Special Features

Cybersecurity Month

EPA flushes water supply cybersecurity rule after losing legal fight with industry, states

What could possibly go wrong?


American public water systems could be safe from cybercriminals and spies — we may not actually know until these systems are compromised, now that the Environmental Protection Agency has pulled the plug on a rule requiring US states to conduct cybersecurity evaluations after being sued by Republican states and water industry groups.

This week the EPA sent a memo [PDF] to state drinking water administrators saying it had "chosen to rescind" an earlier cybersecurity rule, and cited a lawsuit as the reason for its decision.

In March, the EPA began requiring states to evaluate the cybersecurity of their public water systems' operational technology environments.

The EPA cited increasing cyberattacks against water utilities in multiple states, including the Oldsmar, Florida attempted poisoning, and noted that many of these systems "have failed to adopt basic cybersecurity best practices and consequently are at high risk of being victimized by a cyber-attack."

A month later, state attorneys general of Arkansas, Iowa, and Missouri sued the EPA to stop the rule. The American Water Works Association and National Rural Water Association later joined the lawsuit, which argued the EPA didn't have the authority to issue the new regulation without Congressional approval. 

"EPA's new rule thus intrudes on states' sovereignty," according to the complaint [PDF].

In July, an appeals court temporarily blocked [PDF] the federal agency from enforcing the security audit.

In its memo sent to states on Wednesday, the EPA said it "continues to believe that adopting cybersecurity best practices at public water systems is essential to providing safe and reliable drinking water."

Cyberattacks on water and wastewater plants pose "a significant threat to their operations," and as such the agency hopes that states will "voluntarily engage in reviewing public water system cybersecurity programs," it added. 

Blow to Biden's cybersecurity strategy

In addition to dealing a blow to efforts to secure the nation's drinking water, the court's decision and EPA's response may be a setback for the White House's efforts to protect critical infrastructure from nation-state attacks and other cyberthreats like ransomware.

The US National Cybersecurity Strategy, also released in March, centers on five "pillars," the first of which focuses on defending US critical infrastructure and enforcing minimum cybersecurity requirements.

This includes enforcing minimum cybersecurity requirements in critical sectors — but if this attempt by the EPA to improve water systems' cybersecurity is any indication, it looks like it will be an uphill battle.

Industry groups applauded the EPA's rule reversal, while acknowledging that threats against the sector are growing.

"AWWA is pleased that EPA has decided to withdraw its cybersecurity rule," American Water Works Association CEO David LaFrance said in a statement. "We also recognize that cyber threats in the water sector are real and growing, and we cannot let our guard down for even a moment."

LaFrance added that cybersecurity oversight across the industry "remains critical," and urged Congress and the environmental agency to "support a co-regulatory model that would engage utilities in developing cybersecurity requirements with oversight from EPA." ®

Send us news
38 Comments

Five Eyes intel chiefs warn China's IP theft program now at 'unprecedented' levels

Spies come in from the cold for their first public chinwag

US government's Login.gov turns frown upside down, now smiles on facial recognition

Authentication portal to match snaps on existing IDs with user-provided snaps

Cisco warns of critical flaw in Emergency Responder code

Hard-coded credentials strike again

Winklevoss twins back in hot water after NY AG sues over $1B cryptocurrency fraud

SBF comes up like a bad penny

SBF on trial: The Python code that allegedly let Alameda hedge fund spend people's FTX deposits

And Caroline Ellison says she was told by Bankman-Fried to take $10B from customer accounts

Forcing Apple to allow third-party app stores isn't enough

You're excited about Meta offering iOS apps via Facebook ads? Really?

'Gay furry hackers' brag of second NATO break-in, steal and leak more data

'No impact on missions,' military powerhouse insists

Online tracking is alive and well in link decoration

The pending death of third-party cookies won't do much for other privacy intrusions

Feds hopelessly behind the times on ransomware trends in alert to industry

Better late than never, we guess

Watermarking AI images to fight misinfo and deepfakes may be pretty pointless

Basically, it's 'not going to work'

Chinese snoops stole 60K State Department emails in that Microsoft email heist

No classified systems involved apparently, but internal diplomatic notes, travel details, staff SSNs, etc

From chaos to cadence: Celebrating two decades of Microsoft's Patch Tuesday

IT folks look back on 20 years of what is now infosec tradition