Summary
- The committee examined a discussion draft on water cybersecurity, highlighting that 170,000 systems face rising nation-state attacks and need tailored, non-one-size-fits-all federal support.
- D. Scott Simonton (Fellow, Marshall University Institute for Cybersecurity) said small systems lack staff and need circuit-rider assistance, basic hygiene, and micro-credentials for operators.
- Sen. Whitehouse (D-RI) pressed Scott Dewhirst (Deputy General Manager, Fairfax Water) on the NERC model for risk-based, nimble cybersecurity standards tailored to system size.
- Republicans warned one-size-fits-all mandates would burden small systems, while Democrats criticized Trump administration cuts to cyber experts and insufficient funding for resilience grants.
- The hearing underscored urgency as attacks occur daily, with senators able to submit questions until February 18 and witnesses due to respond by March 4.
Topics Discussed
Transcript
And uh it's nice and bright and sunny outside, so that's good. We'll we'll we'll check on the snow removal later and see.
Ice removal.
Ice removal. Um, so good morning and welcome to today's hearing. Um, today we'll examine the change uh the, excuse me, the challenges facing drinking water and wastewater systems to install, implement, and maintain adequate cyber security, as well as trying to identify opportunities to address these challenges through new legislation. First, I want to thank our excellent panel of witnesses uh for making the trip to DC and to share their perspectives on this important topic. Your work to enhance the resilience of our weight our water and wastewater systems incredibly important to Americans' health and daily lives there are approximately this number is stunning really, a hundred and seventy thousand water and wastewater utilities across the country. These utilities fill a vital role in ensuring that communities across the country have access to safe and reliable water and sanitation services. Um, I know in the audience we have several of our uh water system uh utility uh folks here, so I'll shout out to my fellow West Virginians. Um, accessible and reliable water and wastewater services are essential to protect public health and provide fundamental services to our constituents. These services can also be a foundational basis for a strong economy and a strong America. Because of the important role our water systems play in our country, they are unfortunately a target for bad actors. Over the last several years, we've seen a broad trend of entities linked to our geopolitical adversaries, such as Iran, China, Russia, using cyber attacks to attack to uh target our critical water infrastructure. Cyber attacks on water utilities may take various forms. For example, ransomware attacks can compromise business or customer information. Attackers can also gain access and then manipulate a system's operational technology, disrupting the treatment or distribution of water or altering the levels of chemicals to potentially dangerous amounts. Either way, a successful attack that disrupts safe and reliable water or sanitation services or exposes sensitive c- uh customer data could be debilitating for impacting communities. These threats must be acknowledged. and challenged, particularly as technological advances, such as AI, increase the speed and efficiency of these attacks. The rise in cyber attacks is occurring uh at the same time as our water and wastewater systems deploy new digital control technologies, I've seen some of them myself, systems that allow utilities to operate more efficiently and effectively. As we look to upgrade and modernize our water systems in the face of these threats, it is more urgent for our utilities, federal agencies, and water sector and cyber security experts to work together to increase that system resiliency. Increasing water system resiliency requires us to take a clear-eyed look at the many challenges and shortcomings that util our utilities are facing. Legacy systems are difficult to maintain and update. Workforce shortages limit in-house expertise, and fulfilling basic cyber security hygiene practices requires consistent uh monitoring and communication. For instance, in twenty twenty four, the Environmental Protection Agency identified instances where some water systems u utilized a single log-in for all their employees, failed to change default passwords, or did not curtail the ability of former employees to access the systems. While we work to improve the resiliency of our critical infrastructure from cyber attacks solutions to address cyber security must be deliberate and tailored to reflect the challenges faced by utilities in different sizes and location. A one size fits all mandate from the federal government will likely be overly burdensome and unworkable, particularly for our smaller systems, and can hinder utilities' ability to atta- to take achievable steps towards meaningful progress. Water and wastewater systems across our nation are already grappling with how to prioritize limited resources while meeting federal and state requirements under the Clean Water Act and Safe Drinking Water Act. Costly requirements can distract from the core mission of providing safe, reliable and affordable services to the American people. In addressing these cyber cha- challenges, we must strike the right balance between the role of the federal agencies and in empowering local utilities to address their challenges and improve their s- cyber security at their own facilities. Due to the constantly evolving technological environment that we live in, addressing this challenge will require innovative solutions that enable utilities to adapt and respond to quickly changing circumstances. Building and maintaining resilience among cyber threats is not a one and done event, it is ongoing and ever evolving. We should not rely on one specific technological advances as the silver bullet solution or have blinders on when it comes to envisioning or preparing to address potential threats. Look forward to the discussion today, learning how we can be better partners with our water utilities. uh to identify cyber security threats and and provide a flexible tool kit going forward. So I now recognize uh ranking member Whitehouse for his opening statement.
Thank you uh Chair Capito for convening us on another important topic and thank you to our witnesses for uh being here. Cybercrime and cyber warfare are realities of the twenty first century and have been for quite a while. Back in two thousand ten I served on indeed started the intelligence committee cyber task force where we spent six months investigating cyber security threats to our country the water sector has modestly improved information sharing and coordination between the epa and the cyber security and infrastructure security agency and non-profits and water sector trade groups have increased public awareness of cyber threats this however is insufficient meanwhile foreign bad actors to enhance their capabilities and evolve the nature of their attacks. State-sponsored and state-aligned bad actors, linked to countries like Russia, China, Iran and North Korea have been increasingly relentless in their attacks on American facilities. They've stolen sensitive information, scrambled networks, extorted ransoms, and disrupted sectors ranging from healthcare to, as we hear about today, drinking water. There are nearly a hundred seventy thousand water systems across our country. As these systems modernize, they incorporate technology that is more efficient, yet more vulnerable to cyber attacks. According to GAO, many of these facilities have already faced digital breaches, but without more incident reports, it is impossible to know the full scale of the threat they face. Since twenty twenty three, Russian, Iranian and Chinese hackers have successfully attacked small municipal water systems in Texas, Pennsylvania and Massachusetts, and have tested the security capabilities of countless other systems. They're always probing. Over the past six years, Rhode Island municipal facilities, one of them a large wastewater utility, have experienced at least six cyber-attacks, collectively resulting in hundreds of thousands of dollars in losses. These are just the incidents that have been reported. All water utilities without adequate security are at risk, regardless of size. While none of the previous attacks on the water sector have caused major service disruptions, they all cost time and money. A cyber-attack that incapacitated even one major water facility would not only be disastrous for the people affected, it would spread fear across the country. According to an EPA survey, less than twenty-five percent of our water and wastewater utilities perform annual cyber risk assessments. Less than one in four. Just imagine the consequences of a coordinated nationwide hit. Clearly, we are not ready. The trump administration has forced out thousands of federal cyber security experts. Cut funding to research and readiness cyber programs. And crippled our relationships with key international intelligence partners. We need to strengthen our national cyber security capabilities, not weaken them. And water utilities need more knowledge sharing, not less. We can change that. Even when water utilities understand the risk and solutions, updating cyber security measures is often deferred in favor of maintaining service levels to their rate payers. To meet the challenges of the twenty-first century, we must repair and replace outdated infrastructure, while also updating and maintaining our cyber security defenses. This is not either or. To start addressing our nation's massive water infrastructure investment deficit, the Infrastructure Investment and Jobs Act provided more than fifty billion dollars. with some expanded eligibility for cyber security projects. This was a good start, but not enough. I look forward to discussing how this committee can expand EPA's current authority and can help update physical and digital infrastructure across the country to keep water safe, available and affordable. Thank you very much, Madam Chair.
