{"id":17800,"date":"2024-05-30T10:56:03","date_gmt":"2024-05-30T14:56:03","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=17800"},"modified":"2025-07-17T10:41:53","modified_gmt":"2025-07-17T14:41:53","slug":"epa-7-in-10-us-community-water-systems-at-risk-cyber-attacks","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/epa-7-in-10-us-community-water-systems-at-risk-cyber-attacks\/","title":{"rendered":"EPA: 7 in 10 U.S. Community Water Systems Are at Risk of Cyber Attacks"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-since-2020-the-u-s-environment-protection-agency-epa-has-doled-out-more-than-100-enforcement-actions-against-community-water-systems-cws-across-the-u-s-for-violations-of-the-safe-water-drinking-act\">Since 2020, the U.S. Environment Protection Agency (EPA) has doled out more than 100 enforcement actions against community water systems (CWS) across the U.S. for violations of the Safe Water Drinking Act.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Securing the nation\u2019s approximately <a href=\"https:\/\/www.cisa.gov\/topics\/critical-infrastructure-security-and-resilience\/critical-infrastructure-sectors\/water-and-wastewater-sector#:~:text=Overview,systems%20in%20the%20United%20States.\">153,000 publicly owned and operated drinking water systems and 16,000 wastewater systems<\/a> is a responsibility that shouldn\u2019t be taken lightly. However, the majority (70%) of <a href=\"https:\/\/www.epa.gov\/enforcement\/enforcement-alert-drinking-water-systems-address-cybersecurity-vulnerabilities\">community water systems inspected since September 2023<\/a> don\u2019t even meet the baseline security requirements outlined in the Safe Water Drinking Act (SWDA). That\u2019s why the EPA issued an <a href=\"https:\/\/www.epa.gov\/newsreleases\/epa-outlines-enforcement-measures-help-prevent-cybersecurity-attacks-and-protect\">enforcement alert<\/a> outlining the urgency of complying with the SWDA.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gee, that\u2019s comforting, particularly when you consider that cyber attacks against U.S. water and wastewater systems are on the rise. We saw evidence of that this year when <a href=\"https:\/\/www.cnn.com\/2024\/04\/17\/politics\/russia-hacking-group-suspected-texas-water-cyberattack\/index.html\">cybercriminals attacked a small Texas town\u2019s water facility<\/a>, causing a tank to overflow.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What can these community water systems (and other critical infrastructure organizations) do to harden their defenses against potential cyber attacks and avert disaster?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-central-palette-2-background-color has-text-color has-background wp-element-button\" href=\"https:\/\/www.devicecertificates.com\/\" style=\"border-radius:3px;color:#ffffff\">Compare IoT Device Certificates<\/a><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-threats-against-a-public-water-utility-look-like\">What Threats Against a Public Water Utility Look Like<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Eric Goldstein, Executive Assistant Director for Cybersecurity at Computer Information Security Agency (CISA), described Water and Wastewater Systems (WWS) as being <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-fbi-and-epa-release-incident-response-guide-water-and-wastewater-systems-sector\">\u201ctarget rich, cyber poor.\u201d<\/a> This is because subsets of these systems (called community water systems) supply potable water to an estimated 80% of the nation\u2019s population. <a href=\"https:\/\/www.thesslstore.com\/blog\/critical-infrastructure-protection-securing-essential-systems-against-cyber-threats\/\">If something were to happen to this critical infrastructure<\/a>, we\u2019d be up an aptly named brown creek without a paddle.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What sorts of issues or concerns could arise from a cyber attack against public drinking water and wastewater systems? According to the <a href=\"https:\/\/www.cisa.gov\/topics\/critical-infrastructure-security-and-resilience\/critical-infrastructure-sectors\/water-and-wastewater-sector#:~:text=Overview,vulnerable%20to%20a%20variety%20of%20attacks\">Computer Information Security Agency (CISA)<\/a>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>&#8220;The Water and Wastewater Systems Sector is vulnerable to a variety of attacks, including contamination with deadly agents; physical attacks, such as the release of toxic gaseous chemicals; and cyberattacks. The result of any variety of attack could be large numbers of illnesses or casualties and\/or a denial of service that would also impact public health and economic vitality.