Planning improved; legal coverage still had holes

EPA responded to a 2024 GAO recommendation by completing a water-sector cyber risk assessment and developing a risk-management plan. But EPA’s own authority review identified no cybersecurity risk-assessment requirement for wastewater systems and certain drinking-water systems.

EPA also found significant limits in federal drinking-water and clean-water laws for addressing those gaps. The problem was therefore not simply an unfinished agency checklist; the regulator said its legal tools did not reach the full sector.

Status of water-sector cyber oversight
ControlMay 2026 statusLimit
Sector risk assessmentCompletedDoes not create legal authority
Risk-management planDevelopedImplementation still matters
Wastewater assessment requirementAbsentEPA identified legal gap
Certain drinking-water systemsNot coveredEPA identified legal gap
Sources: GAO-26-109159

Nearly 170,000 systems share the risk—but not one legal status

GAO described a sector of close to 170,000 drinking-water and wastewater systems. It did not say every one lacked a risk-assessment requirement, so applying the gap to all 170,000 would overstate the evidence.

The defensible finding is that important categories—wastewater and some drinking-water systems—remained outside a federal assessment requirement, while connected pumps, valves and legacy equipment increased exposure to ransomware and other attacks.

Capacity constraints complicate compliance

GAO said systems vary in cybersecurity capability, face workforce shortages and operate older technology that is difficult to secure. Limited budgets may also force cyber investments to compete with mandatory clean- and safe-water work.

Those conditions are risk factors, not proof that a specific utility is insecure or that an attack will contaminate water. The report names no current compromise at a Kern County utility and should not be read as one.

Method and original finding

The newsroom mapped EPA’s completed actions against the legal gaps it reported and checked GAO’s sector denominator and May 2026 evidence cutoff. The testimony builds on GAO’s 2024 audit and updated EPA documents.

The contribution is to distinguish program progress from enforceable coverage: EPA completed the planning work but still lacked authority to require assessments across key parts of the sector. GAO said it would monitor the response.

Sources and further reading

GAO: Water and Wastewater Cybersecurity ↗