HB3576 would amend the Illinois Public Utilities Act to impose cybersecurity requirements on certain water purveyors, defined as owners of public community water systems with more than 500 service connections. The bill requires each covered water purveyor to develop a cybersecurity program within 120 days of the effective date, including assigned responsibility for cyber risk management, risk assessments, incident response and recovery planning, and ongoing monitoring of threats and vulnerabilities. It also requires incident reporting procedures, cybersecurity insurance, and alignment with recognized cybersecurity frameworks such as NIST, CIS Controls, or ISO/IEC 27000 standards.
The bill further requires annual compliance certifications and detailed annual status reports to the Illinois Commerce Commission, with additional reporting to the Department of Natural Resources and the Commission. Water purveyors must report significant cybersecurity incidents within 48 hours, and the Commission must order audits after failures to comply or after reported incidents. The bill also authorizes rulemaking by the Department and the Commission, establishes civil penalties for violations, and limits public disclosure of submitted reports unless otherwise ordered.
Impact
HB3576 would add a new Section 4-102 to the Public Utilities Act and modify Section 4-101 so that water public utilities’ security policies must also satisfy the new cybersecurity requirements. It would create a regulatory framework for cybersecurity governance, insurance, incident reporting, audits, and annual compliance reporting for larger public community water systems, while giving the Department of Natural Resources and the Illinois Commerce Commission authority to implement rules and penalties. The bill primarily affects water utilities, their management and cybersecurity staff, and state regulators overseeing utility security and compliance.
Sentiment
The available record shows no committee transcript and no recorded votes, so there is no direct evidence of debate or opposition in the materials provided. Based on the bill text and caption, the measure appears to be framed as a proactive utility-security bill aimed at protecting critical water infrastructure from cyber threats. The overall tone of the proposal is regulatory and preventive rather than controversial on its face.
Contention
The main potential points of contention are the compliance burden and cost imposed on water purveyors, especially the requirements to purchase cybersecurity insurance, hire independent auditors at the utility’s expense, and repeatedly update programs to match evolving frameworks. Smaller or resource-constrained utilities may be concerned about implementation timelines, reporting obligations, and the scope of required controls. Another possible issue is confidentiality, since the bill makes reports generally nonpublic, which may raise questions about transparency versus security.