H2 Innovations
Insights
Water Sector Note · August 2026

US water infrastructure is under attack.A proposed Senate bill would fund the defense.

Nobody thinks about their water. You turn the tap and it is there, you flush and it goes away, and the only time it crosses your mind is when a boil-water notice shows up and making coffee suddenly involves a saucepan.

Some of this summer’s notices had nothing to do with a broken main or a failed pump. Somebody got into the control systems, changed the passwords, and locked operators out of their own equipment, and whole plants went back to being run by hand. Federal reporting counts that cyber attack campaign across at least seven states, and public reporting points at a foreign government behind it, even though federal agencies will not yet say so officially.

So the Senate has stepped in with a proposed bill, the Water Cyber Shield Act of 2026, to help water systems defend themselves.

  • The proposed rules come in tiers, so a small utility would not be handed a big city’s homework, and the mandatory assessments would land on the large systems.

  • Smaller systems would get priority and extra flexibility for the federal money, and the newest free help is aimed at them too.

  • Enforcement would ultimately sit with the Environmental Protection Agency (EPA), with states taking the lead where they can.

01 · Tiers

A tiered approach, not one rule for everyone

Senators Adam Schiff and Amy Klobuchar introduced the proposed Water Cyber Shield Act of 2026 on August 11. I wrote about the summer’s incidents themselves in After the disconnect; this note is about the defense. And let me say the quiet part first: it is a proposal, not law. Nothing in it obliges you to do anything today. What catches my eye is the shape of it. Instead of one rule for every system, the Environmental Protection Agency (EPA) would write tiered cybersecurity standards, working with the federal Cybersecurity and Infrastructure Security Agency (CISA), the National Institute of Standards and Technology, the states and the water sector itself.

The obligations would follow the tiers. If you run a large drinking water or wastewater system, you would fold cybersecurity assessments into the risk and resilience planning you already do. Behind all of it sits proposed funding of 300 million dollars a year through the state revolving funds, earmarked for cybersecurity. A thirty-year-old plant serving eight hundred connections and a metropolitan utility would not be handed the same homework, and that is by design. The proposed rules arrive in tiers, and the first question to ask is which tier you would be in.

02 · Small systems

The smallest systems come first in line

If you run a small system, this part is for you. Reporting on the proposed bill says smaller systems would get priority and extra flexibility for the federal money, and that ordering matches where the reality is hardest: the systems with the fewest people to spare are the ones being asked to answer questions that were never anybody’s job.

And you do not have to wait on the proposal. This August at DEF CON 34 in Las Vegas, DEF CON Franklin and the National Rural Water Association announced the Water Watch Center: free managed detection and response for utilities serving fewer than 10,000 customers. I am deliberately not naming the participating firms, because I have that list from a single source; if you are evaluating the offer, get it from the organisers. And keep detection in its own box. It tells you something has happened, while your architecture decides what is reachable at all, so the two are complements rather than alternatives, and you want both. If you serve fewer than ten thousand customers, the newest help is free, already here, and does not wait for the proposed bill to pass.

03 · Enforcement

Enforcement would end at the EPA

So who would come knocking? As proposed, the EPA would hold explicit authority to assess cybersecurity risk at water systems and to require corrective action where it finds significant vulnerabilities. Your state could take the primary role if it has the capacity, with the EPA leading where necessary, so whoever holds your file day to day, the chain would end federally. The reporting also ties the funding to state requirements covering vulnerability assessments, cyber asset inventories, and tighter control of remote access to operational technology. Keep in mind that those three come from reporting on the proposed bill, not from anything you can read as a rule today.

If a version of this becomes law, the questions an enforcer would ask are already visible in that list, and none of them is answered by a purchase order. For the paths where a person reaches into the plant, CISA’s posture is right and comes first: an authenticated and monitored gateway, reachable only from engineering systems you have named, and never a session that ends on a controller. When enforcement comes asking what can reach your control layer, the strongest answer is a short list of encrypted and secure connections.

04 · How we help

How can we help?

Where a purchase does help is enforcement of those encrypted and secure connections. Think about what actually crosses your boundary: mostly it is readings going out, not people reaching in, and the two deserve very different doors.

The reported attacks all took the same shape: a controller reachable from the internet, a password changed, an operator locked out. We designed our Flowgate gateway against exactly that category of exposure. Relay nodes inside your plant initiate every connection outward over an encrypted channel and keep no inbound listener at all, so there is nothing for a stranger to find: nothing waiting for a call, nothing to forward a port to, and nothing left behind after commissioning. It buffers your readings while a link is down, signs people in against your Active Directory instead of another shared password, and keeps a timestamped, hash-chained record of every change. I want to be straight about what kind of claim that is. It describes the configuration, not a promise about attackers, and every other control you run still matters exactly as much. It is one path, not all paths. And because bytes move both ways once a session exists, whether that session may ever write back into your plant is its own decision, taken and recorded separately. A path with no inbound listener does not become an easier row to justify. It stops being a row.

None of this is a rating or a compliance claim, and the proposed requirements do not yet exist as rules anyone can satisfy. What I will say is narrower: a boundary whose exposure description is a single encrypted channel that is built to support the kind of evidence an assessment asks for, and does not require any new holes or exceptions created within your firewall.

05 · Sources

Sources

06 · Take with you

The three things to take with you

The proposed rules arrive in tiers, and the first question to ask is which tier you would be in. If you serve fewer than ten thousand customers, the newest help is free, already here, and does not wait for the proposed bill to pass. And when enforcement comes asking what can reach your control layer, the strongest answer is a short list of encrypted and secure connections.

And if you want one next step for this week, ask your own team a single question: how many paths into our control system could we name from memory? However that conversation goes, you will know which tier of this problem you are standing in.

If you would rather describe your own boundary and ask us what we would do with it, write to us at info@h2innovations.ca.