EPA Warns Water Utilities Against Cyberattacks
American Bar Association – Business Law Today, November 7, 2025

The U.S. Environmental Protection Agency (EPA) published a report in July 2025 outlining a set of non‑regulatory recommendations to strengthen the cybersecurity of drinking water and wastewater systems and increase resilience against cyberattacks. While the report itself is advisory, it arrives amid stepped‑up inspections and enforcement under the Safe Drinking Water Act (SDWA) section 1433, which now includes risk‑and‑resilience obligations related to cybersecurity. Utilities, vendors, investors, and acquirers are encouraged to treat the recommendations as a new baseline for diligence, budgeting, and compliance planning.

The July 2025 report, Securing the Future of Water: Addressing Cyber Threats Today, emphasizes a “holistic” approach and tighter coordination among utilities, state authorities, federal partners, and sector associations. In connection with the report, the EPA has also made grant funding available, including approximately $9 million for midsize and large public water systems under the Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability program.

In addition to advisory guidance, the EPA’s May 2024 Enforcement Alert, updated in July 2025, notes that more than 70 percent of inspected systems since September 2023 failed to meet basic SDWA section 1433 requirements, such as complete Risk and Resilience Assessments (RRAs) and Emergency Response Plans (ERPs). The agency has warned of increased inspections and possible use of its emergency powers under SDWA section 1431, as well as potential civil or criminal enforcement actions for false certifications.

The EPA report outlines ten core recommendations for water utilities and their partners to consider. These include assigning clear executive responsibility for cybersecurity, fostering cross‑entity coordination forums, communicating security priorities to leadership, normalizing essential security controls, embedding cybersecurity into training and continuing education, securing dedicated funding and WaterISAC participation, sharing best practices, elevating vendor and consultant expectations, supporting state partners, and engaging resourced sector partners.

Although the EPA’s report does not have the force of regulation, inspectors are already examining cybersecurity elements in RRAs and ERPs under SDWA section 1433. Common gaps identified by inspections include failure to change default passwords, use of shared logins, and lack of comprehensive asset inventories. Where risk rises to the level of “imminent endangerment,” the EPA may invoke emergency powers under section 1431.

Furthermore, aligning cybersecurity projects with the priority actions identified in the report may strengthen applications for future EPA grant funding and improve diligence outcomes in transactions involving utilities. Over the next 90 to 180 days, key near‑term actions for water systems include naming an accountable executive for cyber risk, validating SDWA section 1433 status and addressing RRA/ERP gaps, enforcing essential security controls such as multifactor authentication and backups, enhancing training and incident readiness, updating vendor contracts with baseline cybersecurity requirements, scheduling third‑party assessments, and coordinating with state agencies.