Meet New York's water cybersecurity rules before the 2027 deadlines.
This page explains what the SECURE grant covers, what Access Gate does, and how they fit together.
Last updated:
The EFC SECURE grant helps NY water utilities meet new state cybersecurity regulations. DOH enforces them for drinking water from January 1, 2027, and DEC for wastewater from March 11, 2027. Access Gate is an on-premise appliance. It fully covers 6 of the EFC 12 steps automatically and does the heavy lifting on 4 more, 10 of the 12 in total. Those steps include asset inventory, access controls, MFA for legacy OT, network segmentation and incident-response logging. The remaining 2 steps, backups and phishing training, are standard IT practice.
On March 11, 2026, Governor Hochul signed first-in-nation cybersecurity regulations for all New York water and wastewater operators. Every system must now meet minimum standards: asset inventory, access controls, incident reporting, and MFA enforced at the network layer for legacy PLCs that cannot run modern auth software. The standards align with EPA and CISA guidance. To help communities comply, the state launched the SECURE grant program, administered by the Environmental Facilities Corporation (EFC). The 2026 grant cycle closed on May 15, but the regulations themselves require compliance by January 1, 2027 for drinking water (DOH) and by March 11, 2027 for wastewater (DEC). Implementation takes time, so it pays to start now. Our operator field guide walks through the requirements, the funding, and how to comply. See the EFC Cybersecurity Hub
For a cybersecurity assessment
- · Risk assessment & penetration testing
- · Network review & asset inventory
- · Compliance roadmap
To implement upgrades
- · Firewalls & segmentation
- · Access control systems
- · Monitoring & alerting
- · Incident response planning
Installed in a day while the plant keeps running.
Access Gate connects to your existing network. Nothing is installed on PLCs or SCADA. No VLAN, no recabling, no downtime.
See the lollipop architectureSee every machine.
Automatically finds all IT, OT, and IoT equipment, including legacy systems. Produces the asset inventory required for the $50K assessment grant.
Access Gate covers what the regulations require.
Covers access controls, MFA for legacy equipment, network segmentation, and audit logging. Priced within the $100K upgrade grant ceiling.
The water keeps flowing if Access Gate goes down.
Access Gate governs the access path to your control equipment, not the control loop inside it. Pump stations, chemical dosing, and tank-level control keep running if Access Gate reboots: local PLCs and HMIs are untouched, and the continuous SCADA poll to your outstations stays on its own path. What stops is new remote and vendor access, which is exactly what you want paused when the enforcement point is unavailable.
Fail-open or fail-closed is a per-asset, logged decision, not a default. Access Gate runs as a high-availability pair with failover, so one fault does not stop access. An authenticated, logged break-glass path covers the 2 a.m. emergency. Cyclic controller-to-I/O traffic never traverses Access Gate, so it cannot add latency to a running process or a safety loop.
Vendors can read the analyzer but cannot change dosing.
A firewall decides yes or no on a port. Access Gate reads the protocol on the wire and decides at the function-code level. Two examples come from a real water district. The district polls 30 outstations over LTE with DNP3 (port 20000), master to outstation, over radio and cellular. Access Gate lets the poll and response through but blocks a control-relay operate to a remote pump. A chem-feed vendor connecting to tune the dosing loop can read the chlorine analyzer over Modbus (FC3, read holding registers) but cannot write the dosing setpoint (FC6 or FC16, write single or multiple registers). The same rule protects tank-level control and pump VFD speed references. Monitoring stays open, and any write that changes plant behavior is blocked.
Go deeper on the mechanism: what an industrial proxy is, securing a legacy PLC, and the operator field guide.
| # | Step | Coverage |
|---|---|---|
| 1 | Change default passwords Flags weak or default credentials on every discovered device. | YES |
| 2 | Strong password policy Enforces credential policy through the access control layer. | PARTIAL |
| 3 | Enforce access controls Who can connect to what, when, enforced and logged automatically. | YES |
| 4 | Inventory all assets Finds every device on your network. OT, IT, IoT. Output used directly as a grant deliverable. | YES |
| 5 | Back up systems Outside scope. Access Gate identifies systems with no backup configured. | MANUAL |
| 6 | Keep software updated Shows firmware and software versions for every device, so you can see what needs updating. | PARTIAL |
| 7 | Incident response plan A full event log and real-time alerts give you the timeline every IR plan needs. | PARTIAL |
| 8 | Enable MFA Enforces MFA even on old PLCs and HMIs that cannot do it natively. Access Gate brokers the session and performs the MFA at the proxy, so the controller is never modified. | YES |
| 9 | Identify phishing Outside scope. Staff training and email security required. | MANUAL |
| 10 | OT not on open internet Wraps all OT equipment in a secure layer, so no device is directly exposed to the internet. | YES |
| 11 | Manage user privileges Every user only sees what they're supposed to. Full visibility for your cybersecurity lead. | YES |
| 12 | Review security resources Compliance gap report delivered at end of deployment, aligned to EFC, EPA, and CISA guidance. | PARTIAL |
Fully covered
Mostly covered
Standard IT
The 2 manual steps, backups and phishing training, need no additional product. Your team likely already handles them.
Get ready before the 2027 deadlines.
Access Gate is installed in a day. We map it to the EFC checklist and the DEC/DOH regulations and scope your deployment. Then we get the asset inventory and access controls running before the deadline.
Access Gate is installed in a day.
One appliance connects to your existing network. Water treatment keeps running.
Access Gate fits the grant budget.
Access Gate fits within the $100K upgrade ceiling. We can help you scope the application to maximize coverage.
How Access Gate maps to NIST CSF 2.0 and New York rules.
The grant application requires NIST CSF 2.0 alignment. The DEC and DOH regulations require specific control families. Access Gate maps to both. Each capability below shows the EFC step it satisfies, the NIST CSF 2.0 function it serves, and which regulation it addresses.
| Access Gate capability | EFC step(s) | NIST CSF 2.0 function | Regulation |
|---|---|---|---|
| Passive OT asset discovery | 4 (Inventory) | Identify (ID.AM) | DEC, DOH |
| Network microsegmentation (overlay, no rewiring) | 10 (OT not on open internet) | Protect (PR.AC, PR.PT) | DEC, DOH |
| MFA enforcement for legacy OT (no agent required) | 8 (Enable MFA) | Protect (PR.AA) | DEC, DOH |
| JIT and time-limited vendor access | 3, 11 (Access controls, privileges) | Protect (PR.AA, PR.IR) | DEC, DOH |
| Session recording and audit logs | 7 (Incident response) | Detect (DE.AE), Respond (RS.AN) | DEC, DOH |
| Real-time network monitoring and alerting | 7 (Incident response) | Detect (DE.CM) | DEC, DOH |
| Incident response evidence and tamper-evident logs | 7 (Incident response) | Respond (RS.AN, RS.MI) | DEC, DOH |
| Air-gap and on-premise only operation | 10 (OT not on open internet) | Protect (PR.IR), Govern (GV.SC) | DEC, DOH |
For deeper coverage of the Detect and Respond functions specifically, see Network Traffic Logs for CMMC & IEC 62443 Compliance, which covers the same audit-evidence pattern that satisfies DEC and DOH logging requirements. For the full reference architecture behind a brownfield water-utility deployment (treatment plants, pump stations, distribution SCADA), see the Zero Trust for Utility OT whitepaper.
Common questions about the SECURE grant and Access Gate.
DOH drinking-water deadline
The SECURE grant is administered by the New York Environmental Facilities Corporation. It provides up to $50,000 for cybersecurity assessments and up to $100,000 for cybersecurity upgrades for water and wastewater systems across New York State. The 2026 application cycle closed on May 15. Future grant cycles are expected.
Yes. Access Gate covers access control systems, network segmentation, monitoring and alerting, and incident response planning. The upgrade grant lists all of these categories explicitly. It is priced to fit within the $100K ceiling.
Access Gate is installed in a day. It connects to your existing network with no changes to PLCs, SCADA or HMIs. No VLAN change, no recabling, no downtime. Your operations keep running.
No. Access Gate is agentless. It protects devices at the network layer without installing anything on endpoints. This is critical for legacy OT equipment that cannot run modern security agents.
Access Gate aligns with the EPA Water Sector Cybersecurity Guidance, CISA Critical Infrastructure guidelines, and the EFC 12-Step Cybersecurity Checklist. It maps to NIST CSF 2.0 (Govern, Identify, Protect, Detect, Respond, Recover) and to NIST SP 800-82 and IEC 62443 for industrial environments.
Yes. The grant cycle has closed, but the regulations still require the controls. The DOH rules for drinking water apply from January 1, 2027, and the DEC controls for wastewater are due by March 11, 2027, regardless of grant funding. Future grant cycles are expected, but operators should not wait. Access Gate is installed in a day and produces the asset inventory, access controls, segmentation, and audit logs the regulations require.
Drinking water (DOH): January 1, 2027. Wastewater (DEC): March 11, 2027, one year after the rule's adoption. The OT-focused cybersecurity regulations under the New York Department of Environmental Conservation (DEC, for wastewater) and Department of Health (DOH, for drinking water) require water utilities to have asset inventory, access controls, network segmentation, monitoring, incident response capability, and audit logging in place by those dates. Incident reporting already applies since adoption on March 11, 2026. Access Gate covers all of these at the network layer without touching the protected OT assets.