70% of All US Water Utilities Fail Basic Cybersecurity Standards, and Experts Warn Your State Could Be Next

0
8
Pavel Danilyuk/Pexels

More than 70% of U.S. drinking water systems inspected by the Environmental Protection Agency since September 2023 have been found in violation of basic federal risk-and-resilience planning requirements, underscoring a broad cybersecurity gap across a critical public utility sector. That national warning is now colliding with a fresh wave of attacks and advisories, raising the stakes for states and local communities that rely on small and midsize water systems.

EPA says most inspected systems are missing basic protections

The EPA said in an enforcement alert released on May 20, 2024, that more than 70% of the community water systems it had inspected since September 2023 were violating basic Safe Drinking Water Act Section 1433 requirements. The agency said those violations included missing sections in required risk and resilience assessments and emergency response plans, documents that must address cyber threats alongside physical threats. EPA inspectors also identified practical weaknesses in the field, including default passwords that had not been changed, single shared logins for staff, and accounts that had not been cut off for former employees.

The agency said it has taken more than 100 Safe Drinking Water Act enforcement actions nationwide since 2020 tied to Section 1433 violations. EPA stated that, as inspections expand, it intends to use enforcement authorities to push utilities to correct deficiencies more quickly. The alert also said cyberattacks against community water systems are increasing in frequency and severity across the country, and that a successful intrusion could allow an adversary to manipulate operational technology.

That warning lines up with subsequent federal reviews. The Government Accountability Office testified in June 2026 that the U.S. water and wastewater sector includes close to 170,000 systems and remains exposed to persistent cyber threats. GAO said recent incidents and security alerts continue to highlight vulnerabilities across the sector and that EPA remains the lead federal agency responsible for coordinating cybersecurity risk reduction for water utilities.

The latest warnings have been reinforced by real-world incidents. Federal and state officials have recently investigated cyberattacks affecting water and wastewater utilities in multiple states, including a 2026 campaign that news reports said reached at least a dozen states. According to federal advisories and reporting cited by Axios and the Associated Press, some affected utilities shifted to manual operations, while officials said drinking water in the reported areas remained safe.

What is not yet known in many cases is the full state-by-state scope of exposure. Utilities and investigators often do not immediately release a comprehensive list of affected systems, and in many states there is no public inventory showing which operators have remediated older weaknesses such as internet-exposed control devices or poor account management. That means residents may know the national numbers without knowing whether nearby systems have closed the same gaps.

The sector’s structure adds to that uncertainty. Many water systems are owned or operated by local governments, and smaller communities often depend on limited technical staff and aging industrial control technology. As a result, confirmed national weakness does not automatically mean a specific utility has been breached, but federal agencies have made clear that no state should assume it is insulated.

GAO said in its 2024 report and 2026 testimony that the water sector faces increasing cyber risk while EPA has lacked a complete sectorwide cybersecurity strategy and has not fully evaluated whether its legal authorities are sufficient for the problem. The watchdog also said EPA needed to improve the credibility of a key risk-assessment tool used by utilities. Those findings point to a broader issue than a single software flaw or isolated attack: the sector’s defenses have been uneven, and the federal framework overseeing them has also been under review.

EPA has responded by increasing inspections, publishing technical resources, and directing utilities to adopt baseline steps such as stronger authentication, better asset inventories, and reduced exposure of operational technology to the public internet. NIST also published new water-sector cybersecurity guidance in 2026 aimed at helping utilities strengthen protection for operational and information systems.

For residents, the immediate message is that water quality is not automatically compromised when a cyber incident is reported, but service disruptions, manual operations, and precautionary notices can occur while systems investigate or recover. EPA has said it will continue stepping up inspections and enforcement, meaning more utilities are likely to face pressure to document and fix cybersecurity weaknesses before a larger disruption occurs.

LEAVE A REPLY

Please enter your comment!
Please enter your name here