New Bill Proposed to Combat Cyber-Attacks Against Utilities

Gottheimer’s Securing Our Critical Infrastructure Act, the second major bill in the U.S' proposed new Critical Infrastructure Security Plan, would create a dedicated rapid-response and threat-notification service within CISA for small and medium-sized water and electric utilities. The intent is to give these operators a central federal point of contact when a cyber-attack occurs. The proposal is particularly relevant as municipal water systems in New Jersey and other states have recently been targeted, in some cases forcing operators to manually control pumps and valves after attackers disrupted access to digital systems.

The bill recognizes a major weakness in the nation’s critical infrastructure: smaller and rural utilities often operate with limited cybersecurity staff, aging technology and fewer resources than large utilities, making them attractive targets. Gottheimer is also calling on CISA, the EPA, and FBI to expand immediate incident-response capabilities and develop water-sector-specific cybersecurity guidance and a permanent rapid-response framework. Together, these measures are intended to move utilities from reacting to individual incidents toward having a more structured federal support system before, during and after an attack.

For utility grids, federal rapid-response support should be complemented by continuous, unified visibility across the entire IT/OT environment. Utilities need a centralized data lake, like NIKSUN, that consolidates network, endpoint, identity, cloud, SCADA, PLC, engineering and other operational telemetry into a single visibility fabric. Bringing this data together allows security and operations teams to correlate activity that might otherwise appear harmless when viewed in isolation, identify anomalous behavior and attack paths earlier, and understand whether a compromise is moving from corporate IT into operational technology. Ultimately, this foundation can help utilities detect and prevent attacks before they disrupt critical physical infrastructure. Read more about this story on our LinkedIn page

We use cookies to offer you a better browsing experience and to analyze site traffic. By using our site, you consent to our use of cookies.

Essential Cookies
Site Analytics