schakowsky (D,IL) introduced HR 1367, the Water System Threat Preparedness and Resilience Act of 2023. The bill would require the EPA to carry out a program to support, and encourage participation in, the Water Information Sharing and Analysis Center (W-ISAC). The legislation would authorize $10-million for FY 2024 and FY 2025 to support this initiative.

Moving Forward

Schakowsky is not a member of the House Transportation and Infrastructure Committee to which this bill was assigned for primary consideration, but she is a member of the House Energy and Commerce Committee to which this bill was assigned for secondary consideration. This means that she may have sufficient influence to see the bill considered in that Committee. Unfortunately, without influence in the T&I Committee, this bill has little chance of moving forward.

I see nothing in this bill that would engender any organized opposition beyond the $10-million authorized. I would expect that there would be some Republican opposition to the additional spending, but support for local water treatment facilities will frequently overcome such philosophical opposition. This bill would probably receive some level of bipartisan support.

Commentary

While the undefined term ‘malevolent acts’ used in §2(b)(4)(B) would certainly seem to include cyber incursions or attacks, I would prefer to see cybersecurity specifically addressed. To that end, I would suggest changing subparagraph (B) to read:

“(B) enhancing the preparedness of community water systems and publicly owned treatment works to identify, protect against, detect, respond to, and recover from cybersecurity threats (as defined in 6 USC 1501), malevolent acts (within the meaning of section 1433 of the Safe Drinking Water Act (42 U.S.C. 300i–2)) or natural hazards.”


For more details about the provision of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-1367-introduced - subscription required.

Sunday, November 14, 2021

Water Cybersecurity – NERC CIP or Something Else

An interesting blog post by Patrick Miller over on Ampersec.com on the topic of using the NERC CIP as a model for cybersecurity regulation of the water treatment/wastewater treatment sector. With his long experience with NERC CIP from a number of different perspectives, Patrick makes a number of important points that should be taken into account in any discussion of how to regulate the water sector. Unfortunately, I think he missed an important question, does cybersecurity really need to be regulated in that sector?

Last February I weighed in on this topic with my post “Call for Cybersecurity Regulations”. I want to take another look at the topic here, from a slightly different perspective, a perspective well familiar to those with experience in the Chemical Facility Anti-Terrorism Standards (CFATS) program, risk-based cybersecurity.

From a regulatory perspective, the federal government has no legitimate interest in insuring that the information services at water treatment facilities are adequately protected from cyberattacks. That is a utility management issue, the purview of State and local utility oversight organizations. Similarly, the EPA is only interested in ensuring that the water leaving the facility (into drinking water distribution systems or back into the wild, depending on the type of treatment plant) meets certain quality standards. As long as output testing controls are adequately protected, the cybersecurity of upstream treatment is not a legitimate federal concern.

So, we do not need a comprehensive set of cybersecurity regulatory controls to protect water treatment facilities from cyberattacks. We need each facility to have a risk-based vulnerability assessment of what controls (manual, analog and digital) at their unique facility are critical to output quality controls and then a properly scoped security plan (physical and digital) to protect those critical controls.

The EPA has taken a poorly crafted crack at the assessment side of the equation, but they are relying on local facility management that is trained and experienced in water treatment engineering to conduct security assessments. And they are just requiring that facilities certify that those assessments have been properly done. Security planning is just an after-thought.

What is needed is an online tool like that used in the CFATS program to submit vulnerability assessment data and relatively formulaic security plans. Water facilities are going to be more similar than chemical facilities, so a water security assessment tool (WSAT) will not need to be as complicated as the CFATS chemical security assessment tool (CSAT).

As I have said before, CFATS is probably a better model to look at rather than something like NERC CIP or the nuclear facility security model.

Tuesday, October 29, 2019

Bills Introduced – 10-28-19


Yesterday with both the House and Senate in session there were 48 bills introduced. Three of those bills may receive future coverage in this blog:

HR 4891 To provide for the conduct of certain water security measures in the Western United States, and for other purposes. Rep. Torres Small, Xochitl [D-NM-2]

S 2714 A bill to amend the America COMPETES Act to reauthorize the ARPA-E program, and for other purposes. Sen. Van Hollen, Chris [D-MD]

S 2718 A bill to provide for the conduct of certain water security measures in the State of New Mexico, and for other purposes. Sen. Udall, Tom [D-NM] 

I suspect that the ‘water security measures’ referenced in HR 4891 and S 2718 are related to ‘supply security’ not physical or cyber security of the water systems.

Saturday, March 15, 2014

Bills Introduced – 3-14-14

The Senate left early for their week-long trip back to their home states for personal contacts, voter schmoozing and fund raising. The House stuck around long enough to introduce 26 bills before they also left town for a week. Of those bills only two may be (remotely perhaps) of particular interest to readers of this blog:

HR 4258 Latest Title: To reauthorize and update certain provisions of the Secure Water Act. Sponsor: Rep Napolitano, Grace F. (D,CA)

HR 4263 Latest Title: To amend the Homeland Security Act of 2002 to authorize the Department of Homeland Security to establish a social media working group, and for other purposes. Sponsor: Rep Brooks, Susan W. (R,IN)

The Secure Water Act was actually a drought protection measure, but there is a remote possibility that this bill may include some actual security measures or, slightly more likely, some chemical protection measures. We will have to wait and see.