Thank you, Senator Senator Whitehouse, and uh we'll now turn to our witnesses. Uh I'm very excited to welcome our first witness this morning. Uh, Doctor S- uh, Scott Simonton is a fellow at Marshall University's Institute for Cybersecurity, is a professor uh at the Department of Mechanical and Industrial uh Engineering. Marshall's Institute for Cybersecurity is working on several projects with water utilities in West Virginia. We're so excited to have the Marshall University Institute of Cybersecurity at Marshall University. Uh, and I look forward to learning more about the institute's work today with uh Doctor Simonton, uh, is his wife, Molly Simonton, so thank you, Molly, for coming. And his son, Nathaniel, who is, I just learned, a, uh, freshman here at, um, George Washington University, but he's a on an ROTC scholarships scholarship. So thank you for, uh, for your service now and what it will be in the future. We also have Alex Donathan with us here, who is the executive director of the Marshalls Institute for Cybersecurity for Critical Infrastructure. So thank you for being here. And Doctor James Lanham, who is also with the Cyber Institute, uh, and a professor and good friend from Marshall University. So with that, I'll turn it over to you, Doctor Simonton, and welcome.
Good morning and thank you, Chairman Capito, Ranking Member, White House, members of the committee. Uh, thanks for the opportunity to to speak with you today. As Chairman Capito mentioned, I am Scott Simonton. I'm a civil and environmental engineer, a professional engineer registered in West Virginia, Kentucky, and Mississippi, a veteran and a fellow in the Institute for Cyber marsha university and professor in our college of engineering my work places me between cyber security professionals and infrastructure operators i'd like that so i'm helping translate cyber threats into real world engineering and public safety consequences so both sides can act on these risks for more than thirty years i worked with water systems across idaho west virginia central appalachia on environmental management infrastructure modernization and now cyber security I wanna offer a practical view, uh, from a region where small systems are are essential lifelines and very resource constrained. West Virginia has several hundred community water systems, and over seventy-five percent f- serve fewer than thirty-three hundred people. These are small rural systems, often with one or two operators who handle everything, treatment, distribution, reporting, and now digital oversight. But even the smallest systems are now relying on SCADA, PLC's, internet connected monitoring and control systems, but they typically lack dedicated IT or cyber security staff. As outlined in our written testimony, the vulnerabilities are common and well documented. These include exposed remote access interfaces, default and shared PLC credentials, flat networks that that connect business and operational systems, and legacy vendor-managed equipment. These issues show up consistently, but not because operators lack commitment, but they lack capacity to deal with some of these issues. Under the Safe Drinking Water Act and amended by America's Water Infrastructure Act systems serving more than thirty-three hundred people must complete risk and resilience assessments and emergency response plans that include cyber security. But in West Virginia, most of the systems fall below that threshold, that population threshold, But they face the same cyber security threats as the large utilities, but they don't have the mandate, the staffing, or the structure that those large utilities have to deal with cyber security risks. So, we leave or we're left with a very significant gap in that modern monitoring and control systems have reached even the smallest utilities but these cyber security requirements have not. At Marshall's Institute for Cyber Security, we're working directly with operators, utilities, partners to close that gap turning federal guidance into real operational improvements and we have three examples that illustrate this currently marshall ic s has helped prepare fourteen national guard cyber units that have since been deployed on real world cyber missions this expands the region's ability to assess and secure infrastructure including water systems and it provides it where that local expertise is needed In the town of Anstead, West Virginia, ICS is guiding the town through its transition from paper-based processes to modern digital systems that support billing, payroll, and a new wastewater treatment facility. Our work includes vendor governance, IT OT separation, secure remote access, and staff training. We're providing, this provides a scalable model to rural communities, we feel. In the Huntington water system, ICS is conducting on-site o t assessments in advance of a major upgrade to a digitally controlled ultraviolet treatment system working alongside operators and national guard cyber units we help ensure cyber security is integrated into the system design, not added after the fact. These engagements demonstrate what works, practical, repeatable assistance delivered where operators actually work. Long-term resilience is going to depend on people. Marshall has developed and is developing stackable micro-credentials in the water sector for cyber security. It's designed specifically for working operators that cannot leave their systems to attend extended training. These programs teach secure remote access, segmentation, vendor oversight, and incident response. These are skills that reduce risk immediately. What, from our field work, what we think is needed are pretty clear one we need targeted support for basic cyber hygiene that includes multi-factor authentication segmentation uh secure remote access and logging number two would be a circuit rider style cyber security program for rural utilities modeled after usda s technical assistance program number three would be incentives for small systems to adopt those safe drinking water act requirements even though they fall below the population threshold, and support for mar- university partnerships, convert federal guidance into applied improvements, uh, and it's exactly what Marshall is currently doing statewide. The operators who run America's small water systems are dedicated professionals who keep communities safe every day. With the right partnerships between utilities, National Guard cyber units, federal agencies, and universities like Marshall, We can make a small, we can make small and rural systems some of the most cyber resilient in the nation. Thank you for the opportunity to testify, and I look forward to your questions.
Thank you. Before we go to the uh next witness, let me just ask you, OT stands for?
Operational technology versus
Okay, and I
information technology.
Right, okay. Thank you. Uh, I'm gonna turn to Senator Kramer to introduce our next uh witness.
Thank you, Chairman, Capital Ranking Member, White House, for holding this very important and timely um uh hearing. It's a pleasure for me to introduce a fellow North Dakotan, uh Matt Oderman. He's here today in his capacity as an executive board member of the North Dakota Rural Water System Association, and he has an a a a big fan base there in the back, I noticed. It's they're all here for the same reasons the West Virginians are here. Um anyway, um Matt brings more than a decade of experience in cyber security and and critical infrastructure protection with a strong understanding of the unique challenges rural water systems. Mat serves as a Cyber Security Supervisor at Minn Kota Power Cooperative. Minn Kota is a regional uh generation and transmission co-op with a number of distrib distribution co-ops uh in the in the upper Midwest, where he leads efforts to to secure that IT and OT in environments across a multi-state utility footprint. He has extensive experience in the rural rural water sector, serving as a board member of the All Seasons Rural Water Users District, and as past president of the North Dakota Rural Water Association. I'm not sure what you do in your spare time, Matt, but anyway, and I'm not sure who all pays you, but anyway, it it it's impressive. You're a great servant. He's he's also a member of the Cybersecurity and Infrastructure Security Agency Water and Wastewater Sector Coordinating Council. He'll provide valuable insight for today's discussion on cyber security challenges facing water systems, and importantly offer the rural system perspective on these challenges. Thank you for sharing your uh knowledge with us today, Matt.
Thank you, and uh, Mister Oederman, you're recognized for five minutes.
Good morning, Chairman Capito, Ranking Member White House, Senator Cramer, and members of the committee. Thank you for the opportunity to testify on this important issue. My name is Matt Oederman and I hail from the great state of North Dakota, where I do serve as past president of the North Dakota Rural Water Systems Association. North Dakota's rural water system has two hundred and eighty-two members serving ninety-seven percent of the state's population. i'm especially proud to be a long-term board member of a small water system all seasons real water district and i'm here today on behalf of national real water association which represents thirty one thousand small and real water utilities across the country nrwa provides a diverse range of services to its members including training disaster planning and relief and several effective technical assistance programs additionally i rep represent nrwa on CISA's water and wastewater sector coordinating council in that role i participated in a cyber security task force focused on developing a practical plan of action to help the sector advance its cyber security posture for more than twenty years i've worked in it in cyber security roles across critical infrastructure sectors i currently serve as a cyber security supervisor for uh electric generation and cooperative and i have seen first hand the cyber security challenges that play out in a converged itot environment the vast majority of water and wastewater systems in this country serve communities of ten thousand people or less we have the same responsibility as large water utilities to deliver safe drinking water every second of every day the difference for us though is scale small systems operate with limited staff limited revenue, and limited technical capacity. Most do not have in-house cyber security personnel. In rural America, cyber security is not a question of indifference, it's a question of capacity. The threats are real, but so is the progress, cyber security awareness in the water sector is growing, largely through trusted non-regulatory partners like NRWA, state rural water associations, and the Water ISAC group. Through these efforts we're seeing a cultural shift, more and more rural water systems are moving to an understanding that cyber risk is part of operating a modern utility. At the same time, how federal security efforts are delivered matters just as much as what is required. From the sector's perspective, the EPA is first and foremost a regulator. When cyber security became part of the sanitary surveys, many utilities felt that they were being asked to self-report cyber weaknesses to an enforcement agency. that created confusion and concern for example water system operators are putting an outdated firewall in an effort to be transparent worried it might lead to some sort of enforcement action even when the intentions were not meant to be punitive the regulatory power dynamics shapes how those actions are received long-term improvements are built on collaboration and trusted technical assistance not fear of violations there's also a cultural gap gap when cyber security is framed as compliance or abstract it risk it feels disconnected however when it's framed as protecting pumps SCADA systems uh in the ability to keep water flowing twenty four seven operators understand that that translation layer is critical and organizations like nrwa state real water associations and others play a key role in bridging that gap based on my experience i offer five following principles first lead with assistance not enforcement adoption is stronger when cyber security is delivered as support not primarily as a compliance obligation second fund any mandate cyber security requires hardware software training and staff time for small systems even a few thousand dollars can be a barrier third focus on foundational controls many systems struggle more with phishing weak passwords and legacy equipment rather than nation state threats fourth rely on established trusted partners guidance delivered through organizations utilities already rely on is more likely to be implemented and fifth recognize diversity a system serving eight hundred people and two employees cannot be treated the same as a large utility In conclusion, protecting small systems must be a s- national security priority. With the right balance of partnership, practical guidance, and resources, we can strengthen cyber security across America's water infrastructure, not through fear but through collaboration and resilience. Thank you for the opportunity to testify, and I look forward to your questions.
Thank you very much. Uh, finally, we're gonna hear from uh Scott Dewhurst. Thank you for coming. Uh, Mister Dewhurst is the Deputy General Manager of Engineering and Technology for Fairfax Water and is testifying on behalf of the Association of Metropolitan Water Agencies this morning. He has held various leadership roles for utilities in Tacoma, Washington and Newport News, Virginia. You've been all over the place there. That's good. Mister Dewhurst, welcome. You are our recognized for five minutes. Thank you for coming.
Thank you. Chairman Capito, Ranking Member of White House, and Senator Kramer, members of the committee. Thank you for the opportunity to be here today and testify. My name is Scott Dewhurst and I am the Deputy General Manager at Fairfax Water over Indian technology. I am here today on behalf of the Association of Metropolitan Water Agencies, otherwise known as AMWA, an organization that represents the large publicly owned drinking water utilities across the country. I also serve on the board of managers of Water ISAC, the Water Infra- Information Sharing Analysis Center, which is the water sector's dedicated information sharing and sharing hub for cyber, physical, and natural threats. Cyber security in the water sector is a growing issue that grows more urgent by the day. Drinking water systems represent an attractive target for cyber adversaries, and there have been insufficient federal resources dedicated to this topic. A success- successful cyber attack on a water utility would not only threaten water quality and public health, but would also undermine public confidence in the safety and reliability of drinking water. Cyber threats have become more frequent, more sophisticated, and more damaging. Addressing them requires sustained investment in people, technology, and planning. According to WaterISAC's most recent cyber incident survey, about fourteen percent of responding water systems reported experiencing at least one cyber incident during the quarter, up from eleven point five percent during the same period in the last year. As a large public water system, Fairfax Water employs a dedicated cyber security staff. incident response plans, and the ability to leverage resources offered by federal and sector sponsors, including the EPA, the Cybersecurity and Infrastructure Security Agency, otherwise known as the CISA, and Water ISAC. However, well Fairfax water is not typical in terms of its robust cyber capabilities. Of the nation's roughly fifty thousand community water systems, many lack the personnel or financial resources needed to utilize federal guidance, assess risk, or implement recommended actions. There are many ways to meaningfully strengthen cyber security across the border sector, including by increasing resources for risk mitigation response, authorizing targeted grant funding for cyber resilience, ensuring that state and local governments are well resourced, and mapping out implementable minimum federal cyber security standards. It's critical that existing resources like Water-ISAC are well funded and being utilized across the industry. Water-ISAC plays an equal role in the sector's cyber security preparedness by actively monitoring cyber threats and vulnerabilities acc- affecting water utilities. It also provides guidance on risk mitigation tools, best practices, and response actions that contribute to an all hazards resiliency posture. Despite its critical role, Water ISAC receives no state or federal grant funding and faces challenges in connecting with the thousands of water systems across the country. My written testimony cites legislation that could help expand access to this wonderful resource. Congress should also recognize that cyber security must compete for water systems' attention with more high profile needs like infrastructure upkeep compliance with regulatory mandates and keeping bills affordable for rate payers. To help water systems invest in cyber defenses, in twenty twenty one Congress authorized the EPA's mid-sized and large drinking water system infrastructure infrastructure resilience and sustainability program and a compatible program for clean water agencies the program's offer grant funding for cyber security enhancements. However, these programs have received minimal funding. Congress should commit to providing adequate funding to help water systems meaningfully invest in the software upgrades security personnel and enhanced threat detection and monitoring procedures. Finally, while guidance and tools provided by EPA and CISA are valuable, there are currently no statutory federal cyber security requirements for water systems making these best practices optional and leaving less-resourced utilities wholly unprepared for a cyber incident. AMWA recognizes the danger in making federal regulations overly burdensome, complicated, or prescriptive, especially in a rapidly evolving threat environment. At the same time, some level of federal guidance would help ensure that all water systems are taking appropriate steps to protect against cyber threats. One proposal I believe warrants further consideration is established Motive A Water Risk and Resiliency Organization, or WRRO. That will be comprised of cyber experts and drinking water and waste water system operators. This WRRO would develop, recommend, and oversee cyber security guidelines for drinking and wastewater systems, tailored to their size and risk profiles. Based on the model of the National, excuse me, North American Electric Reliability Corporation, otherwise known as NERC, and energy sector, this organization would work in partnership with the EPA to ensure that water systems of all sizes secure themselves against cyber threats while avoiding the unworkable one size fits all mandates. While that's clear, there is much more work to be done to strengthen our water system cyber posture, AMWA stands ready to work with you towards meaningful solutions. On behalf of AMWA, thank you for the opportunity to testify today, and I look forward to your questions.
Thank you, very good. Thank you, came right in at the zero zero mark. That's uh very precise, I'll tell you. Um, so we're gonna start the question uh portion. I'll begin uh with Doctor Simonton. Um, you highlighted obviously what Marshall University's uh, Institute for Cybersecurity is pr- is uh, presently partnering with Anstead, which is just to frame it for the audience, very small area, and the Huntington water system, which I don't even know if it would be a medium size, but I would, I would put it in that category, not large large like Fairfax, but large, larger. Um, I was interested to hear, and I heard this from uh, the Royal Water Utilities folks that came in to see me yesterday from West Virginia. The Circuit Rider, Cyber Security Circuit Rider, idea through department of ag. So if you could frame out just briefly how how valuable circuit riders are in general for physical infrastructure and and for the smaller systems, and then how a s somebody dedicated fully to cyber, would you see it as a dedicated cyber? Would that be the best or somebody who has that enhanced credentialing that could could do both on the existing program?
Thank you for that question. Um, As far as the circuit rider is concerned, we're already, the university is is already able or we're moving towards supplying both students to to do these things for utilities or or um uh others that don't have that in-house capacity and of course also with our National Guard units that we're training,
Mm-hmm.
and not just in water cyber but in in infrastructure security uh in general.
Right.
So, i would see or we would see these circuit riders as dedicated certainly to cyber security because that is the need within the utilities if we're if we're
they could fill a day with that
they could fill a day with that absolutely and they provide that expertise they're
yeah
basically become consultants to the various utilities that provide the expertise
right
that they don't already have so that's how we would see those those circuit riders, or that ability to provide that that that uh that capability that the utilities don't currently have.
So let's say at Marshall uh since since you're dealing with this um as cyber security for critical infrastructure as a general rule would it be and and I said in my statement it can't be a one size fits all so would it would it be a parameters thing where you could then have it as long technical assistance is is what all three of you have said would really need. You you're not expecting the one and two and three person utility to be able to meet this challenge on their own. They have to have this assistant. Would it like a framework for for smaller systems that could then sort of be a plug and play type of thing?
That's what we are trying to develop is this scalable plug and play
Uh-huh.
uh um framework. Every system of course is going to be different, but the the needs are gonna be very similar. They're gonna have very similar systems, they're gonna have very similar uh very similar needs. And so we're developing this framework that that can apply, not just to water utilities, but but across infrastructure.
Right.
And so that's again, it's providing that in-house expertise that they don't have.
Great. Alright, good. Thank you. Um, Mister Oderman, um, you know, we're talking about rural water systems here, uh, and then unique challenges of uh of the systems uh in in in rural rural areas and we all know that if you can get into one system lot of times that can lead you to another system you know so the vulnerabilities how are you meaning you said how many uh different systems do you have in north dakota
there's two hundred and eighty-two members of the social
what is that yeah i mean that's a lot of people so
it's ninety seven percent of the state so it it's it's significant
So how do you see that in terms of uh um being able to serve serve where where you are in North Dakota?
The Circuit Rider program?
Yeah.
Uh, the Circuit Rider program is single-handedly the most successful built-out program that I see in our state. Um, it's mature, it's it's well-documented, the deliverables and the administrative stuff is set up already. Um, those trusted relationships between those association that those um systems and the state association are built. And so if we were able to spin up a technical circuit writer for cybersecurity, I've I imagine the uptake on that would be significant.
Workforce Development and Infrastructure Modernization
Thank you.
Mm.
Um, you know, I wanna talk about the workforce challenges because this is something I've been interested in and had several bills in the past have put in some uh availabilities for workforce development as our aging as I see in in West Virginia when I visit utilities are uh, general managers or who are all utility kind of a they do everything, uh, from fixing the leaky pipes to running the system to doing the billing to get everything. Um, trying to get young people interested in this as a career, uh, i- is I think difficult. I think the cyber aspect of it might have a little, uh, bit of a bump of, uh, more the modernization of the systems and you, you would be using all kinds of, uh, skill sets here. Um, I know one of our water systems in the audience has ha- has used like an apprenticeship type thing, where you would c- start in high school, coming to the utility, not even really thinking it's something that you wanna do, but make a little bit of money. And the next thing you know, they're full-time employees working. Have you had any experience with that, Mister Dewhurst?
Um, at Fairfax Water we do take a pretty aggressive approach with summer internships. It gives a, it gives, cuz I th- I think what people don't understand it takes many different types of skill sets and different types of jobs to run a water utility. So this gives students a chance to really see what is what is involved,
Good.
even in the cyberspace, even in the technology space,
Yeah.
a laboratory, whatever it may be. So we we think that's a great approach to to getting people introduced to the industry and to have a long-term career.
OK. Um, Senator Whitehouse.
i'm pretty sure i remember uh driving west virginia supreme court justice richard neely to marshall university to give a speech when i clerked for him years ago so if my memory serves i've actually been on your campus he was a very distinguished and lively uh person fair description that's an understanding so welcome and and thank you to uh seldom i would hear that marshall university for your work on climate change. Your research, sustainability day, uh, or awareness day in the sustainability department, uh, the climate change advocacy work you've done with Citizens' Climate Lobby, the Armstead Labs work on Appalachian climate resilience, Doctor Cartwright's work on young people's understanding of climate. You guys have done a lot of good work and I'm - I'm grateful to you. Um, Mister, uh, Dewhurst, you mentioned the NERC model. what is the nurk model and why might it work for water utilities as opposed to uh electric utilities
yeah so from my former experience in tacoma where we were a shared utility of water and power utility i got to see nurk somewhat in action um so nurk is really a collection
as a utility regulator back in the day so i'm interested
yeah ok nurk is uh set up to where uh it you know my my experience has been where you have a a mix of operators of the system as well as cyber experts that collaborate to develop standards and levels of compliance for different risks associated with each utility. So, I think a model like that is worth worth a conversation to understand how we can make that work for all the different size systems across the country. Um, I think what it does, it allows not, it doesn't prescript things, it's it's more of an outcome-based approach. It also gives um risk-based challenge, a risk-based requirement, so as a a system that has more impact or more connectivity, if you will, across the space, would have higher standards and expectations than one that's a little bit more isolated. But yet it's very important to establish baseline standards for everyone. It also within a a course, you know, uh, work its way across the entire sector, no matter what the size would be. So I think that's a an important concept that we need to think. So we're, we're not leaving anybody behind, but we're growing together and collaborating on what's the best approach. Another, uh, one more aspect I'll bring up is it gives it some chance to be nimble. So as you've, I've heard in all your comments this morning, your opening statements, these threats are evolving, they change quickly, quickly. We have AI which just came out, you know, three years ago, and now we're talking about it all the time. So, it allows us to move quickly and not have to wait upon another congressional action to change a law or a standard. We can actually move more nimbly into other ways to, to address threats as they're coming up.
Uh. when i was first working on cyber and we were trying to do a big um bipartisan cyber reform bill which actually got pretty close senators kyle and graham and mccain and thune were all uh working with me on that we nearly got it done we were trying to figure out what were the best ways to have american businesses step up their cyber defenses in this continually evolving environment where if you set a bar if you have to go back and re-legislate bar when things have changed you've wasted everybody's time. And one of the things that we were uh looking at um was to require um cyber insurance. So that um if you had sort of general liability insurance, you'd have to like carve out a cyber insurance defined sort of rider. or element so it just didn't get buried in the overall thing and that that would then focus the insurance industry year by year as policies were renewed in trying to look at how vulnerable you were and in particular with respect to liability whether you had met sort of the prevailing standard of uh you know adequate defense so that even if something did go wrong you at least had the defense that you'd done every reasonable thing that could be expected of you. And it's a lot to ask of all of you in one minute and thirty seconds, but I would be grateful if you would, um, take a moment after the hearing is over and think about what role requiring insurance, requiring a rider, requiring some specific, um, aspect of the policy, um, might have in terms of being that spur that continually drives forward and requires both the insurance side and the utility side to take a look at where they are uh on all of this is the question clear enough ok my time is up so i'll let that go but i do look forward to hearing your written responses about that and figuring out whether there's an insurance element to this that can help solve the problem thanks
All right, Senator Kramer.
Well, given um Senator Whitehouse's time running out, I'm I'm intrigued because I think Mr. Oedeman in your statement, your five points by the way were great, I couldn't get past the first one because it struck me but it made so much sense.
It makes too much sense.
As a former regulator of recovering myself, um you you said provide assistance not enforcement. Um and and then I and then I hear Senator Whitehouse talk about insurances, as I heard as I'm listening to him for the first time talk about this, I'm thinking to myself, okay that's that's maybe a better regulatory system than a government agency, right there's a market um a market aspect to that.
Mm.
M- maybe um since he didn't have the time to listen, if you could start and maybe the rest of you sorta chime in on on his point and and this point of not enforcement but but assistance.
And you can add Senator Kramer to your QFR response for me, thank you.
Yeah. I I think Senator Whitehouse was listening in to some of my conversations yesterday. Um
I'm not that good.
Yeah.
The the the fiduciary responsibility of being on a board you typically look at, you know, how do we cover our risk, and cyber insurance definitely is part of that. And that is definitely driving some organizations to strengthen their cyber defenses. Uh because you if you're a higher risk you pay higher insurance premiums if you desire more coverage they're gonna they're gonna investigate you little bit more or make sure that hey is this somebody we can actually cover or not so the the point about cyber insurance driving some of the changes is happening already um as far as dictating that in in law or regulation i'm i'm not sure how that would play out um but it's definitely moving the ball uh uh on on the front lines.
So you all have uh you know alluded to obviously your been rather emphatic about the ability to collaborate coordinate particularly in rural um probably some some of the big municipalities provide a little assistance to little people I mean we we've heard this in all my years in congress when it comes to rural water systems, probably more than any other thing uh please just even technical support but this is a little different cause when you think about two hundred and eighty-two as as center capital sort of like um gasped and thought two hundred and eighty two um members that's a lot of members. And one thing I know about your members like most North Dakotans is while they like to collaborate and partner they also protect their sovereignty, and autonomy maybe even in some cases um maybe give me a best a a best practice that that has worked for each of you uh as a as a way just give us a little guidance. Start with Mister Dewhurst then.
Um I I mean I think that you know We as a large system's example, um, we we wanna work together with everyone. I think we we engage with our colleagues across the state and Virginia, for instance, and and share ideas and share best practices. You know, I think through water ice sack, I think that's a great example, we can all collaborate together. I think if we can bring awareness to incidents as they occur, and that becomes a central clearinghouse for everyone in the country, it gives us a way to manage those threats and make sure people large, small, it doesn't matter where you are in the country, is aware of those threats so they can take mitigation steps to to correct that so i think water assets are great tool to kinda weave through all of us um to give us those standards and protections so thanks
uh definitely using trusted partners that already have those relationships built out um that's state primacy agencies uh and you know as state associations have a footprint in every community in north dakota for example um they know those circuit riders by name probably have their cell phone you know they they probably know like their kids names and things like that so that's a very trusted relationship what doesn't work is you know a fifteen page like bulletin uh information disclosure uh that's doesn't land with an operator in a small system um but definitely the trusted uh uh partners is where we should works the best
i would add first of all senator whitehouse i i knew richard neely personally and have very cherished memories of spending time in his office. Um, I could also address it as a former regulator in West Virginia and in Idaho, a consulting engineer that dealt with regulatory agencies. For the most part, especially at the state level, I have found the agencies to be really valuable partners and very helpful. And, um, trying to, regardless of the regulated community, help them comply with the regulations and not always wielding the stick. uh, but actually providing, uh, what can become a very trusted resource, um, uh, if, you know, for these utilities, for example, in this space. So, so that can be part of it and not just the, just the, um, punitive part of the regulatory agencies, but, but I find them to be, uh, actually very helpful at most, most of the time.
Senator Blount Rochester.
Thank you, Chair Capito and Ranking Member Whitehouse, and thank you so much to the panelists for being here today. Um, uh, for me, this hearing on cyber security and our nation's water and wastewater infrastructure is both critical and timely. Uh, according to reports, and these are public reports, um, one, one is even from my region, the Delaware Currents. Um, there's a quote that " once a hacker gets into a water system, they could potentially turn pumps and motors on and off, alter chemical levels in drinking water to dangerous levels, and even plant software bombs that could disrupt the water system later. That same report went on to say that there are risks associated with poor cyber hygiene, as you mentioned, to states, and also that cyber attackers come in many forms, from disgruntled former employees nation states like China, Iran, South Korea and Russia. So, to be to be clear, this is the kind of stuff that could keep you up at night. I don't know if it keeps you all up at night. You're all shaking your heads. Um, but one of the things that I thought about when you add on to it in this moment is extreme weather. That's a whole nother risk. And so, uh, I'm gonna start with you, Doctor Simonton. I come from a state that is urban, suburban, rural and coastal. And we also have many small towns. And I'm curious, do water utilities account for extreme weather events when thinking about cyber attacks and what additional steps are needed?
I think, and thank you for that question, Senator. I th- I think that that we have been blessed in this country with infrastructure that works. And so people don't give it a whole lot of thought because when they turn their tap on, they get clean water. So we are seeing, whether it's chemical spills, extreme weather events, that that our uh infrastructure is fragile. And and so we get these messages on occasion when there are these disruptions. So I think across the industry, and certainly I can speak just across civil environmental engineering in general, we are certainly starting to take um uh extreme weather events into into account in in design, in maintenance, and certainly that's going to apply to cyber systems within these utilities and therefore cyber security becomes an issue.
