Secure every treatment plant and pump station. Water keeps flowing.
Water and wastewater cybersecurity for OT
Control who reaches every PLC, pump and SCADA server. Nothing to install on machines, and no outage.
Last updated:
Water and wastewater cybersecurity protects the SCADA servers, PLCs and remote sites that treat and move water from unauthorized access. In the US, every community water system serving more than 3,300 people must cover its computer and automated systems in a risk and resilience assessment under Safe Drinking Water Act section 1433, and EPA enforces it.
Start with remote access. List every way staff and vendors reach the plant from outside, then put each controller behind a gate that checks who connects and records every session.
Which cybersecurity rules apply to water utilities?
The federal rule comes from the Safe Drinking Water Act. New York adds its own rules for drinking water and wastewater. Federal dates are from EPA.
| Obligation | Who it applies to | Deadline |
|---|---|---|
| Risk and resilience assessment under SDWA section 1433 (AWIA). It must cover electronic, computer and automated systems. | Community water systems serving more than 3,300 people. | Current cycle: March 31, 2025 (100,000 people or more), December 31, 2025 (50,000 to 99,999), June 30, 2026 (3,301 to 49,999). Review at least every five years. |
| Emergency response plan under SDWA section 1433. It must include cybersecurity strategies. | Community water systems serving more than 3,300 people. | Current cycle: September 30, 2025, June 30, 2026 and December 31, 2026, by the same size bands. |
| EPA enforcement alert on drinking water cybersecurity (May 2024). | Community water systems serving more than 3,300 people. | Applies now. EPA found over 70% of systems inspected since September 2023 in violation of basic section 1433 requirements. |
| New York DOH rules, 10 NYCRR Part 5, Appendix 5-E, for drinking water. | New York community water systems serving more than 3,300 people. Extra controls above 50,000. | Incident reporting to DOH within 24 hours applies now. The other controls apply from January 1, 2027. |
| New York DEC rules for wastewater. | New York wastewater systems under DEC permits. | Incident reporting to DEC applies now (by phone within 24 hours, in writing within 30 days). The response plan and cybersecurity controls are due by March 11, 2027. |
Free federal help. EPA offers no-cost cybersecurity assessments and technical assistance at epa.gov/cyberwater. CISA offers no-cost vulnerability scanning for water utilities at cisa.gov/water. New York operators can follow the NY water cybersecurity field guide.
Sessions on securing water and wastewater OT and the New York DEC and DOH rules.
Protect the PLC you cannot patch.
Some of the OT running a water system cannot be fixed by patching. The Rockwell Logix authentication bypass CVE-2021-22681, on CISA's Known Exploited Vulnerabilities list, has no vendor patch, and controllers like it sit in treatment plants and pump stations across the country. When you cannot change the device, the only control left is an enforcement point in front of it.
Trout Access Gate is that control point. It connects to your existing network and acts as a resilient proxy for the controller. No one reaches the PLC without identity, MFA and a recorded session. The PLC itself stays untouched. It is the same compensating-control logic behind the CMMC Enduring Exception and the NERC CIP Intermediate System, applied to water.
Secure remote lift stations and water towers.
The recent disruptions at community water systems hit the sites operators watch least: remote lift stations and remote-monitored water towers reached over cellular modems. A modem that exposes the control network directly is an unauthenticated path in.
Access Gate brokers each remote session through an on-premise proxy with identity and full recording, so the modem stops being a direct route to the PLCs and SCADA. No re-cabling, no downtime, and no agent on the field equipment. Under EPA Safe Drinking Water Act Section 1433, that access control, inventory, and audit trail is exactly what a risk and resilience program is expected to show.
Protect water systems without an outage.
Access Gate connects to your existing network. Treatment keeps running.
See every machine.
Find every machine across treatment plants, pump stations, lift stations and towers.
Control who reaches what.
Keep office traffic away from process control. No VLAN changes.
Reach any machine, securely.
Operators and vendors log in with MFA. Every session is scoped and logged.
Prove every audit.
Every connection is logged. Export the evidence EPA and state reviewers ask for.
Trusted by utilities and critical infrastructure operators.
distributed field assets secured under one central control, in harsh remote conditions.
“Our substations run equipment from four different decades. Trout gave us segmentation and monitoring across all of them without a single firmware update or agent install.”
OT Security Manager
Grid Operations · Regional Energy Provider
Download the SCADA security guide and the Access Gate datasheet.
One email, two files: the 38-page SCADA security guide written for water operators without a security team, and the 2-page Access Gate datasheet with the water utility deployment model and IEC 62443 alignment.
