Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity NewsInfrastructure:Electric,Gas & WaterGovernment: Federal, State and Local

EPA reveals most water systems do not meet compliance requirements

By Security Staff
Bottles of water

Image via Unsplash

May 23, 2024

The Environmental Protection Agency (EPA) has released an enforcement alert, outlining the steps that vulnerable community drinking water systems must take in order to comply with cybersecurity standards set forth by the Safe Drinking Water Act. This alert is part of an ongoing effort to secure the United States’ critical infrastructure. Notably, an investigation by the EPA found that more than 70% of inspected water systems failed to fully comply with the Safe Drinking Water Act requirements. Furthermore, some of these systems have easily compromised cybersecurity vulnerabilities, such as default passwords and single logins. 

Security leaders weigh in 

Tom Kellermann, SVP of Cyber Strategy at Contrast Security:

“The safety of the U.S. water supply is in jeopardy. Rogue nation states are frequently targeting these critical infrastructures, and soon we will experience a life-threatening event. The administration must provide grants to bolster the cybersecurity of these utilities. If funding is lacking, forfeiture of cybercrime proceeds should be used to buttress the cybersecurity of critical infrastructures.”

Roger Grimes, Data-Driven Defense Evangelist at KnowBe4:

“This is the umpteenth time the U.S. government has said the same thing. Will this time be any different? Probably not. I don’t see anything that makes this warning and recommendation any more likely to be fruitful than the previous hundred saying the same thing. Is there a person in the world working at any organization, much less a critical infrastructure plant, that doesn't know their job is to keep the bad hackers out? No. The problem obviously isn’t knowledge and awareness. The problem is in the doing. The problem is in the enforcement. The problem is in management and accountability. We keep treating cybersecurity as this serious thing that everyone should be concerned about, but in practice, it’s treated as a side-job nice-to-have. In nearly every organization you have some soul that really understands the problem and wants to keep the organization secure against the rest of the organization that just wants to do a particular job, cheaply and quickly as possible. And the latter side usually wins.”

“So, cybersecurity is drastically under-resourced, mismanaged and concentrates on the wrong things. As an example, social engineering is involved in 70% to 90% of all successful data breaches and unpatched software and firmware is involved in 33% of all successful breaches. Those two root causes are 90% to 99% of the risk in most environments, including water treatment plants, and yet no organization... no water treatment plant, spends even 5% of their IT resources to mitigate those two huge problems. It’s been this way for decades and it’s not changing now. It is this fundamental misalignment between how organizations are successfully attacked the most and how nearly every organization defends itself that allows hackers and malware to be so damaging. This isn’t a secret. Everyone knows it. It’s a mass delusion that we all understand. And, yet, after every successful compromise, the organization and media readily want to appoint the successful hacker as some uber, super-brilliant hacker that could overcome any defense. Nope, it’s almost never that. It’s hackers and their malware creations doing the same successful things they have done for over 30 years and us responding with the same distracted mitigations wondering why our misaligned defenses aren’t working better.” 

Eric Knapp, CTO of OT at OPSWAT:

“Recent threats, such as those from the Volt Typhoon group, have targeted weaknesses in critical infrastructure and OT environments, and we’ve seen CISA and the Five Eyes alliance issuing recent advisories about the dangers posed by this threat group and others targeting critical sectors. CISA and other U.S. government agencies discovered that these hackers’ access extended to the power grids, communications systems and water supplies for military bases within the U.S. and abroad, showing an even more dire need for these water utilities to improve their cyber resilience.  

“Water systems remain vulnerable for a few reasons, including outdated legacy systems, the use of interconnected networks, limited resources and even a lack of enforced regulations. While a new bill was proposed last month to establish a Water Risk and Resilience Organization that would develop risk and resilience standards specifically tailored for the water sector, we strongly recommend water utilities take immediate action to reduce vulnerabilities and chances of falling victim to a cyber incident. These include: 

  • Changing default passwords
  • Adopting standards applicable to other critical infrastructure and OT environments, such as NERC CIP
  • Controlling peripheral media and securely manage the use of USBs, vendor laptops, and other devices entering critical environments
  • Implementing data diodes or unidirectional security gateways to ensure one-way communication and data sharing
  • Developing and maintaining comprehensive incident response plans
  • Providing regular cybersecurity training.”
KEYWORDS: compliance compliance problems critical infrastructure critical infrastructure cybersecurity federal security requirements water utilties security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Security Enterprise Services
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Cybersecurity
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Cybersecurity
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Pills spilled

More than 20,000 sensitive medical records exposed

Laptop in darkness

Verizon 2025 Data Breach Investigations Report shows rise in cyberattacks

Coding on screen

Research reveals mass scanning and exploitation campaigns

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Computer with binary code hovering nearby

Cyberattacks Targeting US Increased by 136%

2025 Security Benchmark banner

Events

May 22, 2025

Proactive Crisis Communication

Crisis doesn't wait for the right time - it strikes when least expected. Is your team prepared to communicate clearly and effectively when it matters most?

September 29, 2025

Global Security Exchange (GSX)

 

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • water tower in front of clouds

    EPA stresses the need for improved water cybersecurity

    See More
  • Wastewater treatment facility

    US water and wastewater systems targeted by cybercrime

    See More
  • credit- enews

    Payment Data Compliance: 12 Major Requirements of the PCI Data Security Standard

    See More

Related Products

See More Products
  • databasehacker

    The Database Hacker's Handboo

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing