Key Takeaways
- New York is allocating over $9 million through the SECURE grant program to bolster cybersecurity for 153 drinking‑water and wastewater utilities.
- The grants will fund cybersecurity assessments (up to $50 k per utility) and security‑upgrade implementations (up to $100 k per utility), plus free technical assistance from the New York State Environmental Facilities Corporation (EFC).
- Funding supports compliance with New York’s minimum cybersecurity standards introduced in March, which mandate operator training, incident reporting, risk‑based protections, and a designated cybersecurity lead for larger systems.
- The initiative follows a nationwide coordinated cyber campaign in July that hit water and wastewater facilities in at least seven states, including Minnesota, Michigan, South Dakota, and Georgia.
- Although no New York utility has been publicly linked to the attacks, the state is acting proactively to mitigate risk.
- Federal agencies, notably CISA, advise water operators to remove exposed programmable logic controllers from the internet, change default passwords, use secure gateways/VPNs for remote access, and restrict connections to trusted IP addresses.
- The $9 million cybersecurity award is separate from New York’s five‑year, $3.8 billion clean‑water infrastructure investment, which will push the state’s total water‑infrastructure grants since 2017 beyond $10 billion.
Overview of the SECURE Grant Program
Governor Kathy Hochul announced on Monday that New York will distribute more than $9 million to 153 local drinking‑water and wastewater systems under the Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements (SECURE) grant program. The initiative is designed to help utilities evaluate their current cyber defenses and then implement concrete security improvements. By targeting both assessment and remediation phases, the state aims to close gaps that could be exploited by adversaries seeking to disrupt essential water services.
Funding Structure and Eligible Uses
Under SECURE, each participating utility may receive up to $50,000 for a comprehensive cybersecurity assessment and up to $100,000 for the implementation of recommended security upgrades. In addition to the direct funding, the New York State Environmental Facilities Corporation (EFC) will provide no‑cost technical assistance to guide recipients through the assessment process, help prioritize remediation actions, and ensure that investments align with state‑mandated cybersecurity standards. This combination of financial support and expert guidance is intended to lower the barrier for smaller utilities that often lack dedicated cybersecurity staff.
Alignment with New York’s Cybersecurity Standards
The grant money is explicitly tied to helping utilities meet the minimum cybersecurity standards that New York enacted in March. Those standards require: mandatory cybersecurity training for all certified operators; formal incident‑reporting procedures; risk‑based safeguards for critical operational technology and sensitive information; and the appointment of a cybersecurity lead at larger drinking‑water systems. By linking grant eligibility to these requirements, the state ensures that the funds drive systemic, baseline improvements rather than isolated, ad‑hoc fixes.
Context: Recent Nationwide Water‑Sector Cyber Attacks
The announcement follows a coordinated cyber campaign that targeted operational technology (OT) systems at water and wastewater facilities across the United States in late July. More than 30 community water systems in Minnesota reported intrusions on July 26‑27, with some experiencing disruptions to automated control functions. In Braham, Minnesota, attackers shut down operating controls, prompting the city to temporarily take its water plant offline; however, contingency procedures kept most facilities operational, and drinking water remained safe. Subsequent investigations revealed that the campaign affected water infrastructure in at least seven states, including Michigan, South Dakota, and Georgia, though no New York utility has been publicly identified as a victim.
Nature of the Threat and Attribution Indicators
While federal investigators have not formally attributed the attacks, Iran has emerged as a leading suspect. Security analysts note that the tactics, techniques, and procedures observed resemble earlier campaigns linked to Iranian threat actors known for targeting industrial control systems (ICS) and water utilities. The similarity in malware signatures, use of compromised remote access tools, and focus on OT environments strengthens the hypothesis that state‑backed Iranian groups may be probing U.S. water sector defenses for potential disruption or espionage.
Federal Guidance from CISA
In response to the July incidents, the Cybersecurity and Infrastructure Security Agency (CISA) issued urgent recommendations for water and wastewater operators. CISA advised utilities to remove publicly exposed programmable logic controllers (PLCs) and other OT devices from the internet, thereby reducing the attack surface. Additional guidance includes changing default passwords, routing any necessary remote access through secure gateways or virtual private networks (VPNs), and restricting connections to trusted IP addresses only. Implementing these measures can significantly hinder adversaries attempting to gain unauthorized control over critical water treatment processes.
Broader State Investment in Water Infrastructure
The $9 million cybersecurity grant is distinct from New York’s larger clean‑water infrastructure commitment. The state’s fiscal year 2027 budget includes a five‑year, $3.8 billion investment aimed at upgrading aging water mains, treatment plants, and storm‑water systems. When combined with previous allocations, this effort will bring New York’s total water‑infrastructure grants since 2017 to over $10 billion. By pairing massive physical‑infrastructure upgrades with targeted cybersecurity funding, the state seeks to ensure that its water systems are resilient both to physical degradation and to digital threats.
Implications for Utilities and Ratepayers
For the 153 recipient utilities, the SECURE grants provide a tangible pathway to enhance cyber hygiene without straining limited budgets. Improved cybersecurity reduces the likelihood of service interruptions, protects public health, and helps avoid costly regulatory penalties or remediation expenses that could follow a successful cyber incident. Ultimately, ratepayers benefit from more reliable water services and greater confidence that essential infrastructure is defended against evolving cyber threats.
Looking Ahead
As cyber threats to critical infrastructure continue to grow in frequency and sophistication, New York’s proactive approach—combining grant funding, technical assistance, regulatory standards, and federal guidance—offers a model that other states may emulate. Continued vigilance, regular reassessment of defenses, and collaboration between state agencies, utilities, and federal partners will be essential to safeguard the nation’s water supply against future attacks.

