TroutTrout

Meet New York's water cybersecurity rules before the 2027 deadlines.

This page explains what the SECURE grant covers, what Access Gate does, and how they fit together.

Last updated:

The short answer

The EFC SECURE grant helps NY water utilities meet new state cybersecurity regulations. DOH enforces them for drinking water from January 1, 2027, and DEC for wastewater from March 11, 2027. Access Gate is an on-premise appliance. It fully covers 6 of the EFC 12 steps automatically and does the heavy lifting on 4 more, 10 of the 12 in total. Those steps include asset inventory, access controls, MFA for legacy OT, network segmentation and incident-response logging. The remaining 2 steps, backups and phishing training, are standard IT practice.

What just happened

On March 11, 2026, Governor Hochul signed first-in-nation cybersecurity regulations for all New York water and wastewater operators. Every system must now meet minimum standards: asset inventory, access controls, incident reporting, and MFA enforced at the network layer for legacy PLCs that cannot run modern auth software. The standards align with EPA and CISA guidance. To help communities comply, the state launched the SECURE grant program, administered by the Environmental Facilities Corporation (EFC). The 2026 grant cycle closed on May 15, but the regulations themselves require compliance by January 1, 2027 for drinking water (DOH) and by March 11, 2027 for wastewater (DEC). Implementation takes time, so it pays to start now. Our operator field guide walks through the requirements, the funding, and how to comply. See the EFC Cybersecurity Hub

$50K

For a cybersecurity assessment

  • · Risk assessment & penetration testing
  • · Network review & asset inventory
  • · Compliance roadmap
$100K

To implement upgrades

  • · Firewalls & segmentation
  • · Access control systems
  • · Monitoring & alerting
  • · Incident response planning
How Access Gate helps
No disruption

Installed in a day while the plant keeps running.

Access Gate connects to your existing network. Nothing is installed on PLCs or SCADA. No VLAN, no recabling, no downtime.

See the lollipop architecture
Full visibility

See every machine.

Automatically finds all IT, OT, and IoT equipment, including legacy systems. Produces the asset inventory required for the $50K assessment grant.

Compliance-ready

Access Gate covers what the regulations require.

Covers access controls, MFA for legacy equipment, network segmentation, and audit logging. Priced within the $100K upgrade grant ceiling.

What happens if the box goes down

The water keeps flowing if Access Gate goes down.

Access Gate governs the access path to your control equipment, not the control loop inside it. Pump stations, chemical dosing, and tank-level control keep running if Access Gate reboots: local PLCs and HMIs are untouched, and the continuous SCADA poll to your outstations stays on its own path. What stops is new remote and vendor access, which is exactly what you want paused when the enforcement point is unavailable.

Fail-open or fail-closed is a per-asset, logged decision, not a default. Access Gate runs as a high-availability pair with failover, so one fault does not stop access. An authenticated, logged break-glass path covers the 2 a.m. emergency. Cyclic controller-to-I/O traffic never traverses Access Gate, so it cannot add latency to a running process or a safety loop.

How the access control actually works

Vendors can read the analyzer but cannot change dosing.

A firewall decides yes or no on a port. Access Gate reads the protocol on the wire and decides at the function-code level. Two examples come from a real water district. The district polls 30 outstations over LTE with DNP3 (port 20000), master to outstation, over radio and cellular. Access Gate lets the poll and response through but blocks a control-relay operate to a remote pump. A chem-feed vendor connecting to tune the dosing loop can read the chlorine analyzer over Modbus (FC3, read holding registers) but cannot write the dosing setpoint (FC6 or FC16, write single or multiple registers). The same rule protects tank-level control and pump VFD speed references. Monitoring stays open, and any write that changes plant behavior is blocked.

Go deeper on the mechanism: what an industrial proxy is, securing a legacy PLC, and the operator field guide.

What Access Gate covers in the EFC 12-step checklist
#StepCoverage
1Change default passwords

Flags weak or default credentials on every discovered device.

YES
2Strong password policy

Enforces credential policy through the access control layer.

PARTIAL
3Enforce access controls

Who can connect to what, when, enforced and logged automatically.

YES
4Inventory all assets

Finds every device on your network. OT, IT, IoT. Output used directly as a grant deliverable.

YES
5Back up systems

Outside scope. Access Gate identifies systems with no backup configured.

MANUAL
6Keep software updated

Shows firmware and software versions for every device, so you can see what needs updating.

PARTIAL
7Incident response plan

A full event log and real-time alerts give you the timeline every IR plan needs.

PARTIAL
8Enable MFA

Enforces MFA even on old PLCs and HMIs that cannot do it natively. Access Gate brokers the session and performs the MFA at the proxy, so the controller is never modified.

YES
9Identify phishing

Outside scope. Staff training and email security required.

MANUAL
10OT not on open internet

Wraps all OT equipment in a secure layer, so no device is directly exposed to the internet.

