Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Infrastructure Cybersecurity topic

No spam. Unsubscribe anytime.

Committee weighs bill to strengthen cybersecurity oversight for Maryland water systems

2416897 · February 27, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

House Bill 1062 would designate the Maryland Department of the Environment as lead regulator for cybersecurity planning and assessments for community water and wastewater systems and require reporting, risk assessments and coordination with state cybersecurity authorities; local governments urged changes on costs and timelines.

House Bill 1062 would require the Maryland Department of the Environment (MDE) to lead a coordinated program for cybersecurity planning, assessments and incident reporting for community water and wastewater systems serving more than roughly 3,300 people and systems that use operational technology.

Delegate Harrison, the bill sponsor, said the legislation implements recommendations from a National Security Agency (NSA) fellowship report produced by Dr. Matthew Matroka and aligns with MDE’s 2024 action plan. “Cyber attacks on these systems could contaminate drinking water, disrupt services, undermine public confidence in utilities, and jeopardize compliance with federal and state safety regulations,” he told the committee.

Dr. Matthew Matroka, the NSA fellow whose 50 recommendations informed the bill, said rising threats are documented by federal agencies and private-sector cybersecurity research and “House Bill 1062 takes vital steps to increase Maryland's water cyber resilience.”

Supporters framed the bill as a “continuous improvement” program that sets minimum standards, requires incident reporting to the state security operations center, and protects critical infrastructure information from public disclosure. Dr. Greg Von Lehman urged an amendment to require third-party assessments that evaluate cybersecurity program maturity rather than network-level device scans.

County officials and associations raised concerns about the fiscal impact on local governments. Don Butchko of the Maryland Association of Counties said jurisdictions estimate upfront costs of about $2,000,000 (variable by size) and potential annual costs of $1,000,000; municipalities and the Maryland Municipal League urged additional funding and clearer waiver or funding mechanisms. Don Butchko of the Maryland Association of Counties described the fiscal environment as “challenging” and requested a favorable-with-amendments approach.

Representatives from MDE, DoIT and others were listed as cooperating agencies; the sponsor said he would work with MDE and DoIT on amendments to address costs and clarify staged implementation. No final committee vote occurred during the hearing.

(Reporting note: quotes and summaries are drawn from the hearing transcript and attributed to speakers identified in the transcript.)