Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Water Cybersecurity topic

No spam. Unsubscribe anytime.

House subcommittee hears engineers, federal watchdog and policy experts on water-system cyber risks

House Committee on Science, Space, and Technology, Subcommittee on Environment · May 22, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Witnesses told the House Science Committee subcommittee that U.S. drinking-water and wastewater systems are increasingly targeted by state-linked hackers and ransomware, urged practical engineering fixes and more federal coordination, and urged policies that reach small and rural utilities.

The House Science Committee's Subcommittee on Environment convened a hearing titled “Research Driven Resilience: Applying Science to Secure U.S. Water Systems from Cyber Threats,” where federal watchdogs, national-lab engineers and policy specialists warned that many water systems lack the resources or design to withstand advanced cyberattacks.

Chairman Franklin opened the hearing by saying the goal was to identify research and development priorities to protect water infrastructure and described recent incidents, including a 2021 Oldsmar, Florida intrusion, as reasons to invest in resilient design. "We must continue supporting research and development that produces affordable, cyber-resilient technologies for the water sector," Franklin said.

The Government Accountability Office's David Henchman testified that the water sector'with roughly hundreds of thousands of drinking and wastewater systems of widely varying size and ownership'faces "uneven cybersecurity capabilities, cyber workforce shortages, and limited resources." Henchman told members that, as the sector risk management agency for water, the Environmental Protection Agency has taken steps such as a sector risk assessment and issuing advisories, but "they lack cohesive authority and resources" to implement a national, whole-of-government approach. He suggested changes including greater legal authority to collect risk and resilience plans and improved information sharing.

Idaho National Laboratory program manager Virginia Wright described "cyber-informed engineering" approaches that reduce the worst consequences of an intrusion. Wright used a time-delay relay as a concrete example: "It contains no software, and it cannot be hacked," she said, explaining that such hardware mitigations can buy operators time to switch to manual controls and avoid catastrophic pump failures.

Josh Corman of the Institute for Security and Technology pushed for prioritizing the highest-consequence systems. Describing his Disruptible 27 project, he said researchers are focusing on about 6,000 systems that support the nation's hospitals and other critical facilities. "We are prone. We are prey," Corman said, arguing engineering changes can reduce the most damaging failure modes even if attackers retain access.

Policy strategist Nicole Tisdale emphasized the particular vulnerability of small and rural utilities. She cited sector statistics and argued that many federal programs are designed for better-resourced utilities and therefore exclude rural communities. Tisdale recommended program and grant designs tailored to low-bandwidth areas and urged consideration of a rural water and wastewater cybersecurity center at EPA to centralize support and coordination.

Members pressed witnesses on specific gaps and remedies. Chairman Franklin and others asked whether EPA has sufficient authority to act as a sector risk management agency; Henchman answered that many SRMAs operate mainly through persuasion and that Congress could clarify or expand EPA's statutory capabilities while balancing regulatory concerns. Members and witnesses discussed funding mechanisms, including the Drinking Water State Revolving Fund and the State, Local, Tribal, and Territorial (SLTT) cyber grant program, and noted examples where small grants proved effective: one witness cited a New Hampshire program that provided roughly $50,000 per facility to fund a managed firewall for two to three years.

Members also raised supply-chain and hardware concerns, with Rep. Foster and others pointing to the need for inspection rights and supplier transparency to guard against compromised components. Witnesses described voluntary and regulatory options for improving the security of industrial control systems and components used in water infrastructure.

The hearing left a number of policy questions for Congress and the administration: whether to provide EPA broader authority or create a dedicated, funded hub for water cybersecurity; how to tailor grants and technical assistance to rural and small utilities; and how to scale engineering mitigations that reduce the worst-case consequences of attacks. The record was left open for 10 days for additional comments, and the subcommittee adjourned.

Ending: The hearing produced a slate of practical recommendations'from expanding technical-adviser programs and test beds to reconsidering grant design and authority for EPA'but did not produce immediate legislation. The committee left record comments open for 10 days and will consider next steps.