A recent government watchdog report reveals that the Environmental Protection Agency (EPA) is significantly lagging in fulfilling its role as the federal authority responsible for bolstering the cybersecurity of the water and wastewater sector, especially amid a surge in state-sponsored cyberattacks.
According to the Government Accountability Office (GAO), the EPA is in urgent need of a cohesive national strategy to tackle various cybersecurity threats facing the sector. The GAO highlights that the water sector struggles to establish a robust cybersecurity culture, leading to insufficient cyber hygiene practices exacerbated by limited resources and rising infrastructure costs.
Recent years have seen the water sector confronting severe cyber threats: Iranian-linked hackers defaced equipment at a Pennsylvania facility, Chinese state-sponsored actors known as Volt Typhoon infiltrated U.S. water systems, and a Russian nationalist hacktivist group breached Texas water facilities. Although the Biden administration has prioritized water sector cybersecurity, there has been strong resistance from the sector against enhanced regulatory measures.
The GAO points out that the EPA has yet to perform a comprehensive risk assessment for the sector and lacks a risk-informed strategy to guide its efforts. Without such an assessment, the EPA’s decisions to mitigate cyber risks are undermined by a lack of foundational risk management principles.
The report also indicates that while EPA officials have evaluated threats and vulnerabilities, this work has not been integrated into a thorough sector-wide assessment. The absence of a national strategy hampers the EPA’s ability to address the most significant risks effectively.
EPA officials noted that while they support risk assessments for community water systems, these are only applicable to systems serving more than 3,300 people, and the anonymization of data limits its usefulness for broader national assessments.
Furthermore, the GAO criticizes the EPA for not clearly defining cybersecurity goals, objectives, or performance metrics. Although the EPA aims for full cybersecurity coverage for certain technologies, it lacks specific plans and milestones to achieve this objective. The EPA’s general compliance goals do not adequately address specific cybersecurity needs.
The report also highlights a lack of defined roles and coordination within the sector. The Cybersecurity and Infrastructure Security Agency (CISA) has yet to collaborate effectively with the EPA, and past reports suggest a disconnect between EPA’s water expertise and CISA’s cybersecurity knowledge.
The EPA has faced challenges with its cyber reporting requirements, as many water systems are exempt due to their local or state governance structures. Additionally, the EPA’s vulnerability assessment tool for drinking water systems has not undergone peer review, despite guidance suggesting that such reviews are crucial for ensuring credibility.
In response to the GAO’s recommendations, the EPA has agreed to conduct a sector-wide risk assessment, develop a national strategy, and review its legal authorities. The agency aims to complete the risk assessment by January 2025 and initiate a peer review of its risk assessment tool in November. The White House has also directed agencies to reassess their authorities and budget needs for critical infrastructure protection.
The EPA’s attempts to enforce cybersecurity measures have encountered resistance, as evidenced by the withdrawal of a memo proposing mandatory cybersecurity audits for water utilities. Additionally, the sector’s reluctance to provide voluntary baseline data has hampered the development of cybersecurity performance metrics.
The EPA did not provide a comment on the report by the publication deadline. This is not the first critique of the EPA’s cybersecurity efforts; a 2022 Foundation for the Defense of Democracies report similarly criticized the agency’s performance. Industry experts and trade associations have suggested adopting an industry-led regulatory approach, similar to the electric sector, and recommended a substantial increase in cybersecurity funding. However, the EPA’s budget for risk management and cybersecurity in fiscal year 2023 was $11.8 million, far short of the $45 million suggested by the Cyberspace Solarium Commission in 2020.