YES
11Manage user privileges

Every user only sees what they're supposed to. Full visibility for your cybersecurity lead.

YES
12Review security resources

Compliance gap report delivered at end of deployment, aligned to EFC, EPA, and CISA guidance.

PARTIAL
Key
YESHandled automatically, nothing extra needed
PARTIALAccess Gate does the hard part; you complete the step
MANUALStandard IT practice, no additional product needed
Coverage at a glance
6

Fully covered

4

Mostly covered

2

Standard IT

The 2 manual steps, backups and phishing training, need no additional product. Your team likely already handles them.

Next step

Get ready before the 2027 deadlines.

Access Gate is installed in a day. We map it to the EFC checklist and the DEC/DOH regulations and scope your deployment. Then we get the asset inventory and access controls running before the deadline.

Done

Access Gate is installed in a day.

One appliance connects to your existing network. Water treatment keeps running.

Access Gate fits the grant budget.

Access Gate fits within the $100K upgrade ceiling. We can help you scope the application to maximize coverage.

NIST CSF 2.0 and NY regulations

How Access Gate maps to NIST CSF 2.0 and New York rules.

The grant application requires NIST CSF 2.0 alignment. The DEC and DOH regulations require specific control families. Access Gate maps to both. Each capability below shows the EFC step it satisfies, the NIST CSF 2.0 function it serves, and which regulation it addresses.

Access Gate capabilityEFC step(s)NIST CSF 2.0 functionRegulation
Passive OT asset discovery4 (Inventory)Identify (ID.AM)DEC, DOH
Network microsegmentation (overlay, no rewiring)10 (OT not on open internet)Protect (PR.AC, PR.PT)DEC, DOH
MFA enforcement for legacy OT (no agent required)8 (Enable MFA)Protect (PR.AA)DEC, DOH
JIT and time-limited vendor access3, 11 (Access controls, privileges)Protect (PR.AA, PR.IR)DEC, DOH
Session recording and audit logs7 (Incident response)Detect (DE.AE), Respond (RS.AN)DEC, DOH
Real-time network monitoring and alerting7 (Incident response)Detect (DE.CM)DEC, DOH
Incident response evidence and tamper-evident logs7 (Incident response)Respond (RS.AN, RS.MI)DEC, DOH
Air-gap and on-premise only operation10 (OT not on open internet)Protect (PR.IR), Govern (GV.SC)DEC, DOH

For deeper coverage of the Detect and Respond functions specifically, see Network Traffic Logs for CMMC & IEC 62443 Compliance, which covers the same audit-evidence pattern that satisfies DEC and DOH logging requirements. For the full reference architecture behind a brownfield water-utility deployment (treatment plants, pump stations, distribution SCADA), see the Zero Trust for Utility OT whitepaper.

Questions

Common questions about the SECURE grant and Access Gate.

Jan 1, 2027

DOH drinking-water deadline

The SECURE grant is administered by the New York Environmental Facilities Corporation. It provides up to $50,000 for cybersecurity assessments and up to $100,000 for cybersecurity upgrades for water and wastewater systems across New York State. The 2026 application cycle closed on May 15. Future grant cycles are expected.

Yes. Access Gate covers access control systems, network segmentation, monitoring and alerting, and incident response planning. The upgrade grant lists all of these categories explicitly. It is priced to fit within the $100K ceiling.

Access Gate is installed in a day. It connects to your existing network with no changes to PLCs, SCADA or HMIs. No VLAN change, no recabling, no downtime. Your operations keep running.

No. Access Gate is agentless. It protects devices at the network layer without installing anything on endpoints. This is critical for legacy OT equipment that cannot run modern security agents.

Access Gate aligns with the EPA Water Sector Cybersecurity Guidance, CISA Critical Infrastructure guidelines, and the EFC 12-Step Cybersecurity Checklist. It maps to NIST CSF 2.0 (Govern, Identify, Protect, Detect, Respond, Recover) and to NIST SP 800-82 and IEC 62443 for industrial environments.

Yes. The grant cycle has closed, but the regulations still require the controls. The DOH rules for drinking water apply from January 1, 2027, and the DEC controls for wastewater are due by March 11, 2027, regardless of grant funding. Future grant cycles are expected, but operators should not wait. Access Gate is installed in a day and produces the asset inventory, access controls, segmentation, and audit logs the regulations require.

Drinking water (DOH): January 1, 2027. Wastewater (DEC): March 11, 2027, one year after the rule's adoption. The OT-focused cybersecurity regulations under the New York Department of Environmental Conservation (DEC, for wastewater) and Department of Health (DOH, for drinking water) require water utilities to have asset inventory, access controls, network segmentation, monitoring, incident response capability, and audit logging in place by those dates. Incident reporting already applies since adoption on March 11, 2026. Access Gate covers all of these at the network layer without touching the protected OT assets.