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Even seemingly unrelated international events can spill over and directly impact our water supply. Just look at the <a href=\"https:\/\/www.bbc.com\/news\/world-us-canada-68186945\">sanctions that were placed on Iranian officials<\/a> after a government-sponsored militia group launched a cyber attack on a water authority in western Pennsylvania. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the BBC, the facilities used technologies manufactured by an Israeli company. How\u2019d they do it? By exploiting a default password to disable a water pressure regulation monitor. (We\u2019ll speak more about default password security concerns later.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thankfully, in this situation, plant managers were able to manually override the attackers before something worse happened. But that may not always be the case in future attacks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-what-a-suspected-real-life-cyber-attack-on-a-water-treatment-facility-looks-like\">What a Suspected Real-Life Cyber Attack on a Water Treatment Facility Looks Like<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In February 2021, we wrote about <a href=\"https:\/\/www.thesslstore.com\/blog\/hacker-breaches-florida-water-treatment-plant-adds-lye-to-citys-water-supply\/\">how a hacker breached a Florida water treatment plant<\/a>. At the time, it was widely reported that an unknown assailant remotely tampered with the lye levels in the water (which, when used at proper levels, is used for cleaning and pH balancing), raising them to unsafe levels from 100 parts per million to 11,100 ppm. This would cause a wide array of <a href=\"https:\/\/www.bbc.com\/news\/world-us-canada-68186945\">harmful to potentially catastrophic injuries<\/a> \u2014 deadly gastrointestinal issues, hair loss, skin damage, etc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Needless to say, the news spread like wildfire, making <a href=\"https:\/\/www.bbc.com\/news\/world-us-canada-55989843\">international headlines<\/a>. The good news here is that the plant employee reportedly observed the level of the caustic chemical skyrocketing to dangerously high levels and changed it back before anyone got hurt. But the situation doesn\u2019t end there. In April 2023, <a href=\"https:\/\/cyberscoop.com\/water-oldsmar-incident-cyberattack\/\">CyberScoop reported<\/a> that authorities were on the fence about whether an attacker was responsible for the situation after all. They\u2019re still not certain about the cause of the incident.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Whether that situation resulted from a hacker or an overzealous employee, the point is that if it <em>was<\/em> a hacker, then it could be just one of many water treatment plants that are viewed as being at risk of cyber attacks.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-breaking-down-the-risks-to-the-nation-s-critical-infrastructure-sectors\">Breaking Down the Risks to the Nation\u2019s Critical Infrastructure Sectors<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Some good news for the Water and Wastewater Sector is that it ranked among the lowest in 2023 regarding reported ransomware attacks. Yup, it\u2019s not even in the top 10. The FBI\u2019s Internet Crime Complaint Center (IC3) team reported in its <a href=\"https:\/\/www.ic3.gov\/Media\/PDF\/AnnualReport\/2023_IC3Report.pdf\">2023 Internet Crime Report<\/a> that of the 1,193 complaints received in that period, \u201conly\u201d 8 affected Water and Wastewater Systems (WWS).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Granted, this number is more than double what it was in 2022. But it\u2019s still relatively minor when compared to, say, the Healthcare and Public Health Sector and Critical Manufacturing Sector data shared by the FBI\u2019s Internet Crime Complaint Center (IC3) in its 2021, 2022, and 2021 Internet Crime Reports:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"612\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/fbi-ic3-critical-infrastructure-sectors-shadow-1024x612.png\" alt=\"FBI IC3 data on the critical infrastructure sectors that were targeted with ransomware by cybercriminals in 2021, 2022 and 2023.\" class=\"wp-image-17802\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/fbi-ic3-critical-infrastructure-sectors-shadow-1024x612.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/fbi-ic3-critical-infrastructure-sectors-shadow-300x179.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/fbi-ic3-critical-infrastructure-sectors-shadow-768x459.