Summary
- Virginia Wright (Program Manager, Idaho National Laboratory) warned 170,000 U.S. water systems face escalating Russian, Iranian and Chinese cyberattacks exploiting outdated controls.
- Joshua Corman (Executive in Residence for Public Safety and Resilience, Institute for Security and Technology) said Chinese Volt Typhoon hackers remain pre-positioned in civilian water systems to disrupt U.S. mobilization.
- Rep. Menefee pressed David Hinchman (Director, Information Technology and Cybersecurity, U.S. Government Accountability Office) on EPA authority after states sued to block cybersecurity reviews.
- Republican and Democratic members agreed small rural utilities lack resources and staff to defend against sophisticated nation-state cyberattacks without stronger federal support.
- Nicole Tisdale (Founder & Principal, Advocacy Blueprints, LLC) warned 57% of rural operators will retire within ten years as Congress weighs dedicated cybersecurity funding.
Morning digest
Get hearings like this in your inbox
Transcript
The subcommittee on environment will come to order. Without objection, the chair is authorized to declare recesses of the subcommittee at any time. Welcome to today's hearing, entitled Research-Driving Resilience, Applying Science to Secure US Water Systems from Cyber-Threats. I recognize myself now for five minutes for an opening statement. Good afternoon and thank you to our uh witnesses for joining us this afternoon. The purpose of this hearing is to examine how environmental research and development protects our nation's water systems from cyber threats. These threats come from foreign adversaries, malicious actors, and ransomware gangs seeking to exploit vulnerabilities in critical infrastructure. Just last month, the Environmental Protection Agency, the FBI, Cybersecurity and Infrastructure Security Agency, or CISA, and the National Security Agency issued a joint advisory warning the water sector about an urgent cyber security threat linked to Iran affiliated actors. My home state of Florida has already seen the consequences of cyber issues in our own water systems. In twenty twenty one, a cyber lapse in Oldsmar, Florida led to a situation where sodium hydroxide levels in the water supply were increased for a brief period uh from normal treatment amounts to deadly levels before quickly being reverted. During my time in Congress, I've been a strong advocate for increased funding for local water districts. Through the FY twenty-six appropriations process, I helped secure thirteen million in community project funding requests to support critical water and wastewater improvements across Florida's eighteenth district including meaningful upgrades in Auburndale, Baal-Bartow and Lakeland. Now in FY twenty-seven, I'm supporting Polk County with several new projects as well as other water infrastructure upgrades across Hendry and Highland counties. These projects are essential, but they only scratch the surface of the real need. Fewer than twenty percent of Florida's utilities currently meet the Department of Homeland Security's standards for ransomware preparedness. An aging infrastructure only compounds the challenge. That's why I'm continuing to advocate for additional funding in FY twenty-seven. The far-reaching implications of a successful cyber-attack that disrupts water treatment and distribat- distribution systems cannot be overstated. In addition to public health and safety concerns, the obvious concerns, uh access to clean and safe water is foundational to economic growth. A cyber-attack on water systems could lead to widespread ramifications across different sectors including chemicals, manufacturing, and energy, all of which depend on uh abundant access to water. It could also severely impact emergency responses uh uh emergency response operations hospitals firefighters and food production. The water sector is vulnerable because many utilities, especially small and rural systems, rel rely on rate payers to fund the upgrades. Oftentimes, they lack the resources to invest in cyber security and modernization. As infrastructure ages and technology becomes more interconnected, limiting fun- limited funding leaves these systems increasingly exposed to cyber threats at the same time water systems are rapidly digitizing. Many are adopting AI management tools, smart sensors, remote controls, and cloud-based Most importantly, utilities are increasingly dependent on supervisory control and data acquisition systems, which are some of the highest risk targets for cyber attacks. These technologies can greatly improve efficiency, especially for small and rural systems, but they also increase potential p- attack pathways and make incidents harder to detect. That is why we must continue supporting research and development that produces affordable cyber-resilient technologies for the water sector. Security cannot be treated as an afterthought. It must be built into these systems from the start, through approaches like CISA's secure by design framework. We have a responsibility to ensure utilities of all sizes can access technology that is resilient, secure, and practical to deploy. Strengthening the research ecosystem and investing in innovation will defend our critical infrastructure. I'm hopeful today's hearing will help identify the research and development priorities needed to strengthen and protect our water infrastructure from cyber threat. I look forward to today's testimony and discussion. And thank you very much. I now recognize the ranking member of the subcommittee for his opening statement.
Thank you, Mister Chairman, thank you for holding this hearing, and thank you to our witnesses for joining us today. Every American depends on safe and reliable water. It powers our hospitals, our schools, our military installations and our homes. Our nation's three hundred and twenty-four million citizens are served by nearly a hundred and seventy thousand people. public water systems. Yet, uh, the systems that we depend on every day are increasingly vulnerable. Right now, foreign adversaries, ransomware gangs, and criminal networks are seeking to exploit weaknesses in our water infrastructure. And the idea that Iran, China, or Russia could shut off or poison our drinking water sounds like a plot from a blockbuster thriller. But unfortunately, it's a reality. Our systems are being targeted because they're wealthy. not because they're wealthy, but because they're vulnerable. And cyber attacks against water systems have increased tenfold over the past few years. In my home state of Rhode Island, a wastewater treatment facility in Narragansett Bay was hit with a ransomware attack in twenty twenty-two. Operators report were reportedly forced to pay two hundred and fifty thousand dollars to regain access to their computer systems. Luckily, the attack did not disrupt wastewater collection or treatment services. But that money could have gone to upgrading infrastructure, hiring staff, or keeping Rhode Islanders safe. And next time, we might not be so lucky. If these systems go down, or worse, are manipulated, the consequences aren't just digital. They're physical and they're dangerous. Malicious actors target water systems because they're vulnerable and because they know communities will have no choice but to pay. And if they don't, this isn't just a cyber issue. It's a threat to clean drinking water and public safety. This is the challenge before us today. This isn't just a technology problem. We already know how to defend these systems. The problem is implementing best practices and having the right resources. Too many utilities are running on aging infrastructure, with limited to no s- cyber security staff and outdated operational and information techno uh technology systems while trying to defend against sophisticated actors and threats. We're asking local water operators to be IT experts, cyber experts, and public health garden guardians all at the same time. That's a lot for them to take on. And that's frankly not realistic. And it's why the federal government has to step up. As the sector risk management agency, the Environmental Protection Agency is is supposed to lead here. That's their critical function. They're responsible for coordinating cyber security support, guidance and risk management efforts. But unfortunately, it's severely understaffed, under-resourced and stretched thin uh to fully address this growing threat. The Government Accountability Office has been clear, we are not meeting the scale of this threat. It's saying that the EPA has gaps quote " to assess and support the water sector consistent with the scope and scale of the critical infrastructure challenges that this sector faces." So the questions for this hearing I think are straightforward, I think they're simple. How do we ensure that EPA has the personnel, the resources, and the authority to support utilities facing these threats? How do we help smaller and rural systems before vulnerability becomes a full-blown crisis? And how do we build a workforce that is capable of protecting our essential critical water infrastructure? Because as you all know, Uh, water infrastructure isn't just pipes and pumps. It's more complicated. It's public health. It's consequential. It's economic stability. It keeps us safe. It is national security. And we have to do everything in our power as a Congress, with experts, and a whole of government response to treat it, uh, with the - the level of sensitivity, sophistication, and seriousness, uh, that it deserves. And so I'm grateful that you're here, grateful for this hearing, and I yield back.
Thank you, Ranking Member Amo. I now recognize Doctor Babin, the Chairman of the full committee, for a statement.
