Skip to the main content.

Modernize & Transform

Built to help you reimagine IT operations, empower your workforce, and leverage AI-powered tools to stay ahead of the curve.

Untitled design (3)

Empower My Team

We bring together the best of Microsoft’s cloud ecosystem and productivity tools to help your people thrive.

Untitled design (3)

Build My Infrastructure

We offer a comprehensive suite of infrastructure services tailored to support your business goals today and scale for the future

Untitled design (3)

IT Services

Our managed and co-managed IT service plans deliver a responsive and innovative engagement to support your IT needs, improve employee experience, and drive growth for your business. 

Untitled design (3)

Cybersecurity Services

Sourcepass offers innovative solutions, including SOC, GRC, Security Assessments, and more to protect your business.

Untitled design (3)

Professional Services

Grow your business with cloud migrations, infrastructure refreshes, M&A integrations, staff augmentation, technical assessments, and more.

Untitled design (3)

Center of Excellence for Microsoft

Maximize your Microsoft investment through strategy, security, modernization, adoption, and continuous optimization.

Untitled design (3)

Commercial Industries

We understand what most managed service providers don’t – when it comes to industry-specific technology, one-size-fits-all solutions don’t exist.

Untitled design (3)

Public Sector

Specialized IT, cybersecurity, and compliance support for schools, BOCES, local governments, and utilities — backed by 40+ years of public-sector experience.  

Untitled design (3)

Locations

We serve clients across the lower 48, with regional concentration in the Northeast, Mid-Atlantic, Southeast, Mountain West, and West.  

Untitled design (3)

The Sourcepass Story

Built and run by technology, security, and managed services people who were tired of how IT gets delivered – and decided to do it differently. 

Untitled design (3)

The Sourcepass Experience

Excellent service, strategic guidance, and technology delivered with innovation – the operating model behind every Sourcepass engagement, across IT, security, Microsoft, and AI. 

Untitled design (3)

 

NY Water Cybersecurity: IT/OT Security Requirements | Sourcepass

 
NY Water Cybersecurity: IT/OT Security Requirements | Sourcepass

A water system is not a typical IT environment.

A business can lose access to email or a CRM and still operate while systems are restored. A water utility has another layer of technology responsible for monitoring and controlling pumps, valves, treatment processes, storage levels, and distribution infrastructure. When that operational technology is disrupted or manipulated, the consequence can extend beyond data loss or business interruption.

That is why New York drinking water cybersecurity requirements increasingly focus on more than traditional IT controls. The state's cybersecurity requirements recognize the relationship between information technology (IT), operational technology (OT), process control systems, and public health.

New York's Appendix 5-E requirements apply to covered community water systems and specifically address cybersecurity programs, vulnerability analysis, incident response, training, and, for larger systems, network monitoring. The New York State Department of Health also recognizes documented separation between OT and IT, and between OT and external networks, in its exclusion provisions.

For water system executives and IT leaders, the important question is not simply whether the organization is "compliant."

It is whether the technology environment is structured so that a compromise in the business network does not unnecessarily become an operational problem.

 

Why Water Systems Have a Different Cybersecurity Environment

Most organizations think about cybersecurity primarily through the lens of users, endpoints, applications, data, and identity.

Water systems have all of those, but they also have systems that interact with the physical environment.

New York's own Cybersecurity Vulnerability Analysis Checklist distinguishes between business enterprise systems and process control systems. The latter can include supervisory control and data acquisition (SCADA) systems used to operate and monitor pumps, valves, storage tanks, and other water treatment and distribution functions.

That creates two interconnected cybersecurity environments:

 

Information technology

IT generally includes:

  • Microsoft 365 and email
  • User computers and mobile devices
  • Identity and authentication systems
  • Servers and business applications
  • Billing and customer systems
  • Network infrastructure
  • Internet connectivity
  • Administrative systems

These are familiar territory for most IT teams.

 

Operational technology

OT includes technology that directly supports physical operations, such as:

  • SCADA systems
  • Programmable logic controllers (PLCs)
  • Human-machine interfaces (HMIs)
  • Sensors and instrumentation
  • Pumps and valves
  • Treatment and monitoring equipment
  • Industrial communications systems
  • Control servers and workstations

The distinction matters because IT security practices cannot simply be copied into an OT environment without considering availability, safety, legacy equipment, vendor dependencies, and operational requirements.

The EPA's water sector cybersecurity guidance similarly treats OT and IT as connected but distinct areas that require specific cybersecurity considerations.

 

New York Drinking Water Cybersecurity Requirements Start With Understanding the Environment

A cybersecurity program is difficult to manage if no one has a reliable picture of what exists.

That is particularly important in water systems, where equipment may have been deployed over many years by different vendors and may not be managed through the same tools used for conventional IT.

New York's cybersecurity assessment materials specifically call for inventories of process control assets, including applications, servers, workstations, field devices such as PLCs, communications equipment, and network equipment.