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/fbi-ic3-critical-infrastructure-sectors-shadow-400x240.png 400w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/fbi-ic3-critical-infrastructure-sectors-shadow-460x276.png 460w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/fbi-ic3-critical-infrastructure-sectors-shadow.png 1036w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Graph caption: Data collected from the FBI IC3\u2019s Internet Crime Reports (<\/em><a href=\"https:\/\/www.ic3.gov\/Media\/PDF\/AnnualReport\/2021_IC3Report.pdf\"><em>2021<\/em><\/a><em>, <\/em><a href=\"https:\/\/www.ic3.gov\/Media\/PDF\/AnnualReport\/2022_IC3Report.pdf\"><em>2022<\/em><\/a><em>, and 2023). Two sectors (Dams Sector and Nuclear Reactors, Materials, and Waste)<\/em> <em>were not included on this list<\/em>,<em> as this list focuses on the 14 critical infrastructure sectors that had \u201cat least 1 member that fell to a ransomware attack\u201d in each of the three reporting years<\/em>.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">So, even though Water and Wastewater Systems rank near the bottom of the list for reported ransomware incidents, there are other methods of attack that bad guys can employ. They&#8217;re essential systems that consumers and businesses across the country rely on every day and must be protected at any cost.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-makes-water-systems-vulnerable-insecure-it-and-iot\">What Makes Water Systems Vulnerable? Insecure IT and IoT<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The security of WWS IT infrastructure and systems often depends on how organizations use and (don\u2019t) secure their connected technologies.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-how-water-utilities-are-using-iot-and-ot\">How Water Utilities Are Using IoT and OT<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">U.S. drinking water and wastewater systems often rely on a web of Internet of Things (IoT) and operational technology (OT) devices. These tools help reduce operational costs, increase efficiency, and improve monitoring (e.g., to keep an eye on water quality levels and identify leaks more quickly).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what do some of these systems entail? Several Polish researchers compiled a summary list of <a href=\"https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC9864729\/\">common IoT technologies you\u2019ll find in water quality systems<\/a>, which include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Actuators:<\/strong> These devices allow operators to remotely monitor and manipulate specific chemical levels, adjust water flow, or carry out other necessary functions.<\/li>\n\n\n\n<li><strong>Gateways<\/strong>: These network devices serve as intermediaries, connecting multiple systems and devices to a central monitoring system to analyze, process, and store their data.<\/li>\n\n\n\n<li><strong>Smart meters<\/strong>: These tools measure water flow and usage to identify potential issues (such as leaks) and calculate usage for consumers.<\/li>\n\n\n\n<li><strong>Smart sensors<\/strong>: These devices remotely measure various aspects of a water supply (pH levels, chemical levels, contaminants, water quality, etc.) and collect data for record-keeping and compliance-related purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, depending on your environment, there are likely other devices and systems in place. But there\u2019s no way to cover them all here.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-why-improperly-managed-iot-leaves-systems-at-risk\">Why Improperly Managed IoT Leaves Systems at Risk<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/blogs.idc.com\/2021\/01\/06\/future-of-industry-ecosystems-shared-data-and-insights\/\">IDC estimates<\/a> that the number of IoT devices in use will soar to 55.7 billion by 2025, saying that these systems will be responsible for generating nearly 80 billion zettabytes (ZB) of data. (For a layman\u2019s look at what these levels of data really mean, check out our article on <a href=\"https:\/\/www.thesslstore.com\/blog\/how-much-data-is-in-the-world-and-how-do-you-secure-it\/\">how much data there is in the world<\/a>.) &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The problem with using IoT in virtually any system, including WWS, is that these technologies are inherently insecure. Many IoT devices are deployed without a way for manufacturers to deliver secure updates, or updates are infrequent or don\u2019t get rolled out by plant operators quickly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are two main areas of concern:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Data privacy:<\/strong> If organizations don\u2019t use secure, encrypted connections to transmit their data, then the data is at risk of eavesdropping and interception attacks.<\/li>\n\n\n\n<li><strong>Cybersecurity:<\/strong> Every connected device is a potential attack surface for cybercriminals. If even one device has an unaddressed vulnerability or is no longer supported, it\u2019s a neon flashing \u201cWelcome\u201d sign, pointing to an entry point into your network.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Bad guys with the know-how and opportunity can exploit these deficiencies to capture and read your insecure data or even inject their own malicious code. These attacks can result in everything from health and safety issues and system downtime to financial losses and reputational harm in the eyes of your customers and other stakeholders.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Knowing this, let\u2019s explore some of the U.S. federal government laws and various amendments that aim to protect the quality and security of these essential systems. &nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-remember-the-safe-water-drinking-act-mentioned-earlier-let-s-touch-on-that\">Remember the Safe Water Drinking Act Mentioned Earlier? Let\u2019s Touch on That\u2026<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As the name implies, the <a href=\"https:\/\/www.epa.gov\/laws-regulations\/summary-safe-drinking-water-act\">Safe Water Drinking Act<\/a> is a federal law dating back to 1974. It set the stage for the EPA to create and enforce minimum standards for drinking water quality and safety that public water systems must abide by.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The law has been amended several times over the past 50 years, most recently:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>In 2002:<\/strong> SDWA was updated by Title IV of the <a href=\"https:\/\/www.congress.gov\/bill\/107th-congress\/house-bill\/3448\/text\">Public Health Security and Bioterrorism Preparedness and Response Act<\/a>. The revision implemented specific security vulnerability assessment, certification, and emergency planning requirements to improve drinking water infrastructure. It added the following sections to the Safe Drinking Water Act:<ul><li><strong>Section 1433:<\/strong> Terrorist and Other Intentional Acts<\/li><\/ul><ul><li><strong>Section 1434: <\/strong>Contaminant Prevention, Detection and Response<\/li><\/ul>\n<ul class=\"wp-block-list\">\n<li><strong>Section 1435:<\/strong> Supply Disruption, Prevention, Detection and Response<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>In 2013:<\/strong> White House <a href=\"https:\/\/obamawhitehouse.archives.gov\/the-press-office\/2013\/02\/12\/executive-order-improving-critical-infrastructure-cybersecurity\">Executive Order (EO) 13636<\/a> places the EPA in charge of Water and Wastewater Systems Security (including all cybersecurity efforts)<\/li>\n\n\n\n<li><strong>In 2018:<\/strong> The <a href=\"https:\/\/www.federalregister.gov\/documents\/2019\/03\/27\/2019-05770\/new-risk-assessment-and-emergency-response-plan-requirements-for-community-water-systems\">Federal Register<\/a> states that <a href=\"https:\/\/www.epa.gov\/system\/files\/documents\/2023-08\/AWIA-factsheet_updated_08-2023_508.pdf\">Section 2013 of the American Water Infrastructure Act (AWIA)<\/a> amended SDWA Section 1433. The changes create new requirements regarding risk and resilience assessments (RRAs) and emergency response plans (ERPs) for organizations serving populations larger than 3,300 people. It also specifies that the EPA must provide technical assistance and guidance for water systems serving communities that have 3,300 or fewer people.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In early 2024, a joint <a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/water-and-wastewater-sector-incident-response-guide-0\">Water and Wastewater Sector Incident Response Guide<\/a> was released. The comprehensive resource aims to help organizations augment their incident response plans and procedures and includes contributions from more than organizations across the sector.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a quick timeline that showcases this chain of events relating to the industry\u2019s cybersecurity-related concerns:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"357\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/wws-timeline-1024x357.png\" alt=\"A timeline of some key events in the timeline of water safety and cybersecurity\" class=\"wp-image-17803\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/wws-timeline-1024x357.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/wws-timeline-300x105.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/wws-timeline-768x268.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/wws-timeline.png 1501w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-water-systems-are-responsible-for-securing-their-infrastructures\">How Water Systems Are Responsible For Securing Their Infrastructures<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Under the AWIA-amended Safe Water Drinking Act, the EPA must provide \u201ctechnical guidance\u201d to CWS serving 3,300 or fewer people. If a CWS entity serves more than 3,300 people, its owners and\/or operators must perform <a href=\"https:\/\/www.epa.gov\/waterresilience\/americas-water-infrastructure-act-2018-risk-assessments-and-emergency-response-plans\">RRAs and ERPs<\/a> every five years.