AIGovHub
Vendor Tracker
CCM PlatformSentinelProductsPricing
AIGovHub

The AI Compliance & Trust Stack Knowledge Engine. Helping companies become AI Act-ready.

Tools

  • AI Act Checker
  • Questionnaire Generator
  • Vendor Tracker

Resources

  • Blog
  • Guides
  • Best Tools

Company

  • About
  • Pricing
  • How We Evaluate
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Affiliate Disclosure

© 2026 AIGovHub. All rights reserved.

Some links on this site are affiliate links. See our disclosure.

Water Cyberattacks in 12+ US States: CIRCIA Compliance and CISA's Urgent Call to Action
cybersecurity
CISA
CIRCIA
water utilities
critical infrastructure
EPA

Water Cyberattacks in 12+ US States: CIRCIA Compliance and CISA's Urgent Call to Action

AIGovHub EditorialAugust 11, 20260 views

What Happened: A Coordinated Attack on US Water Systems

In late July, a coordinated cyberattack campaign linked to Iranian hackers targeted water and wastewater facilities in at least 12 US states, including New Jersey and Alabama. The attacks focused on industrial control systems (ICS) and operational technology (OT) devices, primarily from Rockwell Automation, a leading provider of automation systems. While no significant disruption to water services has been reported, several systems were shut down as a precautionary measure.

Minnesota confirmed over 30 water systems were targeted, with Michigan, South Dakota, and Georgia also reporting incidents. In New Jersey, the Cape May and Woodbine water systems were hit, though only phone systems were disrupted. Alabama's Childersburg Water, Sewer, and Gas system was also attacked. The FBI confirmed at least seven states were targeted as of July 30, and Wisconsin, Pennsylvania, and Washington have issued warnings without confirming attacks.

CISA has urged the water sector to secure OT systems in response to this campaign, emphasizing the growing threat to critical infrastructure and the need for robust cybersecurity compliance.

Why It Matters: Regulatory Context for Water Utilities

This incident underscores the urgent need for water utilities to comply with existing and emerging cybersecurity regulations. The US regulatory landscape is evolving, and water utilities are increasingly in the crosshairs of both federal and state authorities.

EPA Cybersecurity Rules for Water Systems

The Environmental Protection Agency (EPA) has been actively pushing for stronger cybersecurity measures in the water sector. In 2023, the EPA issued a rule requiring states to certify that public water systems conduct cybersecurity risk assessments and incorporate findings into their emergency response plans. This rule, however, faced legal challenges and was withdrawn, but the agency continues to signal its intent to enforce cybersecurity standards through other means.

Additionally, America's Water Infrastructure Act (AWIA) of 2018 requires community water systems serving over 3,300 people to conduct risk assessments and develop emergency response plans. These requirements are not new, but the recent attacks highlight their critical importance.

CISA and CIRCIA: Incident Reporting Obligations

The Cybersecurity and Infrastructure Security Agency (CISA) plays a central role in coordinating national critical infrastructure security. Under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022, critical infrastructure entities, including water utilities, must report significant cyber incidents to CISA within 72 hours and ransomware payments within 24 hours. However, the final rule implementing CIRCIA has not yet been issued (expected 2025-2026). Until the final rule is effective, mandatory reporting under CIRCIA is not yet enforceable. In the interim, CISA encourages voluntary reporting of incidents to help build situational awareness and coordinate response efforts.

For water utilities, this means that while CIRCIA reporting is not yet mandatory, proactive reporting to CISA is strongly recommended. The recent attack campaign demonstrates the value of timely information sharing to protect the sector.

Compliance Implications: What Water Utilities Must Do Now

The attack serves as a wake-up call for water utilities to assess their cybersecurity posture and ensure compliance with existing regulations. Key compliance areas include:

  • Risk Assessments: Conduct thorough assessments of OT and ICS environments, as required by AWIA and EPA guidelines. Identify vulnerabilities in remote access points, legacy systems, and third-party connections.
  • Incident Response Plans: Develop and test incident response plans that align with CISA's guidance and incorporate lessons learned from the recent attacks. Ensure plans cover OT-specific scenarios, including manual operations if systems are shut down.
  • Reporting Timelines: Familiarize yourself with CIRCIA's proposed reporting timelines (72 hours for incidents, 24 hours for ransomware payments) and establish internal processes to meet them once the rule is final. In the meantime, report incidents voluntarily to CISA.
  • Supply Chain Security: Review the security of OT vendors, such as Rockwell Automation, and ensure that their products are configured securely and monitored for anomalies.
  • Staff Training: Train staff to recognize phishing attempts and other common attack vectors that may have been used to gain initial access.

Potential Penalties for Non-Compliance

While CIRCIA penalties are not yet finalized, non-compliance with existing regulations can have serious consequences. EPA enforcement actions can result in fines and administrative orders. For example, the EPA has previously issued administrative orders against water systems for failure to comply with AWIA requirements. Additionally, under state laws, water utilities may face penalties for inadequate cybersecurity measures that lead to service disruptions or data breaches.

Moreover, the reputational damage and potential liability from a successful attack can be far more costly than any regulatory fine.

Actionable Steps for Water Utilities

  1. Conduct a Cybersecurity Gap Analysis: Compare your current practices against AWIA requirements and CISA's recommended safeguards.
  2. Segment OT Networks: Isolate OT systems from IT networks to limit the blast radius of an attack.
  3. Implement Continuous Monitoring: Deploy tools that monitor OT environments for unusual activity, such as unauthorized access or changes to control logic.
  4. Engage with CISA: Participate in CISA's free services, such as vulnerability scanning and incident response support. Report incidents voluntarily to help protect the sector.
  5. Leverage Threat Intelligence: Use geopolitical risk monitoring platforms to stay ahead of state-sponsored threats. For example, AIGovHub SENTINEL provides real-time threat monitoring across 435+ sources, including CISA advisories, and can help water utilities anticipate and respond to emerging cyber threats.

Conclusion

The recent water cyberattacks are a stark reminder that critical infrastructure remains a prime target for state-sponsored actors. While CIRCIA reporting is not yet mandatory, water utilities must take proactive steps to secure OT systems and comply with existing regulations. By conducting risk assessments, developing robust incident response plans, and leveraging threat intelligence, utilities can strengthen their resilience against future attacks.

For organizations seeking to enhance their cybersecurity posture, consider integrating geopolitical risk monitoring into your compliance strategy. AIGovHub SENTINEL offers AI-driven threat intelligence that can help you detect and respond to risks before they impact your operations.

This content is for informational purposes only and does not constitute legal advice.