Thank you, Mr. Chairman. Uh, I want to thank our subcommittee chairman, Mister Franklin, for presiding over this important hearing. Thank you, Mister Amo, as well. Thank you to our witnesses for coming up here. Looking forward to your, uh, uh, say, hearing you share your insights on this very important subject. Many associate cyber security with financial net networks or electric grid, or the or the electric grid, yet uh the infrastructure that provides safe drinking water and manages waste water is equally vital to households and industries nationwide. Recent cyber-attacks on water utilities in my home state of Texas highlight the growing threat facing critical infrastructure across our country. In January, twenty twenty-four, the water system in Muleshoe, Texas which is right on the border with New Mexico, was reportedly hacked, leading to thousands of gallons of water spilling into the streets after attackers manipulated the city's control systems. I see nodding heads up there, so I'm, now some of you are very aware of this. Authorities indicated that the suspected perpetrators even released footage demonstrating how they accessed and reset the controls. Incidents like this are a stark reminder that water and wastewater systems especially those serving small and medium sized communities, are increasingly vulnerable to cyber threats that can disrupt essential public services and jeopardize our public safety. What concerns me is not just that these systems are being targeted, but how unevenly prepared they are to respond across the country. There are more than fifty thousand community water systems, many of them serving small populations with a very limited technical staff. Often these facilities lack the funding to implement cyber security measures. Many rely on decades-old industrial control systems designed when cyber warfare was more science fiction than a real-world threat. Others depend on third-party contractors for maintenance and software updates, creating additional points of entry for these attackers. Reality is that defending this infrastructure has become extraordinarily complex. It's no longer a challenge that human operators alone can manage. As water systems undergo rapid digital modernization, the boundaries between information technology and operational technology have blurred. Today, an attack can begin with something as simple as a phishing email, which then moves across unsecured computer systems into the controls that manage the pumps the valves the chemical treatment processes. In some cases, attackers do not even need to directly seize control uh to cause disruption. Simply by targeting monitoring systems, bad actors can force operators to pause services. For years, conventional wisdom suggested that keeping critical systems isolated from the internet a security technique known as air gapping was the best defense against cyber threats but that approach alone is no longer uh, sufficient or practical. Modern water and s- water systems depend on connectivity for cost-effective remote management. And even so-called isolated networks have proven vulnerable to determine an increasingly sophisticated adversaries. We need to examine how innovation can help close these gaps. Advances in automation, artificial intelligence, and anomaly detection c- could offer new tools for identifying threats much earlier. But adopting these technologies could also have the unintended consequences of introducing new risks if they are not implemented securely from the start. Research will be critical to ensuring our cyber security is it that is is being incorporated into the design of new technologies, intended to address existing vulnerabilities and improve system efficiency. This hearing is an opportunity to move beyond identifying problems and toward meaningful solutions that recognize the complexities of our water systems, the constraints they face, the evolving nature of the threat landscape, and how we fight back and put teeth into uh to some of the uh techniques that we use uh to thwart these efforts. I look forward to today's discussion and I yield back the balance of my time, Mister Chairman. Thank you.
Thank you, Chairman Babin. I now recognize the ranking member of the full committee, Miss Lofgren, for her statement.
Uh, thank you Chairman Franklin and Ranking Member Amo uh for today's hearing. Uh, the hearing really is an important opportunity for us to better understand the challenges local communities face in securing our water systems from cyber attacks and how science and technology can potentially address some of these challenges and I wanna thank the witnesses for their expertise and for being, uh, with us today. Access to clean water and functioning uh waste water systems is a privilege most of us have long taken for granted in this country. When things work the way they're supposed to, we don't think about everything and every one that makes it work. But our country's water infrastructure is aging and at risk on multiple fronts. And if we don't act to address those risks, widespread water insecurity for Americans could become a reality. Today's hearing is focused on just one of those risks, uh, the number and severity of cyber-attacks against our drinking water systems, treatment plants, and waste water systems have been increasing. It should worry us that EPA has found that over seventy percent of the water systems the agency has inspected since twenty twenty three do not meet basic security practices. If any of these cyber attacks become successful, the consequences could be dire. A disruption of water systems at a minimum could lead to health crises and economic uncertainty. These risks are only being compounded with the advancements in AI and the evolving methods that are accessible to malicious actors. Our aging infrastructure, especially in rural communities, is under-resourced and falling behind and becoming cyber-resilient. This lag is making our water systems ever more susceptible to threats, for malicious hackers as well as foreign adversaries. In recent years there have been several reports of hackers accessing water treatment plants across the country, attempting to poison the water, gain financial leverage, or prove their ability to infiltrate systems. A twenty twenty four uh cyber attack was directed at the largest water and waste water utility in the country, that services several uh states, including California. There have been many more reports of these attacks on smaller facilities. In my district, for example, we have a large and very well-resourced water utility called San Jose Water Company. They are well positioned uh to be a leader on water security and have been featured in a case study by the Water Information Sharing and Analysis Center. But the district I represent also includes a large area of uh rural uh communities with several less-resourced smaller water utilities. Both the smaller and larger water utilities support many tech companies uh in uh in uh Silicon Valley and it makes them a target. uh for national security threats from foreign adversaries. Uh the situation isn't unique to my district. These threats are only being exacerbated by a change we're seeing in our country today. Large corporations are decentralizing their businesses from large uh urban areas to more rural regions as we build data centers and new manufacturing facilities across the country. The intelligence community has pointed uh to water infrastructure, being a major weakness in cyber warfare. State-sponsored criminals are targeting facilities that support major manufacturing data centers, or even military facilities, in an attempt to destabilize supply chains and cripple the central nervous system of information systems and networks. We're lucky they haven't been successful in any significant uh degree so far. But no matter how much a utility spends to defend itself, They're simply not gonna have the same resources to bring uh to bear that nation-states have. Therefore, this is a national security issue that requires a federal response. So how do we go about addressing the water infrastructure's cyber security weaknesses? What would be an appropriately funded and resourced EPA uh in terms of accomplishing, supporting thousands of water systems across the nation? I look forward to investigating these questions and learning more from our spectacular witnesses uh on their thoughts on what we can do to be better equipped against these cyber attacks. And with that, Mr. Chairman, I yield back.
Thank you, Ranking Member Lofgren. Let me now introduce our witnesses. Our first witness today is Mr. David Hinchman, the Director of Information, Technology and Cybersecurity at the US Government Accountability Office. Mr. Hinchman oversees government-wide reviews of critical infrastructure, Cybersecurity, the Federal Cyber Workforce, Emerging Cybersecurity Issues, and How New Technologies, including Artificial Intelligence, are being used by the federal government. He also served as a Surface Warfare Officer in United States Navy. Go Navy. Our second witness is Ms. Virginia Wright. She is a Cyber-Informed Engineer Program Manager for National and Homeland Security at Idaho National Laboratory. She leads INL's implementation of the National Security for Cyber-Informed Engineering, developed by the Department of Eng- Department of Energy, and works closely with the lab's water security testbed program. Our third witness is Mr. Joshua Korman. He is the Executive in Residence for Public Safety and Resilience at the Institute for Security and Technology. Mr. Korman leads their undisruptable twenty-seven program, working to translate high-level cyber risk awareness into readiness at the local level. He previously served at the Cybersecurity and Infrastructure Security Agency, or SISA. uh during the first Trump administration and during the Biden administration. Our final witness is Miss Nicole Tisdale. She's a founder and principal at Advocacy Blueprints, LLC. Miss Tisdale is a national security attorney and apology strategist. Her work largely focuses on cyber impl- implications for small and rural communities. She previously served at the White House National Security Council during the Biden administration and prior to that on the House Committee on Homeland Security. I now recognize Mister Hinchman for five minutes to present testimony.
Thank you.
