EPA Expands Cybersecurity Tools for Water Systems

Posted

The U.S. Environmental Protection Agency (EPA) has released a new suite of planning tools to help public water and wastewater systems strengthen cybersecurity defenses and emergency preparedness. 

“Strengthening cybersecurity for the U.S. water sector is critically important because cyber resilience and water security are key to national security,” said EPA Assistant Administrator for Water Jess Kramer. “Water systems across the country are facing cyberattacks that threaten the ability to provide safe water.”

The release advances the Powering the Great American Comeback Initiative, a federal effort to modernize critical infrastructure and safeguard public health.

New Tools for a Changing Threat Landscape

The EPA’s new and updated materials include:

  • Emergency Response Plan (ERP) Guide for Wastewater Utilities, which updates strategies for responding to natural or man-made incidents that threaten life, property, or the environment.
  • Cybersecurity Incident Response Plan Template, providing a step-by-step framework for isolating breached systems, restoring operations, and coordinating with law enforcement and regulators.
  • Incident Action Checklists, designed to help utilities quickly respond to wildfires, floods, power outages, and cyber events.
  • Cybersecurity Procurement Checklist, enabling utilities to assess the security practices of vendors and suppliers during procurement.

Together, the tools aim to help utilities maintain compliance with the America’s Water Infrastructure Act (AWIA) while addressing evolving threats to both operational technology (OT) and information technology (IT) systems.

EPA’s 2025 Wastewater ERP Template Adds Cyber Focus

According to the newly published Wastewater Emergency Response Plan Template and Instructions (EPA 817-B-25-001), cybersecurity preparedness is now a required component of every utility’s ERP. The guide outlines four core sections:

  1. Resilience Strategies – detailing incident-command roles, communications, and cybersecurity procedures.
  2. Emergency Plans and Procedures – integrating core and incident-specific response steps for floods, earthquakes, and cyberattacks.
  3. Mitigation Actions – including a 15-point Cybersecurity Mitigation Checklist covering password management, multi-factor authentication, asset inventory, and regular system backups.
  4. Detection Strategies – recommending intrusion monitoring, SCADA alerts, and partnerships with local emergency management agencies.

The appendix offers “Practical Mitigation Options for Utilities,” encouraging utilities to join WARN mutual-aid networks, enroll in CISA’s free vulnerability scanning, and incorporate flood and power-resilience upgrades. The EPA also links these plans to FEMA’s Public Assistance Program and Fed FUNDS to ensure eligible cost reimbursement.

Faster Recovery, Stronger Infrastructure

Cyberattacks on water systems have surged in recent years, disrupting operations and threatening public health. EPA data show that smaller utilities are often the most vulnerable, lacking in-house IT support or cybersecurity staff.

By embedding cybersecurity within emergency management, the agency is signaling that digital resilience is now fundamental to clean water access. Through coordinated action with the Cybersecurity and Infrastructure Security Agency (CISA), state programs, and local water associations, the EPA aims to help utilities build systems that can withstand both the next storm and the next cyberattack.

Environment + Energy Leader