TroutTrout
New York · DOH & DEC compliance

Water & wastewater cybersecurity for New York

Trout Access Gate is an on-premise appliance to meet New York's water cybersecurity rules: it puts access control, segmentation, and audit in front of your treatment systems, using the staff you already have.

Last updated:

New York water treatment control systems
Jan 1 2027

DOH and DEC operational technology deadline

3,300+

people served: the threshold where the rules apply

318

NY public water systems covered by the rules

$9M

SECURE grants awarded to 153 NY water systems (Aug 2026)

SECURE grant funding

The money is flowing: $9M awarded in August 2026

In August 2026, New York's Environmental Facilities Corporation (EFC) awarded $9 million in SECURE cybersecurity grants to 153 water systems, with individual awards from $5,000 to $308,500. The grants fund the exact work the DOH and DEC rules require: cybersecurity risk assessments, incident response plans, firewall implementation, SCADA and control-system upgrades, and network assessments.

$120,160

Albany Water Board

$308,500

South Huntington Water District (implementation)

$150,000

Niagara County (penetration testing)

“New York is taking action to protect our critical water infrastructure from cyberattacks that could disrupt services and threaten public health and safety.”Governor Kathy Hochul

Access Gate is grant-eligible equipment you own and install. See the SECURE grant guide for eligible uses and how to buy without running a bid.

Trout Software
Who is Trout

New York State small business, built in the Catskills to protect the nation's critical networks and water systems. Securing critical infrastructure is what we do. Meet the team

What the rules require, and by when

In March 2026, Governor Hochul announced finalized cybersecurity regulations for public water and wastewater systems, developed jointly by DOH (drinking water) and DEC (wastewater) and aligned with federal EPA and CISA guidance. Incident reporting and operator training apply now; the IT rules took effect January 1, 2026; the core OT rules take effect January 1, 2027.

  • A formal cybersecurity program aligned with the six functions of NIST CSF 2.0.
  • Annual vulnerability assessments, updated within 30 days of any major infrastructure change.
  • A cyber asset inventory, authentication and access management, and network monitoring and logging.
  • Incident reporting to DOH within 24 hours, vulnerability reporting within 48 hours.
  • A tested incident response plan and cybersecurity training for certified operators.

Systems above 50,000 people must also appoint a designated cybersecurity lead and conduct continuous monitoring. For the full walkthrough, including the OT asset inventory method and the air-gap exemption, see the operator field guide.

Coverage

How Access Gate covers the DOH and DEC requirements

Cyber asset inventory

Covered

NY requires: Identify every device on the OT network

Access Gate: Agent-free discovery maps PLCs, HMIs, SCADA servers, and remote links from day one, including legacy gear that cannot run an agent.

Authentication & access management

Covered

NY requires: Control who can reach critical systems

Access Gate: Every session is authenticated and tied to a named user. Operators and vendors reach only what they are authorized to, time-boxed and revocable.

Segmentation (IT/OT and within OT)

Covered

NY requires: Separate the plant floor from the office network

Access Gate: Microsegmented enclaves enforced at the network level, without recabling or touching existing VLANs.

Monitoring & logging

Covered

NY requires: Record activity on critical systems

Access Gate: Tamper-evident session records: identity, equipment, commands, duration. Usable by a SIEM or in an investigation.

Incident reporting (24h to DOH)

Partial

NY requires: Report incidents within 24 hours of detection

Access Gate: The audit trail gives you the timeline to report accurately inside the window. It supports, but does not replace, the reporting process.

Annual vulnerability assessment

Partial

NY requires: Assess, updated within 30 days of a major change

Access Gate: Visibility and asset data feed the assessment; the SECURE assessment grant is meant to pay for it.

Tested incident response plan

Out of Scope

NY requires: Keep operations running during an attack

Access Gate: Access Gate supports containment and evidence, but the plan and its testing are yours to own.

Operator training

Partial

NY requires: Cybersecurity training for certified operators

Access Gate: Trout's operator cybersecurity training is approved by DEC and DOH to qualify for the training requirement. Your certification and EFC's no-cost technical assistance cover the rest.

Coverage reflects a typical deployment. Confirm scope for your system with the Trout team.

Operator questions

New York water cybersecurity, answered

Jan 1

2027 OT deadline

Any community water system serving more than 3,300 people. The rules, from the Department of Health (DOH) for drinking water and the Department of Environmental Conservation (DEC) for wastewater, cover about 318 public water systems, most in the 3,300 to 50,000 population band. Systems above 50,000 carry additional obligations. New York is the first state to finalize cybersecurity rules for public water and wastewater systems.

The core operational technology (OT) requirements from DOH and DEC take effect January 1, 2027. Information technology rules under the Public Service Commission took effect January 1, 2026. Incident reporting and operator training obligations apply immediately on adoption. Because the OT work takes months, systems should start well ahead of 2027.

A formal cybersecurity program aligned with the six functions of NIST CSF 2.0; annual vulnerability assessments; a cyber asset inventory with authentication, access management, and network monitoring and logging; incident reporting to DOH within 24 hours and vulnerability reporting within 48 hours; a tested incident response plan; and cybersecurity training for certified operators. Systems above 50,000 also need a designated cybersecurity lead and continuous monitoring.

Yes. In August 2026, the Environmental Facilities Corporation (EFC) awarded $9 million in SECURE cybersecurity grants to 153 water systems, with individual awards from $5,000 to $308,500. The grants fund cybersecurity risk assessments, incident response plans, firewalls, SCADA and control-system upgrades, and network assessments, the equipment you own and install to meet the state's minimum cybersecurity standards for drinking water and sewer systems. EFC's Community Assistance Teams offer free assessments and can flag the next round.

Put one protective layer in front of the control equipment instead of software on every device. It authenticates who is asking, enforces what each user or device can reach, keeps PLCs off the open network, and produces tamper-evident records. This meets the identify, protect, detect and respond functions the rules ask for, with no agent on legacy PLCs, no plant rebuild, and no dedicated OT security engineer, running with your existing IT support.

Respect Your Elders water pump sticker
Respect Your Elders PLC sticker

Respect Your Elders.

Your legacy pumps, PLCs, and RTUs don't need replacing. Get free stickers and learn how Trout secures water OT for the New York DEC and DOH rules.

Get Free Stickers

Meet the January 1, 2027 deadline with the staff you have

No agent on your PLCs, no plant rebuild, no dedicated OT security engineer. Grant-eligible as equipment, deployable in about three weeks.