{"id":3660,"date":"2024-05-20T17:33:39","date_gmt":"2024-05-20T22:33:39","guid":{"rendered":"https:\/\/cyberscoop.com\/?p=80475"},"modified":"2024-05-20T17:33:39","modified_gmt":"2024-05-20T22:33:39","slug":"epa-will-step-up-inspections-of-water-sector-cybersecurity","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/20\/epa-will-step-up-inspections-of-water-sector-cybersecurity\/","title":{"rendered":"EPA will step up inspections of water sector cybersecurity"},"content":{"rendered":"<p><head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <meta name=\"robots\" content=\"index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1\"> <!-- This site is optimized with the Yoast SEO Premium plugin v21.7 (Yoast SEO v21.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ --> <title>EPA will step up inspections of water sector cybersecurity | CyberScoop<\/title> <meta name=\"description\" content=\"A new enforcement alert said that the majority of inspected water systems do not fully comply with federal requirements.\"> <link rel=\"canonical\" href=\"https:\/\/cyberscoop.com\/epa-water-inspections-cyber-alert\/\"> <meta property=\"og:locale\" content=\"en_US\"> <meta property=\"og:type\" content=\"article\"> <meta property=\"og:title\" content=\"EPA will step up inspections of water sector cybersecurity\"> <meta property=\"og:description\" content=\"A new enforcement alert said that the majority of inspected water systems do not fully comply with federal requirements.\"> <meta property=\"og:url\" content=\"https:\/\/cyberscoop.com\/epa-water-inspections-cyber-alert\/\"> <meta property=\"og:site_name\" content=\"CyberScoop\"> <meta property=\"article:published_time\" content=\"2024-05-20T22:33:39+00:00\"> <meta property=\"article:modified_time\" content=\"2024-05-20T22:33:40+00:00\"> <meta property=\"og:image\" content=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity-2.jpg\"> <meta property=\"og:image:width\" content=\"1920\"> <meta property=\"og:image:height\" content=\"1280\"> <meta property=\"og:image:type\" content=\"image\/jpeg\"> <meta name=\"author\" content=\"Christian Vasquez\"> <meta name=\"twitter:card\" content=\"summary_large_image\"> <meta name=\"twitter:creator\" content=\"@chrismvasq\"> <!-- \/ Yoast SEO Premium plugin. --> <link rel=\"dns-prefetch\" href=\"\/\/securepubads.g.doubleclick.net\">\n<link rel=\"dns-prefetch\" href=\"\/\/use.typekit.net\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Feed\" href=\"https:\/\/cyberscoop.com\/feed\/\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Comments Feed\" href=\"https:\/\/cyberscoop.com\/comments\/feed\/\"> <link rel=\"stylesheet\" id=\"all-css-2\" href=\"https:\/\/cyberscoop.com\/wp-includes\/css\/dist\/block-library\/style.min.css?m=1715117951g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-6\" href=\"https:\/\/cyberscoop.com\/wp-content\/mu-plugins\/search\/elasticpress\/dist\/css\/related-posts-block-styles.min.css?m=1715187471g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-8\" href=\"https:\/\/cyberscoop.com\/wp-content\/themes\/scoopnewsgroup\/dist\/css\/frontend.css?m=1715961501g\" type=\"text\/css\" media=\"all\">\n<link rel=\"stylesheet\" id=\"typekit-css\" href=\"https:\/\/use.typekit.net\/itk2qbh.css?ver=74528d75ce0daeb8628a\" media=\"all\"> <link rel=\"https:\/\/api.w.org\/\" href=\"https:\/\/cyberscoop.com\/wp-json\/\"><link rel=\"alternate\" type=\"application\/json\" href=\"https:\/\/cyberscoop.com\/wp-json\/wp\/v2\/posts\/80475\"><link rel=\"EditURI\" type=\"application\/rsd+xml\" title=\"RSD\" href=\"https:\/\/cyberscoop.com\/xmlrpc.php?rsd\">\n<meta name=\"generator\" content=\"WordPress 6.5.3\">\n<link rel=\"shortlink\" href=\"https:\/\/cyberscoop.com\/?p=80475\">\n<link rel=\"alternate\" type=\"application\/json+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fepa-water-inspections-cyber-alert%2F\">\n<link rel=\"alternate\" type=\"text\/xml+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fepa-water-inspections-cyber-alert%2F&amp;format=xml\"> <!-- Google Tag Manager --> <!