Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Free Cyber ServicesSecure by design Secure Our WorldShields UpReport A Cyber Issue

Cybersecurity & Infrastructure Security Agency logo America’s Cyber Security Defense Agency National Coordinator For Critical Infrastructure Security and ResilienceCybersecurity & Infrastructure Security Agency logo America’s Cyber Security Defense Agency National Coordinator For Critical Infrastructure Security and Resilience
CISA Logo

Search

 

America's Cyber Defense Agency
 
  • Topics
    Cybersecurity Best Practices
    Cyber Threats and Advisories
    Critical Infrastructure Security and Resilience
    Election Security
    Emergency Communications
    Industrial Control Systems
    Information and Communications Technology Supply Chain Security
    Partnerships and Collaboration
    Physical Security
    Risk Management
    How can we help?
    GovernmentEducational InstitutionsIndustryState, Local, Tribal, and TerritorialIndividuals and FamiliesSmall and Medium BusinessesFind Help LocallyFaith-Based CommunityExecutivesHigh-Risk Communities
  • Spotlight
  • Resources & Tools
    All Resources & Tools
    Services
    Programs
    Resources
    Training
    Groups
  • News & Events
    News
    Events
    Cybersecurity Alerts & Advisories
    Directives
    Request a CISA Speaker
    Congressional Testimony
    CISA Conferences
    CISA Live!
  • Careers
    Benefits & Perks
    HireVue Applicant Reasonable Accommodations Process
    Hiring
    Resume & Application Tips
    Students & Recent Graduates
    Veteran and Military Spouses
  • About
    Divisions & Offices
    Regions
    Leadership
    Doing Business with CISA
    Site Links
    CISA GitHub
    CISA Central
    Contact Us
    Subscribe
    Transparency and Accountability
    Policies & Plans

Free Cyber ServicesSecure by design Secure Our WorldShields UpReport A Cyber Issue

Breadcrumb
  1. Home
  2. Topics
  3. Critical Infrastructure Security and Resilience
  4. Water and Wastewater Cybersecurity
Share:
Image of water in dam and seal for CISA and the EPA.

Water and Wastewater Cybersecurity

Report a Cyber Issue
Organizations should report anomalous cyber activity and or cyber incidents 24/7 to report@cisa.gov or 1-844-Say-CISA.

Introduction

Americans rely on the supply of safe drinking water and wastewater treatment every hour of every day for personal use as well as for supporting other critical infrastructure sectors and the nation’s economy. The Water and Wastewater Sector depends on the digital world, leveraging technology for monitoring, operations and communicating with customers. Any disruption to a drinking water or wastewater system digital ecosystem could have significant impacts to the community its serves as well as to other critical infrastructure.

The Cybersecurity and Infrastructure Security Agency (CISA) and the Environmental Protection Agency (EPA) developed the toolkit below to highlight the most relevant CISA and EPA resources to protect against, and reduce impacts from, threats posed by malicious cyber actors looking to attack water and wastewater systems. CISA brings technical expertise as the nation’s cyber defense agency and EPA, as the Sector Risk Management Agency, offers extensive sector expertise and resources.

Fact Sheet: Top Actions For Securing Water Systems

How to Use this Toolkit

This toolkit consolidates key resources for water and wastewater systems at every level of cybersecurity maturity. For organizations that are just starting to develop their cybersecurity strategies, the fundamental cyber hygiene steps are basic, low or no cost steps that every organization and individual should take to improve their security. The toolkit can help water and wastewater systems build their cybersecurity foundation and progress to implement more advanced, complex tools to strengthen their defenses and stay ahead of current threats.

CISA and EPA are providing this toolkit because cybersecurity is one of many areas where the Water and Wastewater Sector faces persistent challenges. The toolkit provides resources to enable sector stakeholders to proactively assess vulnerabilities and implement solutions to reduce risk and increase resilience. CISA and EPA will update the toolkit periodically to include new resources and respond to the evolving needs of the sector.

A photo of a water system

Free Cyber Vulnerability Scanning for Water Utilities

CISA's Free Cyber Vulnerability Scanning for Water Utilities fact sheet explains the process and benefits of signing up for CISA’s free vulnerability scanning program.

Hands typing on a laptop with a design on top of the image featuring a multiple safety locks.

EPA Water Resilience Cybersecurity Help Desk

EPA’s help desk is available 24/7 and responds to water cyber inquiries within two days. The help desk provides guidance to help prevent, detect, respond to and recover from cyber incidents.

A hand holding multiple technology devices

EPA Free Cybersecurity Assessment Service

EPA conducts free cyber assessment for drinking water and wastewater utilities using EPA’s Cybersecurity Checklist derived from CISA’s CPGs. Utilities receive a summary report and a Risk Management Plan to help in prioritizing cybersecurity efforts.

A graphic that says "Cybersecurity Performance Goals"

Cross-Sector Cybersecurity Performance Goals

Cybersecurity Performance Goals are a common set of protections that all critical infrastructure entities - from large to small - should implement to meaningfully reduce the likelihood and impact of known risks and adversary techniques.

cybersecurity abstract image

EPA Cybersecurity for the Water Sector

EPA has a wide range of services and tools to help drinking water and wastewater systems increase their cybersecurity, including assessments, planning, training and response. 

Incident Response Guide Water and Wastewater Sector. Seals of CISA, the EPA, and the DOJ.

Water and Wastewater Systems Sector Federal Roles and Resources for Cyber Incident Response

This guide outlines how water utility owners and operators can collaborate with federal partners as they prepare for, respond to and mitigate the impact of a cyber incident.

STOP Ransomware logo

CISA Stop Ransomware Resources

CISA provides best practices and guidance to water entities to reduce the impact and likelihood of ransomware incidents and data extortion. 

Secure Our World graphic

Recognize and Avert Phishing Attempts

Secure Our World provides numerous tools and resources to help keep water systems safe online, including teaching employees to avoid phishing.

Dollar sign within gear

Funding

There are several resources drinking water and wastewater systems can use to increase their cyber resilience, including the Clean Water State Revolving Fund, Drinking Water State Revolving Fund, and CISA State and Local Cybersecurity Grant Program.

Share Information and Report Cyber Incidents

Voluntarily sharing information about cyber-related events that threaten critical infrastructure organizations is critical to creating a better, more holistic understanding of the threat environment in the Water and Wastewater Sector. Reporting incidents enables CISA to rapidly deploy resources and render assistance to impacted entities and quickly share that information to warn potential victims and prevent future attacks.

Report suspicious activity such as:

  • Unauthorized access to systems
  • Email or mobile messages associated with phishing attempts or successes
  • Ransomware incidents
Report
CISA Regional Map

Connect with CISA's Regional Team for Cyber and Physical Services

CISA offers a range of cyber and physical services to support the security and resilience of critical infrastructure owners and operators - including water and wastewater systems - and state, local, tribal and territorial partners. 

Connect with Us

Related Resources

Three people inspecting dam

EPA Water and Wastewater Resilience

EPA has extensive tools, resources, and training for drinking water and wastewater systems on emergency preparedness and response and physical and cyber resilience.

Encircled padlock with phone, shield, laptop, monitor figures containing padlock.

Explore Additional Resources from CISA for Physical Security

This toolkit focuses primarily on cybersecurity resources, but CISA has a wide array of offerings to help the Water and Wastewater Sector and other critical infrastructure organizations improve their security and resilience.

man with laptop at factory

Priority Telecommunications Services

Ensuring Priority Telecommunications Services (PTS) for water and wastewater utilities is vital during a crisis. Priority Services provides three priority telecommunications services to ensure uninterrupted communication.

Shields Ready

Shields Ready

Learn more about making resilience during incidents a reality by taking action before incidents occur.

Text of Secure by Design on grid background in a colorful isometric design

Secure by Design

It's time to build cybersecurity into the design and manufacture of technology products. Find out here what it means to be secure by design.

3D image of microchip on glowing, digital, blue, circuit board

Artificial Intelligence

As the nation’s cyber defense agency and the national coordinator for critical infrastructure security and resilience, CISA plays a key role in addressing and managing risks at the nexus of AI, cybersecurity and critical infrastructure.

ChemLock logo

ChemLock

CISA's ChemLock program is a voluntary program that provides facilities that possess dangerous chemicals no-cost services and tools to help them better understand the risks they face and improve their chemical security posture.

Advisories, Alerts, and Other Information

EPA Cyber Alerts

Sign up to receive EPA Water Sector alerts.

CISA Cybersecurity Alerts and Advisories

View and search CISA’s Cybersecurity Alerts and Advisories.

Automated Indicator Sharing

CISA’s Automated Indicator Sharing (AIS) platform provides a public feed for real-time sharing of cyber threat indicators and defensive measures.

Water and Wastewater Systems

The Water and Wastewater System page provides sector information and resources such as the sector specific plan and roadmap.

EPA Webinar on Recent Unitronics Programmable Logic Controllers Hacked at US Water and Wastewater Systems

Speakers from the EPA, CISA and the Federal Bureau of Investigation (FBI) discuss the hacks and recommended mitigations.

Subscribe to Updates

Subscribe through GovDelivery for email updates from CISA.

Subscribe

Follow Us!

Follow Us!
facebook twitter youtube instagram linkedin
Return to top
  • Topics
  • Spotlight
  • Resources & Tools
  • News & Events
  • Careers
  • About
Cybersecurity & Infrastructure Security Agency
  • Facebook
  • X
  • LinkedIn
  • YouTube
  • Instagram
  • RSS
CISA Central 1-844-Say-CISA SayCISA@cisa.dhs.gov
DHS Seal
CISA.gov
An official website of the U.S. Department of Homeland Security
  • About CISA
  • Budget and Performance
  • DHS.gov
  • FOIA Requests
  • No FEAR Act
  • Office of Inspector General
  • Privacy Policy
  • Subscribe
  • The White House
  • USA.gov
  • Website Feedback