OTSecurity

US water systems face persistent cybersecurity gaps as July attacks renew scrutiny of federal protections, CRS says


A new report from the U.S. Congressional Research Service revealed that the cyberattacks reported against water systems in at least seven U.S. states in July 2026 have renewed scrutiny of cybersecurity protections for the nation’s municipal water infrastructure. Nearly 144,000 privately and publicly owned public water systems are regulated under the Safe Drinking Water Act, including about 49,500 community water systems serving more than 324 million people. While federal cybersecurity requirements largely focus on larger drinking-water systems, smaller systems face fewer mandatory requirements despite making up 81% of community water systems. 

In its report titled ‘July 2026 Water System Cyber Incidents: Considerations for Congress,’ the CRS said compliance remains a significant concern even among systems subject to mandatory cybersecurity requirements. More than 70% of water systems inspected by the Environmental Protection Agency since September 2023 were found in violation of basic requirements for risk-and-resilience assessments and emergency response plans, according to a 2024 EPA enforcement notice. 

The EPA conducted at least 100 enforcement actions over such violations between 2020 and 2024. Separately, an EPA Inspector General assessment of 1,062 water systems serving at least 50,000 people identified 97 systems with critical or high-risk cybersecurity vulnerabilities, affecting about 26.6 million users. 

“Federal efforts to address the cybersecurity of the water sector have primarily focused on drinking water systems rather than wastewater systems,” Elena H. Humphreys, specialist in environmental policy, wrote in the CRS report. “Authorized through the Safe Drinking Water Act (SDWA), these federal efforts have generally involved specific vulnerability assessment requirements for larger drinking water systems and technical and financial assistance for smaller systems. This In Focus discusses EPA efforts under SDWA to address cybersecurity. It does not include information on Cybersecurity and Infrastructure Security Agency (CISA) authorities or EPA’s SRMA role.”

Reported cyberattacks on water systems have raised questions about the sector’s approach to cybersecurity. SDWA Section 1433 requirements are targeted to systems serving a larger number of individuals because, if disrupted, the public health impact would be larger. Also, these larger systems benefit from economies of scale, resulting in greater capacity to update technology, adopt practices, or hire security specialists. SDWA assessments and plans are voluntary for smaller systems. “Some have raised concerns about SDWA Section 1433 compliance and the quality of larger systems’ vulnerability assessments and emergency response plans,” according to Humphreys. “A 2024 EPA enforcement notice indicated that larger systems were experiencing compliance challenges, stating that more than ‘70% of systems inspected by EPA since September 2023 are in violation of basic SDWA Section 1433 requirements.’ Between 2020 and 2024, EPA conducted at least 100 enforcement actions due to violations of SDWA Section 1433.” 

Also in 2024, EPA’s Office of Inspector General (OIG) conducted a cybersecurity assessment of 1,062 water systems that serve 50,000 or more individuals. Of the 1,062 systems, OIG ‘identified 97 … water systems serving approximately 26.6 million users as having either critical or high-risk cybersecurity vulnerabilities.’

This comes as others have questioned the EPA’s use of its SDWA authorities to address cybersecurity. “For example, in March 2023, EPA issued an interpretive memorandum to require states, as a part of their SDWA primary enforcement responsibilities, to evaluate water system operational technology cybersecurity during triennial inspections, called ‘sanitary surveys.’ Sanitary surveys are onsite inspections of a water system’s components (e.g., treatment technologies) and operational functions. Stakeholders filed a petition for judicial review, arguing that EPA did not follow the Administrative Procedure Act when issuing the memorandum and that EPA’s expansion of the sanitary survey exceeded its statutory authority under SDWA. In October 2023, EPA rescinded the interpretive memorandum and its requirements.”

