New York public water systems face a new cybersecurity compliance deadline that requires action before January 1, 2027. The New York State Department of Health's new cybersecurity requirements apply to covered community water systems serving more than 3,300 people and require organizations to establish a cybersecurity program, conduct a cybersecurity vulnerability analysis, address identified vulnerabilities, and maintain documentation.
The timing matters beyond the regulation itself. In July 2026, more than 30 Minnesota community water systems were targeted in a coordinated cyberattack that affected operational technology at multiple utilities. In 2023, an Iranian-affiliated cyber group compromised a system at the Municipal Water Authority of Aliquippa in Pennsylvania, demonstrating that water infrastructure can be targeted through the technology used to monitor and control operations.
For New York water districts, the question is no longer simply whether cybersecurity is important. The more immediate question is:
Is your water system prepared to meet the new requirements before the deadline?
The New York State Department of Health adopted Appendix 5-E, Cybersecurity Requirements for Public Water Systems, in March 2026. The requirements apply primarily to community water systems serving more than 3,300 people, with additional requirements for systems serving more than 50,000 people. Covered systems have until January 1, 2027, to comply with most of the new requirements.
The New York State Department of Health provides a cybersecurity requirements overview and implementation resources for affected water systems.
The regulation requires covered systems to establish a cybersecurity program based on a cybersecurity vulnerability analysis and maintain that program as their technology, personnel, and environment change.
The requirements generally apply to community water systems serving more than 3,300 people. Additional provisions apply to systems serving more than 50,000 people, including certain cybersecurity personnel and certification requirements.
There are exclusions in the regulation, so individual water systems should review the applicability provisions rather than assume the requirements apply or do not apply based solely on their size.
The regulation is broader than implementing a firewall or purchasing cybersecurity software. It requires water systems to establish an ongoing cybersecurity program that addresses governance, vulnerabilities, access, monitoring, incident response, recovery, and documentation.
Covered water systems must prepare a Cybersecurity Vulnerability Analysis (CVA) that identifies cybersecurity risks associated with the water system.
The CVA must be reviewed and updated annually, as well as when major changes to water infrastructure occur. Certain CVA information must also be submitted to the Department of Health on a defined schedule.
For a water district, this means understanding more than its office network.
The assessment should account for the systems and technology that support water operations, including relevant operational technology, information technology, remote access, connected devices, accounts, network infrastructure, and other cyber assets.
The regulation requires each covered water system to establish a cybersecurity program incorporating the findings of its CVA. The program must be updated when changes in technology, staff, or other aspects of the water system could affect cybersecurity.
New York's requirements specifically identify areas such as:
This makes the requirement an ongoing management responsibility, not a one-time compliance project.
Covered water systems must report certain cybersecurity vulnerabilities to the New York State Department of Health within 48 hours of identification when they may affect the system's ability to comply with applicable drinking water requirements or pose a potential risk to public health.
The regulation also establishes a 120-day timeframe for beginning or completing mitigation of certain identified vulnerabilities.
That creates an important operational requirement: a district needs a process for identifying vulnerabilities, determining whether they meet the reporting threshold, documenting them, assigning responsibility, and tracking remediation.
Drinking water operators must receive one hour of cybersecurity training every three years, with proof of training maintained for the Department of Health. This requirement became effective upon adoption of the regulation.
Training is one of the areas where cybersecurity becomes an operational behavior issue rather than solely a technology issue.
A regulatory deadline changes the cybersecurity conversation.
Without a defined requirement, a water district may reasonably prioritize infrastructure projects, staffing, maintenance, or other operational needs ahead of cybersecurity improvements.
With a regulatory requirement, cybersecurity becomes part of the organization's documented responsibilities.
The January 1, 2027 deadline means covered systems need to understand their current position, identify gaps, and establish a plan for addressing those gaps before compliance is required.
The New York Department of Health's requirements also make clear that cybersecurity programs must evolve as technology, staff, and the water system change.
That means compliance should not be treated as a document that gets completed once and filed away.
The regulatory changes are occurring against a backdrop of documented cyber incidents involving water infrastructure.
In July 2026, Minnesota IT Services reported that a coordinated cyberattack targeted operational technology at more than 30 community water systems across the state. Some affected systems experienced disruptions involving technology used to monitor and control water operations. The investigation remains ongoing, and Minnesota officials have not publicly attributed the activity to a specific actor.
The incident was not the first example of attackers targeting water infrastructure.
In November 2023, the Municipal Water Authority of Aliquippa in Pennsylvania reported that an Iranian-affiliated group compromised a system at a remote booster station. Federal agencies subsequently warned that Iranian government-affiliated actors were exploiting internet-exposed programmable logic controllers in multiple sectors, including U.S. water and wastewater facilities.
These incidents illustrate an important distinction for water district leadership:
Cybersecurity risk is not limited to the office network.
Water systems increasingly depend on interconnected technology to monitor, control, communicate with, and maintain critical infrastructure. A cybersecurity program therefore needs to account for both traditional IT and the operational systems that support the water system.
A practical approach is to treat the January 2027 deadline as a structured readiness project rather than waiting until the final weeks before compliance is required.
Confirm whether the water system falls within the regulation's definition of a covered water system and identify which requirements apply based on population served and system characteristics.
Determine whether the district already has:
The goal is to identify what already exists before creating something new.
Identify the systems, devices, accounts, applications, networks, and connections that could affect the security or operation of the water system.