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(<strong>NOTE<\/strong>: Much of this info is covered under the Section 2013 AWIA resource provided earlier):<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-1-conduct-and-certify-a-risk-and-resilience-assessment-rra\">1. Conduct and Certify a Risk and Resilience Assessment (RRA)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">These risk assessments evaluate the following physical security risks, tolerances, and practices of a WWS entity:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Resilience of the water systems\u2019 physical infrastructure,<\/li>\n\n\n\n<li>How chemicals are used, handled, and stored,<\/li>\n\n\n\n<li>Impacts of man-made and natural emergencies, and<\/li>\n\n\n\n<li>Other key considerations.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">According to the EPA, utilities self-certify and create certification statements that they submit to the overseeing agency. (Nothing like having the fox guard the hen house, right?) However, the EPA provides the following resources for carrying out the RRA process:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.epa.gov\/waterresilience\/small-system-risk-and-resilience-assessment-checklist\">Small System Risk and Resilience Assessment Checklist<\/a> for communities under 50,000 people.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.epa.gov\/waterriskassessment\/vulnerability-self-assessment-tool-conduct-drinking-water-or-wastewater-utility\">Vulnerability Self-Assessment Tool<\/a> for communities that have 50,000+ residents.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-2-develop-and-certify-an-emergency-response-plan-erp\">2. Develop and Certify an Emergency Response Plan (ERP)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This involves documenting strategies and resources for improving physical and cybersecurity responses for if\/when crap hits the fan. Although the EPA provides a <a href=\"https:\/\/www.epa.gov\/sites\/default\/files\/2019-07\/documents\/190712-awia_erp_template_instructions_kab_508c_v6.pdf\">CWS ERP template<\/a>, it\u2019s best to tailor the strategy and documentation to meet your organization\u2019s specific needs. The comprehensive resource should touch everything from emergency response and incident command system roles and communication strategies to emergency response and incident detection and mitigation strategies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An ERP must be done within six months of completing the RRA. (NOTE: ERPs are also self-certified.)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-3-submit-their-certification-confirmations-to-the-epa\">3. Submit Their Certification Confirmations to the EPA.<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This involves submitting the certification statements, not the certification documents themselves, to the EPA via email, traditional mail, or via the EPA\u2019s online portal. The EPA tracks each certification by its corresponding Public Water System Identification (PWSID) number.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-4-review-revise-and-re-certify\">4. Review, Revise, and Re-Certify<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Nothing lasts forever, including your RRA or ERP. CWSs must update these plans every five years as necessary and re-submit their re-certification statements. The next round of <a href=\"https:\/\/www.epa.gov\/waterresilience\/awia-section-2013\">RRA and ERP certification deadlines<\/a> are as follows, divided by the size of the population served:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Population Served<\/strong><\/td><td><strong>Previous RRA Deadline<\/strong><\/td><td><strong>5-Year Re-Submission RRA<\/strong><\/td><td><strong>Previous ERP Deadline<\/strong><\/td><td><strong>5-Year Re-Submission ERP<\/strong><\/td><\/tr><tr><td>\u2265100,000<\/td><td><strong>March 31, 2020<\/strong><\/td><td><strong>March 31, 2025<\/strong><\/td><td><strong>Sept. 30, 2020<\/strong><\/td><td><strong>Sept. 30, 2025<\/strong><\/td><\/tr><tr><td><strong>50,000-99,999<\/strong><\/td><td><strong>Dec. 31, 2020<\/strong><\/td><td><strong>Dec. 31, 2025<\/strong><\/td><td><strong>June 30, 2021<\/strong><\/td><td><strong>June 30, 2026<\/strong><\/td><\/tr><tr><td><strong>3,301-49,999<\/strong><\/td><td><strong>June 30, 2021<\/strong><\/td><td><strong>June 30, 2026<\/strong><\/td><td><strong>Dec. 31, 2021<\/strong><\/td><td><strong>Dec. 31, 2026<\/strong><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-aren-t-small-towns-safe-from-these-cybersecurity-risks\">Aren\u2019t Small Towns Safe From These Cybersecurity Risks?