In the 119th Congress, some Members have introduced legislation regarding water sector cybersecurity. The Water Resources Development Act of 2026 (S. 4949), for example, includes several cybersecurity provisions. S. 4949 would reauthorize appropriations for SDWA Section 1459F, revise an existing SDWA small and disadvantaged communities grant program to make ‘reducing cybersecurity vulnerabilities’ an eligible funding activity, and amend an existing water infrastructure workforce grant program to include support for cybersecurity training. 

Additionally, it would authorize a wastewater cybersecurity grant program and a digital infrastructure grant program. The legislation also directs EPA to establish, subject to appropriations, a program to support participation in the Water Information Sharing and Analysis Center (WaterISAC) and to report on water sector cybersecurity within three years of enactment.

Other bills focus on water sector cybersecurity and use different approaches. Some bills authorize new grant programs, such as H.R. 2109/S. 1018, H.R. 9776/S. 3967, and H.R. 2344/S. 1118, while others reauthorize appropriations for existing authorities, including H.R. 10083 and S. 1549. 

Additional legislation reauthorizes appropriations for SDWA Section 1442(b) and authorizes a wastewater grant program, exemplified by H.R. 9690/S. 4980. Some bills revise SDWA Section 1433 vulnerability assessment requirements for water systems, expand oversight of water system vulnerability assessments, and add similar wastewater requirements, such as S. 5368. Other proposals establish a new framework to require systems to adopt cybersecurity standards developed and enforced by an independent organization. 

Humphreys calls upon Congress members to consider several issues regarding water sector cybersecurity. “In the 119th Congress, several bills propose to add cybersecurity grant programs for specific types of systems (e.g., rural) or to reauthorize appropriations for existing TA and/or grant programs. One consideration is whether new programs would be additive to or duplicative of existing ones. Another is whether existing programs are receiving appropriations.” 

She highlighted that Congress has not specified appropriations for cybersecurity TA and grants under SDWA Section 1433(g) or the advanced technology grants under SDWA Section 1459G. Congress has provided appropriations for SDWA Section 1442(b) emergency assistance to address the Jackson, MS, water crisis and damage from Hurricanes Helene and Milton. 

Additionally, Congress began funding resiliency grants for larger systems under SDWA Section 1459F in FY2023. Other considerations may involve revising SDWA Section 1433 risk-and-resilience assessments and emergency response planning to include specific standards. In prior Congresses, some bills (e.g., H.R. 3258 in the 111th Congress) proposed a similar approach but were not enacted. Considerations for this approach could include how these standards would affect systems that face challenges in meeting the existing requirements. Another potential consideration involves EPA’s or a state’s ability to develop or oversee standards, as some have questioned whether water system expertise extends to cybersecurity expertise. 

Humphreys wrote that another consideration relates to the risks of sharing water systems’ vulnerability information with entities tasked with overseeing or supporting cybersecurity. “Proposals to require water systems to transmit vulnerability assessments to EPA, states, or an independent organization to check compliance with certain standards may risk creating a repository of water system vulnerabilities that could be targeted for a cyberattack. Similarly, ensuring the cybersecurity of third-party entities that provide TA to specific water systems may be another consideration for proposals to expand TA.” 

Moreover, policymakers are considering a proposal to establish an independent organization to set cybersecurity standards for adoption by water systems. Several water associations support this approach. 

“Under this proposal, EPA would retain oversight of the standard-setting organization, similarly to how the Federal Energy Regulatory Commission (FERC) oversees cybersecurity standards developed by the North American Electric Reliability Corporation (NERC) in the electricity sector,” Humphreys detailed. “Policymakers assessing this approach may consider the differences between the electricity and water sectors, such as interconnectedness. Local electricity distribution systems connect to a larger transmission network, so an attack on transmission could affect several states. NERC standards apply to the interconnected network.” 

She observed that water systems generally are not interconnected, so any disruption from an attack would be limited to a community rather than affecting water service in several states. Although water systems are not interconnected at the state level, an attack (e.g., water contamination) could still be significant, as some systems serve millions of people.



Source link