Two things happened for US water utility security in the same week, from opposite directions — one legislative, one volunteer — and both are aimed at the same population.

The population is the point. Of roughly 50,000 US community water systems, 91% serve fewer than 10,000 people. These are utilities with a handful of staff, no security team, and equipment that was installed to last thirty years.

The bill

The Water Cyber Shield Act, sponsored by Senators Adam Schiff (D-Calif.) and Amy Klobuchar (D-Minn.).

What it does:

  • Gives the EPA explicit authority to perform cybersecurity assessments, enforce corrective measures and set standards, alongside CISA and NIST
  • Authorises $300 million annually for the Drinking Water and Clean Water State Revolving Funds
  • Mandates risk assessments for large water systems
  • Expands mandatory incident reporting to state and locally owned facilities
  • Protects sensitive utility data from public disclosure

The first item is the one that has been missing. The EPA's authority to require anything on cybersecurity has been contested for years, and a regulator without clear authority produces guidance that utilities are free to file away.

The last item matters more than it looks. Utilities have resisted reporting partly because a public record of a vulnerability is itself a risk. Removing that disincentive is cheap and probably increases reporting more than the mandate does.

Note what the mandate covers: risk assessments for large water systems. The 91% are not the ones being regulated here — they are the ones being funded.

The volunteer effort

Water Watch Center, launched at DEF CON in Las Vegas by DEF CON Franklin and the National Rural Water Association.

Five security firms — Defendify, Legato Security, L1 Secure, Rapid7 and Sentinel Technologies — provide managed detection and response, sharing threat intelligence through the NRWA. Seed funding came from Craig Newmark, the Craigslist founder.

It is expanding into Maryland, covering civilian water systems that support critical national security and military assets, and it is working with Vanderbilt University on DARPA's CASTLE programme to build AI-driven defensive agents.

Why both are needed, and why neither is enough

A small utility's problem is not that it does not know it should segment its network. It is that there is one operations person, the SCADA system was configured by a contractor who has retired, and the budget line for security is zero.

Money fixes some of that. $300 million a year across tens of thousands of systems is roughly $6,000 each if spread evenly, which it will not be — revolving funds go to the utilities with the capacity to apply for them, and capacity is exactly what the 91% do not have.

Managed detection fixes a different part. Someone else watches the network, which is the only model that works when there is nobody local to watch it.

Neither addresses the actual attack pattern. We covered the Minnesota water systems reached with no exploit at all — controllers exposed through cellular modems, default credentials, no vulnerability required. Detection catches that after it starts. Money can remove it beforehand, but only if it reaches the utilities where the exposure is.

What to actually watch

  • Whether the bill moves. Water infrastructure bills have a long history of being introduced and not passing. Sponsorship is not enactment.
  • Whether EPA authority survives the process. That clause is the substantive one and it is the one most likely to be negotiated away.
  • Whether Water Watch Center scales past Maryland. Five firms donating MDR is a pilot, not a national programme, and volunteer capacity has a ceiling.
  • Whether the funding formula favours capacity. Revolving funds reward applicants. The utilities most at risk are the worst applicants.

The honest position: this is more attention than US water security has had in years, and it is still small relative to fifty thousand systems that mostly cannot defend themselves.