AI-generated analysis ยท Water and Wastewater Systems ยท 3 min read

Small water utilities: EPA's checklist turns cybersecurity into one measurable fix

EPA's checklist lets water systems serving fewer than 50,000 people pick one cybersecurity practice, prove it and improve it.

The post

Background briefing. EPA's Small System Risk and Resilience Assessment Checklist is intended for water and wastewater systems serving fewer than 50,000 people. Its July 2024 drinking-water checklist added a table of priority cybersecurity practices based on CISA's cross-sector goals. It also combined business-system and process-control cyberattacks into a single threat category. [1]

Context

EPA's checklist is scoped for systems serving fewer than 50,000 people. [1] At that size, the same small team may run both the office systems and the treatment process. The July 2024 update matters because it puts cybersecurity practices into an assessment utilities may already be doing, rather than asking for a separate program. [1]

Treating business-system and process-control attacks as one threat category [1] reflects the same idea found across critical infrastructure guidance: the office network and the plant network are connected, so they fail together. The international OT principles also emphasize knowing which systems are vital and what recovery requires. [2]

Exposed: drinking-water and wastewater systems serving fewer than 50,000 people, along with the communities that depend on them. Drinking-water and wastewater guidance is separate, and the two shouldn't be assumed to carry identical obligations. [1]

What changes is how progress is measured. Instead of a vague goal to 'improve cybersecurity', a utility can pick one listed practice and record the evidence, the gap, the owner and a review date.

The checklist is available now, and the exercise needs no new tools. Start with document review before considering any testing of operational equipment.

Analyst thread

Bottom line

Small water systems have a federal checklist with priority cybersecurity practices built in. Start with one practice you can verify.

Whether each checklist answer has an owner, evidence and a review date, and whether unknowns stay marked as unknown.

One completed item is not a full risk assessment or proof of compliance. This thread does not evaluate any utility.

Sources

  1. [1] Small System Risk and Resilience Assessment Checklist, U.S. Environmental Protection Agency. Intended scope and July 2024 drinking-water checklist updates; separate wastewater guidance
  2. [2] Principles of operational technology cyber security โ€” Quick reference guide, ASD ACSC and international partners; hosted by FBI IC3. Page 1: six principles; safety and recovery requirements