Water utility cyber compliance risk after Minnesota hack
- Authority
- U.S. Environmental Protection Agency
- Rule type
- statute
- Jurisdiction scope
- US federal
- Source text
- Read primary rule text ↗
Community water systems must complete and certify SDWA §1433 cybersecurity risk and resilience assessments and emergency response plans, and address identified risks.
The legal question after the July 2026 Minnesota water-system attacks is not whether every fact is now settled. It is what a utility can prove it had already done before an operator was locked out, a controller was exposed, or a public notice had to be drafted. The FBI and EPA described malicious actors targeting internet-facing programmable logic controllers in the water and wastewater sector and causing operational disruptions; CISA separately urged utilities to remove exposed systems from the internet; Minnesota IT Services said it was responding to cyber incidents affecting municipal water systems in the state.[1][2][3]
Attribution should stay where the primary sources leave it. Federal and state notices support a finding of targeted activity against water and wastewater controls, not a confirmed public attribution to Iran or any other government. That distinction matters less for most utility exposure analyses than it does for headlines. A negligence complaint, an insurer’s reservation of rights, or an EPA information request will start with the condition of the utility’s own controls, assessments, certifications, and remediation record.

That is why the Minnesota incidents matter even before the post-incident facts are complete. They landed on a documented compliance record. In May 2024, EPA’s Office of Enforcement and Compliance Assurance warned that, since September 2023, more than 70% of inspected drinking water systems had violated basic Safe Drinking Water Act Section 1433 cybersecurity requirements.[4] That number is not a prediction about future rulemaking. It is an inspection-based enforcement finding.
The failed 2023 memo is not a free pass
The most tempting wrong answer after Minnesota is that EPA tried to regulate water cybersecurity in 2023, lost the fight, withdrew the memo, and therefore left utilities in a standards vacuum. The chronology is real, but that conclusion is too broad.
EPA issued a March 3, 2023 memorandum directing states to evaluate cybersecurity during sanitary surveys of public water systems. The Eighth Circuit stayed the memorandum in July 2023, and EPA withdrew it in October 2023.[5] Counsel should be precise about what fell with that memo: EPA did not finalize a new cybersecurity rule through that path, and the sanitary-survey approach did not survive.
But the withdrawal did not repeal the America’s Water Infrastructure Act amendments to SDWA Section 1433. Community water systems above the statutory threshold still had risk-and-resilience assessment and emergency-response-plan duties, including certification duties. EPA’s May 2024 enforcement alert treated failures to assess cybersecurity risks, address identified risks, and certify required work as enforceable matters under existing law.[4]

For a utility lawyer, that distinction controls the file review. The question is not, “Did EPA’s 2023 memo survive?” It is, “Which SDWA Section 1433 duties applied to this system, what did the utility certify, what risks were identified, and what remained unresolved when the July 2026 attacks occurred?”
The companion status tracker, Legal Response to Iran-Linked Minnesota Water Cyberattacks, is the better place for a full map of currently binding duties. The point here is narrower: after Minnesota, a utility that treated the 2023 memo’s withdrawal as permission to defer cyber work has a proof problem.
How exposure forms under existing water-law duties
A water utility’s post-incident exposure starts with ordinary documents, not malware analysis. Counsel needs the risk-and-resilience assessment, the emergency response plan, the certifications submitted to EPA, board materials approving or deferring cyber work, outside assessment reports, vulnerability scans, incident logs, remote-access inventories, and any correspondence with state primacy agencies or EPA.
