Cybersecurity is increasingly part of the water sanitary survey, not through a single federal mandate but through state primacy programs, EPA voluntary guidance, and the AWIA risk and resilience requirements. The federal rule that tried to require it was withdrawn, but the direction of travel is clear, and preparing for it is straightforward.
The regulatory state of play
Under the Safe Drinking Water Act, state primacy agencies conduct periodic sanitary surveys of public water systems. In March 2023 the EPA issued a memo directing that these surveys evaluate operational technology cybersecurity. That memo was withdrawn in October 2023 after a legal challenge. What did not go away is the underlying concern: states are adding cybersecurity to their own survey programs, EPA continues to offer voluntary assessments and technical assistance, and AWIA already requires larger systems to assess electronic control systems. In practice, expect cybersecurity to come up.
What a survey looks at in your OT
The questions cluster around access and segmentation:
- Remote access into the SCADA network: is it a flat VPN, or controlled and recorded?
- Segmentation between business IT and the control network.
- Who can reach PLCs and HMIs, and whether that access is identity-bound and logged.
- Default or shared credentials on control-system accounts.
- Detection and response: could you tell what happened after an incident?
How to prepare
Start with the highest-impact move: put an on-premise access gateway in front of the control network so remote access is controlled, recorded, and logged. Segmenting OT from IT and clearing shared credentials are complementary steps, not something the gateway does on its own. See the NY water cybersecurity field guide for the practical version, and note that for many systems this work is grant-eligible.