Pay particular attention to:
Evaluate the identified systems and controls to determine where vulnerabilities exist and which risks require remediation.
The assessment should result in more than a list of technical findings. Each material issue should have an owner, priority, remediation plan, and evidence of progress.
Use the CVA findings to establish the district's cybersecurity program.
The program should clearly define:
The regulation requires the cybersecurity program and CVA to remain current.
A useful operating model is to establish a recurring review cadence around:
Assess → Prioritize → Remediate → Monitor → Document → Review
This turns compliance into an ongoing management process rather than an annual scramble.
Many water districts use Microsoft 365 for email, collaboration, document management, identity, and administrative operations.
Securing that environment is an important part of the broader cybersecurity program, but it is not the entire program.
A water district should evaluate areas such as:
These controls help protect the district's IT environment and administrative systems. They should be considered alongside the controls protecting operational technology and other systems involved in water operations.
The objective is not simply to deploy more security tools. It is to establish appropriate controls based on the district's actual risks and demonstrate that those controls are being managed.
The immediate issue is not simply whether a district has purchased enough cybersecurity technology.
The more important questions are whether the district can demonstrate that it has:
New York's regulation establishes specific consequences for non-compliance. The Department of Health states that non-compliance with certain vulnerability-analysis requirements is considered a significant deficiency, which must be corrected within the applicable 120-day timeframe.
For leadership, the broader issue is governance. If a cyber incident occurs, having a documented process for identifying risks, addressing vulnerabilities, and maintaining required controls provides a materially different position than discovering those gaps after an incident.
Many water districts do not have dedicated cybersecurity staff with the time or specialized expertise to manage every component of a modern security program.
A qualified IT or security partner can help bridge that gap by supporting the district's internal team with:
The important distinction is that a provider should not simply deliver a compliance document.
The goal should be to connect regulatory requirements to actual technology, people, processes, ownership, and measurable remediation.
Before the January 1, 2027 deadline, leadership should be able to answer:
If several answers are unclear, the next step is not necessarily to buy another security tool. It is to establish the district's current state, identify the gaps, and build a prioritized path to compliance.
The New York cybersecurity requirements give water districts a defined framework for strengthening cybersecurity, but meeting the requirements requires more than checking boxes.
A practical program connects the regulation to the district's actual environment: its IT systems, operational technology, users, vendors, access points, vulnerabilities, response procedures, and recovery capabilities.
For covered water systems, the January 1, 2027 deadline provides a clear point around which to organize that work. Starting with a cybersecurity vulnerability analysis and using the results to build a documented, operational cybersecurity program gives leadership a clearer view of both compliance requirements and security priorities.
Sourcepass helps organizations evaluate their cybersecurity environment, identify and prioritize risk, strengthen security controls, and establish the ongoing processes needed to manage cybersecurity as an operational responsibility.
New York Appendix 5-E requires covered community water systems to establish a cybersecurity program, conduct and maintain a cybersecurity vulnerability analysis, address certain identified vulnerabilities, maintain applicable documentation, and meet additional requirements for training, incident reporting, and cybersecurity personnel depending on the system.
Covered water systems generally have until January 1, 2027, to comply with the requirements of Appendix 5-E. Certain training and vulnerability-reporting requirements became effective earlier upon adoption of the regulation.
The requirements generally apply to community water systems serving more than 3,300 people. Additional requirements apply to certain systems serving more than 50,000 people. The regulation also includes exclusions, so individual systems should review the applicability provisions.
A cybersecurity vulnerability analysis, or CVA, evaluates cybersecurity vulnerabilities affecting a covered water system. New York requires covered systems to review and update the CVA annually and when major water infrastructure changes occur.
New York identifies requirements including a cyber asset inventory, access control procedures, detection and incident response procedures, recovery plans, and a review schedule. Additional network monitoring and designated-personnel requirements apply to systems meeting the applicable population threshold.
Yes. Drinking water operators must receive one hour of cybersecurity training every three years, and proof of training must be available to the Department of Health upon request.
The cybersecurity requirements are designed around the covered water system's cyber environment, including relevant operational technology. Water systems should evaluate the technology and connections that could affect water system operations as part of their cybersecurity vulnerability analysis. The New York Department of Health's requirements specifically call for identifying cyber assets and establishing appropriate access, detection, response, and recovery procedures.
Start by confirming applicability, reviewing existing documentation, inventorying relevant cyber assets, conducting the cybersecurity vulnerability analysis, identifying gaps, and building the required cybersecurity program. Then establish ownership, remediation timelines, documentation, and recurring review processes.
An MSP or managed security provider can support assessments, vulnerability management, identity and Microsoft 365 security, monitoring, incident response planning, documentation, and ongoing security management. The district should establish clear responsibility for regulatory compliance and ensure its provider's scope addresses the specific requirements applicable to the water system.
Starting early gives the district time to understand its current environment, identify vulnerabilities, prioritize remediation, establish required documentation, and implement the cybersecurity program before January 1, 2027. Waiting until the deadline can compress assessment, procurement, remediation, and documentation into the same period.
In July 2026, more than 30 Minnesota community water systems were targeted in a coordinated cyberattack involving operational technology. In November 2023, the Municipal Water Authority of Aliquippa in Pennsylvania experienced an intrusion affecting a remote booster station. Federal agencies subsequently warned about Iranian government-affiliated actors targeting internet-exposed programmable logic controllers used in multiple sectors, including water and wastewater systems.