New York's $9 Million Water Cybersecurity Grant: Why Critical Infrastructure Protection Is a Shared Responsibility

As coordinated cyberattacks hit water systems across seven U.S. states, New York's SECURE grant program signals a new era of mandatory standards and funded resilience for utilities.

New York's $9 Million Water Cybersecurity Grant: Why Critical Infrastructure Protection Is a Shared Responsibility

New York Takes Aim at Water System Cybersecurity Gaps With $9 Million in Grants

New York State has announced more than $9 million in funding to bolster water system cybersecurity across 153 drinking water and wastewater utilities — a move that arrives against a backdrop of escalating, coordinated cyberattacks targeting critical water infrastructure across the United States. The grants, distributed through the state's Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements (SECURE) program, represent one of the most substantial state-level commitments to hardening operational technology (OT) systems in the water sector to date.

Governor Kathy Hochul announced the funding, framing it as a direct response to a threat landscape that is no longer theoretical. "These threats are real and escalating," Hochul stated, pointing to a wave of cyberattacks that has swept through water and wastewater facilities across multiple states. For IT and security professionals tracking the convergence of cyber threats and physical infrastructure, the announcement is significant — not just for its dollar value, but for the regulatory and compliance architecture it helps enforce.

The SECURE grants will fund two core activities: cybersecurity risk assessments at local utilities, and the implementation of concrete security improvements. Utilities receiving grants will also gain access to no-cost technical assistance from the New York State Environmental Facilities Corporation (EFC), lowering the barrier for smaller municipalities and rural operators who may lack in-house security expertise.

What the SECURE Grant Program Covers — and Who Qualifies

Cybersecurity professional monitoring critical infrastructure systems
Water and wastewater operators are increasingly being required to meet mandatory cybersecurity standards as attacks on OT systems grow in frequency and sophistication.

When New York launched the SECURE program, it established clear funding caps designed to cover the most urgent security needs: up to $50,000 for cybersecurity assessments and up to $100,000 for implementing security upgrades. These thresholds are meaningful in a sector where many utilities operate on thin budgets and have historically deprioritized cybersecurity in favor of physical infrastructure maintenance.

The grants are also tied to compliance with New York's minimum cybersecurity standards, which were introduced in March. These standards include mandatory cybersecurity training for certified operators, incident reporting requirements, risk-based protections for critical operations and sensitive data, and — crucially for larger drinking water systems — the designation of a dedicated cybersecurity lead. For security teams in other regulated industries, this will look familiar: it mirrors the kind of role-based accountability that GDPR introduced for data protection officers, or that financial regulators mandate for Chief Information Security Officers at banks.

According to the U.S. Environmental Protection Agency's water resilience guidance, the majority of community water systems in the United States serve fewer than 10,000 people — meaning most operators lack dedicated IT staff, let alone cybersecurity specialists. The SECURE program's inclusion of free technical assistance from the EFC addresses precisely this gap, making it a model worth watching for other states and, arguably, for European regulators navigating similar challenges under frameworks like NIS2.

$9M+New York SECURE grant total
153Water utilities receiving funding
$100KMax per utility for security upgrades
7+U.S. states hit in recent attack campaign

The Coordinated Attacks That Made This Funding Urgent

The timing of New York's announcement is not incidental. It follows a coordinated cyber campaign that targeted operational technology systems — specifically programmable logic controllers (PLCs) — at water and wastewater facilities across the United States. More than 30 community water systems in Minnesota were targeted on July 26 and 27, with some municipalities reporting disruptions to automated control functions.

The city of Braham was among the hardest hit, briefly taking its water plant offline after attackers shut down operating controls and stopped both well and water treatment operations. While contingency procedures allowed most facilities to remain operational, the incident demonstrated a critical vulnerability: many water systems rely on internet-exposed OT devices with minimal authentication controls.

The campaign ultimately affected water infrastructure in at least seven states. Michigan confirmed malicious activity in a small number of communities. Rapid City, South Dakota, reported an incident involving a wastewater lift station. Georgia was also reportedly among the states targeted. No New York utility has been publicly linked to the campaign, but the proximity of the grant announcement to these events makes the connection clear.