Thank you for, for that answer. Uh, the mid-sized large drinking water systems, um, infrastructure program, which is run by EPA, is one of the few federal grant programs that helps water systems reduce cyber security threats. Unfortunately, the program has never been funded near its authorized level of fifty million dollars, and is set to expire in FY twenty twenty six. Last month, my Republican colleague, Senator Curtis and I introduced the Water Infrastructure Resilience and Sustainability Act to reauthorize this critical program. Uh, Mister Dewhurst, thank you for mentioning our bill and your written testimony. Why is reauthorizing this program so important right now, and how do utilities use the program's resources to strengthen cyber security protections.
First of all, thank you for the question and thank you for your sponsorship and Senator Curtis of that bill. Um, I can just, I would just alert to that bill has such a wide range of uses it can be used for. Um, cyber is one of them for sure. Um, so it allows a lot of the basic stuff that needs to be done on the cyber front to be done, whether it's doing a a simple assessment about where your vulnerabilities are located, um, employing some software tactics, factor authentication, segmenting your network, um, other other types, things like firewall additions, those sorts of things. It's all, it's there for everyone to to partake in. I will, I will echo your comments that it has not been funded to the level that it should, even though it's authorized, it's not been appropriated. So I think any any improvement in that front would be appreciated by all of us sitting at this table I think here. Um, because I think it also does touch all the systems of all sizes, um, in various ways. So, uh, we would very much strongly echo your your sentiments to to
thank you mister oterman you're shaking your head i wanna give you an opportunity to respond
he he nailed it but uh uh the only thing with some grant applications for smaller systems
right
is it can uh be administrative workload that they simply just don't have the capability to
right the it's back to the capacity
yeah and so again that's where a circuit rider concept could assist in those types of of ok capacity applications and and management.
Thank you. Thank you. And and also, um, you know, Doctor Simonton, when you also talked about the stackable water credentials, I think that is so important too, uh, you know, as a former, uh, personnel director for the state of Delaware, uh, understanding that when you don't have that capacity, you really do need to, it might be only two people or three people that are working in these small places. And so making sure that we have those. The other question I, my time has expired.
Well, thank you, Chairman Capito and Ranking Member of White House for holding this, uh, important, uh,
Uh.
hearing today,
Thank you.
and thank you to our witnesses for coming and sharing your perspective. on what we can do to better secure our water systems against the cyber security challenges that we face in our world. In Nebraska, our water and wastewater utilities manage and protect our state's groundwater. They provide critical services to Nebraskans. And, uh, uh, we've talked about how it impacts the states that, uh, you're from. The security is increasingly at risk from foreign adversaries seeking to undermine critical infrastructure. and threaten public safety through cyber attacks on our water systems. Communist China uh has actively been involved in targeting wastewater systems, critical infrastructure in every community across the US. And in twenty twenty four, the EPA OIG found that nearly a hundred drinking water systems serving twenty six point six million people had critical or high-risk cyber security vulnerabilities. This includes open internet portals, default passwords, unpatched systems, uh these vulnerabilities leave utilities exposed to cyber criminals and foreign adversaries. It's important that rural water systems have the tools, resources and technical support necessary to defend against these cyber and foreign threats. Yet many small and rural communities face significant barriers in accessing these tools and resources. Just yesterday I met with the Nebraska Rural Water Association who shared some of these challenges such as the staffing shortages we've discussed and reduced technical capacity. To protect our water systems, our food supply and ultimately our national security, we must ensure rural communities are equipped to build and maintain resilient water infrastructure. In West Point, Nebraska, they are doing just that. They have upgraded their system to a cloud-based management platform. These platforms allow water utilities to monitor and manage infrastructure from any location and house data in a secure location. uh mister oberman what what do you think the relative advantages of moving uh water operations to a more advanced automated programs like the cloud versus uh what they historically been in
there is definitive advantages to that model uh scalability um there is long term cost savings typically you're not having to house as much uh technology equipment in house um you get baked in security practices they they're not gonna let you do certain things on the cloud platform without following certain guidelines and standards and then to speak to the weather thing it's uh geo-location diversity with where your data is stored so you have some disaster recovery uh advantages as well the one negative would be um there is it takes a different technical set up and configuration to manage cloud services so that's a little less limited than the traditional server client setup. And then also you're dependent on an internet connection, so if you are somewhere without an internet connection you you're you're you're stuck.
Yeah.
But there's definitely uh a a model that would work uh there.
One of the other things we heard is that with modern systems you have to upgrade them more often. Is that what your experience is in North Dakota as well?
Yeah, updates are con all consuming in my life right now um. that's what keeps me up at night uh jim uh yeah it's it's a challenge and again that's where uh you know this smaller systems just don't have the capacity to manage all those it and ot assets and and uh giving them technical technical assistance to align with a trusted vendor that meets standards would would be uh uh uh an avenue for them.
great thank you uh doctor i was mentioning some of the cyber attacks some of the things that uh can leave us open and vulnerable uh what documentation do we have on attempted attacks against water infrastructure and what do we know about the sources of the, or the actors behind these attacks
I don't know that I can really speak to that senator because so much of what happens I mean as you probably well know uh the United States suffers uh mind boggling number of of attacks everyday and so how many of those are directed specifically at the water sector i i couldn't answer that
so would it be helpful then if we were trying to do more documentation specifically on the water our water systems and waste water systems to be able to know how much is that being targeted versus say hospitals which have typically been very high profile when they get a text and they've got a ransomware attack you know because it's everybody at the hospital can't get treatment right
absolutely and and what we are seeing across the board in uh, infrastructure and what we're doing at Marshall University is not just focused on water cyber security which is what we're talking about today and really where we started um, to build the framework, but we're already working in healthcare, finance, uh, s- transportation, specifically aviation, because all of these areas of infrastructure are coming under, uh, more and more attack and with automation of course, more and more vulnerabilities.
Yeah. And I will note that uh there are members of the nebraska rural water association in the audience today so thank you very much for your help and with that jim i'll turn it back over to you
uh senator houston
thank you uh chairman capito and and lot of lot of great questions and comments uh appreciate i i actually when i was lieutenant governor in ohio worked on cyber security issues with local governments all the time uh and they were quite common uh uh attempts at a local government i'm just curious if any of you would like to just to put in context how common a rural water system how often a rural water system will receive an attempted cyber attack
everybody is looking at me so uh
i'll i i was gonna let you choose who
yeah
how common is it
um i would say that it happens probably daily uh whether there's impact from these cyber attacks and to me
the attempted attack yeah
attempted attack would could be just a phishing email or port scan of their their device and nothing really occurs um i do know that we've had some in north dakota that have risen to where it's been passed on to the state and local information center to investigate and provide some some uh technical assistance on investigating what happened there um but a true number um i don't
it it happens daily
it i would say daily yeah
yeah it and um and to senator ricketts you know made a very good point about you know migrating your systems to a cloud based system because that in almost every case i know of is a preferable way to mmm to manage it would you agree with that
there there's definite advantages like i said um i personally what i like the most about that
but that's the advice you would give to somebody right it doesn't it it's just general advice and then
yeah yeah yeah it's
um but i also have learned in the past that it's despite the training despite the the systems and all that it's usually a human error that leads to this and so that's the training that's the awareness and i see all your heads nodding please feel free to speak up on that if any of you wanna make a a point about the importance of that.