Chairman Franklin, Ranking Member Amo, um, Chairman Babin, and Ranking Member Lofgren. Thank you for inviting GAO to discuss our work on federal efforts to ensure the cyber security of the n- our nation's water and wastewater systems. Our nation increasingly depends on computer-based information systems and data to execute fundamental operations in the process and maintain crucial information throughout our nation's infrastructure. In parallel with this growth, cyber-based intrusions and attacks on infrastructure systems by malicious actors are becoming more common and more disruptive. Since two thousand and three, GAO has identified the cyber security of critical infrastructure as a key component of our cyber security high-risk area, and an area in need of focused executive and congressional attention. As part of our reporting on this issue, we have also found that threats to the national infrastructure are on the rise including cyber attacks that increasingly pose risk to the systems that manage the clean and safe water, essential for modern life in the US economy. However, the challenges in ensuring the water's secur- sector security are complex. Composed of almost one hundred and seventy thousand drinking water and wastewater systems of varying sizes and ownership types, water has critical dependencies with other infrastructure sectors, such as food and agriculture, energy, health care and public health, and critical manufacturing. Further, water infrastructure is often physically dispersed, covering large geographic areas with distribution and collection networks connected to centralized facilities. As a result, the failure of any of these systems can lead to service disruptions that harm public health or the environment. To efficiently manage this sprawling infrastructure, most systems rely on technology that provides remote control of pumps, pipes, and other physical water management equipment. These facilities also incorporate electronic networks, used to link monitoring and control systems for water distribution and treatment. However, much of this physical infrastructure and its controlling technologies require modernization, and in many cases across the sector, equipment is reaching the end of its design life. As a result, the connectivity between these outdated technologies makes water systems more vulnerable to cyber-attack, with each unsecured connection representing a potential point of access for a threat actor. But system operators also face other related challenges in reducing elec electronic vulnerabilities. Our work has found varying levels of cyber security capabilities across the sector, cyber workforce shortages, and limited resources to address these issues. Further, as owner-operators navigate effective responses to these challenges, it has become less clear what leadership role the federal government plans to take. As the designated sector risk management agency for the water sector, the Environmental Protection Agency is responsible for coordinating sector activities, such as incident management, supporting sector risk management and sharing information. In this regard, and to their credit, EPA and its federal and non-federal partners have taken key actions to improve water sector cybersecurity, such as completing a risk assessment and management plan, regularly issuing alerts and advisories, conducting sector outreach and coordination, carrying out research and development, and distributing guidance and best In addition, federal agencies also provide technical assistance and tools to help the sector identify and mitigate cyber vulnerabilities. However, the federal role in infrastructure security is changing. The current administration has stated that it will increasingly defer to state and local governments to take the lead in infrastructure protection, but has not yet provided details on this departure from the federal government's historical role. Further guidance from the administration will be important to help sector stakeholders manage this change and better understand their cyber security expectations and responsibilities. In closing, attacks on our nation's water-related resources threaten the continuity integrity of these insi- essential systems, and never has there been a greater need to ensure that these vital systems have the appropriate direction guidance and resources needed to ensure their security. By taking these actions, we can better position our nation's critical infrastructure, to successfully defend itself against the growing and ever-present cyber security threat. Mister Chairman, this concludes my statement. Thank you.
Thank you, Mister Hinchman, and now I'll recognize Miss Wright for five minutes of testimony.
Thank you. Chairman Franklin, Ranking Member Amo, and Ranking Member Lofgren, and members of the committee. I'm Virginia Wright, a Program Manager at the Idaho National Laboratory, where I have spent nineteen years securing the critical infrastructure that Americans depend on every day. I'm here today because our water sector is under active assault and we are not prepared. The one hundred and seventy thousand water and wastewater systems that serve every American range from major metropolitan utilities to tiny rural systems serving a few hundred people. They all face the same adversaries. Most small utilities have no cyber security staff, no IT department, And no- and budgets are committed entirely to keeping critical services flowing. When a cyber attack hits, they have no resources to deploy. The attacks are real and they are escalating. In January, twenty twenty four, three small Texas water systems were attacked by Russian-linked hackers. Storage tanks overflowed and tens of thousands of gallons of water were lost. This April, last month, Federal agencies warned that Iranian hackers are again attacking our water system components and causing disruption. The threat is also getting more sophisticated. Earlier this year, Dragos documented an intrusion into a water utility in Mexico, where the attacker used commercial artificial intelligence tools to identify industrial control systems and develop customized attacks and execute them without any prior control system knowledge. They didn't succeed, but the warning is clear. AI is helping adversaries attack our water infrastructure. And cyber security alone is no longer enough. So, what should we do? I'd like to show you something. This is a time delay relay. It's a simple, inexpensive engineering component. It introduces a deliberate pause before executing a command. It contains no software, and it cannot be hacked. In one of our case studies at the Idaho National Laboratory, engineers identified that the worst thing a cyber-attack could do to a particular water system was overheat and destroy the pumps. This could have caused an eighteen month outage while plate replacement parts were sourced and installed. By slowing the attacker down, this relay prevents that. Even with an adversary in full control, the relay buys enough time that to run the system manually. The attack cannot cause its worst consequence. That is an example of cyber-informed engineering. Engineering out the worst consequence of what an attacker, even a well-resourced attacker, can do. The American Water Works Association has published guidance on it, and Idaho's Department of Environmental Quality is using it in their funded water infrastructure projects. I make a number of recommendations in my written testimony, but I'd like to leave you with a few that I feel are most critical. First, continue to prioritize full-scale cyber-physical water and wastewater research infrastructure. The work has started at the INL, and we can use it to get ahead of the attackers and help the defenders. Second, make cyber-informed engineering a standard approach for building water and wastewater systems, paired with technical assistance. so that small utilities can actually implement it. Third, use the free federal cyber security training that already exists. Less than five percent of participants in our advanced courses at INL come from the water sector. Increase awareness and support travel and time away, and that will change. The water systems that protect every American are small. under-resourced, and facing a threat that grows more sophisticated every year. They cannot close that gap alone. Federal R and D, applied with urgency, and designed for the realities of this sector, can. Thank you, and I look forward to your questions.
Thank you, Ms. Wright, I now recognize Mister Korman for five minutes for his testimony.
Chairman Franklin, Ranking Member Amo, Ranking Member Lofgren. Uh, thank you for the opportunity to speak with you today. I'm Josh Korman. I'm a formally trained philosopher that's been in the hacker culture for thirty years and I try to be a protector here at IST, a non-profit policy think tank. But every day I wake up trying to save lives in cyber security, wherever bits and bytes meet flesh and blood. I'm gonna tell you some hard things, uh, in part because I respect you, in part because they're consequential, and in part because time is very short. So here we go. When it comes to medical care, Time matters. Even a four point four minute delay can affect mortality rates for heart attacks. Time is brain. One, three, or four hours is sufficient to, just for up to if you can walk again, talk again, even survive your stroke. What about two hours? Within two hours, a hospital cannot function without water pressure. No water, no hospitals, no kidding. And when hospitals shut down, people die. Because we are over-dependent on undependable technologies, disruptive attacks from cyber are a very real possibility, even concurrently across various towns and states. On its own, disruption to water can carry life and death consequences, but far worse, water is a critical linchpin dependency for a dozen other life safety functions, some of which were mentioned in your opening remarks. We are not prepared. Water is deeply under-resourced. with fewer than one percent participating in information sharing plan- plans for the, for the federal government. We are prone, we are prey, we've just thus far lacked sufficient predator appetite. But that's over. These new predators seek not money, not data, they seek to disrupt and destroy. Outrageously, Chinese military units known as Volt Typhoon are in our systems now. Not eventually, not maybe, right now. They're laying in wait in civilian infrastructure in towns like Littleton, Massachusetts, near my house. This is a small town. There's no military target. It's outrageous to target these non-combatant civilians. But why are they doing it? They want the US to stand in their fight with Taiwan, and they're using us as leverage. It's not just China. Iran had hit US water before we were at war, and now they're hitting programmable logic controllers like this. This pervasive device has a decade-old old known vulnerability that is being taken advantage of bec- but it's also critical to support the functioning of water across the country. So whether you knew what a PLC was or not, um, we are in danger. And worse, AI is enhancing our predators' ability to attack us, but we lack a comparable ability to quickly and scalably defend ourselves across these prone systems. So, I get kinda angry when I think about this, and I'm tired of wondering who's gonna hit us, when they're gonna hit us, how they're gonna hit us. I wanna know what we're gonna do to fight back. My project on Disruptible-twenty-seven is an example of applied research and how I'm fighting back. When everything is critical, nothing is. So at the outset of this project, we knew we had to be apply ruthless prioritization. So you've heard the numbers of how many water facilities we have, hundred and fifty thousand, hundred and seventy thousand. But we chose to look at the highest consequences of failure where we could see casualties or threats to public safety and human life. And what we focused on instead was out of those, we wanna focus on the six thousand that support one of the nation's hospitals. Out of all those potential failure modes, we started with the most devastating possible attack, attacks like a water hammer that can destroy pipe infrastructure. So we're innovating narrowly with twelve US hospital communities such that we can replicate widely to the rest. What are we doing? Well, we're not adding cyber security. We're adding engineering. We're leveraging much of what you just heard from Ms. Wright. I'm very grateful that you did the heavy lifting in advance. But also we're meeting people where they are. While we're scant on cyber security experts in these water facilities, we have an abundance of engineers. And they know how to engineer out risk. So we're using their love languages. We're identifying familiar, affordable, and effective engineering mitigations, so that if a punch is thrown from any predator, we know that we're able to take that punch. So the threat may come from cyber, but the solutions come from engineering. It's not always sh- shields up. Sometimes it's connections down. So, we hope on the shrubble, shrubble lights the way for others looking to develop actionable solutions in this most dangerous period. I'll highlight two lessons we've learned. For this crisis, we had to design for the world the way it is, not the way we wish it was. And that means these systems caught in the greatest risk are owned and operated by what I like to call target rich. but cyber poor, and that's where the focus needs to be. Second, heroism only takes you so far. So unless and until we examine the incentives, drive the behavior, we're gonna continue to remain prone to our predators. We have some recommendations in here, but let me wrap up by saying, we are prone, we are prey, but we are not powerless. Um, just this past Friday, a workshop in New Hampshire, utility produced five mitigations for under a hundred dollars, something like this pressure release valve. that can maybe be a shock absorber from one of these water hammers. And they found five ways to protect their citizens, their hospital, and their families. These solutions energized me, I hope they energize you, and I look forward to answering your questions today.