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Absolutely not. Remember that town in Texas we mentioned at the beginning of the article that suffered a water system cyber attack? Muleshoe is a community of about 5,000 people, so the town\u2019s water utility would likely fall under these requirements. The Florida water treatment plant we previously wrote about likely would as well, as it\u2019s serving an even larger population. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.epa.gov\/enforcement\/enforcement-alert-drinking-water-systems-address-cybersecurity-vulnerabilities\">According to the EPA<\/a>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cSmall water systems are not immune from cyberattacks. Recently, disruptive cyberattacks from adversarial nation states have impacted water systems of all sizes, including many small systems. As a result of these increased threats, EPA is increasing its enforcement activity to protect our nation\u2019s drinking water.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">So, no matter if you work at a big or small CWS, you\u2019re an attractive target for hackers and other cyber miscreants. Furthermore, a <a href=\"https:\/\/crsreports.congress.gov\/product\/pdf\/IN\/IN12311#:~:text=In%202002%2C%20P.L.%20107%2D188,or%20other%20intentional%20acts%20that\">report from the Congressional Research Service<\/a> shows that nearly half of the public and privately owned water systems in the U.S. fall within the Community Water Systems classification.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Most CWSs (81%) serve fewer than 3,300 individuals.<\/li>\n\n\n\n<li>9% of CWSs serve more than 83% of the U.S. population served by these water systems (~260 million people).&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For example, here\u2019s a look at Florida\u2019s Public Water Supply Plants, which lists 5,884 non-federally controlled or owned facilities:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"526\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/florida-non-federal-public-water-supply-wells-shadow-1024x526.png\" alt=\"A screenshot from Florida's Department of Environmental Protection Geospatial Open Data tool, which maps out locations of non-federal public water supply plants\" class=\"wp-image-17804\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/florida-non-federal-public-water-supply-wells-shadow-1024x526.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/florida-non-federal-public-water-supply-wells-shadow-300x154.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/florida-non-federal-public-water-supply-wells-shadow-768x394.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/florida-non-federal-public-water-supply-wells-shadow-1536x788.png 1536w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/florida-non-federal-public-water-supply-wells-shadow-2048x1051.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: We captured this screenshot using the <\/em><a href=\"https:\/\/geodata.dep.state.fl.us\/datasets\/1df064433629466ba40ac8efffd5eea6\/explore?layer=1&amp;location=28.407305%2C-83.454642%2C6.00\"><em>Florida Department of Environmental Protection\u2019s Geospatial Open Data<\/em><\/a><em> tool.<\/em><\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-13-ways-to-harden-the-security-of-your-water-systems\">13 Ways to Harden the Security of Your Water Systems<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The joint fact sheet <a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/top-cyber-actions-securing-water-systems\">\u201cTop Cyber Actions for Securing Water Systems\u201d<\/a> from CISA, EPA, and FBI outlines actions that WWS sector companies and municipalities can take to secure their resources and increase resiliency.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve put together the following recommendations of best practices (broken down by area of risk):<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-know-what-s-on-your-network-and-if-it-s-up-to-date\">Know What\u2019s on Your Network (And If It\u2019s Up to Date)<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Perform regular cybersecurity assessments.<\/strong> These are related but separate from the RRAs that are required for EPA certification. This should involve assessing your organization for physical and digital cybersecurity risks so they can be mitigated.<\/li>\n\n\n\n<li><strong>Inventory your IoT\/OT systems and assets.<\/strong> If you don\u2019t know already, then get a proper accounting of every device, app, or other digital asset operating within your IT ecosystem. Regularly update these inventories and keep them current so no legacy systems fall through the cracks over time.<\/li>\n\n\n\n<li><strong>Perform regular systems patching.