Join our Newsletter — 33% off our NHI Course

What are the signs that a public water system is not ready for the EPA’s new cybersecurity expectations?

Common warning signs are no formal cybersecurity program, no regular vulnerability review, no patching cadence, and no clear way to document controls during sanitary surveys. A system may also be underprepared if it lacks internal expertise and cannot identify an approved assessor or support path. These gaps usually show that compliance will be difficult to sustain.

How to tell a public water system is behind the EPA’s cybersecurity expectations

The clearest signal is not a single missing control, but an absence of repeatable security operations. If a system cannot show a formal program, current vulnerability review, patch cadence, or evidence during sanitary surveys, it is probably treating cybersecurity as an ad hoc task rather than a managed obligation. That usually means the system is not ready to demonstrate compliance under scrutiny.

Readiness also depends on whether the system can translate controls into proof. In practice, the question is not just “do we do the work?” but “can we document it, defend it, and sustain it when regulators ask?”

What operational gaps usually expose underprepared systems?

Most underprepared systems fail in the same few places: they have no defined ownership, no consistent review cycle, and no way to keep patches, inventories, and control evidence aligned. A program that exists only informally tends to break down when staff change, vendors are involved, or a sanitary survey requires a quick answer.

Another common gap is limited internal capability. If the system cannot identify who will assess controls, interpret findings, or support remediation, then even basic requirements become difficult to sustain. That is especially true when cybersecurity knowledge is concentrated in one person or borrowed from another function without clear accountability.

Public water systems also tend to struggle when cybersecurity is separated from day-to-day operations. If patching, asset review, and access oversight are not tied to maintenance and risk tracking, the program may look acceptable on paper while remaining weak in practice. For a broader model of how basic controls should be organized, the NIST Cybersecurity Framework 2.0 is a useful reference point because it aligns governance, identification, protection, detection, response, and recovery.

What does failure to meet the new expectations look like in practice?

Failure usually shows up as inconsistency rather than drama. One month there is a patch review, the next month there is no record. One operator knows where the controls live, but no one else can explain them. That pattern is a warning that the system may pass a conversation but fail an audit trail.

It is also a problem when the system relies on informal troubleshooting instead of a documented process for vulnerability handling. If a weakness is found but there is no assigned owner, no deadline, and no evidence of closure, then the system has not yet built the operational discipline regulators expect.

In utility environments, external advisories and exploitation trends matter because exposed or unpatched systems can quickly move from “not ready” to “actively at risk.” Public-sector operators should watch CISA’s Known Exploited Vulnerabilities Catalog and related CISA cyber threat advisories because those sources help distinguish routine backlog from issues with real exploitation pressure.

Risk and Threat Considerations

When a public water system lacks program structure, the risk is not only noncompliance, it is exposure to operational disruption and poor recovery from a real incident. Weak documentation, slow patching, and unclear ownership also make it easier for a compromise to persist unnoticed or for a regulator to view the control environment as unreliable.

Failure mechanism: the system has gaps in governance, asset visibility, and vulnerability closure, so weaknesses remain untracked or unproven during review, and an attacker or routine failure can exploit the delay.

Impact: the system may lose the ability to demonstrate control, respond quickly, and sustain compliance, which raises both safety and service continuity concerns.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 provides the primary governance reference for this topic.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context Water-system cybersecurity readiness depends on defined ownership and operational context.
GV.RM-01 — Risk Management Strategy The question centers on whether cybersecurity is managed as a repeatable program.
PR.PS-01 — Configuration Management Patch cadence and control evidence depend on controlled system configuration and maintenance.
Recommendation — Define cybersecurity ownership and responsibilities for the water system. Set a risk-based cybersecurity program with recurring review and remediation. Maintain a disciplined patch and configuration management process.

Practitioner Guidance

What to verify: confirm that the system can produce a current program owner, a vulnerability review cadence, a patching workflow, and evidence of closure for the most recent issues. If any of those items depends on one person or an outside party with no documented backup, treat readiness as fragile rather than established.

What good looks like: the system can answer a sanitary survey with dated records, clear responsibility, and a simple explanation of how findings move from discovery to remediation to verification. That is the practical test, not whether the team can describe cybersecurity in general terms.

Practitioner takeaway: the strongest indicator of readiness is not policy language, it is whether the system can repeatedly prove control, ownership, and follow-through under external review.