-- End Google Tag Manager --> <link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=32\" sizes=\"32x32\">\n<link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=192\" sizes=\"192x192\">\n<link rel=\"apple-touch-icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=180\">\n<meta name=\"msapplication-TileImage\" content=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=270\"> <\/head><body class=\"post-template-default single single-post postid-80475 single-format-standard\" id=\"readabilityBody\"> <a href=\"https:\/\/cyberscoop.com\/epa-water-inspections-cyber-alert\/#main\" class=\"skip-to-content-link visually-hidden-focusable\">Skip to main content<\/a> <\/p>\n<div class=\"ad ad--top ad--top-desktop\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p> <main id=\"main\" role=\"main\" tabindex=\"-1\"> <\/p>\n<div class=\"ad ad--top ad--top-mobile\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<section id=\"stickybar\" class=\"stickybar stickybar--newsletter js-stickybar\" readability=\"0.82\"> <button class=\"stickybar__close js-stickybar-close\" aria-controls=\"stickybar\"> <svg class=\"icon icon--close\" width=\"21\" height=\"22\" viewBox=\"0 0 21 22\" fill=\"none\"><path d=\"m.822.518-.805.805L9.695 11 .017 20.678l.805.805 9.678-9.678 9.677 9.678.806-.805L11.305 11l9.678-9.677-.806-.805-9.677 9.677L.822.518Z\" fill=\"currentColor\" \/><\/svg> <span class=\"visually-hidden\">Close<\/span> <\/button> <\/section>\n<article class=\"single-article content\">\n<div class=\"single-article__container js-single-article-content\">\n<header class=\"single-article__header \" readability=\"24.176948051948\">\n<div class=\"single-article__header-content\" readability=\"29.022321428571\">\n<ul class=\"single-article__eyebrow\">\n<li class=\"single-article__category\"> <a class=\"single-article__category-link\" href=\"https:\/\/cyberscoop.com\/news\/government\/\"> <span>Government<\/span> <\/a> <\/li>\n<\/ul>\n<p> A new enforcement alert said that the majority of inspected water systems do not fully comply with federal requirements. <\/p>\n<\/p><\/div>\n<div class=\"single-article__cover-wrap\">\n<figure class=\"single-article__cover\"> <img data-recalc-dims=\"1\" fetchpriority=\"high\" width=\"640\" height=\"426\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity.jpg?resize=640%2C426&#038;ssl=1\" class=\"single-article__cover-image wp-post-image\" alt decoding=\"async\" fetchpriority=\"high\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity-2.jpg 1920w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity-2.jpg?resize=300,200 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity-2.jpg?resize=768,512 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity-2.jpg?resize=1024,683 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity-2.jpg?resize=1536,1024 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity-2.jpg?resize=600,400 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity-2.jpg?resize=252,168 252w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity-2.jpg?resize=506,337 506w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity-2.jpg?resize=1013,675 1013w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity-2.jpg?resize=1265,843 1265w\" sizes=\"(max-width: 1013px) 100vw, 1013px\"><figcaption> A pipe carrying potable water is seen in a water purification plant. (Getty Images) <\/figcaption><\/figure>\n<\/p><\/div>\n<\/header>\n<div class=\"single-article__content\">\n<div class=\"single-article__content-inner has-drop-cap\"> <html readability=\"38.710526315789\"><body readability=\"79.328990228013\"><\/p>\n<p>The Environmental Protection Agency issued an alert Monday warning the nation\u2019s water utilities that as cybersecurity threats continue to rise the agency will also increase its security-focused inspections and enforcement activities.<\/p>\n<p>The EPA said in a <a href=\"https:\/\/www.epa.gov\/newsreleases\/epa-outlines-enforcement-measures-help-prevent-cybersecurity-attacks-and-protect\">statement<\/a> that the agency has found that more than 70% of inspected water systems do not fully comply with certain security requirements in the Safe Drinking Water Act (SDWA). Some of the water systems are missing basic cybersecurity practices, the agency said, such as not relying on default passwords and not using multi-factor authentication.<\/p>\n<p>The EPA said that attacks on the water sector \u201chave increased in frequency and severity to a point where additional action is critical.