Thank you, Mister Korman, and finally Miss Tisdale, if you could give us five minutes of testimony.
Thank you so much. Um, thank you Chairman Franklin, Chair- Ranking Member Amel, um, Chairman Babin, and Ranking Member Lofgren for inviting me to testify today. I grew up in Nettleton, Mississippi, which is a rural town of less than two thousand people and a piggly-wiggly that closes at seven o'clock. I understood as a young, at a young age that the federal government had made a decision decades before I was born that a small town like mine was worth investing in and protecting. Those investments looked like rural electrification and rural water, and they did not happen on their own. They happened because Congress decided that rural communities were worth protecting. We are at the same decision point today for cyber security. I am a congressional expert, I'm a policy strategist, I don't have props and technical tools, I am drink and tap water, so I feel like that's the right thing, the right move for this hearing. But for seventeen years, I've been the congressional staff sitting behind you, when I was on the House Homeland Security Committee, but I was also Director of Congressional Affairs at the National Security Council. I have always centered Congress in my work because I know Congress serves the most American people and protects the biggest constituency. I know that every- everyone's district looks very different when it comes to national security, but I also know that everybody, no matter what side of the aisle you're on, we are all trying to do the same thing, and that's to keep Americans safe. And so my job is to try to figure out how do we close the gap between good ideas and the communities that need them. My work on rural cyber security is in ground is grounded in the inclusive cyber policy framework. It's a framework that I created to give lawmakers and policy makers a design lens for evaluating whether a federal program will reach the communities it is meant to protect or if it's gonna potentially exclude them by design. Water is where the gap is most urgent right now in cyber security. As you've heard, there are roughly fifty thousand community water systems across this country. More than ninety-one percent of them serve fewer than ten thousand people. The appendix to my written testimony documents the rural water and wastewater systems doing the work in every member of this subcommittee's congressional district. And it looks very different from coastal Rhode Island, to the Florida heartland, to Texas, and to California. But every one of those systems operates under the same legal obligations of the largest facilities in this country. Most of them operate with one person who runs the treatment plant, they read the meters, and they file the compliance reports. There is no cyber security team, there is no IT department. And in some of these communities, there is not even reliable internet access. Those systems are under active attack by foreign adversaries and ransomware crews who have learned that small and rural utilities are some of the easiest entry points into American infrastructure. This is not speculation. Both the twenty twenty three and the twenty twenty six national cyber security strategies and the twenty twenty five annual threat assessment from the intelligence community all name water as a primary target for our adversaries. Those national documents span two administrations, both political parties. And the consequences of a su- successful attack do not stay local. More than four hundred military installations nationwide depend on rural water for potable water, firefighting, and base operations. More than four thousand data centers across the country depend on local water for cooling. Rural water also feeds the processing facilities, livestock operations, and the irrigation systems for our national food supply. A water attack on a small town is a military readiness problem, it is a digital economy problem, and it is a food security problem. The threat is real. But unfortunately, As the systems have been designed, most of the federal resources are not reaching the systems most at risk. And the workforce crisis is growing. I am here to ring the alarm and tell you the fire alarm of what is happening in rural water is going to have ripple effects around the country. Fifty-seven percent of rural water operators plan to retire in ten years. Nearly one third of them are going to be gone in five years. We are losing the people who run these systems at exactly the moment our adversaries have decided those systems are worth attacking. And I wanna be clear, rural water communities are not behind on cyber security. They are underserved from cyber security policies. They, most cyber security policies are designed in environments do- that do not exist in rural America and programs that assume cash on hand, dedicated IT staff, and the administrative capability to navigate complex fe- federal regulations. That is something that only Congress can fix. And this subcommittee has the tools to do it. My written testimony has eight recommendations. That's a lot. That's aggressive. Four of them are squarely in this committee's jurisdiction, and I wrote them very specifically as tools that are needed in the cyber community that this committee can authorize. The other four recommendations are gonna require some cross-jurisdictional uh partnership. But they are all all of you all sit on most of the other committees
Thank you, Miss Tisdale, and I'll now recognize myself for five minutes of questions. I'll start with Mister Hinchman. Uh GAEO has recommended that EPA assess whether it has the authorities necessary to fully carry out its responsibilities as a sector risk management agency for water infrastructure. Uh right now, responsibility for wastewater and drinking water systems is split between the Clean Water Act and the Safe uh Drinking Water Act, which results in a lack of cohesiveness in federal programming and oversight, hindering research and development e- efforts. Can you discuss the lack of sufficient authorities? uh, if you, if you agree that those exist and, and how Congress can address this disconnect to help secure the water sector from cyber attacks while also strengthening research and development opportunities.
Absolutely. I think the relationship of SRMAs to their sectors is fascinating in the federal government for the most part they don't have power over the owner operators that they work with they have to use the power of persuasion, education, collaboration to get things done, and I think EPA is a good example of that with the water sector. Uh, there are some legal authorities they have. For instance, owner-operators are required to do a risk assessment and resilience plan. Uh, EPA can go to onsites to view those plans, but they're not allowed by law to collect them themselves, to keep them in one repository where we could survey across the sector to get a sense for what the security is. I think that's one opportunity to fix that. Um, CISA is allowed to gather those plans because they have a FOIA exemption, which is what people are worried about. primarily. So I think that's a possibility just to allow information to be better shared across these thresholds that that exist to a degree artificially, um, but which can be breached. And I think that R and D is also a complicated thing for EPA as a small agency, with a lot of responsibilities that they're required to do. And I think in the sector risk management arena, as with most SRMAs across the federal government, this is an ancillary duty they're being asked to accomplish in addition to what we call their day jobs. And so there's rarely budget for what they wanna do. There's rarely the resources that they feel they need to really have a very strong, powerful outreach connection with their owner-operators. And this is almost any sector across the sixteen. Uh, so I think there's opportunity there as well. And additional resources or at least better planning of resources and prioritization could help EPA to think about the R and D aspect of it, because there's also obviously great organizations like the Idaho National Labs that's doing great work in this. And, you know, how do we bring that together so that we're working as a whole of government rather than individual pockets across the federal enterprise?
Great, thank you. Ms. Wright, how does INL's research inform the day-to-day decisions water systems, uh, make to keep their facilities secure? And what additional research is needed to ensure that these utilities are protected from cybercriminals and other advanced threats?
