New York is making a strong push for cybersecurity water sector. The state has awarded more than $9 million to 153 organizations responsible for drinking water and wastewater. The goal is to increase their resilience against cyberattacks, with hands-on support for carrying out security measures.
According to Governor Kathy Hochul, the funding is delivered through the Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements (SECURE) grant program. This gives local utilities support for both analyzing risks and implementing improvements.
What does the water sector get from SECURE grants?
The funding is intended to strengthen security at utilities in practical terms. Municipalities and water companies can use the money for cybersecurity assessments (reviews of their current situation), and then for the implementation of security improvements.
In addition, recipients gain access to free technical support from the New York State Environmental Facilities Corporation (EFC). This matters because many water organizations need to do more than deploy technology—they also have to set up processes and responsibilities.
Why extra attention right now?
The announcement comes at a time when cyber threats to water and wastewater infrastructure are becoming increasingly urgent. Hochul pointed to recent attacks targeting water organizations across multiple states.
In the United States, a coordinated campaign was also reported targeting operational technology (OT) in water and wastewater facilities. In some cases, automated control functions could be temporarily disrupted, although some affected locations indicated they had emergency procedures, allowing services to continue largely uninterrupted.
Examples from the US: disruption and emergency measures
Reports indicate interruptions in the control layer. For example, a city in Minnesota (Braham) allegedly shut down its water treatment plant briefly after attackers had shimmed the operational control, causing wells and water treatment to stop. Other municipalities, however, reported that drinking water remained safe and that services could continue.
The campaign then appeared to have affected at least seven states. Michigan confirmed malicious activity affecting a small group of communities, while Rapid City in South Dakota reported an incident involving a wastewater lift station. Georgia may also be part of the impacted areas. As far as publicly known, no New York utility has been directly linked to this campaign.
New minimum rules in New York for water safety
The funding helps water organizations meet minimum cybersecurity standards that New York introduced in March. The standards cover both people and technology.
Specifically, this includes:
- Mandatory cybersecurity training for certified operators
- Reporting requirements related to incidents
- Risk-based protection for critical processes and sensitive information
- Appointing a cybersecurity lead for larger drinking water systems
When the SECURE program was launched, the state said utilities could receive amounts up to $50,000 for assessments and up to $100,000 for implementing upgrades.
What does CISA advise water and wastewater operators?
Alongside the subsidy approach, there is also a focus on operational measures. The US cybersecurity and infrastructure authority (CISA) urged water and wastewater operators to better shield OT environments from exposure to the internet.
In particular, it was recommended not to place publicly accessible programmable logic controllers and other forms of operational technology directly on the internet.
Additionally, more traditional hardening measures were also reiterated in the recommendations:
- Change default passwords
- Route necessary remote access through secure gateways or via a VPN
- Limit connections to trusted IP addresses
By taking measures like these, you reduce the likelihood that attackers will reach critical systems by abusing access or network paths.
Involvement and attribution: what is known?
While the attacks are framed as serious in the reporting, there has been no formal attribution by federal investigators. Still, one possible perpetrator has emerged in the discussion: Iran would be suggested as the main suspect, because the reported tactics appear to resemble earlier campaigns linked to threat groups that more frequently target industrial control systems and water utilities.
It’s important to emphasize that, in the source context, this is a suspected link based on similarities with prior activity—not an official attribution.
How does this relate to broader investment in water infrastructure?
The $9 million in cyber funding is separate from larger investments in water infrastructure. In addition, according to the reporting, New York is also working toward a budget of $3.8 billion over five years within the fiscal year 2027 budget for “clean water infrastructure.”
The state reports that this brings the total amount of water infrastructure grants since 2017 to more than $10 billion. This suggests a broader strategy: not only modernize physical infrastructure, but also strengthen digital resilience.
What does this mean for other organizations in the water supply chain?
Even if you’re not in New York, this development shows which direction the sector is moving. The combination of training, incident handling, responsibilities, and risk-driven technical measures is a pattern you see across many critical industries.
Especially for organizations working with OT environments, it’s worth checking internally whether remote access is set up properly, whether standard account details still exist, and whether there is enough focus on reducing “exposure” toward the internet.
Want to follow the broader context of OT vulnerabilities and recent attacks in the water domain? Then also read cyberattacks on water networks in Minnesota for an extra look at what can go wrong in practice with control systems.
Practical checklist to strengthen cybersecurity in the water sector
If you want to translate subsidies and advice into your own approach, a short, feasible inventory can help. For example:
- Identify which OT components and PLCs (or similar control elements) are reachable, and where
- Check whether remote access runs through secure gateways/VPNs rather than open connections
- Replace default passwords and verify the password policy for accounts
- Make incident reporting and responsibilities clear, including who reports what
- Schedule periodic cybersecurity training for operators
- Document who inside the organization is responsible for cybersecurity for larger systems
By combining these steps with a formal assessment approach, you can invest more targetedly instead of taking ad hoc measures.
Conclusion: With more than $9 million, New York makes it clear that cybersecurity water sector is not a side issue. Through SECURE grants for assessments and improvements, plus free technical support, the state helps 153 utilities meet minimum requirements around training, incident reporting, and risk-based protection. At the same time, the CISA approach underscores the importance of limiting internet exposure and securing remote access to operational systems.
