This statement from the EPA is the crux of it: "Most cybersecurity practices can be implemented at minimal cost."; a statement that anyone involved with software/cybersecurity knows has never been true about any software system, ever. It feels very reasonable to me that some of these dirt-poor counties could look at a new set of cyber requirements and say, we physically cannot pay for this; and while the EPA goes on to list sources of funding they offer, I don't know much about those; its possible that given they've already vastly underestimated the cost of securing an industrial software system, they're also vastly under-provisioning the grant funding available to do it.
No one wants their water systems insecure. Republicans aren't a comic book villain; and to help empathize with how they think, right or wrong, consider this: What if we took a good chunk of the EPA's budget and distributed it to the local water utilities directly (in other words: Your federal taxes go down, your county taxes go up). The EPA seems really good at drafting memorandums they have to redact and publishing reports about how insecure our water systems are; Republicans would argue, the money we spent on those things did nothing to help actually fix the problem, so maybe the solution is "less EPA".
I'm not saying this is right, and I'm not saying its even representative of a cogent reality. I'm just saying, this is the line of thinking.