<\/strong> Much like any regular computer, the IT devices and systems running our facility also need to be maintained. This includes regularly implementing security patches and other updates that eliminate vulnerabilities within your systems.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-know-who-and-what-accesses-your-network-devices-and-data\">Know Who (and What) Accesses Your Network, Devices, and Data<\/h3>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li><strong>Use PKI to authenticate all IoT devices on your network.<\/strong> <a href=\"https:\/\/www.thesslstore.com\/blog\/pki-uses-applications-examples\/\">Public key infrastructure (PKI)<\/a> is a great way to secure internal resources. You can use <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-device-certificate-device-certificates-explained\/\">IoT device certificates<\/a> to enable mutual authentication for your IoT devices.<\/li>\n<\/ol>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-central-palette-2-background-color has-text-color has-background wp-element-button\" href=\"https:\/\/www.devicecertificates.com\/\" style=\"border-radius:3px;color:#ffffff\">Buy Device Certificates<\/a><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<ol start=\"5\" class=\"wp-block-list\">\n<li><strong>Use certificate-based authentication for network users as well.<\/strong> This approach enables you to bypass the traditional password-based authentication systems and serves as a form of multi-factor authentication (MFA).&nbsp;<\/li>\n\n\n\n<li><strong>Shore up your user access controls.<\/strong> Don\u2019t want unauthorized users and devices accessing your critical systems? Don\u2019t give them the chance. Set robust <a href=\"https:\/\/www.thesslstore.com\/blog\/the-role-of-access-control-in-information-security\/\">access controls<\/a> and restrict permissions to only those who absolutely need it to do their jobs and don\u2019t forget to revoke that access <em>immediately<\/em> once they no longer need it (i.e., when they change or leave their jobs or if their roles\/responsibilities change).<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Pairing access permissions with PKI-based authentication ensures that only authenticated, authorized users and devices can access your secure systems and data.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-secure-your-entity-s-it-ecosystem\">Secure Your Entity\u2019s IT Ecosystem<\/h3>\n\n\n\n<ol start=\"7\" class=\"wp-block-list\">\n<li><strong>Button up your public-facing internet exposure risks.<\/strong> One great way to do this is to keep your IoT devices on a separate (ideally dedicated) network from other critical systems. Cross your T\u2019s and dot your I\u2019s to ensure that your public and private network resources stay in their respective lanes. To quote Kipling: <a href=\"https:\/\/www.merriam-webster.com\/dictionary\/never%20the%20twain%20shall%20meet#:~:text=idiom,never%20the%20twain%20shall%20meet.\">\u201cNever the twain shall meet.\u201d<\/a> &nbsp;<\/li>\n\n\n\n<li><strong>Secure all network connections.<\/strong> SSL\/TLS security isn\u2019t just for your public website. You can use <a href=\"https:\/\/www.thesslstore.com\/blog\/how-to-become-a-certificate-authority\/\">private CA<\/a> SSL\/TLS certificates to secure the data in transit between your internal network apps, services, and sites using public key encryption.<\/li>\n<\/ol>\n\n\n<span style=\"--tl-form-height-m:927.562px;--tl-form-height-t:999.781px;--tl-form-height-d:999.781px;\" class=\"tl-placeholder-f-type-shortcode_17591 tl-preload-form\"><span><\/span><\/span>\n\n\n<ol start=\"9\" class=\"wp-block-list\">\n<li><strong>Educate your employees.<\/strong> Educate and train your employees to recognize and respond to threats appropriately and follow industry cybersecurity best practices. They\u2019re often your organization\u2019s first line of defense against threat actors.<\/li>\n\n\n\n<li><strong>Avoid using default passwords or hard-coded credentials. <\/strong>Don\u2019t use default credentials and never, ever hard-code them into your systems and apps! This is one of the biggest mistakes companies and organizations across all sectors can make, and they often end up getting leaked by accident.<\/li>\n\n\n\n<li><strong>Automate your IoT device security lifecycle.<\/strong> DigiCert recently announced its new <a href=\"https:\/\/www.digicert.com\/device-trust-manager\">DigiCert Device Trust Manager<\/a> (formerly known as IoT Trust Manager), a robust IoT device security and lifecycle management solution that&#8217;s part of DigiCert ONE. This tool enables you to secure your devices and data and use automation to deploy and manage your devices.