TroutTrout
Back to Blog
WaterCompliance

Cybersecurity in the EPA Sanitary Survey: What to Expect

Trout Team2 min read

Cybersecurity is increasingly part of the water sanitary survey, not through a single federal mandate but through state primacy programs, EPA voluntary guidance, and the AWIA risk and resilience requirements. The federal rule that tried to require it was withdrawn, but the direction of travel is clear, and preparing for it is straightforward.

The regulatory state of play

Under the Safe Drinking Water Act, state primacy agencies conduct periodic sanitary surveys of public water systems. In March 2023 the EPA issued a memo directing that these surveys evaluate operational technology cybersecurity. That memo was withdrawn in October 2023 after a legal challenge. What did not go away is the underlying concern: states are adding cybersecurity to their own survey programs, EPA continues to offer voluntary assessments and technical assistance, and AWIA already requires larger systems to assess electronic control systems. In practice, expect cybersecurity to come up.

What a survey looks at in your OT

The questions cluster around access and segmentation:

  • Remote access into the SCADA network: is it a flat VPN, or controlled and recorded?
  • Segmentation between business IT and the control network.
  • Who can reach PLCs and HMIs, and whether that access is identity-bound and logged.
  • Default or shared credentials on control-system accounts.
  • Detection and response: could you tell what happened after an incident?

How to prepare

Start with the highest-impact move: put an on-premise access gateway in front of the control network so remote access is controlled, recorded, and logged. Segmenting OT from IT and clearing shared credentials are complementary steps, not something the gateway does on its own. See the NY water cybersecurity field guide for the practical version, and note that for many systems this work is grant-eligible.

FAQ

Frequently Asked Questions

Is cybersecurity required in the EPA sanitary survey?
Not as a single federal mandate. The EPA's March 2023 memo requiring cybersecurity in sanitary surveys was withdrawn in October 2023 after a legal challenge. But cybersecurity is still entering surveys through state primacy programs, EPA voluntary guidance and technical assistance, and the AWIA risk and resilience requirements. Treat it as expected, not optional.
What do surveyors look at for OT cybersecurity?
The recurring themes are remote access into the SCADA network, whether the control network is segmented from business IT, who can reach PLCs and HMIs and whether that access is controlled and logged, default or shared credentials, and whether there is a way to detect and respond to an incident.
How do you prepare a small system for a cybersecurity survey?
Control and record remote access, segment OT from IT, remove shared credentials, and keep evidence you can show. An on-premise access gateway solves the remote-access and access-logging findings; segmentation, removing shared credentials, and detection are separate steps. The work is often grant-eligible.