“Strengthening cybersecurity for the U.S. water sector is critically important because cyber resilience and water security are key to national security,” said EPA Assistant Administrator for Water Jess Kramer. “Water systems across the country are facing cyberattacks that threaten the ability to provide safe water.”
The release advances the Powering the Great American Comeback Initiative, a federal effort to modernize critical infrastructure and safeguard public health.
The EPA’s new and updated materials include:
Together, the tools aim to help utilities maintain compliance with the America’s Water Infrastructure Act (AWIA) while addressing evolving threats to both operational technology (OT) and information technology (IT) systems.
According to the newly published Wastewater Emergency Response Plan Template and Instructions (EPA 817-B-25-001), cybersecurity preparedness is now a required component of every utility’s ERP. The guide outlines four core sections:
The appendix offers “Practical Mitigation Options for Utilities,” encouraging utilities to join WARN mutual-aid networks, enroll in CISA’s free vulnerability scanning, and incorporate flood and power-resilience upgrades. The EPA also links these plans to FEMA’s Public Assistance Program and Fed FUNDS to ensure eligible cost reimbursement.
Cyberattacks on water systems have surged in recent years, disrupting operations and threatening public health. EPA data show that smaller utilities are often the most vulnerable, lacking in-house IT support or cybersecurity staff.
By embedding cybersecurity within emergency management, the agency is signaling that digital resilience is now fundamental to clean water access. Through coordinated action with the Cybersecurity and Infrastructure Security Agency (CISA), state programs, and local water associations, the EPA aims to help utilities build systems that can withstand both the next storm and the next cyberattack.