Illinois bill would strengthen cybersecurity rules for water utilities

The Stickney Water Reclamation Plant and water tower
The Metropolitan Water Reclamation District of Greater Chicago's Stickney Water Reclamation Plant and water tower. State lawmakers are considering a bill to ramp up cybersecurity protections for water utilities.
Bloomberg News

Illinois lawmakers are hammering out legislation to increase cybersecurity protections for local water utilities, an effort that comes in the wake of coordinated cyberattacks that struck municipal water systems across the country this summer.

Processing Content

The bill, HB 3576, would require public water utilities to have cybersecurity insurance policies, to conform to industry-recognized cybersecurity frameworks, and to submit compliance, annual status and cybersecurity incident reports.

The bill is currently with the House rules committee, and lawmakers are in discussions with stakeholders about fine-tuning its language, said the bill's lead sponsor, state Rep. Dagmara Avelar, D-Romeoville. 

"We're going to be making changes to the language with regards to oversight," Avelar said. "After talking to stakeholders, it seems that the (Illinois Environmental Protection Agency) is better suited to do the oversight, as opposed to the Illinois Commerce Commission, because the Commerce Commission is looking only at privately-owned utilities." 

Lawmakers also want to make sure that the agencies "are getting the resources that they need… to be able to meet reasonable expectations and accountability for systems that are providing something as fundamental as drinking water," she added.

The negotiations come after municipal water systems in multiple states were struck by cyberattacks this summer, and as analysts warn the summer attacks on local water systems may have tested out a broader strategy by foreign adversaries or criminal hacking groups.

"What happened this summer should be a wake-up call," Avelar said. "But the truth is that we've seen cyber attacks happening even prior to this summer, whether it's been to municipally owned water systems or those that are privately owned."

HB 3576 was written after the University of Illinois at Chicago's Government Finance Research Center released two reports on water rate setting in Northeastern Illinois and across the rest of the state. 

In a section on fund balance requirements and debt in the first report, the report's authors quote a local official talking about the need for separate water system capital improvement plans, with funding set aside for the water system CIP.

That may involve a water rate increase, the official said, but "what this will do is provide security, will provide more of a guarantee that if something crashes, I don't have to do a boil order." 

However, the report notes that some municipal water utilities may lack the ability or willingness to issue bonds. Debt can put upward pressure on rates, and some municipalities choose to maintain artificially low water rates, the report says, even though a rate structure in which capital costs are covered by water rate increases "is supported by industry recommendations."

Avelar said the UIC reports raised questions about "some of the gaps that each municipality faces, as water rates are also tied to capacity, as well as staffing for… water and wastewater operations. 

"So there are gaps when it comes to cybersecurity, because water operators are not necessarily trained on cybersecurity, yet a lot of systems are moving toward automation," she said. "Things such as remote access to computers or automatic billing, to as complex as the chemicals that are used to treat water — those processes have been automated."

In a keynote speech at The Bond Buyer's recent Infrastructure conference, Chicago Department of Water Management Commissioner Randy Conner said remote access makes smaller municipal water systems particularly vulnerable.

"There's never anybody doing anything remote on our system anywhere at any time," he said. "Smaller communities, they don't have the ability to pay for people to work around the clock. So a lot of their access is remote." 

Chicago requires physical presence in the facility and password access to make any changes to the system, all of which is tracked, he said, and Chicago partners with "all of the three-letter government agencies" to test for vulnerabilities.

But as the attacks of this summer demonstrated, smaller municipal utilities are much more stretched, and threat actors know and prey on that.

In Illinois, Avelar said, the federal government's state and local cybersecurity grant program, which is now poised to sunset, has been helpful to local water utilities, and "we don't know whether" those grants will be revived.

"I have serious concerns about the reductions in federal cybersecurity capacity," she said. "Especially because when we talk about (the Cybersecurity and Infrastructure Security Agency), they historically have provided states and local governments with the expertise, the threat intelligence, the vulnerability identification, and much more assistance that many smaller jurisdictions simply cannot do independently."

The state also operates cybersecurity programs that serve state agencies, she said, and those provide some assistance to local governments through initiatives such as the Cyber Navigator program. 

"But we know that we could do a lot more," Avelar said. "That is something I've been in conversations with the IEPA (about), because we do understand that at a bare minimum, we need to set up a program that allows, especially for those very small municipally owned water systems, (for systems) to be able to tap into funding to get at least a cybersecurity audit on their systems."

The Association of Metropolitan Water Agencies did not respond to a request for comment by press time.


For reprint and licensing requests for this article, click here.
Illinois Water bonds Cyber Security
MORE FROM BOND BUYER
Load More