What's inside
The six paths that reach SCADA with the public water cases behind them, six controls that touch no controller, the AWIA, EPA and New York requirements, a first-year plan and a fifteen-question checklist. Plus the datasheet.
See it in action
Request a live demo. See how Access Gate fits your water network without stopping operations.
Common questions about water utility security.
agents to install on PLCs, dosing controllers or SCADA. Access Gate protects water OT from the network.
Yes. The Access Gate is agentless: it operates at the network level, and no agents are installed on PLCs, dosing controllers, SCADA servers or any OT device. It protects everything connected to the network, regardless of age, firmware or operating system.
No. The Access Gate connects to existing network infrastructure rather than cutting into it. No re-cabling, no process interruptions, no changes to control system configurations. Water operations continue normally during and after deployment.
The Access Gate creates encrypted overlay networks connecting all sites, treatment plants, pumping stations, lift stations, and control centers. Policy is managed centrally and enforced consistently at every location, including unmanned remote sites.
The Access Gate supports the cybersecurity work EPA expects of water systems, including the AWIA risk and resilience assessment, and IEC 62443 for industrial security. It generates assessment-ready documentation and provides continuous control enforcement for regulatory audits.
Yes. The Access Gate enforces identity-based access policies, so only authorized users reach specific process control systems. Every session is authenticated with MFA, scoped to authorized resources and fully logged. Unauthorized access attempts are detected and blocked in real time.
New York adopted first-in-nation water cybersecurity regulations on March 11, 2026. The DEC rules (6 NYCRR Parts 616, 650, and 750) require every SPDES-permitted wastewater system, of any size, to report cyber incidents within 24 hours, with access control, vulnerability management, network monitoring for POTWs at 10 MGD or more, and a response plan due by March 11, 2027, one year after the rule's adoption. The DOH rules (10 NYCRR Appendix 5-E) require community water systems serving more than 3,300 people to run an annual Cybersecurity Vulnerability Analysis and report incidents within 24 hours, with remaining controls due by January 1, 2027. Trout maps utility OT networks and enforces segmentation to meet these controls with no agents and no downtime.
The DEC and DOH requirements build on federal EPA obligations under America's Water Infrastructure Act, which already requires community water systems serving more than 3,300 people to include cybersecurity in their Risk and Resilience Assessments. To offset the cost, New York's EFC runs the SECURE grant program, with up to $50,000 for cybersecurity assessments and up to $100,000 for upgrades aligned to the new rules. Trout gives water and wastewater operators the network visibility, segmentation and access control needed to pass a DOH Cybersecurity Vulnerability Analysis and satisfy DEC controls, with nothing to install on existing SCADA and OT equipment.
Under Safe Drinking Water Act section 1433, community water systems serving more than 3,300 people certify a risk and resilience assessment and an emergency response plan to EPA, and review both at least every five years. In the current cycle, the last assessments (3,301 to 49,999 people) were due June 30, 2026, and the last plans are due December 31, 2026. In New York, the DOH operational technology rules for drinking water apply from January 1, 2027, and the DEC wastewater controls are due by March 11, 2027.
When a controller cannot be patched, like the Rockwell Logix authentication bypass CVE-2021-22681 on the CISA Known Exploited Vulnerabilities list, which has no vendor fix, the only remaining control is an enforcement point in front of it. The Trout Access Gate proxies the controller so no session reaches it without identity, MFA, and a full recording, and the PLC itself stays untouched.
Remote sites reached over cellular modems are a common water and wastewater attack surface. Access Gate brokers every remote session through an on-premise proxy with identity and recording, so the modem is no longer a direct, unauthenticated path into the control network. No re-cabling and no agent on the field equipment.
Under Safe Drinking Water Act Section 1433 (America's Water Infrastructure Act), community water systems serving more than 3,300 people must assess risks, including their electronic, computer and automated systems, and maintain an emergency response plan that includes cybersecurity. EPA has enforced these requirements since 2020 and issued a cybersecurity enforcement alert in May 2024. Access Gate delivers the asset inventory, segmentation, access control, and tamper-evident audit trail these call for, on-premise.


Respect Your Elders.
Your legacy pumps, PLCs, and RTU don't need replacing. Get free stickers and learn how Trout secures water OT for AWIA, NERC CIP, and the water sector.
The gate is the first service you run, not the last.
Commissioning a new utility site, or hardening an existing one?
Zero-Trust reference architecture for water and electric utilities. Identity-bound access, brokered sessions, tamper-evident audit. NERC CIP + CCCS coverage matrix.
