top of page

A Wake Up Call for OT Security : OTCC Statement on Critical Infrastructure Cybersecurity and the Need for Congressional Action

  • 2 hours ago
  • 3 min read

Following reports of cyberattacks on water and wastewater systems across at least seven states, including a significant incident affecting more than 30 water systems in Minnesota, OTCC Executive Director Tatyana Bolton issued the following statement calling on CISA and Congress to take immediate action to protect the nation's critical infrastructure.

This week we are facing a reckoning of the consequences of ignoring the importance of investing in our nation’s cybersecurity for our critical infrastructure. As of July 30, the FBI is aware of at least seven states where water and wastewater entities reported a cyber incident, some of which degraded water facilities. The worst impact, for now, appears to be in Minnesota where alleged Iranian-affiliated state actors targeted over 30 water systems. We must view this through a clear lens: an adversary has directly impacted a core American necessity. 


While we fully support CISA, ONCD, and the FBI actions on critical infrastructure security including alerts and advice for utilities, we must move from simple bulletins to action. As a coalition of the leading operational technology (OT) cybersecurity organizations and owners and operators, we believe the U.S. Government must take tangible and immediate action to enhance the security and resilience of our critical infrastructure. 


Most critically, CISA must issue a Binding Operational Directive (BOD) on OT security.


The Federal Civilian Executive Branch (FCEB) relies on more than 8,000 managed-owned and leased facilities, as well as thousands of agency-managed laboratories, hospitals, research campuses, warehouses, ports of entry, and other specialized facilities. The OT that supports these environments, including HVAC, power management, access control, building automation, and water systems, is essential to maintaining federal mission continuity. 


CISA should issue a BOD focused on OT security that places fundamental cybersecurity controls across these systems. This is not a novel or unimplementable idea. In 2024, the National Security Agency recognized the importance of OT security to National Security Systems and issued a BOD to require security, reporting, and inventory requirements. To be sure, an OT BOD only applies to FCEB entities, and the water utilities in Minnesota would not have been required to implement the requirements detailed in the BOD. However, BODs send strong and important demand signals to the private sector while ensuring the US government takes every step to secure its own networks. 


But an OT BOD for government-owned networks isn’t sufficient to address the urgency of this moment. We call on Congress to take these three critical actions:


  1. Congress needs to reauthorize and fund the State and Local Cybersecurity Grant Program. All incidents are local. State and local governments and local critical infrastructure entities like Minnesota’s are the first line of defense against malicious cyber actors. And by not extending this grant program, Congress is leaving small towns to protect themselves from nation state actors like Iran.  This cannot happen. This grant program is essential to secure the industrial control systems that underpin essential services such as water, energy, transportation, and public safety. This program will also help drive forward the President’s recently released National Resilience Strategy, which seeks to enhance state and local entities’ resilience.

  2. Congress must support Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER). While the Environmental Protection Agency is the Sector Risk Management Agency for the water sector, the energy sector is imperative to the functioning of all 16 critical infrastructure sectors. CESER leads efforts to strengthen the cybersecurity and resilience of the nation's energy sector, including protecting OT systems that underpin the electric grid and other critical energy infrastructure. Supporting Andrew McClure will ensure there is dedicated leadership and attention to enhancing the security and resilience of the energy sector. 

  3. Congress must pass long-term authority for the Cybersecurity Information Sharing Act of 2015 (CISA 2015). This authority is imperative for CISA to receive technical evidence and specific cybersecurity information from private sector partners. This information allows the U.S. government to identify widespread, large scale cyber campaigns and trends across sectors. It also enables CISA and the FBI to warn other potential victims before they are potentially impacted. With this authority expiring at the end of September, we risk severely undermining our nation’s cybersecurity. We can no longer keep doing minor extensions of CISA 2015. We must have long-term authority to keep CISA 2015 operational to further enable the foundation of public-private partnership that allows us to operationalize actionable, timely, and relevant information. 


These are the core, fundamental steps we must take to secure our critical infrastructure. Despite years of guidance, increasing convergence between IT and OT, and repeated warnings that Chinese and Iranian actors have pre-positioned themselves inside critical infrastructure, the US government has not done enough to take action. To date, we have been lucky that a more catastrophic incident hasn’t occurred. We can no longer rely on luck. We must act. 


Tatyana Bolton

Executive Director

Operational Technology Cybersecurity Coalition



Interested in joining the OTCC?

We welcome organizations committed to advancing OT cybersecurity through collaboration and shared expertise. If you’re interested in becoming a member, please visit the Join the OTCC page. If you have any further questions, please reach out to info@otcybercoalition.org.

bottom of page