Thank you for the question. Today, INL's research is in Idaho, ensuring that the investments that are made out of the EPA state revolving fund, in our state, come with cyber security. Eighty-five percent of their twenty twenty-seven water and waste water revolving fund projects proposed to use cyber-informed engineering to keep the cyber threat designed out of that infrastructure and to future-proof that infrastructure against emerging threat landscapes. That is a wonderful impact for a national lab's research to go straight into the state. We look for opportunities to expand that. Um, Idaho started because we were close and talking to one another, but we are talking to other states and to other entities about how to replicate this success nationwide. Additionally, uh, the American Water Works organization has taken some of INL's research and created a book tailored to the needs of water asset owners and made that available for the sector. The additional things that Idaho looks to do with our water security test bed are to actually experiment on at-scale infrastructure, understand what the cyber-attacks can accomplish, and where we can recommend timely, appropriate, and specific mitigations for water asset owners. We look to get ahead of the adversaries using artificial intelligence by understanding that ourselves and preventing everything that we can. And we look forward to your support in continuing to do that. Thank you.
Great. Thank you. I have other questions but not a whole lot more time, so I uh we'll go ahead and uh turn it over to ranking member Amo for his questions.
Thank you, Mister Chairman. Um Rhode Island's water infrastructure consists of mostly small and mid-sized system, uh with most serving fewer than ten thousand people. And so as we've noted in uh the discussion thus far, these utilities were never built with the level of sophistication uh that, you know, that the cyber threats uh of today, you know, pose in danger uh to them and the response that can meet those moments. Um but the expectations are there, expected to defend. uh against these attacks while continuing to provide safe, reliable drinking water. Um, Mi- Miss Sisdale, I know you referenced uh some recommendations you have and how federal programs fail to reflect the realities for small and rural systems. Can you give me a sense, and I know you have a recommendation that it addresses this, that how do, can we make sure that small and rural systems get the tools to support the resources, uh that they need to prevent being the next headline?
Yeah, thank you for the question. I think the first thing, especially within this committee's purview, is making sure that as you all are doing re- or encouraging and authorizing research and development for AI tools, that you make sure these tools are gonna be able to be used in a rural environment. And so one of the things that I've been seeing a lot of tools as we're rolling out for AI, the cyber community is actually very excited about what some of these AI tools can do for rural communities. Because the truth is, most rural communities cannot hire their s- their way out of this. They don't have the money to bring in new people, and they're going to have to train folks who are already living in a lot of these communities. And so, AI tools that can operate in areas where there is low broadband or no broadband, are what we need to be focused on. And a lot of the AI tools that we are centering our work around in cyber security just require a level of broadband and connectivity that these communities are never gonna have. Also, I think this committee is in a good position to think about if we need to establish a rural water and wastewater cyber security center um at the at EPA. As you've heard today, water is spread out across multiple agencies, and for rural water I would add not only EPA, CISA, but also USDA's Rural Development Program and the Department of Labor. That is a lot of agencies.
Thank you, Mr. Zil. Uh, Mr. Gorman, do you wanna comment on this question?
I I think if we meet people who are there right now, it's gonna be, we have a current state and a desired state, and then we're gonna have to have a thoughtful transition plan. So now, with that abundance of engineers, we should be using tools like Idaho National Lab's CIE to engineer down the highest consequences. we do need to crawl, walk, run, and give fit-for-purpose advice. So that's gonna take strategy, planning, and understanding the demographic we're dealing with. So I look forward to further discussing some of your ideas. Um, one other important thing is it takes a long time to build trust in these public-private partnerships.
Mm-hmm.
And at times there's been an acrimony for this sector with their sector risk management agency. So while we're looking at funding and authorities, we should also look at a strong way to reset and realign for common cause and common purpose against our mutual adversaries.
Thank you. And uh, Mister Hirschman, I and I think you touched on this a little bit in in your testimony, but you know, w- without the full resourcing of the EPA uh, we aren't in a position to sort of get to the position where we can identify and reach success here. But tell me w- you know, what success would look like if we effectively supported and strengthened our water infrastructure cyber defenses.
There are a lot of different ways to answer that. Um, I think that from a basic level what's missing right now is the drill down on the national cyber strategy about how to implement this across all sectors, all sectors are in the same position. Everyone has small owner operators that they're trying to get resources to. No one's really sure where to go to on this. There have been some federal programs out there, one of which I've done work on, the state and local tribal territorial cyber grant program. So I think that as we get further explanation from the administration about what their national strategy is going to look like, what is it going to look like to implement it, that's where you start to do that planning. Because until you have that umbrella document, it's hard for even a sector to do a lot of things and know for sure that this is the right thing. I think a great example is, I mentioned in my opening statement that EPA did a risk management assessment and a risk management plan in response to recommendations we made. And those are great, and they built a framework for how they're going to address sector But until we know for sure what that larger umbrella strategy looks like, there's always the chance that this is not the right thing. And cyber moves so quickly, it evolves so quickly, both from the threat and the protection side, that we really need that broader whole of government framework in place, so that people can start to build against that framework and start to drill down. Cuz I think we need to start with some of these larger issues about collaboration and information sharing across the sector, and then start drilling down into resource prioritization as well as giving people the tools and resources that will make them more successful.
Thank you. There's so much to cover. I I wish we had more time, but I yield back.
Thank you, ranking member Remo. I now recognize my colleague from Tennessee, Mister Van Etts.
Thank you, Mister Chairman, and thank you to our witnesses for being here today. The risk to operational technology supporting our critical infrastructure continues to grow as our adversaries expand their attack capabilities. In February, twenty twenty-three, PRC-affiliated Volt Typhoon compromised a Massachusetts water facility. Last month CISA warned that a U. S. water facility was hit with over nineteen hundred hacking attempts from Iran's IRGC. Modern warfare is now a confrontation between opposing operational systems, rather than mere opposing armies. And our adversaries are currently seeking to disrupt and destroy the operational capabilities of the key systems facilitating the functions of our drinking water and wastewater utilities. Mister Korman, in your testimony you noted that Chinese cyber forces have quietly occupied positions inside our critical infrastructure systems. What can CISA and sector risk management agencies like EPA do to work with private industry to identify and eliminate pre-positioned cyber attacks on our industrial systems before they unleash disruptions to the system?
So I appreciate the question. Thank you. Um, It's a bit unintuitive, but um, when I look at how difficult it is for one of our best funded water systems, one of our peak level of operations for cyber security, they too are worried they can't keep pace with the Chinese military. So we're currently adopting for this crisis a posture of they're likely to get in, let's mitigate the full extent of damage. These are things like making a circuit breaker, such that a water hammer which is a destructive force of uh turning the valve honor off too quickly. uh, it can shatter pipes. So what do you do? You can maybe say, let's have a pressure sensor that if it goes over a certain level, it disables the pump, right? So we may not keep them out, but we can keep the highest consequence failures from doing damage. Now, I don't like that answer, but that's the answer for now, and I think, uh, one thing that would help a ton is when I was running the Sysadkova task force, we had weekly CPAC-covered public-private partnership conversations. And unless and until we restore that authority, it really ties our hands behind our back to do those rapid, urgent communications to our sector.
Thank you. I, I also serve as a member of the House Committee on Homeland Security. The improvement of the most recent frontier AI models like Anthropics, Claude Mythos, significantly increases the threat of cyber attacks to traditional information systems and critical information infrastructure systems. This development presents an urgent risk to the homeland. Mister Korman, again, uh, you stated in your written testimony that Anthropic's project last week did not include an OT vendor as part of its early access to Claude Mythos. Anthropic claims Claude Mythos has found system vulnerabilities in every major operating system Do you think these new frontier models developed by Anthropic and OpenAi OpenAI have advanced to discover deep-rooted vulnerabilities on PLC's and SCADA technologies, perhaps explaining why the model was not given to OT vendors?
Interesting question. I may write a more thoughtful response. Uh, immediately, I think the cyber security industry is quite biased towards the four to five thousand, towards the confidential data, towards criminal behavior. We don't have a ton of participation towards OT, ICS. We're also biased towards the top of the market, the haves, not the have-nots, which is the overwhelming majority of our asset owners and operators for critical infrastructure. So I don't think it's a moral failing, more so it just reflects the current bias. It's important to note that many of these software packages also exist in OT and ICS environments. They're using similar open source. They're similarly flawed. So whether, while they are not at the table, they may suffer similar disruptions, even by accident, for many of these adversaries. So it's imperative we get some balance and some OT participation, both for the top of the market and the bottom of the market, lest we suffer the consequences.
