Cybersecurity for water and wastewater utilities

The state has taken several measures to establish and promote cybersecurity requirements for water and wastewater utilities to prevent cyberattacks. The approach has been regulatory, legislative, and administrative, and has included mandating risk assessments, integrating cybersecurity into emergency planning, ensuring confidential handling of sensitive assessments, funding upgrades, and building a state-level response framework for cyber incidents.

More specifically, the measures include the following:  

  • The Massachusetts Department of Environmental Protection (MassDEP) Drinking Water Regulations at 310 CMR 22.04(13) require all public water systems (PWS) to include cybersecurity measures in their Emergency Response Plans and as part of routine maintenance. Systems with operational technology are required to perform formal cybersecurity assessments as part of routine operations and sanitary surveys. MassDEP and the MassDEP Drinking Water Program can review those at any time.
  • MassDEP has issued advisories regarding threats to water systems, citing incidents abroad and in other states, and provides guidance in best practices.
  • Cybersecurity data is treated as confidential. Cyber risk assessments, data, and related documents submitted to MassDEP are not subject to disclosure under the state’s public records law. Additionally, certain review reports and corrective action plans that are made public include only non-sensitive high-level information. These measures help to ensure that sensitive information is not publicly available such that safety and security could be compromised. MassDEP publishes more information about its approach to records access.

Published by Will Brownsberger

Will Brownsberger is State Senator from the Second Suffolk and Middlesex District.

Leave a comment

Your email address will not be published. Required fields are marked *