Key Takeaways
- New York Gov. Kathy Hochul awarded > $9 million through the SECURE grant program to bolster cybersecurity at 153 local water and wastewater systems.
- Funding supports $50,000 cybersecurity assessments and $100,000 implementation upgrades, aligning with new state‑mandated security controls.
- Regulations require least‑privilege access, banning default credentials, multifactor authentication, network monitoring for large plants (>10 MGD), and refresher training every five years.
- The increase from an earlier $2.5 million estimate reflects a rising threat landscape, with cyberattacks now reported in at least 12 states and suspected Iranian involvement.
- Security experts praise New York’s proactive stance, note the water sector lags behind energy in cyber readiness, and recommend basic hygiene steps such as disconnecting unneeded devices, changing default passwords, and maintaining device inventories.
Announcement of $9 Million in Cybersecurity Grants
Governor Kathy Hochul this week unveiled a announced more than $9 million in grants aimed at strengthening the cybersecurity posture of dozens of water systems across New York. The funding is part of the Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements (SECURE) program, a state‑wide initiative designed to help local utilities meet newly adopted cybersecurity standards. By directing resources toward assessments and technical upgrades, the governor hopes to close gaps that could be exploited by hostile actors seeking to disrupt essential water services. The move underscores a growing recognition that water infrastructure, though often overlooked, is a critical component of public safety and economic stability.
Structure of the SECURE Grant Program
The SECURE initiative allocates two tiers of funding: $50,000 grants for comprehensive cybersecurity assessments and $100,000 grants for implementing recommended upgrades. One hundred‑and‑fifty‑three local government projects have been selected to receive support, ranging from small municipal utilities to larger regional treatment facilities. The assessment phase helps operators identify vulnerabilities, prioritize remediation, and develop tailored action plans. The subsequent implementation grants enable the purchase of security tools, staff training, and the deployment of safeguards such as firewalls, intrusion detection systems, and secure configuration management. This two‑step approach ensures that funding is both diagnostic and remedial, maximizing the impact of each dollar spent.
Core Requirements of New York’s Water Utility Cybersecurity Rules
Accompanying the grant program, New York enacted regulations that set a baseline for cybersecurity hygiene across the state’s water and wastewater utilities. Facilities must enforce least‑privilege access, prohibiting users from accessing systems beyond their job functions, and must eliminate the use of default credentials. Complex passwords and multifactor authentication are now mandatory for all administrative and operational accounts. Treatment plants that process ≥ 10 million gallons per day are required to continuously monitor and log network activity, enabling early detection of anomalous behavior. Additionally, plant operators must complete cybersecurity refresher training every five years to maintain certification, although the regulations stipulate that total training hours will not increase, ensuring compliance without overburdening staff.
Leadership Perspective: Moving Beyond Reactive Defense
Colin Ahern, New York’s former cyber director who recently assumed the role of the state’s first director of security and intelligence, highlighted the strategic shift embodied by the new rules. Speaking at the regulations’ March rollout, Ahern asserted that the measures would move the state “be reactive defense” toward a more proactive, resilient posture. By institutionalizing continuous monitoring, regular training, and systematic access controls, the state aims to anticipate and thwart threats before they can cause service disruption. Ahern’s comment reflects a broader trend among state governments to treat cyber risk as an ongoing management challenge rather than a series of isolated incidents to be patched after the fact.
From Initial $2.5 Million Estimate to a $9 Million Commitment
When the SECURE program was first disclosed, officials indicated that it would provide roughly $2.5 million in grants—a figure that quickly proved insufficient given the level of interest from utilities across the state. The governor’s office did not immediately explain the funding increase, but in a subsequent press release Hochul cited the “real and escalating” risks demonstrated by a recent wave of cyberattacks targeting water infrastructure in at least 12 states. The decision to more than triple the original allocation signals a heightened sense of urgency and a willingness to invest substantially in preventive measures as the threat landscape evolves.
Nationwide Surge in Water‑Utility Cyber Incidents
The backdrop to New York’s expanded funding is a series of coordinated cyber incidents that have struck water systems nationwide. Earlier this month, more than 30 communities in Minnesota experienced brief disruptions to their water utilities in what appeared to be a synchronized attack. Federal officials later confirmed that seven additional states had been hit, and news outlets have since raised the total to 12 affected states, including Georgia, Michigan, and South Dakota. While the attacks have thus far resulted mainly in service interruptions rather than physical damage, their geographic spread and timing have raised alarms about the vulnerability of the nation’s water sector to state‑sponsored or politically motivated cyber campaigns.
Attribution Analysis: Iran as the Likely Actor
Although no official attribution has been made, many analysts point to Iran as the probable perpetrator of the recent wave. Cynthia Kaiser, a former deputy director of the FBI’s Cyber Division and now a senior vice president at Halcyon, observed that while the attacks have not been formally linked to any specific group, Iran’s historical pattern of targeting U.S. water‑infrastructure targeting makes it “more than a guess” that the attacks, now a senior vice presidentially suggested that the state is “more than a guess” responsible. Kaiser noted that Iran has repeatedly demonstrated a willingness to probe and disrupt critical infrastructure as part of its broader hybrid strategy, even though the regime often exaggerates the impact of its operations for propaganda purposes.
Expert Endorsement: New York as a Model for Other States
Kaiser also lauded New York’s approach, describing the state’s cybersecurity policies as “commendable” and a “great sign and example for a lot of other states.” She emphasized that the combination of grant funding, clear regulatory standards, and mandatory training creates a robust framework that many jurisdictions could emulate. However, she cautioned that the pace of adoption elsewhere will depend on factors such as local tax bases, political appetite for regulation versus incentive‑based programs, and the availability of technical expertise. Ultimately, all states must prioritize hardening their water sectors, as the consequences of a successful breach could extend far beyond temporary service loss.
Sector‑Wide Gaps and Practical Steps for Improvement
Mauricio Papa, a computer science professor at the University of Tulsa, echoed the view that water utilities lag behind other critical industries—particularly energy—in cybersecurity maturity. He attributed this gap partly to chronic underfunding and limited technical staff at municipally run facilities. Papa, alongside Kaiser, recommended a series of low‑cost, high‑impact measures that utilities can adopt immediately: disconnecting non‑essential devices from the internet, replacing default passwords with strong, unique alternatives, maintaining an up‑to‑date inventory of all digital assets, and segmenting operational technology (OT) networks from corporate IT networks. These steps, while not a substitute for comprehensive security programs, can significantly reduce the attack surface and mitigate the risk of opportunistic intrusions.
Cautionary Note: The Incremental Threat of Repeated Small‑Scale Attacks
Both experts warned against complacency, stressing that the current spate of incidents may represent only the visible tip of a larger, creeping threat. Kaiser likened the danger to “death by 1,000 cuts,” noting that a succession of modest disruptions—each seemingly harmless in isolation—can erode public trust, strain emergency response resources, and mask more sophisticated attempts to cause physical harm or long‑term degradation of water quality. By treating each alert as a data point in a broader risk assessment, utilities and policymakers can better allocate resources, refine detection capabilities, and build the resilience needed to withstand both low‑frequency, high‑impact events and the relentless pressure of continuous low‑level probing.
This summary captures the essential points of the original article while adhering to the requested length, structure, and formatting.