EPA’s 2024 alert identified common failures that are easy to understand in a courtroom or enforcement conference: default passwords, single logins shared by multiple employees, former employees retaining access, vulnerable equipment connected to the internet, and missing cybersecurity elements in risk assessments or emergency response plans.[4] None of those allegations requires a novel theory of critical-infrastructure law. They are the kind of conditions that make a regulator ask why they survived the last assessment cycle.
| Counsel’s first question | Why it matters after Minnesota |
|---|---|
| Was the system subject to SDWA Section 1433 risk-and-resilience and emergency-response-plan duties? | If yes, the file review starts with statutory obligations and certifications, not with EPA’s withdrawn 2023 sanitary-survey memo. |
| Did the assessment actually address cybersecurity risks to operational technology, remote access, and internet-facing controls? | A generic emergency plan is weak evidence if the incident involved exposed controls or operator lockout. |
| Were identified cyber risks remediated, accepted, deferred, or ignored? | The legal consequence often turns on documented decision-making, funding choices, and follow-through. |
| Who knew which systems were exposed before July 2026? | Foreseeability arguments become sharper when notices, scans, vendors, or prior assessments identified the same class of weakness. |
| What notices were made, and to whom? | Current state obligations, contract duties, insurance conditions, and future CIRCIA obligations may all depend on incident reporting facts. |
That review should include small, unglamorous records. A stale asset inventory may matter more than a board presentation about national cyber threats. A maintenance vendor’s remote-access credential may matter more than a threat-intelligence label. If a utility cannot say which controllers were internet-facing, who could access them, and when those facts were last checked, counsel should assume the missing record will be treated as part of the exposure.
The authority gap limits EPA, but it does not erase risk
GAO’s water-sector work is useful because it prevents overstatement. The sector is fragmented, with about 170,000 public water systems, and GAO has reported significant limitations in EPA’s authority over wastewater systems and many small drinking water systems.[5] GAO’s May 2026 work continued to identify the open authority question for EPA in this area.[6]
That limitation is not a reason to tell a client that the risk is theoretical. It changes the route by which pressure arrives. For some utilities, EPA may be the direct enforcement concern. For others, the more immediate risk may come from a state drinking-water regulator, a state cybersecurity office, a public-utility commission, a municipal insurer, a bond disclosure review, or a plaintiff using federal alerts and GAO reports to argue that the utility knew the risk class was foreseeable.
The authority gap may also push state action. A state does not need to wait for a new federal rule before asking why a public water system left operational controls exposed or failed to update an emergency response plan. After a local service disruption, the political appetite for treating those questions as paperwork questions usually disappears.
The earlier enforcement-history companion, Why the US legal response to Iran's water cyberattacks lags, explains why federal water-cyber authority has developed unevenly. For exposure purposes, uneven authority is not the same as no standard of care.
What likely accelerates after the July 2026 attacks
The Minnesota incidents give regulators and plaintiffs a cleaner story than abstract cyber-risk warnings ever did. Public water systems were warned about internet-facing controls; federal agencies issued sector-specific notices; operators and municipalities faced operational disruption; and EPA already had an inspection record showing widespread noncompliance with basic SDWA Section 1433 cyber duties.[1][2][3][4]
EPA inspections are the first acceleration point. EPA’s May 2024 alert already instructed drinking water systems to review cybersecurity practices and warned that noncompliance may result in enforcement.[4] After Minnesota, an inspector or enforcement attorney can ask more pointed questions about exposed controls, remote access, shared credentials, and whether the emergency response plan had any practical cyber component. A utility should not expect the collapsed 2023 memo to answer those questions.
State action is the second. GAO’s authority findings make it foreseeable that federal gaps will be filled unevenly by states rather than cured all at once by Congress or EPA.[5][6] State regulators can tighten sanitary-survey expectations, add cyber questions to inspection practice, require incident notification through state channels, condition grants on cyber controls, or use emergency authority after a disruption. Those moves may not look like one national water-cyber regime, but they still create a record against which individual utilities will be judged.