"The attack surface for water utilities is enormous — legacy PLCs often run firmware that hasn't been updated in a decade, and many are directly reachable from the public internet with default credentials still in place."

— Industrial control systems security analyst, cited in context of recent U.S. water sector incidents

Federal investigators have not formally attributed the attacks. However, Iran has emerged as a leading suspect, with the activity reportedly resembling previous campaigns linked to Iranian threat actors known to target industrial control systems and water utilities. This mirrors CISA's longstanding warnings about nation-state interest in disrupting water infrastructure as a means of causing civilian harm with relatively low technical sophistication.

What CISA Is Telling Water Operators to Do Right Now

Following the attacks, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued urgent guidance for water and wastewater operators. The recommendations are technically straightforward but operationally challenging for under-resourced utilities — which is precisely why grant funding like New York's SECURE program matters.

CISA's guidance includes: removing publicly exposed PLCs and other OT devices from the internet; changing default passwords immediately; routing necessary remote access through secure gateways or virtual private networks (VPNs); and restricting connections to trusted IP addresses only. For any developer or IT professional reading this, these are table-stakes security hygiene measures — the kind of controls that would be unthinkable to neglect in a cloud environment or enterprise SaaS deployment. Yet for many water utilities, they represent a significant operational shift.

Network security monitoring and industrial control systems
Industrial control systems and programmable logic controllers at water facilities are increasingly targeted by nation-state threat actors.

The challenge is structural. OT environments in water utilities were designed decades ago with availability and uptime as the primary engineering constraints, not confidentiality or integrity in the cybersecurity sense. Patching a PLC or reconfiguring network architecture can mean taking a system offline — something operators are understandably reluctant to do with drinking water at stake. This is the same tension that security professionals in healthcare, energy, and manufacturing navigate daily, and it has no easy resolution without dedicated funding and expertise.

According to WaterISAC, the information sharing and analysis center for the water sector, threat intelligence sharing remains one of the most effective tools available to operators — but participation rates among small utilities are low. The SECURE program's technical assistance component could help bridge this gap by connecting utilities with resources they wouldn't otherwise know how to access.

Mandatory Cybersecurity Standards: What New York's March Rules Actually Require

Requirement Applies To Key Detail
Mandatory cybersecurity training All certified operators Required for license maintenance
Incident reporting All utilities Mandatory disclosure requirements
Risk-based protections All utilities Covers critical ops and sensitive data
Designated cybersecurity lead Larger drinking water systems Named individual accountable for security
Cybersecurity assessment Grant recipients Up to $50,000 funded via SECURE
Security upgrade implementation Grant recipients Up to $100,000 funded via SECURE

The standards introduced by New York in March establish a compliance baseline that mirrors broader trends in critical infrastructure regulation globally. The mandatory designation of a cybersecurity lead, for instance, echoes requirements under the EU's NIS2 Directive, which came into force across EU member states and requires essential entities — including water utilities — to appoint accountable individuals for cybersecurity governance. For European readers on this platform tracking digital sovereignty and regulatory convergence, the parallels are notable.

The incident reporting requirements also align with a global shift toward mandatory disclosure. Just as GDPR requires data breach notification within 72 hours, New York's standards create a reporting obligation that generates the kind of threat intelligence dataset that agencies like CISA and WaterISAC need to identify coordinated attack campaigns early — ideally before they spread across dozens of systems.

It's worth noting that the $9 million in cybersecurity grants is entirely separate from a five-year, $3.8 billion clean water infrastructure investment included in New York's fiscal year 2027 budget. The state says that broader investment will bring its total water infrastructure grants since 2017 to more than $10 billion — underscoring that cybersecurity is now being treated as a genuine infrastructure concern, not an IT afterthought.

Why Water System Cybersecurity Matters Beyond the United States

For IT decision makers, policy professionals, and privacy advocates outside the U.S., the New York SECURE program offers a template worth studying. Water infrastructure cybersecurity is not a uniquely American problem. In Europe, the NIS2 Directive specifically names water supply and wastewater treatment as critical sectors subject to enhanced security obligations. Member states are required to ensure that operators in these sectors meet baseline security standards, implement incident reporting procedures, and undergo regular audits.

Yet implementation has been uneven,

Originally reported by Security Week. Summarised and curated by European Purpose.