I, I can in developing our micro-credentials we've worked closely with water utilities, especially water, small water utilities, and they do kind of throw their hands up on when it comes to the cyber security aspect. They know that they are vulnerable, but they know they know what they don't know. And, and they know that they need the training. They need the, they know they need the expertise. to help at least from an awareness standpoint so so the industry is quite aware of the need for training and uh i i think that's what's what's important
yeah i would just echo that again i think the phishing campaigns that are out there are becoming more sophisticated and that's a simple email and we all get a thousand emails a day sometimes and you're scrolling through and you can actually hit the wrong button and automatically go to a link that could cause a lot of problems a lot of harm
don't click i links
so so But, but again, it takes that culture, it takes that awareness, and takes people to take a minute to think about it before they do it. And oftentimes you're in such a hurry to get things done, you don't do that, right? So.
And where are rural water systems, I mean, do you think they know that? Do you think, is there, if we're, do you think they're aware of that? And, and, and then I wanna, I wanna add, um, and then what should they do if there's a breach? What if they have a, what, what is it that they're supposed to do? What's the first thing that they're supposed to do
first yes i think generally they're aware that
mmm
there's phishing attacks and and things of that nature the first thing they should do um if they're under attack is reach out to that trusted resource for most people in north dakota that would be you know probably their their membership's uh their systems it group that they work with and after that would be north dakota slick which is state and local information center, and so on and so forth. And hopefully, um, that state and local information center can direct them into the resources that they need.
And I think one thing, if I could, the utilities really pride ourselves on being prepared and having a plan. I think one of the most important things for every utility, whatever size, is to have an, have a cyber response plan. So you know what to do, you know what to do if and when it happens, cuz you're ill-prepared to think. clearly in that moment. So to know what you need to do and address that is something we should all be aware of and have on our, on our ready.
Yeah. And, and if, is there a federal agency that you would inform, and if so, who?
I would guess, I mean CISA is be the, be the obvious choice,
Yeah.
I mean I again wanna echo my comments earlier about Water-Ice Act and how I think it could play a critical role in connecting utilities so that when incidents occur, no matter where they are, they can be brought to light and shared with others across the country in a very, uh expeditious ways that we can guard against that happening somewhere else for the same vulnerability
yeah well i will just close i know my time is running out but uh from my research most of the attacks come from north korea iran russia and china they don't come from ukraine or israel and uh and i just wanna note that thank you madam chair
thank you senator schiff
Thank you, Madam Chair, uh, for calling this hearing on such an important but often overlooked topic. I share many of the concerns I think you have uh, about making sure our water and wastewater systems are protected from cyber attacks. This is a critical issue at the nexus of water affordability, environmental quality, and national security. Uh, I've been working on a bill to provide EPA with more tools to address the issue, and provide water systems with the resources they need properly fortify their cyber systems without impacting the water and sewage bills paid by american households. i'm hopeful that this committee uh can work together uh to work on addressing this problem. um i have a couple of questions and i offer to anyone on the panel who would like to uh weigh in um how prevalent do we believe the ransomware attacks are um i know there are uh particularly in corporate america there's a reluctance to notify the bureau or anyone else when there is a cyber attack um for fear of it becoming public and uh reputational harm um do we have any sense of how often water systems are under ransomware attacks
i don't think we have uh a clear understanding what it is but ransomware attacks are definitely um more prevalent in nation state attacks uh nation state or you know nation sponsored threat threats uh tend to just lie in wait they try to exfilt exfiltrate data where ransomware is more of a criminal mindset where we're gonna try to leverage and get some money out of these people um it's devastating to a to to a a a members uh i know in north dakota uh there's been a few hospital systems have suffered ransomware attacks and it's been particularly hard for them they've had to get short term financing just to bridge through to like get their billing reenabled um it's a very serious thing and it
i i remember a hospital in my district this was probably
yeah
eight or ten years ago and this was quaint compared today um locked up all the hospital's data um and the hospital went to the fbi and said what do we do and they were demanding i think seventeen thousand in cryptocurrency uh and the fbi said do you want your data back and they said we need our data and the fbi said then pay them um i'm sure they wouldn't demand seventeen thousand anymore uh but there's no requirement that water systems report when they're the victims of uh cybertax so do we really just not have much of a sense at all how how often it happens
well i mean i would just say again water isek tries to be that central repository so we are aware of some but they're usually anonymized so we don't like single out a we don't say a certain city or county or whatever we try to make it just hey make awareness that this is a ransomware attack did occur here's the avenue by which they access their system make sure you address this vulnerability so that's how i think we can you know grow together and learn together is by that central repository
And and and how many are you notified by,
Sort of an exact.
say within the last year?
Of ransomware attacks?
Yeah.
I don't think that many. I mean, I think a handful.
Yeah.
For the water specific, I think it's water specific is what you're asking.
Yeah.
Yeah.
Um, some of the uh, destructive attacks that we've become aware of, uh, have targeted smaller water systems, um, in kind of random locations. Do we think it's just because they were targets of opportunity? That is, that foreign malign actors, Iran, whoever, um, are simply looking to punish the United States and they've identified, hey, this water system is using outdated software or whatever. Uh, is that what we think is going on with the kind of strange, um, target selection?
i believe that what's happening is is they're attacking many systems all at one time and and looking for those vulnerabilities and some of those systems will provide those vulnerabilities so i think that it's a widely cast net and then just just the unlucky few are are actually getting hit
and is the net cast by a spear phishing email that's sort of blasted out or how do they cast the net
i'm gonna let you answer that one
uh it can be uh in my current occupation we see that uh weekly you know that that spear phishing campaign uh generally speaking when it comes to ot networks and the it networks that are live on the internet that's through like a random port scan they're just scanning a whole list and they get return values yup this port's open i'm gonna see if we can uh go further here
uh and that kind of search is done not just of water agencies it's a kind of a broad search for someone using an unpatched uh software
yeah there's really no way to tell uh like from a port scan that's a small real water system or a large utility it's it's just a wide net and uh soon as they see that that port or that service is open they they dig further and see if they can exploit the vulnerability
uh last question um The major infiltrations like the Chinese salt typhoon, uh. Do we know whether we're having any success in excising that, uh, stocking horse? Um, I don't know whether that may be a beyond the scope of what we can discuss in this hearing, but, uh, how much do we know about what may be lying in wait?