Thank you. My district includes two major water systems serving our metro areas in Nashville and Clarksville. along with our many rural counties whose water utilities are at greater risk of disruption due to outdated cyber capabilities and aging infrastructure. The battlefield is here, and I see an urgent need to fortify my district from these malevolent foreign cyber threats equipped with advanced capabilities. Mister Hinchman, in GAO's twenty twenty-four report on risk to water and wastewater systems, your team noted that industry officials stated that water system operators do not dedicate significant time or effort
to increase their system's capabilities to defend against cyber attacks. The report noted that EPA recognized this challenge. Do you believe that EPA's sector-specific risk assessments and risk management plans sufficiently address cyber security risks to rural water systems in particular?" I think that everyone recognizes the extent of the problem, um, which is huge, and as we've all talked about, we all mentioned in all of our opening statements just how broad the sector is and how pervasive the threat is. When we talked to the owner-operators, a lot of them were happy with some aspects of what they got from epa um as well as department of agriculture. There are technical advisors that are out there that they really rely on. These are folks who tend to be in the community so they're very familiar with them. It helps them with day-to-day operations, with small little problems they run into. So I think there's opportunity to boost that program, which has been relatively relatively successful and was very popular with owner-operators. And I think that the risk assessment and risk management plan that EPA came up with, uh, uh, properly addresses cyber security. As I mentioned, there's the challenge, we're not sure what the overall federal government umbrella looks like for cyber, but as we work through that in the coming months, as we get more information from the administration, hopefully that will all sync together well and provide the sector for something they can start to move out on in terms of really beefing up their, their cyber controls.
Thank you. Miss, Mr. Chairman, I'm over my time, but you're back.
Thank you, Representative Van Epps. I now recognize my colleague from Oregon, Miss Bonamici.
Well, thank you very much to the chair and the ranking member, and especially to the witnesses. I'm I'm really grateful we're having this hearing today. Sometimes it feels like we're here in DC and we wonder what our constituents back home think. And I think if you ask them about cyber security, they might think somebody's gonna hack into my bank account or maybe shut down the internet or maybe get my email but I don't think most of them think about the water system. And so we have to highlight that and really raise awareness about it. Um, there's uh somewhere between twenty five hundred and thirty six hundred water systems of all sizes in my home state of Oregon and my understanding more than a hundred and fifty-two thousand across the country so just just thank you for being here and raising this awareness because we know that the cyber attacks are increasingly frequent and more sophisticated, and water systems are among that infrastructure most vulnerable. uh to cyber threats. And and maybe that's in large part because there's so many of them, and they're different sizes and different places. And inspections by the EPA determined that more than seventy percent of the water systems are not compliant with the Safe Drinking Water Act cyber security requirements. So, uh we know uh and and you've established that these attacks can disable pumps, they can leave homes and hospitals without clean water, interfere with chemical treatment, threaten public health, uh release untreated sewage into rivers and coastal waters, uh and cut off water access during wildfires and extreme heat. Those are all significant issues uh in the district I represent, which um and I want to ask you, Miss Tisdale, because you were talking about uh rural areas and I and I represent a big urban area in the in the Portland uh area but all the way out to the coast in some very very rural areas urban, suburban and rural. Um and I know that in many of the, especially the small systems, they lack the resources for regular risk assessments and training and operational technology upgrades. And and it's our understanding, uh, that EPA is itself is understaffed and under-resourced in e- under-resourced in this area, uh, and water managers often have to try to mitigate the risks, uh, without, um, adequate support. So you mentioned broadband and the need for rural broadband, which continues to be an issue, not just for cyber-seq- water cyber-security, but many reasons. Uh, we have in Oregon a sustainable infrastructure planning project program that offers a hundred percent forgivable loans up to fifty thousand dollars for public water systems to conduct uh risk and resilience studies and it's funded by the Drinking Water State Revolving Fund really has a been a lifeline for some of the small systems,
Mm.
but I wonder what other resources can support those small systems,
Mm.
uh especially for operational technology upgrades and workforce training. that may not be covered by those uh those loans and what additional programs could address those gaps and again for the particularly for the small and rural systems.
Thank you for the question, Congresswoman. I will say your district looks like a lot of folks' districts too, where you have uh resourced, big urban water facilities,
Right.
and then you also have those that are rural and underserved. So I appreciate this question. I will say As you are thinking about what programs exist for cyber security, most of the program, the biggest program is the state and local cyber security grant program that uh Witness Hitchman recommended. That is a place that you can look for your rural communities, but I wanna be clear, that that grant program also has some blind spots when it comes to rural cyber. I worked on that program at the White House and so I can say it was a program that was built at the time but it has some barriers for your rural communities. There is a twenty-five percent carve-out in that program that two hundred and fifty million dollars can go to rural communities. But what happens is your water community is gonna have to compete with transportation, is gonna have to compete with the schools and the hospitals.
Right.
So as you all are looking at grant programs, what I would advise, especially coming from the environmental side of the house, you're gonna have to create new programs that are specific to cyber security. What you don't wanna do is start asking people to rob Peter to pay Paul.
Right.
Right? So you need to establish a new cyber security.
But that never goes over well.
Never goes over well. And then you'll take money from other areas that are still needed on the public safety and the,
Right.
the safe drinking water side of the house. And so what you need to do is what that program is. With rural communities, you cannot make them re-emba- they cannot have any reimbursement requirements. A hundred percent loan forgiveness is a
Right. They don't have the resources to do that.
Exactly. And you've learned from other programs, like the one that you mentioned,
Sure.
that those you need to have a hundred percent forgiveness for loans. I will also say if you're gonna give out grants, you've got to ease the grant applications. Most of these people cannot write the grant,
Right. Right.
and so as you're looking for a program
Exactly, and and real quickly I just wanna ask Mr. Hinchman real quickly cuz my the clock is ticking. How could some of the federal programs be more flexible um to address the operational operational realities for the smaller water systems?
Well, you know, it it's hard to say because the problem is so big. For instance, I think the SLTT cyber grant program that I talked about was a billion dollars over four years, but spread across fifty states for every year.
Right.
That money gets eaten up very quickly. And I think, as Miss Tisdale points out, the competing uh industries that need help with all those things. And so I think that it needs to be a thoughtful whole of government opportunity to really sit down with the nation's cyber strategy as the basis, to think through how do we start attacking these problems. Because it can't be done in pockets, otherwise you're just people doing things and there's no coordinated response. And cyber, the cyber threat now is such that it's something that needs to stretch across the legislative and executive branch and really coming together to think thoughtfully about how we can approach these problems because it's not enough to say we just need more money because that's not always available. Great. Yeah, we need a plan. So we need to think creatively about how we can approach this. What Money is certainly an aspect, resource is important, but I think there's also a cohesive strategy that gets at these issues, presents education opportunities to the owner-opper.
Right, that's uh uh wor- workforce um uh is is important too. And my time has expired, but thank you for your expertise today. You're all back.
Thank you, Ms. Bonamici. I now recognize my fellow Floridian, Mister Herodopolis, for five minutes.
First, Mr. Chairman, thank you much for uh holding this important meeting. It's it's a threat that unfortunately is real, and I appreciate the experts being here to help us mitigate that threat or take it on firsthand. Uh, there's an old saying, water is life. And this is exactly what we're talking about today. Uh, as we look at today's world, whoever controls water infrastructure can literally threaten public health, uh, threaten economic security, and of course, even national security. And when Americans turn on the tap, they just want clean water. And, uh, what we are trying to handle in these increasing attacks is just a common sense way to use the existing resources with the best ROI given this threat. Um, in Florida we understand this reality very clearly. Along the Space Coast we rely on reliable drinking water and wastewater systems every day and we know that disruption is is changing lives every day and it could also disrupt not just of course households but hospitals uh launch facilities, tourism, you name it. Um, given that reality, uh these remote access systems which are increasingly antiquated, as you all have mentioned, each of you, what is a typical cost for an individual, the unit, I mean literally I think as some of the other members
It can vary, but because they're so cash-strapped, they tend to go to the the cheapest ones, and
Mm.
with a slight pivot here, this is a very important point that none of us have made yet. Most of the successful compromises from Volt-Syphoon into US water have been through known edge devices like cheap routers, TP-link routers owned and manufactured in China, or even security remote access technologies, which have CISA, known exploited vulnerabilities, associated with them. So if we look at how China's been getting in, it's often through these remote access tools themselves. So a race to the bottom, just like we don't put a
But again, just again, we we deal with big numbers all the time. Is there a number that you say if if we put in fifty thousand, is it a hundred thousand, is it a million dollars, just give us a ballpark, just to get a feel for how many, uh, you're never just talking about grants,
Sure, sure.
but what's the real price tag. And so when you, we talk, I mean, one of the things we found success in when I was in the state legislature is you'd have a public partner- private partnership or local, state, federal dollars. I mean, what kind of dollars are we talking about?
