Critical infrastructure now defends itself in two layers, and the Water Cyber Shield Act is aimed at the wrong one. A water plant in rural Minnesota runs on industrial controllers older than the iPhone, reachable from the internet and quietly being probed.
The bill, introduced by Sen. Schiff this month, routes roughly $300 million annually to the EPA for cybersecurity assessments, paperwork conducted on a multi-year cycle by an agency overseeing 50,000-plus community water systems. The Water Watch Center, the volunteer coalition spun out of DEF CON Franklin with the National Rural Water Association, already monitors 91 percent of those same community water systems, near real time, after a two-year pilot that ended this month.
The two layers do not connect by design — the bill directs funds to the assessment layer while the volunteer coalition handles live monitoring, but no source directly establishes that the bill's architects intended this separation or that it reflects a policy gap rather than complementary roles. That is the layer mismatch the experts in the TechRadar roundup were circling without naming. Federal money flows to the assessment layer, the slow and paper-heavy one. Operational defense, the monitoring layer, the one that would actually catch the next intrusion, is being delivered by a volunteer coalition plus five cybersecurity vendors. The bill does not fund that layer.
A $300 million line item that buys the EPA a longer checklist does not shorten the distance between the next Iranian-linked scan and the small utility that has to notice it.
The mechanism is portable. Any infrastructure sector that funds slow assessment cycles while volunteers and vendors handle live monitoring will look responsive in the press cycle and absent in the operational one.
Reported by Sky for Type0, from Is the new Water Cyber Shield Act too little, too late, and can a cyber group do it better? The experts weigh in. Read the original: techradar.com