i'll do my best to answer this question it that's a very serious uh concern in the cyber security community uh have we made a headway i i think there's a little bit more uh information sharing coming down from like fbi infra guard on some of those things we get that information faster through the information sharing in our analysis centers, like water isek and isek and the like so that information does get to us faster um whether it's acted on i i don't know if i can provide like any details on that but it's definitely a concern
thank you madam chair
thank you uh senator markey
uh thank you madam chair very much uh mister duherst your testimony outlines recommended legislative solutions to address the cyber security challenges facing the water sector including my bill the water intelligence security and cyber threat protection act and i was proud to develop that legislation with the association of metropolitan water agencies uh boston water and sewer played a central role in establishing the water eh sharing and uh analysis center which is known as uh water isac so water infrastructure cyber security is a point of pride in our state in fact in twenty twenty four uh boston water and sewer experienced a ransomware attack that water ice act successfully assisted them in navigating avoiding widespread damage to our system mister are there any other organizations that compare with water ice act in terms of services in real time assistance to water utilities
yeah thank you for the question and thank you for your uh support of that bill i think that's a avenue for us all utilities to take advantage of and to really make water ISAC an important pillar uh in our response to cyber security threats. Um, I would say many, many utilities have to have third-party assistance at the ready. We have contracts that are, you know, typically a zero retainer contract with different firms to be ready to respond to a cyber incident, should that occur. Um, so I think water ISAC can provide some initial support and some initial guidance if something were to occur. But I go back to the need to have a plan a cyber plan in place and it's a response plan in place to know how to behave as soon as that happens
but right now there are no other organizations that uh are comparable
not that i'm really aware of uh i i'll i'll defer to others yes
well that's that's fine yeah so it's clear that if we wanna support our water systems in dealing with cyber threats we need to support this water cyber security organization mister do hearst do you agree that the primary barrier for water utilities vital cyber security services is simply funding
i think it's funding and also i think time you know i think we've heard up here a lot with the rural systems especially they've got a lot of things they're doing um they don't have dedicated staff to certain things so i think that's an aspect so i think what i said can hopefully hopefully
is funding the principal reason
fund funding is a funding is a big deal and so we're trying to we're trying to establish that
vision without funding is a hallucination right so you can say it's all a problem but if you're working on a system without funding how are you gonna get it done
absolutely absolutely we need we need money we need funding yes
yeah so thank you and that's why i introduced my legislation uh which would provide the funding to water utilities to access the cyber security services offered by water isek and i look forward to working with my colleagues on that the reason i'm really apprehensive about this is that there was a a cyber incident uh called stuxnet back in twenty ten and it really drew a lot of attention to this entire area and so um the cia and of the national security apparatus of the united states came to me as the chairman of the energy uh subcommittee to ask me if i would pass legislation um that would mandate that electric utilities in america upgrade their cyber security and so i took my counterpart fred upton the ranking member on the committee we went down we got the top secret briefing we could see how dangerous it was then we brought all the other members down to get the secret briefing they were terrified at the fact that the iranians and the north koreans and the russians and the chinese were all attacking our electric grid system every single day trying to find the vulnerabilities getting ready for the moment when they could do it and again thomas alva edison would recognize our electric system in terms of the level of protections that are built in so we had a piece of legislation we drafted it we passed it on a bipartisan basis ok what happened was it came over here to the senate this wonderful institution that i now serve in senator kyle from arizona got lobbied by his um electric utility and they didn't wanna spend the money even though fort huachuca in arizona is on the public grid making it easy access into that incredibly important military facility in our country and it died over here in the senate and it has died year after year even though we passed it unanimously in the house because the electric utilities did not want to spend the money but it's a game of cat and mouse right and the cat or all of these incredibly powerful supersophisticated cyber you know giants around the world and the mouse is our electric grid and our water systems and they're unprotected they still haven't had the upgrade uh in the cyber security protections which they need waiting for the eventual inevitable inexorable successful catastrophic attack so it's just time for us to get real about this issue it's only now a hundred times worse because of ai in terms of the sophistication of the technology which can be used and it's time for us to put the mandate in place and the funding that the company's got um so that all of these vulnerable infrastructure um systems are able to protect themselves against the attack which is coming the only question is how we gonna protect against it thank you madam chair
thank you thank you that uh that uh We don't have any further questions, and I'd like to thank the witnesses. I would like to say, and uh, yes, Senator Whitehouse.
I just wanted to make one, uh, brief point about the
Of course.
distinction between nation-state cyber attacks and, um, ones that are done more by criminal organizations. Just to be clear that there is not really a very clear dividing line between the two.
Hmm?
It is quite apparent that Russia while it may engage in some specific cyber-attacks on its own account through the fsb and other um official organs of putin's thug oligarch government also supports encourages and funds all sorts of organizations that are driving hacks out of moldova or out of or out of wherever um and while those are not purely nation state attacks they are subsidized and authorized and they're constantly probing for weaknesses so that while they may get a hit at um putting the target's equipment into a lockbox and extracting ransom they're also providing information to russia about where vulnerabilities are so that when they wanna move as a nation state to attack uh our resources they can do so and maybe even light up these other groups to go and do it on their behalf so they can keep a veneer of deniability the same way that putin is keeping a veneer of deniability of the destruction of infrastructure through the baltic by pretending that uh these ships that are dragging their anchors through cables and disrupting them are somehow not anything that he has anything to do with so i just wanna make sure that in the record of this proceeding it's quite clear that the difference between a direct nation state cyber attack and the sort of gray zone of nation state supported semi-deniable partly kind of just gangster and criminal behavior stuff is not that clear
right Right. Yeah, I'd like to make an additional point as somebody who lives in a community who lost their water source through a chemical spill for many weeks, uh the uh there's a couple things beyond uh what happens to the destruction of the system. It becomes a very emotional response. Uh and it it c- it can really grow because you you begin to lose trust, your authorities, uh the authorities, health authorities and otherwise. uh, unless they're crystal clear and we've gone through this with the CDC because they were not in this case uh eh eh you know begin to take on a greater role and they have to be prepared for this too whether it's a cyber attack or chemical spill or whatever. So if you if you are able to infiltrate uh successfully a cyber attack on one of your smaller systems uh you know there might be people that would say, oh well that only serves twenty five hundred people, that doesn't really matter. But what matters is the lack of trust and the cascading effect that it has in every rural community of this could be me. And how do I know? And so that's why I think at every level, uh, that we need to make sure that the protections that we afford, the larger systems are the same protections that we can provide for the smaller systems. And, um, you know, I was also thinking if, let's say, you s- have the same IT person or something, they get into a small system and an instead and then maybe that same IT system does Fayetteville. And then is there a way in? And then you're into a bigger system because you're into the whole IT system, so it's no longer instead of as, I don't know, six, seven hundred people. Uh, and they're into a bigger thing. So I think there's a lot more connectivity here and a lot more emotional part of protecting our rural water systems than uh that we really got into today. I'd, I would identify also a gap. I think we need better data on how many uh attacks we have, cuz nobody really had the answer to that question. Uh, I think, you know, how many, where are they occurring, how have they occurred, that's always gonna be good for best practices to try to prevent. So those those are my little uh commentaries. I'd like to thank all the rural water people who are in the audience today for coming. Um, senators who wish to submit written questions, and we did hear at least from Senator Whitehouse and Senator Bl- Rochester, they are gonna wanna submit questions and maybe Senator Rickett. They have until five PM on Wednesday, February the eighteenth. The wa- witness responses to these questions are back to the committee no later than five p m on Wednesday, March the fourth, and will be submitted for the record. With that, this hearing is adjourned. Thank you all very much. It was very interesting.
Same-day access
Read every hearing transcript the day it happens
Paid seats unlock fresh transcripts immediately, including synced video and clear summaries.



