On March 3, 2023, the United States Environmental Protection Agency (“EPA”) published a memorandum requiring states to evaluate the cybersecurity of operational technology used by public water systems (“PWSs”) “when conducting PWS sanitary surveys or through other state programs.” EPA’s memorandum “interprets the regulatory requirements relating to the conduct of sanitary surveys to require that when a PWS uses operational technology (“OT”), such as an industrial control system (“ICS”), as part of the equipment or operation of any required component of a sanitary survey, then the sanitary survey of that PWS must include an evaluation of the adequacy of the cybersecurity of that operational technology for producing and distributing safe drinking water.” Specifically, “EPA’s interpretation clarifies that the regulatory requirement to review the ‘equipment’ and ‘operation’ of a PWS necessarily encompasses a review of the cybersecurity practices and controls needed to maintain the integrity and continued functioning of operational technology of the PWS that could impact the supply or safety of the water provided to customers.”
Continue Reading EPA Requires States to Address the Cybersecurity of Public Water Systems
Matthew Harden
Matthew Harden is a cybersecurity and litigation associate in Covington’s New York office. He advises clients on cybersecurity and national security matters, including cybersecurity incident response, crisis management, enterprise risk management and governance, internal investigations, and regulatory compliance.
Matthew helps clients prepare for and respond to cybersecurity incidents and data security events. He advises on cybersecurity investigations, counsels on incident response strategy, and helps clients assess legal, regulatory, and litigation risks arising from data breaches, network intrusions, ransomware, insider threats, digital threats, and other cyber matters.
Matthew counsels clients on cybersecurity and information security governance. He assists with drafting, designing, and assessing enterprise cybersecurity policies, information security programs, incident response plans, and related procedures. His work includes advising on cybersecurity and privacy compliance obligations, emerging cybersecurity regulations, and legal risks associated with artificial intelligence (AI), Internet of Things (IoT) technologies, and connected products.
As part of his litigation and investigations practice, Matthew draws on his cybersecurity experience to advise clients in high-stakes disputes, internal investigations, and regulatory matters. He represents government contractors in False Claims Act matters involving cybersecurity and national security. He also maintains an active pro bono practice focused on veterans’ rights.
Matthew serves as a Judge Advocate in the U.S. Coast Guard Reserve.