Several constituents have contacted me with concerns about the security of our drinking water and wastewater systems because of cyberattacks targeting those utilities in other states. Teri Williams Valentine, my legislative director and general counsel, prepared the following memo after looking into Massachusetts’ preparedness.
The state has taken several measures to establish and promote cybersecurity requirements for water and wastewater utilities to prevent cyberattacks. The approach has been regulatory, legislative, and administrative, and has included mandating risk assessments, integrating cybersecurity into emergency planning, ensuring confidential handling of sensitive assessments, funding upgrades, and building a state-level response framework for cyber incidents.
More specifically, the measures include the following:
- The Massachusetts Department of Environmental Protection (MassDEP) Drinking Water Regulations at 310 CMR 22.04(13) require all public water systems (PWS) to include cybersecurity measures in their Emergency Response Plans and as part of routine maintenance. Systems with operational technology are required to perform formal cybersecurity assessments as part of routine operations and sanitary surveys. MassDEP and the MassDEP Drinking Water Program can review those at any time.
- MassDEP has issued advisories regarding threats to water systems, citing incidents abroad and in other states, and provides guidance in best practices.
- Cybersecurity data is treated as confidential. Cyber risk assessments, data, and related documents submitted to MassDEP are not subject to disclosure under the state’s public records law. Additionally, certain review reports and corrective action plans that are made public include only non-sensitive high-level information. These measures help to ensure that sensitive information is not publicly available such that safety and security could be compromised. MassDEP publishes more information about its approach to records access.
- A Clean Water Trust Grant Program to eligible Public Water Suppliers (PWS) to support upgrades to cybersecurity infrastructure. To date, $1.3 million in grants have been awarded to 38 water systems in the state. The program is a partnership between MassDEP and the Massachusetts Clean Water Trust. More information about it is available here.
- Executive Order No. 602, issued by Governor Baker in December 2022, established the Massachusetts Cyber Incident Response Team (MA-CIRT), that is tasked with responding to cyber incidents affecting critical infrastructure, including water utilities.
Bills pending in the current legislative session would codify and expand the MA-CIRT (see S.39, An Act protecting sensitive personal information from breaches and other cybersecurity incidents) and S.49, An Act relative to cybersecurity and artificial intelligence). Though the bills address cyberattacks more broadly, they include water utilities in the definitions of critical infrastructure addressed in the scope of the bills.
Well, we have been getting hit by cyber events right after this post. I can’t help but think if the Beacon Hill Regime weren’t drinking from the same intellectual well as the DSA et al, we’d be in a better place. There’s having a “big tent,” and then there’s getting in bed with the Devil.
The GWOT hasn’t ended, it’s changed. The Axis of Evil hasn’t gone away, it’s pulled up new chairs. We, well we Republicans, may be mopping up and consolidating the gains from our victory in the post WWII Cold war in our hemisphere and beyond it where we have worked so hard to give mutual aid to our our friends who share our civilizational views and heritage, but we’re in the foothills of the next war and the Democrats are working against our survival by endeavoring to hamstring our efforts in “The AI Race,” and by giving aid and comfort to our enemies and adversaries by using their social media manipulations, what Ryan McBeth describes as FIRES, for short-sighted, avaricious and nihilistic political aims.