Senators Adam Schiff and Amy Klobuchar introduced the Water Cyber Shield Act, which would give the EPA explicit authority to conduct cybersecurity assessments, require corrective actions and establish security standards for water systems alongside CISA and NIST.
The bill would also authorize $300 million annually for water infrastructure upgrades, require risk assessments for large systems and expand mandatory cyber incident reporting.
The legislation follows coordinated cyberattacks against dozens of community water systems across at least 12 states. Separately, DEF CON Franklin and the National Rural Water Association launched the Water Watch Center to provide cybersecurity services to utilities serving fewer than 10,000 people, a group representing 91% of the roughly 50,000 community water systems nationwide. Five cybersecurity firms will provide managed detection and response services, building on a two-year pilot involving nearly 450 volunteer cybersecurity experts across seven states.
Damon Small, Board of Directors, Xcape, Inc.:
“The Water Cyber Shield Act attempts to address a major regulatory gap by granting the Environmental Protection Agency explicit authority to enforce baseline security standards and allocate $300 million annually for utility upgrades, but federal dollars alone cannot fix this sector’s systemic fragility. Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.
“The industry already possesses robust reference architectures and standards for protecting control systems, so the primary barrier is execution rather than a lack of guidance. Furthermore, claiming that capital injections will solve the threat ignores the reality that maintenance windows are rare in continuous operational technology environments. Rather than waiting on Congressional appropriations, security leaders and asset owners must immediately execute foundational controls: strictly isolate industrial control networks from corporate IT, eliminate publicly exposed management interfaces to the Internet, enforce multi-factor authentication, and replace default device credentials.
“Critical Takeaways
- Funding dilution: Allocating $300 million across 50,000 utilities yields $6,000 per facility, failing to cover basic operational technology remediation.
- Operational reality: Standards already exist, but infrequent maintenance windows choke security execution far more than funding deficits.
- Immediate action: Operators must enforce network segmentation, eliminate Internet-facing control systems, and rotate default credentials immediately.
“Operational security standards already exist; what utilities lack is not awareness, but the uptime flexibility to actually apply patches.”
Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs:
“While it’s always exciting to see Congress attempt to get some good cybersecurity hygiene laws in place, it’s likely a far reach from what will actually happen. The Water Cyber Shield Act feels a lot like a round two attempt from when this was attempted back in 2023 under the existing Safe Drinking Water Act authority as a rule, but that got shut down when water industry groups and a coalition of GOP states argued that it would increase costs on ratepayers, and then the EPA folded and pulled the rule. (More info can be found here https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys)
“I hate to say it, but historically speaking, this is likely to fail before making it to a vote, just like all other bills that have been attempted to improve water cybersecurity in the past. If we look at just the 118th and 119th Congress, we have had 9 bills introduced, as far as I’m aware, that pushed language that would have focused on either providing monetary assistance for, directly enforcing industry standards, and/or regulation around cybersecurity for water systems and CI, each varying in degree of what they would have provided and who they would have protected (rural vs non), but of those 9, all from within the 118th congress died within committees and without comments or markup, meaning no one even bothered to fight for them to get a vote across. Technically, the 4 from this congress (119) are still “pending’ but considering no movement has occurred on them, they will likely reach the same fate.
- https://www.congress.gov/bill/118th-congress/house-bill/3809 – H.R.3809 – Cybersecurity for Rural Water Systems Act of 2023
- https://www.congress.gov/bill/118th-congress/house-bill/7922– H.R.7922 – To establish a Water Risk and Resilience Organization to develop risk and resilience requirements for the water sector.
- https://www.congress.gov/bill/118th-congress/senate-bill/5335 – S.5335 – Rural Prosperity and Food Security Act of 2024
- https://www.congress.gov/bill/118th-congress/house-bill/10389 H.R.10389 – Water Authority Cybersecurity Protection Act
- https://www.congress.gov/bill/118th-congress/house-bill/10483 – H.R.10483 – Water Cybersecurity Enhancement Act
- https://www.congress.gov/bill/119th-congress/house-bill/2109 – H.R.2109 – Cybersecurity for Rural Water Systems Act (attempt 2 of the Cybersecurity for Rural Water Systems Act)
- https://www.congress.gov/bill/119th-congress/house-bill/2344 – H.R.2344 – Water ISAC Threat Protection Act
- https://www.congress.gov/bill/119th-congress/house-bill/2594 – H.R.2594 – To establish a Water Risk and Resilience Organization to develop risk and resilience requirements for the water sector.
- https://www.congress.gov/bill/119th-congress/senate-bill/1549 – S.1549 – Water Cybersecurity Enhancement Act of 2025
“Ultimately, Congress has been unreliable in pushing forward regulation and standards towards CI for quite some time, and the mantle thankfully has been picked up by private organizations and security practitioners who wish to have a safer and more secure water source. Even though it shouldn’t be dependent on the goodwill of private citizens to protect public infrastructure. Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn’t the first time we have had this situation happen before. So, my fingers are crossed, but I’m not holding my breath.”
John Strand, Owner, Black Hills Information Security, Inc.:
“I think this type of legislation is important, but it’s also long overdue. People have known about the security weaknesses in critical infrastructure, especially within municipalities, for well over a decade. Unfortunately, this is another example of a reactive approach to cybersecurity. Too often, meaningful action doesn’t happen until the damage has already been done.
“My concern is that by the time these programs are fully implemented and organizations begin benefiting from them, many of the municipalities with the same vulnerabilities that enabled recent attacks will have already been compromised. It’s a positive step, but it’s arriving years after the underlying risks were widely understood. This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.”
While addressing critical infrastructure is long overdue, the time to act is now as the threat is real and present. Will lawmakers act on that threat is the real question.
Cybernews comments on fake Wi-Fi network on Delta flight
Posted in Commentary with tags Cybernews on August 13, 2026 by itnerdFollowing a report of a fake Wi-Fi network on a Delta flight to Atlanta, Cybernews’ Senior Information Security Researcher Aras Nazarovas has commented on the risks such networks may pose, as well as what the people affected should know.
What risks do fake Wi-Fi networks pose? What is an evil twin attack?
“An evil twin attack is when hackers create fake Wi-Fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present on victim devices. The fake networks often have a very similar (or identical) name to the legitimate network, which was the case here.
Once a person connects to the hacker’s Wi-Fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private.
The risk here is that the hacker may attempt to redirect the victim to a phishing website – for instance, in this case, it may have been a fake Delta login page asking for personal data like name, email, address, etc. Or, the hacker may even go further and provide fake login pages for banks, social media, and try to extract login details from the victims.”
Are the people who connected to the network at risk?
“Connecting to such a network comes with some risk in itself. Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers.
If a person entered credentials into a Wi-Fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen. In that case, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze the bank account until new credentials are received.
However, if a user just connected and disconnected to the Wi-Fi without entering any details or clicking suspicious links, they should be fine.”
Leave a comment »