Cyber Hygiene Now Part of Public Water System “Sanitary Survey” Check-Ups

03.16.2023
Nossaman eAlert

Public Water Systems (PWS) are now required to conduct cyber defense check-ups at the same time they conduct their routine “sanitary surveys,” according to a new requirement issued by the Environmental Protection Agency on March 3, 2023. Driven by the attack on the Oldmar, Florida water system in February of 2021, and the increasing number of threats from sophisticated criminal and state-sponsored hackers, the EPA issued guidance

Understanding that many public water systems may not have staff dedicated to monitoring their cybersecurity, the EPA also is providing technical assistance to PWS as they modernize their cyber systems. EPA’s guidance entitled “Evaluating Cybersecurity During Public Water Sanitary Surveys” is intended to assist PWS with building cybersecurity into sanitary surveys. The guidance includes critical information for assessing and improving the cybersecurity of operational control systems used for safe drinking water. EPA also plans to offer additional training on implementation of best practices for cybersecurity and use the available resources and consultations with subject matter experts and direct technical assistance to water systems to conduct assessments of their cybersecurity practices and plans for closing identified security gaps.

The EPA acknowledges that many PWS do not implement cybersecurity practices, and efforts to improve cybersecurity through voluntary measures have yielded minimal progress in protecting this component of the nation’s critical infrastructure.

Twitter/X Facebook LinkedIn PDF
Jump to Page

Nossaman LLP Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. For more information about how we use Cookies, please see our Privacy Policy.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek