Security News

Cybersecurity news aggregator

đŸ›ïž
INFO News SecurityWeek

New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems

  • What: New York allocates $9 million to improve cybersecurity at water systems
  • Impact: 153 water and wastewater systems in New York will receive funding to strengthen cyber defenses
Read Full Article →

ICS/OT New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. By Mike Lennon | August 3, 2026 (9:54 PM ET) Flipboard Reddit Whatsapp Whatsapp Email New York is awarding more than $9 million to help 153 drinking water and wastewater systems strengthen their defenses against cyberattacks. Governor Kathy Hochul announced the funding Monday through the state’s Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements (SECURE) grant program. The grants will fund cybersecurity assessments and the implementation of security improvements at local utilities. Recipients will also have access to no-cost technical assistance from the New York State Environmental Facilities Corporation (EFC). The funding is intended to help utilities comply with minimum cybersecurity standards introduced by New York in March. Those standards include mandatory cybersecurity training for certified operators, incident reporting requirements, risk-based protections for critical operations and sensitive information, and the designation of a cybersecurity lead at larger drinking water systems. When the SECURE program was launched , New York said utilities could receive up to $50,000 for cybersecurity assessments and up to $100,000 for implementing security upgrades. “These threats are real and escalating,” Hochul said, pointing to the recent cyberattacks against water systems in multiple states. Advertisement. Scroll to continue reading. The funding announcement comes shortly after a coordinated cyber campaign targeted operational technology systems at water and wastewater facilities across the United States. More than 30 community water systems in Minnesota were targeted on July 26 and 27. Some municipalities reported disruptions to automated control functions, although contingency procedures allowed most facilities to remain operational. The city of Braham briefly took its water plant offline after attackers shut down operating controls, stopping the well and water treatment plant. Other affected municipalities said their drinking water remained safe and services continued operating. The campaign was subsequently found to have affected water infrastructure in at least seven states . Michigan confirmed malicious activity involving a small number of communities, while Rapid City, South Dakota, reported an incident involving a wastewater lift station. Georgia was also reportedly among the states targeted. No New York utility has been publicly linked to the campaign. Federal investigators have not formally attributed the attacks. However, Iran has emerged as a leading suspect because the activity reportedly resembles previous campaigns linked to Iranian threat actors known to target industrial control systems and water utilities. Following the attacks, the US Cybersecurity and Infrastructure Security Agency (CISA) urged water and wastewater operators to remove publicly exposed programmable logic controllers and other operational technology from the internet. The agency also recommended changing default passwords, routing necessary remote access through secure gateways or virtual private networks, and restricting connections to trusted IP addresses. The $9 million in cybersecurity grants is separate from a five-year, $3.8 billion clean water infrastructure investment included in New York’s fiscal year 2027 budget. The state said that investment will bring its total water infrastructure grants since 2017 to more than $10 billion. Related : US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Ot her States Written By Mike Lennon For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is founder and director of several leading cybersecurity industry conferences around the world. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Mike Lennon Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security SecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary Edition Cisco Moves to Acquire Astrix Security to Tackle Non-Human Identity Risks Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks Latest News Black Hat USA 2026 – Summary of Vendor Announcements (Part 1) Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations River Bank Says Hackers Deleted Data Stolen in Ransomware Attack Horizon3 Raises $250 Million to Fund Continuing Growth N‑able Patches Vulnerability Exploited to Hack N-central Servers Brinks Home Discloses Data Breach as Hackers Leak Files Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move PNC Financial Services Group has appointed Christian Winward as CISO. Brian Gumbel has joined Armadin as Chief Revenue Officer. EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO. More People On The Move Expert Insights Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email

Share this article