Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

    • Environmental Topics
    • Air
    • Bed Bugs
    • Cancer
    • Chemicals, Toxics, and Pesticide
    • Emergency Response
    • Environmental Information by Location
    • Health
    • Land, Waste, and Cleanup
    • Lead
    • Mold
    • Radon
    • Research
    • Science Topics
    • Water Topics
    • A-Z Topic Index
    • Laws & Regulations
    • By Business Sector
    • By Topic
    • Compliance
    • Enforcement
    • Laws and Executive Orders
    • Regulations
    • Report a Violation
    • Environmental Violations
    • Fraud, Waste or Abuse
    • About EPA
    • Our Mission and What We Do
    • Headquarters Offices
    • Regional Offices
    • Labs and Research Centers
    • Planning, Budget, and Results
    • Organization Chart
    • EPA History

Breadcrumb

  1. Home
  2. Water Resilience
  3. Cybersecurity

Cybersecurity Planning

cybersecurity conference room

Find valuable resources to support creating a response plan for cybersecurity incidents. 

On this page:

  • Addressing Cybersecurity in your America’s Water Infrastructure Act Emergency Response Plan
  • Top 8 Cyber Actions for Securing Water Systems 
  • Cybersecurity Incident Action Checklist
  • Water and Wastewater Sector Incident Response Guide
  • Water Sector Cybersecurity Program Case Studies
  • Cybersecurity Insurance Considerations
  • Other US Government and Partner Cybersecurity Resources

Addressing Cybersecurity in your America’s Water Infrastructure Act Emergency Response Plan

Safe Drinking Water Act (SDWA) section 1433, which was amended by America’s Water Infrastructure Act (AWIA) section 2013 in 2018, requires community water systems (CWS) serving more than 3,300 people to prepare or revise risk emergency response plans (ERPs) and certify to EPA that this work has been completed. SDWA section 1433(b) states that ERPs must “incorporate findings of the [risk and resilience] assessment’ and “shall include strategies and resources to improve the resilience of the system, including…cybersecurity.” The ERP must address the overall cybersecurity resilience of the water system and vulnerabilities found in the cybersecurity assessment portion of the RRA. A utility must incorporate the steps of preparing for, responding to, and recovering from a cyber incident in the ERP. To address cybersecurity concerns in the Emergency Response Plan, a utility can start with the Cybersecurity Incident Action Checklist.

Top 8 Cyber Actions for Securing Water Systems

The Top 8 Cyber Action Fact Sheet highlights the top cyber actions water systems can take today to reduce cyber risk and improve resilience to cyberattacks and provides free services, resources, and tools to support these actions, which can be taken concurrently.

  • Principales acciones cibernéticas para proteger los sistemas hídricos (pdf) (353.85 KB, 2/23/2024) (Spanish Version)

Cybersecurity Incident Action Checklist

Cybersecurity Incident Action Checklist (pdf) (689.82 KB, December 2024, 810-B-17-004) : This resource provides on-the-go convenience, to help utilities prepare for, respond to, and recover from a cyber incident through a checklist of activities. The checklist can be added to an Emergency Response Plan to address cybersecurity response. 

Water and Wastewater Systems Sector Federal Roles and Resources for Cyber Incident Response

Water and Wastewater Sector Incident Response Guide (pdf): This guide, co-sealed by CISA, EPA, and FBI, outlines how water and wastewater utility owners and operators can expect to work with federal partners as they prepare for, respond to, and mitigate the impact of a cyber incident.

Water Sector Cybersecurity Program Case Studies

  • Small Combined System (pdf) (178.11 KB, April 2024, 817-F24-001)
  • Small Wastewater System (pdf) (283.59 KB, 09/2023, 817-F23-003)
  • Medium Drinking Water System (pdf) (192.17 KB, 09/2023, 817-F23-004)
  • Medium Drinking Water System #2 (pdf) (258.68 KB, December 2023, 817-F23-007)
  • Medium Combined System (pdf) (203.87 KB, 12/2023, 817-F23-005)
  • Large Combined System (pdf) (204.75 KB, 10/13/2023, 817-F23-008)

Cybersecurity Insurance Considerations

  • Cyber Insurance for Drinking Water and Wastewater Systems (pdf) (705.38 KB, October 2024, 810-F-24-31)
Average costs for all claims figure
Source: NetDiligence-Cyber-Claims-Study-2024-Report-1

Other US Government and Partner Cybersecurity Resources

  • CISA Water and Wastewater Cybersecurity offers significant resources, guidance, and tools to assist critical infrastructure facilities, including water and wastewater systems, with cybersecurity.
  • United States Department of Agriculture (USDA) Rural Development Circuit Rider Program
  • Water Information Sharing and Analysis Center (WaterISAC)
  • Presidential Policy Directive 41:  Information on roles that government agencies will perform in the event of a cybersecurity incident.
  • Industrial Control Systems Cybersecurity Initiative (pdf) (178.16 KB):  Considerations for ICS/OT Monitoring Technologies with an Emphasis on Detection and Information Sharing.

Water Resilience

  • Basics of Water Resilience
  • Water Resilience Tools
  • America's Water Infrastructure Act (AWIA)
    • AWIA Section 2013
    • AWIA Section 2018
  • Cybersecurity
    • Cybersecurity Assessments
    • Cybersecurity Planning
    • Cybersecurity Exercises and Technical Assistance
    • Cybersecurity Response
    • Cybersecurity Funding
  • Contamination
  • Supply Chain Resilience
    • Chemical Suppliers and Manufacturers Locator Tool
    • Defense Production Act
    • Safe Drinking Water Act Section 1441
  • Interdependencies
    • Emergency Services Sector
    • Energy Sector
    • Healthcare Sector
  • Preparedness Exercises
  • EPA Events
Contact Us about Water Resilience
Contact Us to ask a question, provide feedback, or report a problem.
Last updated on December 30, 2024
  • Assistance
  • Spanish
  • Arabic
  • Chinese (simplified)
  • Chinese (traditional)
  • French
  • Haitian Creole
  • Korean
  • Portuguese
  • Russian
  • Tagalog
  • Vietnamese
United States Environmental Protection Agency

Discover.

  • Accessibility Statement
  • Budget & Performance
  • Contracting
  • EPA www Web Snapshot
  • Grants
  • No FEAR Act Data
  • Plain Writing
  • Privacy
  • Privacy and Security Notice

Connect.

  • Data
  • Inspector General
  • Jobs
  • Newsroom
  • Regulations.gov
  • Subscribe
  • USA.gov
  • White House

Ask.

  • Contact EPA
  • EPA Disclaimers
  • Hotlines
  • FOIA Requests
  • Frequent Questions
  • Site Feedback

Follow.