<\/li>\n<\/ol>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-central-palette-2-background-color has-text-color has-background wp-element-button\" href=\"https:\/\/www.devicecertificates.com\/certificate-management\/\" style=\"border-radius:3px;color:#ffffff\">Learn More About DigiCert ONE<\/a><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-plan-for-the-worst-hope-for-the-best\">Plan For the Worst, Hope For the Best<\/h2>\n\n\n\n<ol start=\"12\" class=\"wp-block-list\">\n<li><strong>Develop and maintain current cybersecurity incident response and recovery plans.<\/strong> When things go wrong, it\u2019s crucial to know the systems, plans, and people you have in place to respond and get you back to working order.<\/li>\n\n\n\n<li><strong>Create regular backups of essential IoT\/OT systems and data.<\/strong> It\u2019s virtually inevitable that something will go wrong at some point, so it\u2019s best to be as prepared as you can be for when things do.<\/li>\n<\/ol>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-notice is-variation-info has-icon\" data-type=\"info\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><circle cx=\"12\" cy=\"12\" r=\"10\"><\/circle><line x1=\"12\" y1=\"16\" x2=\"12\" y2=\"12\"><\/line><line x1=\"12\" y1=\"8\" x2=\"12\" y2=\"8\"><\/line><\/svg><p class=\"wp-block-advanced-gutenberg-blocks-notice__title\">Want to Learn More About IoT Device Security?<\/p><p class=\"wp-block-advanced-gutenberg-blocks-notice__content\"><strong>Related resource: <\/strong><a href=\"https:\/\/www.thesslstore.com\/blog\/how-to-secure-iot-devices-within-your-enterprise\/\"><strong>A 5-Minute Guide on How to Secure IoT Devices Within Your Enterprise<\/strong><\/a><strong>.<\/strong><\/p><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-do-you-work-in-another-critical-infrastructure-sector-these-security-concepts-still-apply\">Do You Work in Another Critical Infrastructure Sector? These Security Concepts Still Apply<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Critical infrastructure is a term encompassing a total of 16 independent sectors, including WWS. So, if you think that many of these security best practices won\u2019t apply to you because you work in another critical infrastructure sector\u2026 you\u2019d be wrong.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The overwhelming majority of the practices we mentioned aren\u2019t limited to only Water and Wastewater Systems but are applicable across many (if not all) of the nation\u2019s other 15 critical infrastructure sectors, as they often involve IoT technologies in one form or another:&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Chemical Systems<\/li>\n\n\n\n<li>Commercial Facilities<\/li>\n\n\n\n<li>Communications<\/li>\n\n\n\n<li>Critical Manufacturing<\/li>\n\n\n\n<li>Dams Sector<\/li>\n\n\n\n<li>Defense Industrial Base<\/li>\n\n\n\n<li>Emergency Services<\/li>\n\n\n\n<li>Energy<\/li>\n\n\n\n<li>Financial Services<\/li>\n\n\n\n<li>Food and Agriculture<\/li>\n\n\n\n<li>Government Facilities<\/li>\n\n\n\n<li>Healthcare and Public Health<\/li>\n\n\n\n<li>Information Technology<\/li>\n\n\n\n<li>Nuclear Reactors, Materials, and Waste<\/li>\n\n\n\n<li>Transportation Systems<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Although each of these sectors is very different regarding the functions they serve, all of these industries share a growing reliance on IT\/OT systems.&nbsp; Without proper security mechanisms in place, these systems are vulnerable to physical or remote access.<\/p>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-central-palette-2-background-color has-text-color has-background wp-element-button\" href=\"https:\/\/www.devicecertificates.com\/\" style=\"border-radius:3px;color:#ffffff\">Shop Device Certificates<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Since 2020, the U.S. Environment Protection Agency (EPA) has doled out more than 100 enforcement actions against community water systems (CWS) across the U.S. for violations of the Safe Water&#8230;<\/p>\n","protected":false},"author":17,"featured_media":17815,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13107,16],"tags":[13279,10177],"class_list":["post-17800","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-hashed-out","category-hashing-out-cyber-security","tag-critical-infrastructure","tag-cybersecurity","post-with-tags"],"views":8866,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/05\/epa-community-water-systems-cyber-attacks-feature.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/17800","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=17800"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/17800\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/17815"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=17800"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=17800"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=17800"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}