EPA Cybersecurity for the Water Sector
Cyber-attacks against public water systems are increasing. Implementing basic cyber hygiene practices can help your utility prevent, detect, respond, and recover from cyber incidents. Learn more about EPA’s Cybersecurity Resources for Drinking Water and Wastewater Systems.
EPA & CISA Release Information to Help Water Systems Reduce Cybersecurity Vulnerability
The Environmental Protection Agency (EPA) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing information about a common cybersecurity vulnerability at water and wastewater systems using unsecured Human Machine Interface (HMI) devices. In the absence of cybersecurity measures, unauthorized remote users could exploit Human Machine Interfaces to view and adjust real-time system settings. These unauthorized adjustments can potentially disrupt the facility’s water and/or wastewater treatment process. EPA and CISA's fact sheet provides water and wastewater utilities with recommendations for cybersecurity measures that will limit the vulnerability of Human Machine Interfaces and secure them against malicious cyber activity.
Cybersecurity Assessments
Learn about cybersecurity assessment resources available for drinking water and wastewater systems.
Request Cybersecurity Technical Assistance
Request Cybersecurity Evaluation
On this page:
- Cybersecurity Guidance for Drinking Water and Wastewater
- Cybersecurity Risk Self-Assessment Resources
- Cybersecurity Risk Third-Party Assessment Resources
- Cybersecurity Vulnerability Assessment Resources
- Addressing Cybersecurity in your America’s Water Infrastructure Act Risk and Resilience Assessment
- Technical Assistance
Cybersecurity Planning
On this page:
- Addressing Cybersecurity in your America’s Water Infrastructure Act Emergency Response Plan
- Top 8 Cyber Actions for Securing Water Systems
- Cybersecurity Incident Action Checklist
- Water and Wastewater Sector Incident Response Guide
- Water Sector Cybersecurity Program Case Studies
- Cybersecurity Insurance Considerations
- Other US Government and Partner Cybersecurity Resources
Cybersecurity Training
Learn about cybersecurity basics for water systems, how to conduct a cyber risk assessment, find out about upcoming cybersecurity training for drinking water and wastewater systems, and request training.
On this page:
- Request Cybersecurity Training
- Upcoming Cybersecurity Training
- Recorded Cybersecurity Training
- EPA Tabletop Exercise Tool Cybersecurity Scenario
Cybersecurity Response
Learn about responding to a cyber incident and gain knowledge on current active threats.
On this page:
- Report a Cybersecurity Incident
- EPA Webinar on Unitronics PLCs Hacked at US Water and Wastewater Systems
- Cybersecurity Alerts
Cybersecurity Funding
Learn about funding options available to support increasing cyber resilience.
On this page:
- Clean Water State Revolving Fund
- Drinking Water State Revolving Fund
- CISA State and Local Cybersecurity Grant Program
Is Your Utility Cyber Aware?
The Federal Bureau of Investigation (FBI) and U.S. Environmental Protection Agency (EPA) are partnering on a joint venture to increase cyber awareness in the water sector. View FBI and EPA's resources related to cybersecurity in the water sector.