EPA calls off cyber regulations for water sector
Full article978 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The announcement is a major blow to the Biden administration's efforts to improve the cybersecurity of U.S. critical infrastructure.
In a major blow to the Biden administration’s efforts to improve the cybersecurity defenses of critical infrastructure, the Environmental Protection Agency will no longer require cybersecurity audits of U.S. water utilities through sanitary surveys.
In a letter to state drinking water administrators on Thursday, the EPA said litigation from Republican states and trade associations, which raised questions about the long-term legal viability of the initiative to regulate the cybersecurity of water utilities, drove the decision to rescind a March memorandum implementing the rule.
The announcement represents a major setback to the White House’s efforts to add more stringent cyber mandates to critical infrastructure sectors. The Biden administration’s National Cybersecurity Strategy described improving the digital defenses of critical infrastructure as a key priority.
Owners and operators of these systems are struggling to combat the deluge of ransomware and state-backed attacks and infiltration of the nation’s most sensitive networks. For critical infrastructure sectors, the consequences for a major cyberattack can be dire, and U.S. water utilities have been identified as particularly lacking in security.
“While the memorandum is being withdrawn due to litigation, improving cybersecurity across the water sector remains one of EPA’s highest priorities,” an EPA spokesperson said in a statement. “Cybersecurity represents a serious and increasing threat to drinking water and wastewater utilities.”
EPA said it encourages “all states to voluntarily review public water system cybersecurity programs to ensure that any vulnerabilities are identified and corrected, and assistance is provided to systems that need help.”
The decision to withdraw the EPA’s cybersecurity rule was first reported by the Messenger.
The withdrawal of the rule does not bode well for future efforts to harmonize regulations among the existing 16 critical infrastructure sectors. Many critical infrastructure sectors like water and wastewater lack cybersecurity regulations. Using a voluntary approach to regulate cybersecurity in these industries was described in the National Cybersecurity Strategy as resulting in “inadequate and inconsistent outcomes.”
Using the EPA to regulate the cybersecurity of water utilities represented a creative piece of policymaking by the Biden administration, but the effort to do so has been controversial from the start, with the water industry loudly opposing the use of EPA’s existing authorities to add cybersecurity regulations. Some experts questioned whether sanitary survey was the right tool to enforce cybersecurity mandates, as the process traditionally does not involve auditors who understand the complex nature of protecting industrial systems.
A month after the rule was issued, Missouri, Arkansas and Iowa sued to block the EPA from enforcing cybersecurity rules via sanitary checks. The U.S. Court of Appeals for the Eight Circuit stayed the measure from being implemented while it was litigated.
In a statement, the American Water Works Association and the National Rural Water Association — both of which were involved in the lawsuit causing the rule to be blocked — said they were “pleased with the decision and have renewed their call for a collaborative approach to cybersecurity measures in the water sector.”
The two trade groups renewed their call for a co-regulatory model inspired by the electric sector, which would give the EPA oversight and auditing authority of standards developed in collaboration with industry.
The EPA has faced criticism for not being up to the task of protecting the nation’s water and wastewater systems and some have suggested creating a new Department of Water to take on the task.
More Scoops
In most cities, nobody owns the whole network
July’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions…
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/epa-calls-off-cyber-regulations-for-water-sector/