So New Hampshire has a fifty thousand dollars per U per facility grant to do a managed firewall. first two to three years and then you have to pick up the costs afterwards. So that's inclusive of managing it for two to three years, about fifty K fifty K.
And and to build on that same idea, where have we seen successes where some of these water um uh, or you should say utilities have come together, have they pooled their resources to try to handle different regions, different states, to to bring down the cost by um just just sharing in these uh meeting these challenges together? Can anyone answer that?
We have some friends in the cyber civil they're looking at doing some regional, small, medium, rural managed security services things. We c-
But that's not been done to this point?
There's the the margins are pretty terrible, so when we often ask the big ones to do so, they they look at it, they wanna do it, and then they give up on it.
OK. Um and then given the increasing um activity from Iran, China, you name it, as a as a target critical infrastructure, um what what are the uh the the ones that you they are looking at most closely? Are these Uh, at, at military facilities, are they at, uh, public facilities, are they at hospitals? What's the biggest threat in your mind?
They're really two forks to the old typhoon. Initially, they were looking at military bases, the ability to degrade and delay our forced mobilization. Even a day or two could advantage their advance on Taiwan. But the second wave was non-combatant civilian infrastructure, like the ten thousand person town in Littleton, Massachusetts. And the purpose of that leg was to sow chaos on civilian infrastructure to undermine public support for our intervention. So it's both.
Thank you. I miss write if I could. If, look, you guys are obviously the experts. I I know you want to give your opinion. If you could do one thing, one one thing to get the most ROI for whatever dollars we put forth from taxpayers, what's the one thing you would do in order to try to mitigate this threat?
Congressman, thank you for that very important question. If I had one thing, I would work with water utilities to understand the most serious consequences of a cyber attack and engineer them out. Thank you.
Thank you. And, Mister Hinchpin, if you have that same question, please.
Uh, as a matter of a band-aid, I would bulk up the technical advisory program to get more boots on the ground to local facilities that otherwise don't have the resources to to get help.
Yes.
It's a bit of a band-aid, but it would help.
OK. Well, Mister Chairman, again, thanks for taking this on. It's an unfortunate reality what we're facing today with these uh finally foreign threats but of course oth- other deviant actors, uh it's very much appreciated. And I my only suggestion is We're we're really successful and we get everyone to have some skin in the game. It shouldn't be just a federal program. And I think that one of the things I I see coming out of this is it's it's pretty scary that they're not working in concert with each other. And I hope that this hearing uh stimulates some action because it's, this is a uh threat that's real and and we should figure out ways that so so that smaller communities can work together and solve this problem. So thanks again, Mr. Chairman, and I yield back.
Right. Thank you, Mr. Heronopolis. I now recognize my colleague from North Carolina, Ms. Ross.
Thank you, Chairman Franklin and Ranking Member Ammo for holding this very important hearing. And thank you to our great witnesses. You guys have been a real team and so, so helpful for sharing your testimony and your insights. I think we all can agree that water is one of our most precious and non-negotiable resources. And we've heard today that EPA plays a critical role in overseeing federal cyber security efforts for drinking water and wastewater systems, but there are other So in Apex, North Carolina, which is a suburb of Raleigh, they had a ransomware incident, I see Miss Wright nodding her head. This wasn't a health and safety issue, it was a financial issue, but there were people who had bill drafts of eighteen hundred dollars out of their checking account. You know, then they wouldn't be able to pay their mortgage or whatever. It turned out, w- actually Apex is still dealing with this issue, And you know where they got the best help? The National Guard. The National Guard. So now, more than ever, we need to be able to work together. But I also believe that EPA needs to be well-equipped and prepared to do its job in concert with other folks. Cyber-attacks are becoming faster and more sophisticated, as you know, with the advent of AI. And despite this, um, EPA has been under-resourced and people have been fired. And a lot of this has also happened in North Carolina at the RTP campus. Part of it was doge and part of it was just a dislike for the EPA. Um, I also represent, um, the second congressional district which includes the city of Raleigh and part of Apex, which is why I know all about that. And we're in a severe drought, which impacts our water supply. The drought has even pushed us to activate s- activate stage one water restrictions a month ago. And during these kinds of restrictions, we need better federal partnerships, not just on cyber security, but on how we can deal with the most challenging times in our water system. And then finally, North Carolina is no stranger to extreme weather events. And the water systems all over western North Carolina were completely decimated by Hurricane Helene. This makes those systems even more vulnerable to cyber attacks. I mean, they didn't even have internet, everything was on Starlink, and then it went on all these other things, and then we had disinformation. So all of this is coming together in what we've been talking about. We need to have a central area, central place that coordinates with local governments, everyone from, you know, a a rural community that may not be able to afford anything like Princeville, North Carolina, to Western North Carolina where they're having these threats. But I do think that ignoring EPA's fundamental role here and their historical role here is a big mistake. So in um twenty twenty one the Foundation for Defense of Democracies described the US water infrastructure as the weakest link in critical infrastructure security, citing significant cyber security deficiencies with, which we've heard. EPA is required to oversee this. Miss Tinsdale, you have worked in the, in the Biden administration, you worked on homeland security. How would you set up a nice hub at the EPA to work with all these other good actors?
Thank you so much for the question. Um, I think for all of the reasons that you have identified, it, I think it is important for this committee to strongly consider if EPA would be the hub. I would point you all to the Department of Energy's Office of Cybersecurity. DOE's set-up a cyber security office is funded at about two hundred million dollars a year that serves as the hub for all of their coordination on cyber security for the energy sector. Right now, the points that you pointed out with water, water is spread out across multiple agencies. If you s- if you set up a program and it has to be authorized and it has to continuously be funded like DOE's it would centralize cyber security for the water sector. It's going to still require rural program at USDA to work on water as well. You still need CISA to be involved, but elevating an office like that, and I will also say a little bit in the weeds, making sure the people who run that office are designated at the assistant secretary level, so that they have budget authority, but also so that they can be involved in political conversations at the highest levels at the White House but also with you all here in Congress.
Thank you, and I yield back.
Thank you, Miss Ross, and I now recognize my colleague from Texas, Mister Menefee.
Thank you very much, uh, Chairman and Reconnaidment, um, all for setting up this, uh, subcommittee hearing today, and, uh, good afternoon to our witnesses. I represent Texas. is the eighteenth congressional district, which uh includes much of Harris County, Houston, uh we're home to the Texas Medical Center, to the Port of Houston. In Harris County we got about five million people who all depend on a water system that our main city's own Water Director has warned us could suffer catastrophic failure, if it's not rebuilt. Houston's East Water Purification Plant is seventy years old, and serves about two point two million people, and city officials have said that if that plant fails it would impact both regional and national. So the port, the medical center, all of it. Now throw a cyber attack into that equation. Our witnesses have told us today that Chinese military hackers are already pre-positioned inside American water systems, so not planning on attacking but already inside, waiting. And Iranian-linked and Russian-linked hackers have already forced water utilities onto manual operations in Pennsylvania and compromise systems in Texas. And to make matters worse, the GAO has told us that the EPA is not resourced or organized to address the scale of this threat. On top of all of that, this administration has gutted the EPA and they're trying to gut them further, making our country more vulnerable. And Houston, I believe, is exactly the kind of target that our adversaries are looking for. So I wanna start with you, Mr. Korman. Uh, in your testimony you talked to us about Chinese hackers and and their pre-positioning inside of our water systems. You say their access could be used to cause a water hammer effect that burst pipes and that full recovery from a coordinated a coordinated attack could take years not weeks. Uh, the Texas Medical Center is the largest medical complex in the entire world. And you've told us that hospitals can only operate on two to four hours once water is cut off and of course in peak Houston summer heat that's gonna be even
Forty five minutes.
