Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Water Cybersecurity topic

No spam. Unsubscribe anytime.

House committee advances bill requiring water and wastewater systems to report cyber intrusions

2866441 · April 2, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The House Environmental Affairs Committee passed Senate Bill 459, amended to add wastewater systems and to set a two-business-day reporting window for certain cyber incidents; the bill also requires annual vulnerability assessments and authorizes rulemaking on treated-wastewater reclamation.

Senate Bill 459, which would require water and wastewater utilities to report certain cybersecurity incidents to state agencies and perform annual vulnerability assessments, passed the Indiana House Environmental Affairs Committee on a 13-0 roll call Tuesday.

The measure, presented by Senator Niemeyer and supported by the Indiana Department of Environmental Management, adds wastewater systems to existing proposals, establishes a two-tiered incident-reporting timeline and directs the Environmental Rules Board to consider rules for reclamation of treated wastewater.

Jake Tory, legislative director for the Indiana Department of Environmental Management, told the committee the bill grew from cybersecurity problems discovered last summer when a hacker accessed controls at a Tipton-area water system. "Thankfully, it was during regular business hours and a technician was there and saw something on the controls kind of going haywire and was able to switch it over to manual operations," Tory said. He said IDEM did not learn of the incident for a long time and that timely notification would let state agencies respond faster.

The amended bill requires water and wastewater operators to report incidents that impact operations to IDEM and the Indiana Office of Technology within 24 hours of discovery, and to report incidents that do not impact operations within two business days. The amendment adopted in committee aligned the timing language with a related cybersecurity bill moving through the Legislature.

Senator Niemeyer described the specific change: the amendment expands the original water-only language to include wastewater and makes the reporting window consistent with companion legislation. "We want to make them compatible with both of them," Niemeyer said, referring to the Senate cybersecurity bill and the amended timing language.

Republican Representative Kyle Pierce asked why the bill distinguishes the two reporting timelines and suggested a single 24-hour requirement after discovery could remove ambiguity. Tory said the two-tier approach was intended to match best-practice language in companion legislation and to avoid duplicative reporting requirements.

Representative Carolyn Jackson asked how the public would be notified if a contamination event occurred. Tory said he could not immediately answer that question and offered to follow up with the committee.

The Indiana Wildlife Federation testified in support. Rick Cochran, a volunteer board member, said that while a ransomware attack on a wastewater plant may be unlikely, the environmental consequences could be substantial. "We could be talking about miles and miles of fish kill and other impacts to wildlife," Cochran said.

Committee members approved the bill as amended on a voice and roll-call motion. The committee record shows the motion to pass as amended carried 13 yeas and 0 nays.

The amended bill also requires annual cybersecurity vulnerability assessments for covered water and wastewater systems. It exempts certain entities from duplicative reporting requirements; testimony and committee discussion said the exemption language was intended to avoid overlapping state reporting duties already in other statutes or rules, though committee members asked IDEM to clarify which entities would be exempt.

The committee moved SB 459 forward with the amendment that (1) adds wastewater, (2) establishes the two-tier reporting requirement (24 hours if operations are impacted; two business days otherwise, as aligned with the other cybersecurity bill), and (3) requires annual vulnerability assessments and Environmental Rules Board rulemaking authority on reclamation of treated wastewater. A staff follow-up was promised on how and when the public would be notified after a confirmed incident.

The measure will proceed to the next committee or floor consideration under normal legislative procedures.