In a hearing on January 31, 2024, on cybersecurity before the Environment, Manufacturing, and Critical Materials Subcommittee of the U.S. House Committee on Energy and Commerce, the American Water Works Association (AWWA) testified about a collaborative approach to cybersecurity oversight in the water sector.
The hearing was titled “Ensuring the Cybersecurity of America’s Drinking Water Systems” and included experts from water organizations across the country. AWWA Federal Relations Manager Kevin Morley testified on behalf of the Association, which represents 50,000 water professionals throughout the United States and beyond.
“Strong cybersecurity measures are essential to ensuring a cyber incident does not threaten public health. Water systems need resources and regulatory oversight designed to mitigate the potential risks from cyberattacks around the clock, every day of the year. This means we need to act now,” Morley said.
Morley testified that a combination of regulatory and non-regulatory actions are necessary to tackle the cyber threats facing water systems. AWWA has recommended congressional action to support a new cybersecurity governance framework in the water sector that leverages the technical knowledge of utilities, cybersecurity experts and regulators to implement a comprehensive cybersecurity risk management strategy. This model, authorized by federal legislation, would create an independent, non-federal entity to lead the development of cybersecurity requirements using in part subject matter experts from the water sector. Federal oversight and approval of requirements would be provided by the U.S. Environmental Protection Agency, which already regulates drinking water and wastewater utility operations.
This collaborative approach builds on a similar model that has already been successfully applied in the electric sector. The recommendation also aligns with calls for greater public-private collaboration included in the National Cyber Strategy.
“The diverse nature of water utilities requires a tiered framework that recognizes the technical challenges facing the sector and sets reasonable cybersecurity requirements that focus on practical, protective, and implementable solutions,” Morley said.
In addition to establishing a sound oversight model, Morley shared three essential areas of collaboration that could enhance cybersecurity in the water sector. These areas include:
- Overcoming the digital divide
- Threat information sharing
- Vulnerability mitigation and technical assistance
Established in 1881, the American Water Works Association is the largest nonprofit, scientific and educational association dedicated to managing and treating water, the world’s most vital resource. With approximately 50,000 members, AWWA provides solutions to improve public health, protect the environment, strengthen the economy and enhance our quality of life.
Comments