Exactly. Uh, if Chinese hackers activated its access in Houston today, walk me through what the following seventy-two hours would look like for the Texas Medical Center and the patients inside it.
Wow. Um, well this is one of the things we do in Undisruptable, phase two of our, of our engagement with these tall communities is we run a tabletop crisis simulation with the water or the power of the city planner the hospital, and the emergency management for the county or state. And it helps us to surface and chatter assumptions. And we have a pretty good idea what we do, so I'll give you a tiny example. One of the reasons we've run out of the ability to provide care is HVAC. Air conditioning is one of the top users. A typical hospital uses about two hundred and fifty gallons per bed per day, so it's unbelievable amounts of water. And while all of them have a generator on the roof, if the power goes out, none of them have an alternative source of water. So it's surgery, scrubbing, sanitation, hydrating patients, chemical tests for labs. Um, at some point, especially in the heat of the summer, you're gonna have to
Well, I'm I'm hopeful that the federal government's gonna work with local officials and we're gonna make real investment because I don't want that ever happening anywhere in this country and certainly not in the Texas Medical Center. Uh, Mister Hirschman, I wanna talk a little bit about uh the EPA. I was reading through your report and one of the things that struck me uh was the statement that we also reported in twenty twenty four that to ensure water and wastewater entities take action to improve their cyber security had faced legal and other challenges uh dug into that a little bit more and it looks like in twenty twenty three the EPA had actually taken steps to ensure that we were addressing some of our cyber security issues uh I I believe they had a a memo or a letter uh ensuring that whenever there is a sanitary review of water systems that there would also be a cyber security assessment that is done and they were sued by states, by Missouri, by Arkansas, by Iowa, uh and ultimately went up to the eighth circuit and that memo was pulled. So it it seems like there's some contention uh at the state level and the federal government level. And so I'm wondering in ensuring that the EPA has the authority it needs to be able to begin to address these issues and there aren't challenges from states who don't wanna play ball, is there a role for Congress to play and ensuring the EPA has that legal authority.
I, the short answer is yes, but it's a little more complicated as always. Um, Congress can pass laws. Um, you'll need regulations to implement those laws, and that's when we start getting into the over-regulated, under-regulated debate. Um, it's complicated with infrastructure sectors, which are traditionally unregulated environments, except for a couple specific examples where the SRMA tends to have some regulatory authority over the, the owner-operators. So it's really it's a balance, and that's why I think this needs to be, and I think I've talked about the whole of government, but someone else was mentioning working with the private sector as well, to figure out what this relationship should look like, so that we have the ability for the sector risk management agency to have a little more teeth to implement some of the the controls that we feel we need in the sector, that maybe states or owners are dragging their feet a little bit, but to give them the oomph they need to get that done. But I think that without working with the private sector through the various public partner- public-private partnerships that you're gonna run into the same problem. And that's why it really is just takes everyone coming together under a common umbrella with a common strategy to put in place common sense approaches to resolve some of these really tricky situations.
Everyone playing well in the sandbox, and that includes those states. Thank you very much. I yield back, Mr. Chairman.
Thank you, Mr. Minifee. I now recognize my colleague from Illinois, Mr. Foster.
Uh, thank you, Mister Chairman, to our witnesses. You know, it it strikes me a lot of the vulnerabilities in in water systems are really part of a larger problem of cyber security and secure electronics, trusted electronics. You know, more and more our systems that we live by uh depend on not only in having high quality software, but also um silicon that you know that it's doing what you say it should be doing, and circuit boards that you know, I mean there was a famous situation where the There was the these wireless uh ports in the um in the voltage converters for solar cells, and they were just they were delivered from China. And it strikes me we do not have any agency that can certify trusted electronics. And it seems like that's a big uh gap in our effort. You know, we have NIST that's under this committee that will provide uh specifications for best practices but they do not call balls and strikes on specific projects. products. You know, and uh just a simple example of that is uh for finance. Uh more and more people are using their cell phones basically as security dongles, uh to, you know, the secure key storage inside a cell phone, the biometric uh identity, the from a cell phone. You know, they're used by all of the, you know, Apple wallets and Google Pay and digital driver's licenses by which people assert their identity on the internet. OK? And the problem is not all of the cell phones are have secure key storage. There are well-documented public exploits that allow you to extract the keys, and thereby impersonate anyone using those, which will be a disaster for finance. Uh, same thing happens for system administrators. You know, if you're you're using your cell phone for second factor ID, you know, that's that, you know, that's an equal problem. And so I was wondering if, um, you know, I'm familiar with what the Nash, what Sandia lab is doing in terms of the control electronics for nuclear weapons. which is something they've been doing for decades and I mean they do a very impressive job of that. However, that's not a commercial thing and what they're doing is too expensive for commercial devices. So, what is the role that you have and how do we deal with this tension of of um over-specifying and over-regulating versus the kind of disaster that is lurking if we all of a sudden find the electronics that we depend on are not what they say they are.
Okay.
Um, yeah, Miss Wright, do you want to Uh, can you comment on that or what the - the best way forward might be?
Congressman, thank you for the question. The digital supply chain, including the hardware, firmware, and software of our critical infrastructure is a crucial national security priority. At Idaho National Laboratory, we work under the Department of Energy's CAESAR organization on a program called CITRIX, where we, with vendor cooperation, look at the security of the hardware, the software and the firmware, and make recommendations to the vendors on how to improve.
Yeah, but that's, you know, this is this voluntary framework, at some point after we have a big enough disaster, voluntary can't be good enough. That if you're gonna bring something in in to market and connect it at scale to the US internet, you're gonna have to have some sort of good he's, good housekeeping seal on it.
You're right,
And
and we recommend a right to inspect capability thinking about that as whether however that happens, whether that happens through the Department of Commerce or somewhere in the procurement process right now if I buy a commercial uh in industrial control system, I often contract away my ability to look at it, to understand what's in it, and to to know anything about it. If we have a place where we do call balls and strikes, we can make some success. Idaho National Laboratory is doing some research into using which is a way of ensuring the outcomes of computer programs are what you expect them to be um to try to create these while we work to try to make that cost-effective in the short term inspecting the things that come in to make sure that they are what we want them to be is a good short-term answer.
Yeah. But but in the end it's it's a big enterprise that I'm talking about. And it's not gonna be cheap because it costs a lot to hire the smart
This this is ultimately an incentives problem.
Mm.
Um, we tried to push a lot of transparency. father and grandfather where software built materials are here in the room, but we also have in Europe the CRA is being put in place and they're even gesturing for to finally introduce software reliability typically in other areas like cars we say the the the party in the market with the best possible chance to identify and manage down risk in the supply chain is the final goods assembler so putting some alignment there where they reduce elective complexity elective attack service they do as much risk as they want to would dramatically cut down on how much is passed downstream.
Yeah, has anyone come up with a a general, you know, a a proposed solution to this that would actually make sure we have the security we need in the supply chain? Has ever any think tank or anything written down a proposal?
Some of the programs pointed to by secure by design, secure by demand, secure by default. They hint at other long-standing programs, but I'd be happy to brief your office at length. It's been my career for very long time.
Um, yeah, well I think we have to get specific and and and get mandatory on this.
Yep.
um is unfortunately the world we live in. Thanks Mike.
One more tiny example. We did this in a universe in a grain of sand. La uh five twenty four B was passed through Congress uh to give the FDA the authority to do based essentially secure by design for pre-market and post-market for medical devices it may be a a concrete example of something we can repeat.
Thank you. You're up there.
Thank you, Mister Foster, and I thank the witnesses for their valuable testimony today and for the members for the questions. Look like we've Got everyone here. I know there were others who wanted to be here. Some got pulled out cuz there's some bill markups going on in other committees. The record will remain open for ten days for additional comments and written questions from members and our hearing is adjourned.
Morning digest
Start every morning briefed on yesterday’s hearings
A free weekday email covering yesterday’s hearings and transcripts newly unlocked in the archive.