The Department’s use of social media is mixed at best, with some organizations (TSA is a good example) aggressively using social media and others not so much. The Department has taken some heat for monitoring social networks for situational awareness (NOTE: This blog has appeared on the lists of sites monitored; I welcome the attention). It will be interesting to see which side of that focus this bill falls.

Friday, May 14, 2010

Water System Security Issues

There is an interesting story on EastBayRI.com that, while it doesn’t deal with water treatment chemicals, does shed some light on how little attention is paid to water supply security issues by the Environmental Protection Administration. According to this local news story the police are investigating the release of 40 million gallons of water from a reservoir. Someone had cut locks on chains securing some large water valve handles which allowed the water to discharge into a creek. Interestingly no one knows when the valves were opened, but it was discovered by a water system employee making a ‘routine check’ of the reservoir. Any security professional knows that locks do not provide any kind of security unless they are watched; bolt cutters are available at any hardware store. Since this reservoir is a secondary water source for the water system, it probably doesn’t make any sense to have anyone on-site watching the locks. There are, however, a number of devices that could do that watching; video cameras, flow meters on the discharge lines, valve position sensors, etc. Any of these would have allowed for a response that would have prevented 40 million gallons of water being discharged. The local police chief told the reporter for this story that, because “it involves a water supply and water safety, it is something we take very seriously”. Unfortunately, current federal regulations do not take water system security seriously. The only requirement is for facilities to certify that they have completed water system security vulnerability assessments. There are no security standards, not even risk-based performance standards. There are no requirements for outside inspectors to check or verify that security measures are actually in place and functional. The EPA has the technical knowledge necessary to assure water quality issues, but does not have the necessary security background to assure that water quality is defended against potential attack or even vandalism. Congress needs to realize that security issues at such a vulnerable yet crucial public resource needs to be overseen by security professionals. Either EPA needs to be given that capability/responsibility by Congress or it should be given to DHS.

Saturday, April 3, 2010

Reader Comments 03-30-10 Water Security

It’s been a busy week and I missed mentioning two comments posted to my earlier blog about water facility security. Bob Radvanovsky, who brings us WaterSec List, posted both comments and they are well worth reading. Security and Bond Ratings Bob’s first comment looks at the ‘compliance vs security’ issue, noting that in many cases following the rules does not mean that the facility is secure. In that posting he makes an interesting observation that I haven’t seen before, writing: “In most cases, these organizations would loose their bond ratings if they were to admit that they had a security flaw or vulnerability, so instead, do nothing.” I’m pretty sure that Bob is right, any adverse information about the facility could have an effect on their bond rating and that rating is very important to any organization that must rely on the sale of bonds to finance capital improvements. I’m not sure how bond rating organizations would find out about adverse security reports since they are ‘classified’ SSI and should be protected against disclosure. Having said that, I would be interested in hearing if any of the public water treatment facilities that were mentioned in the CAP Chemical 101 report have had their bond ratings affected by that listing. An interesting side light to that question relates to funding for security measures. If a water treatment facility had to execute a major capitol project to effect a mandated increase in security (like substitute sodium hypochlorite for chlorine gas), would that have an effect on the bond rating for the facility? One could argue that the improvement would reduce the risk associated with the facility and that should improve (or at least be neutral to) the facility bond rating. On the other hand, it does point out a severe security issue that would remain while the project proceeded (which could take a couple of years in some cases), so that might temporarily decrease the facility bond rating. Another possibility would be that the new security related capital project could adversely affect the bond rating by increasing the amount of borrowing for the facility to a level that would have an effect on the bond rating. In the normal course of events this project would not be pursued until other projects were paid off, but if the project were mandated by the Federal (or State under the current version of HR 2868) government, that might not be possible. This should be part of the economic evaluation of the projected IST implementation. Insider Attacks In his second post Bob writes that: “This, to me, represents a form of sabotage, and perhaps someone internally who knew the base operations of the organization and what impact this would have on the sudden removal of said equipment.” He also notes that, with the recent increase in radical militias, there might be an expected increase in the potential for insider attacks on facilities. One explanation is a non-terroristic action; employees might have realized that the manual operation of the facility would result in more overtime work to affect the manual operation of the facility. This would mean increased paychecks for those employees. Another explanation, much more threatening, would be that if there were an insider working for or with a terrorist organization, the lack of electronic supervisory control would make it easier to undertake a serreptious attack that would allow for contamination of the drinking water leaving the facility. I’m not sure how successful this would really be with the on going investigation of the ‘theft’, but it would be an interesting attack profile.
 
/* Use this with templates/template-twocol.html */