EPA $11.75M Grants Target PLC Cybersecurity in Water Systems

EPA $11.75M Grants Target PLC Cybersecurity in Water Systems

The aging automation layer of America's drinking water infrastructure has become a national security concern. With 277 water systems flagged for cybersecurity vulnerabilities in 2025, the U.S. Environmental Protection Agency is moving $11.75 million into resilience upgrades. San Diego is using its share to replace programmable logic controllers (PLCs)—the industrial devices that command pumps, valves, and chemical dosing—to close cyber and natural-hazard gaps. The move signals a hard pivot from reactive patching to hardware-level defense.

EPA's $11.75 Million Program Targets PLC Cybersecurity

The funding flows through the Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability Grant Program. It supports 10 drinking water systems across the country. Each project is designed to harden operations against two converging threats: cyberattacks and extreme weather.

The agency paired the announcement with a sobering audit figure. In 2025, inspectors identified cybersecurity vulnerabilities at 277 water systems, ranging from weak authentication to inadequate access controls.

Analyst Insight: The emphasis on hardware replacement—not just software patches—reflects a maturing view of operational technology risk. Legacy PLCs often ship with default credentials and lack encryption, making them a one-stop target for threat actors seeking to disrupt water treatment.

San Diego: Replacing PLCs at the Control Layer

San Diego is directing its grant toward replacing programmable logic controllers to address both natural-hazard and cybersecurity vulnerabilities. PLCs orchestrate the real-time control loops that keep treatment plants running. Aging units, however, frequently run unsupported firmware that cannot receive security updates.

Replacing them closes a critical gap. Newer controllers support role-based access control, encrypted communications, and audit logging—capabilities that map directly to the authentication and access-control issues the EPA flagged nationwide.

Bloomington: Backup Generators and SCADA Improvements

Bloomington is taking a broader infrastructure route. Its allocation funds facility upgrades, backup generators, and supervisory control and data acquisition (SCADA) improvements. Backup power ensures control systems stay online during extreme weather, while SCADA upgrades tighten visibility and remote-access controls.

Why 277 Flagged Systems Should Worry Every Utility

The 277-system figure is not an anomaly; it is a warning. Water and wastewater remain among the most underfunded sectors for operational technology security. Many utilities operate with flat IT budgets and part-time cybersecurity staff.

Attackers understand this asymmetry. Disabling a single PLC can halt chemical dosing, overflow storage, or interrupt pressure regulation—with public health consequences that outlast the intrusion itself.

Key Cybersecurity Data: 2025 Water Sector Audit

Systems flagged: 277

Primary issues: Authentication weaknesses and inadequate access controls

Grant total: $11.75 million across 10 drinking water systems

Focus areas: PLC replacement, SCADA upgrades, backup power, facility hardening

From Reactive Patching to Hardware-Level Defense

The grant program marks a strategic shift for the water sector. Rather than layering software on obsolete controllers, utilities are beginning to replace the hardware itself. This aligns with broader industrial automation trends toward secure-by-design control systems.

Market Trend: Expect rising demand for PLCs and SCADA platforms with native security features—secure boot, encrypted protocols, and centralized identity management—as federal funding conditions increasingly reward cyber-resilient procurement.
FAQ: What This Means for Water Utilities and Automation Suppliers

Why are PLCs a cybersecurity risk in water systems? Many installed PLCs are decades old, lack encryption, and use default or shared credentials. They often cannot be patched, leaving remote-access pathways exposed.

What does the EPA grant actually fund? The $11.75 million supports 10 midsize and large drinking water systems for resilience projects, including PLC replacement, SCADA improvements, backup generators, and facility upgrades.

How significant is the 277-system finding? It underscores systemic exposure. The EPA worked with flagged utilities to remediate authentication and access-control gaps, but many un-audited systems may carry similar risks.

The water sector's automation backbone is finally receiving the scrutiny—and the funding—it has long needed. As federal dollars flow, utilities and industrial automation vendors alike should expect cybersecurity to become a core procurement criterion, not an afterthought.

Related Articles

Back to blog