\u201d<\/p>\n<p>\u201cProtecting our nation\u2019s drinking water is a cornerstone of EPA\u2019s mission, and we are committed to using every tool, including our enforcement authorities, to ensure that our nation\u2019s drinking water is protected from cyberattacks,\u201d EPA Deputy Administrator Janet McCabe said in the statement. \u201cEPA\u2019s new enforcement alert is the latest step that the Biden-Harris Administration is taking to ensure communities understand the urgency and severity of cyberattacks and water systems are ready to address these serious threats to our nation\u2019s public health.\u201d<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>A series of incidents over the past year has shown just how vulnerable water systems in the United States are to malicious hackers. In April, Russian hacktivists targeted several water systems in Texas, including one incident that caused a utility in Muleshoe to experience an overflow, although services remained operational.&nbsp;<\/p>\n<p>While the attacks themselves were fairly pedestrian \u2013 highlighting just how easy it is for&nbsp; nation-backed hackers to hack U.S. water systems \u2013 security researchers have <a href=\"https:\/\/cyberscoop.com\/sandworm-apt44-texas-water-facility\/\">linked the hacktivists<\/a> to Sandworm, Russia\u2019s most notorious hacking group that has repeatedly brought down Ukraine\u2019s grid.<\/p>\n<p>In November, <a href=\"https:\/\/cyberscoop.com\/pennsylvania-water-facility-hack-iran\/\">an attack<\/a> on the Israeli firm Unitronics, which manufactures industrial control equipment, resulted in programmable logic controllers used in U.S. water systems being defaced. The defacements were claimed by the Cyb3r Avengers, which officials have linked to the military intelligence arm of Iran\u2019s Islamic Revolutionary Guard Corps.<\/p>\n<p>The EPA said that many inspected utilities have failed to conduct risk and resilience assessments or develop emergency response plans, both of which are called for under the SDWA. The agency is planning on stepping up the number of inspections of community water systems, a term used for systems that provide drinking water to the same area year-round and serve more than 3,300 people.<\/p>\n<p>The EPA said it has already taken more than 100 SDWA enforcement actions against those water systems since the 2020 deadline to develop risk assessments and response plans and warned that it will continue to use enforcement authorities to \u201caddress the problem quickly,\u201d warning that&nbsp; criminal sanctions are possible in response to false certifications.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>The agency <a href=\"https:\/\/cyberscoop.com\/epa-calls-off-cyber-regulations-for-water-sector\/\">has tried<\/a> to impose cybersecurity mandates on the sector before. Last year, EPA issued an update that would require utilities to follow new cyber rules but held off after legal challenges from several states and water trade associations through existing state sanitation laws. Opponents to the rule said the agency overstepped its authority.<\/p>\n<p>Industry groups like the American Water Works Association have been advocating for a new body to take the role of federal regulator for the water sector modeled after the electric sector. Reps. Rick Crawford, R-Ark., and John Duarte, R-Calif., recently introduced a measure known as the <a href=\"https:\/\/crawford.house.gov\/posts\/reps-crawford-and-duarte-introduce-legislation-to-protect-water-systems-from-cyber-threats\">Water Risk and Resilience Organization Establishment Act<\/a>, which would create such a governing body with a specific focus on both cybersecurity and water systems.<\/p>\n<p>The EPA and the White House <a href=\"https:\/\/cyberscoop.com\/epa-water-threats-governors\/\">recently sent a letter to governors<\/a> both to warn about the cyber threats to water systems and to invite state officials to a meeting with EPA and White House officials. The letter pointed to threats like the Chinese-linked hacking group dubbed Volt Typhoon, which administration officials might seek to disrupt U.S. critical infrastructure in the event of a conflict between the United States and China.<\/p>\n<p><\/body> <\/p>\n<footer class=\"single-article__footer\" readability=\"1.3546666666667\">\n<div class=\"author-card\" readability=\"9\">\n<div class=\"author-card__avatar\">\n<figure class=\"author-card__image-wrap\"> <img data-recalc-dims=\"1\" decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/epa-will-step-up-inspections-of-water-sector-cybersecurity-1.jpg?w=640&#038;ssl=1\" alt=\"Christian Vasquez\"> <\/figure>\n<\/p><\/div>\n<p><h4 class=\"author-card__name\">Written by Christian Vasquez<\/h4>\n<p> Christian covers industrial cybersecurity for CyberScoop News. He previously wrote for E&amp;E News at POLITICO covering cybersecurity in the energy sector. Reach out:&nbsp; christian.vasquez at cyberscoop dot com <\/p>\n<\/p><\/div>\n<div class=\"single-article__tags-container\">\n<h4 class=\"single-article__tags-title\">In This Story<\/h4>\n<\/p><\/div>\n<\/footer>\n<p> <\/html><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"single-article__ads js-single-article-sidebar\">\n<div class=\"ad ad--sidebar js-single-article-sidebar-5 ad--rightrail_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-4 ad--rightrail_2 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-3 ad--rightrail_3 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div><\/div>\n<\/article>\n<div class=\"popular-stories popular-stories--single-post\">\n<div class=\"popular-stories__container\">\n<h2 class=\"popular-stories__title\"> More Scoops <\/h2>\n<p> <!-- .popular-stories__stories --> <\/div>\n<p><!-- .popular-stories__inner -->\n<\/div>\n<p><!-- .popular-stories --> <\/p>\n<section class=\"latest-podcasts\">\n<h2 class=\"latest-podcasts__title\"> Latest Podcasts\t<\/h2>\n<\/section>\n<div class=\"top-categories\">\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Government<\/h3>\n<\/p><\/div>\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Technology<\/h3>\n<\/p><\/div>\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Geopolitics<\/h3>\n<\/p><\/div>\n<\/p><\/div>\n<p> <\/main> <\/p>\n<div class=\"ad ad--bottom \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div id=\"interstitial\" class=\"welcome__container\"> <button id=\"close-modal-1\" class=\"welcome__clickable_area\"><\/button> <\/p>\n<div class=\"welcome__ad_wrapper\">\n<p> <button id=\"close-modal-3\" class=\"welcome__continue-button\">Continue to CyberScoop<\/button> <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p> <!-- Start of HubSpot Embed Code --> <!-- End of HubSpot Embed Code --> <\/body> <a href=\"https:\/\/cyberscoop.com\/epa-water-inspections-cyber-alert\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>EPA will step up inspections of water sector cybersecurity |<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[858,413,859,117,1965,439,270,1066],"tags":[861,415,862,119,1966,443,276,1067],"class_list":["post-3660","post","type-post","status-publish","format-standard","hentry","category-american-water-works-association","category-critical-infrastructure","category-environmental-protection-agency-epa","category-government","category-hacktivists","category-policy","category-russia","category-water-sector","tag-american-water-works-association","tag-critical-infrastructure","tag-environmental-protection-agency-epa","tag-government","tag-hacktivists","tag-policy","tag-russia","tag-water-sector"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Cyber Scoop","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/cyberscoop\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/american-water-works-association\/\" rel=\"category tag\">American Water Works Association<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/critical-infrastructure\/\" rel=\"category tag\">critical infrastructure<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/environmental-protection-agency-epa\/\" rel=\"category tag\">Environmental Protection Agency (EPA)<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/government\/\" rel=\"category tag\">Government<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/hacktivists\/\" rel=\"category tag\">hacktivists<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/policy\/\" rel=\"category tag\">Policy<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/russia\/\" rel=\"category tag\">Russia<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/water-sector\/\" rel=\"category tag\">water sector<\/a>","tag_info":"water sector","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3660"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3660\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}