CIRCIA is the third, but it must be described carefully. The final rule was expected in September 2026 under the Unified Agenda as reported in July 2026; that is an expected rulemaking milestone, not a final rule already in force.[7] Once final reporting obligations apply, covered critical-infrastructure entities that fail to report may face CISA requests for information, subpoenas, DOJ referral, and false-statement exposure, including potential imprisonment of up to five years, or up to eight years with a terrorism nexus, as summarized from the proposed enforcement structure.[8]
Civil liability is the fourth. The strongest negligence arguments will not need to prove that a utility could have stopped every sophisticated intrusion. They will focus on whether the utility ignored known, basic, and already-documented cyber weaknesses. EPA’s violation figure, CISA’s warning about exposed systems, and a utility’s own assessment record may be used to frame foreseeability and breach, even where the underlying enforcement authority is contested or incomplete.[2][4][5]
What not to overclaim
Several claims should stay out of a serious exposure assessment unless the record supports them. Do not describe the July 2026 Minnesota attacks as officially attributed to Iran when the FBI, EPA, and Minnesota notices cited here do not do that. Do not tell a board that EPA has finalized a new water-cybersecurity rule. Do not treat CIRCIA as already imposing final reporting duties before the final rule is issued and effective.
Do not rely on reported private litigation numbers unless court records have been checked. A reported class-action dollar figure may be useful as a research lead, but it should not become part of a legal risk memo simply because it appears in a blog post. The more defensible materials are dated agency notices, GAO reports, statutory duties, inspection findings, court action on EPA’s 2023 memo, contracts, insurance policies, and the utility’s own records.

A practical exposure screen for counsel
The first pass should be fast enough to use during an incident but disciplined enough to survive after one. Counsel should separate binding duties, known vulnerabilities, incident facts, and future reporting risk instead of collapsing them into a general statement that water cybersecurity law is unsettled.
- Identify the utility type, population served, ownership structure, and whether SDWA Section 1433 risk-and-resilience and emergency-response-plan duties applied.
- Collect the latest risk-and-resilience assessment, emergency response plan, EPA certifications, board approvals, budget deferrals, third-party assessments, and remediation evidence.
- List known cyber conditions before July 2026: internet-facing controls, default or shared credentials, unsupported systems, former-employee access, vendor remote access, and missing asset inventory.
- Match the incident facts to prior warnings. If the event involved the same class of exposure already identified by EPA, CISA, a vendor, or an assessment, foreseeability risk increases.
- Check existing notice duties under state law, contracts, insurance policies, grant conditions, bond disclosures, and mutual-aid agreements.
- Track CIRCIA readiness separately: it is not the same as current SDWA compliance, but it may soon affect incident intake, evidence preservation, and reporting workflows.
The hard cases will be small utilities with real resource constraints and thin administrative records. That context matters for remedies, timing, and credibility. It does not eliminate the need to show what was assessed, what was known, what was deferred, who approved the deferral, and what compensating measures were put in place.
After Minnesota, the record will be read differently. The attacks did not create every duty that matters, and they did not cure EPA’s authority limits. They did make it harder to describe exposed controls, incomplete assessments, and unresolved basic vulnerabilities as background conditions rather than evidence.
References
- Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers Causing Operational Disruptions, Federal Bureau of Investigation, July 30, 2026.
- AA26-097A, Cybersecurity and Infrastructure Security Agency.
- MNIT statement, Minnesota IT Services, July 28, 2026.
- Enforcement Alert: Drinking Water Systems to Address Cybersecurity Vulnerabilities, U.S. Environmental Protection Agency, May 2024.
- Critical Infrastructure Protection: EPA Urgently Needs a Strategy to Address Cybersecurity Risks to Water and Wastewater Systems, U.S. Government Accountability Office, August 2024.
- Critical Infrastructure Protection: EPA Needs to Assess Its Authority to Address Cybersecurity Risks to Water and Wastewater Systems, U.S. Government Accountability Office, May 2026.
- CIRCIA, other big cyber rules expected to get finalized this fall, Federal News Network, July 7, 2026.
- New Federal Cybersecurity Reporting Rules Are on Their Way, Fisher Phillips, April 7, 2026.
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →