Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity NewsInfrastructure:Electric,Gas & WaterGovernment: Federal, State and Local

EPA reveals most water systems do not meet compliance requirements

By Security Staff
Bottles of water

Image via Unsplash

May 23, 2024

The Environmental Protection Agency (EPA) has released an enforcement alert, outlining the steps that vulnerable community drinking water systems must take in order to comply with cybersecurity standards set forth by the Safe Drinking Water Act. This alert is part of an ongoing effort to secure the United States’ critical infrastructure. Notably, an investigation by the EPA found that more than 70% of inspected water systems failed to fully comply with the Safe Drinking Water Act requirements. Furthermore, some of these systems have easily compromised cybersecurity vulnerabilities, such as default passwords and single logins. 

Security leaders weigh in 

Tom Kellermann, SVP of Cyber Strategy at Contrast Security:

“The safety of the U.S. water supply is in jeopardy. Rogue nation states are frequently targeting these critical infrastructures, and soon we will experience a life-threatening event. The administration must provide grants to bolster the cybersecurity of these utilities. If funding is lacking, forfeiture of cybercrime proceeds should be used to buttress the cybersecurity of critical infrastructures.”

Roger Grimes, Data-Driven Defense Evangelist at KnowBe4:

“This is the umpteenth time the U.S. government has said the same thing. Will this time be any different? Probably not. I don’t see anything that makes this warning and recommendation any more likely to be fruitful than the previous hundred saying the same thing. Is there a person in the world working at any organization, much less a critical infrastructure plant, that doesn't know their job is to keep the bad hackers out? No. The problem obviously isn’t knowledge and awareness. The problem is in the doing. The problem is in the enforcement. The problem is in management and accountability. We keep treating cybersecurity as this serious thing that everyone should be concerned about, but in practice, it’s treated as a side-job nice-to-have. In nearly every organization you have some soul that really understands the problem and wants to keep the organization secure against the rest of the organization that just wants to do a particular job, cheaply and quickly as possible. And the latter side usually wins.”

“So, cybersecurity is drastically under-resourced, mismanaged and concentrates on the wrong things. As an example, social engineering is involved in 70% to 90% of all successful data breaches and unpatched software and firmware is involved in 33% of all successful breaches. Those two root causes are 90% to 99% of the risk in most environments, including water treatment plants, and yet no organization... no water treatment plant, spends even 5% of their IT resources to mitigate those two huge problems. It’s been this way for decades and it’s not changing now. It is this fundamental misalignment between how organizations are successfully attacked the most and how nearly every organization defends itself that allows hackers and malware to be so damaging. This isn’t a secret. Everyone knows it. It’s a mass delusion that we all understand. And, yet, after every successful compromise, the organization and media readily want to appoint the successful hacker as some uber, super-brilliant hacker that could overcome any defense. Nope, it’s almost never that. It’s hackers and their malware creations doing the same successful things they have done for over 30 years and us responding with the same distracted mitigations wondering why our misaligned defenses aren’t working better.” 

Eric Knapp, CTO of OT at OPSWAT:

“Recent threats, such as those from the Volt Typhoon group, have targeted weaknesses in critical infrastructure and OT environments, and we’ve seen CISA and the Five Eyes alliance issuing recent advisories about the dangers posed by this threat group and others targeting critical sectors. CISA and other U.S. government agencies discovered that these hackers’ access extended to the power grids, communications systems and water supplies for military bases within the U.S. and abroad, showing an even more dire need for these water utilities to improve their cyber resilience.  

“Water systems remain vulnerable for a few reasons, including outdated legacy systems, the use of interconnected networks, limited resources and even a lack of enforced regulations. While a new bill was proposed last month to establish a Water Risk and Resilience Organization that would develop risk and resilience standards specifically tailored for the water sector, we strongly recommend water utilities take immediate action to reduce vulnerabilities and chances of falling victim to a cyber incident. These include: 

  • Changing default passwords
  • Adopting standards applicable to other critical infrastructure and OT environments, such as NERC CIP
  • Controlling peripheral media and securely manage the use of USBs, vendor laptops, and other devices entering critical environments
  • Implementing data diodes or unidirectional security gateways to ensure one-way communication and data sharing
  • Developing and maintaining comprehensive incident response plans
  • Providing regular cybersecurity training.”
KEYWORDS: compliance compliance problems critical infrastructure critical infrastructure cybersecurity federal security requirements water utilties security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • water tower in front of clouds

    EPA stresses the need for improved water cybersecurity

    See More
  • Return to Work

    G4S Announces Expansion of Return to Work Assurance Program to Help Organizations Meet Compliance Requirements During COVID-19 Reopenings

    See More
  • Majority of Honolulu Airport Workers not in Compliance with Security Requirements

    See More

Related Products

See More Products
  • SSCP.jpg

    SSCP Systems Security Certified Practitioner Practice Exams

  • intelligent.jpg

    Intelligent Network Video: Understanding Modern Video Surveillance Systems, Second Edition

  • 9781498767118.jpg

    Intelligent Video Surveillance Systems: An Algorithmic Approach

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing