Advertisement

New York boosts funding for water cybersecurity grants

New York Gov. Kathy Hochul announced the state will distribute $9 million to fund more than 150 cybersecurity projects tied to the state's water infrastructure.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
Kathy Hochul
Gov. Kathy Hochul speaks during a roundtable discussion regarding her recent executive order establishing a moratorium on data centers in the state. (Alexander MacDougall / Albany Times Union via Getty Images)

Reminding everyone that not all of the nation’s water infrastructure will be so readily disrupted by cyberattack, New York Gov. Kathy Hochul this week announced more than $9 million in grants to improve the cybersecurity of dozens of water systems across the state.

One hundred and fifty-three local government projects are set to receive funding through Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements, or SECURE, a grant program created to support new cybersecurity standards governing the state’s water and wastewater utilities. The program includes grants of $50,000 for cybersecurity assessments and $100,000 for implementing cybersecurity upgrades.

The regulations hold that facilities must implement common cybersecurity controls, such as limiting users’ access to only systems they need, prohibiting the use of default credentials and requiring complex passwords and multifactor authentication. Larger treatment plants, those processing at least 10 million gallons of water per day, are required to begin monitoring and logging network activity. And treatment plant operators will be required to complete cybersecurity training, every five years, to renew their certifications (though the regulations offer assurance that their total training hours will not increase). When officials unveiled the new cybersecurity regulations for New York water utilities in March, Colin Ahern, the state’s former cyber director, who recently became New York’s first director of security and intelligence, said the new rules would move the state “beyond reactive defense.”

In at least two press releases, New York officials have said the SECURE program would offer just $2.5 million in grants, an amount that fell short of funding all of the water utilities that had expressed interest. The governor’s office did not immediately respond to an email asking why funding had been increased to $9 million, but in a press release Monday, Hochul said the recent wave of cyberattacks against water utilities, which have now reportedly been detected in at least 12 states, demonstrate that risks to the nation’s water infrastructure are “real and escalating.”

Advertisement

This publication reported last Tuesday that more than 30 communities in Minnesota saw their water utilities briefly disrupted by the coordinated cyberattack. The federal government soon after announced that seven additional states had been targeted, possibly by Iran. And news outlets this week have raised the total number of affected states to 12, a list that also includes Georgia, Michigan and South Dakota.

Notwithstanding the president’s confusing suggestion that Minnesota is somehow to blame for the cyberattacks, Iran has, for most analysts, remained the most likely perpetrator. Cynthia Kaiser, a former deputy director of the FBI’s Cyber Division, said that although the recent attacks haven’t been formerly attributed to any particular party, it’s “more than a guess” that Iran is responsible, based on its habit in recent years of targeting the United States’ water infrastructure.

Kaiser, now a senior vice president at the cybersecurity firm Halcyon, said the extent to which New York has developed its cybersecurity policies is “commendable” — “they’ve taken it really seriously and I think that’s a great sign and example for a lot of other states.” The available tax bases and varying appetites for new regulations, versus enticements, she said, will influence how other states approach the challenge of shoring up the water sector’s security, but all states “need to focus on ensuring that their water sector is hardened and shored up.”

Mauricio Papa, a computer science professor at the University of Tulsa, said in a recent interview that water lags behind other sectors, such as energy, on cybersecurity. Kaiser partially attributed the absence of standards to the lack of funding and technical staff available to municipally run facilities. And though Iran consistently exaggerates the outcomes of its cyberattacks — “Iran lies about its impact constantly,” Kaiser said — she recommended utilities take several remedial steps that don’t require a ton of technical know-how, such as disconnecting devices from the internet, changing default passwords and creating inventories of digital devices.

The recent rash of cyberattacks has received widespread news coverage, a fact that might be attributed to its connection to the United States’ war in Iran and the attacks’ broad geographical scope. But there are plenty of cyberattacks against water utilities that have gone under-reported or weren’t reported at all. And there’s no guarantee their impact to the public will remain so negligible  — “It’s death by 1,000 cuts,” Kaiser said.

Latest Podcasts