The EPA recommends the same foundational approach. Its guidance calls for maintaining an updated inventory of both OT and IT assets, including third-party and legacy equipment.

 

An effective inventory should answer more than "what do we own?"

A useful IT/OT asset inventory should help answer:

  • What is the asset?
  • Where is it located?
  • What network is it connected to?
  • What does it control or support?
  • Who administers it?
  • Which vendor supports it?
  • How is it accessed remotely?
  • What credentials or accounts can access it?
  • What other systems does it communicate with?
  • What happens if it becomes unavailable?
  • How is it monitored?
  • How is it restored?

This turns an asset inventory from a compliance document into an operational decision-making tool.

 

IT/OT Separation Is a Security Control, Not Just a Network Diagram

One of the most important concepts in water system cybersecurity is segmentation.

If a user's laptop, Microsoft 365 account, or business application is compromised, the objective should be to prevent that compromise from providing an easy path into systems controlling physical operations.

New York explicitly recognizes documented OT/IT separation and OT/external-network separation in its cybersecurity exclusion provisions. Those exclusions do not eliminate requirements related to training, emergency response planning, or reporting.

The underlying security principle is broader than regulatory compliance.

The fewer unnecessary pathways between IT and OT, the fewer opportunities there are for an IT compromise to become an operational compromise.

 

What effective separation can look like

Depending on the environment, controls may include:

  • Separate IT and OT network segments
  • Firewalls between IT and OT environments
  • Controlled communication paths
  • Jump servers or bastion hosts for administrative access
  • Restricted administrative privileges
  • Separate credentials and accounts
  • Network access control
  • Logging and monitoring of connections between environments
  • Explicit vendor access procedures

The EPA's cybersecurity guidance for drinking water and wastewater systems recommends that connections between OT and IT networks pass through an intermediary such as a firewall, bastion host, jump box, or DMZ that is monitored and logged. It also recommends MFA for remote access to OT and IT networks.

The goal is not to make OT inaccessible.

The goal is to make access intentional, limited, observable, and reversible.

 

Remote Access Is One of the Most Important IT/OT Security Decisions

Remote access can be operationally necessary. Water systems may depend on vendors, engineers, operators, or IT personnel who need to troubleshoot systems without being physically present.

The risk comes when remote access is treated as a permanent convenience rather than a controlled pathway into critical infrastructure.

An OT remote-access review should consider:

  • Who can connect?
  • From where?
  • Using which device?
  • Through which system?
  • At what times?
  • With what level of privilege?
  • Is MFA required?
  • Is the session logged?
  • Can access be disabled immediately?
  • Is vendor access temporary or persistent?
  • What happens when a vendor relationship ends?

The EPA specifically recommends MFA for remote access to OT networks and controlled, monitored connections between OT and IT environments.

For organizations using Microsoft 365, this is where identity security becomes relevant to OT security.

Microsoft Entra ID, MFA, conditional access, privileged access controls, endpoint security, and centralized identity governance can strengthen the business side of the environment. But those controls should not create a false assumption that the SCADA or OT environment is therefore secure.

The important question is how identity and access controls connect to the actual operational architecture.

 

SCADA Security Requires More Than Protecting the SCADA Server

SCADA is often the most recognizable component of a water system's OT environment, but it is not an isolated application.

A typical operational environment can include:

Operator → HMI → SCADA server → PLC → equipment

with sensors, communications infrastructure, engineering workstations, remote-access tools, and other dependencies surrounding it.

A weakness anywhere in that chain can affect the security of the overall system.

For example, an exposed HMI can provide an unauthorized user with visibility into operational information and, depending on the configuration, the ability to make changes to system settings. EPA and CISA have specifically warned about internet-exposed HMIs in water and wastewater environments.

That means an OT security review should not stop at asking whether the SCADA platform itself is patched.

It should examine the surrounding architecture.

 

Questions worth asking

  • Is any OT equipment directly accessible from the internet?
  • Are HMIs exposed externally?
  • Are PLCs reachable from unnecessary network segments?
  • Are engineering workstations adequately protected?
  • Are vendor connections controlled?
  • Are default or shared accounts still in use?
  • Are privileged accounts separated from standard accounts?
  • Are legacy systems still connected?
  • Are unsupported operating systems present?
  • Are backups available and tested?
  • Can the system operate safely if SCADA becomes unavailable?

These questions turn cybersecurity from an abstract IT exercise into an operational risk assessment.

 

Network Monitoring Creates Visibility Into What Is Actually Happening

Segmentation reduces unnecessary pathways.

Monitoring helps determine whether those pathways are being used.

New York's requirements include additional network monitoring and logging provisions for community water systems serving more than 50,000 people.

But visibility is valuable regardless of system size.

A practical monitoring strategy should help identify:

  • Unexpected connections between IT and OT
  • New or unknown devices
  • Failed authentication attempts
  • Unusual privileged activity
  • Remote-access sessions
  • Changes to critical systems
  • Suspicious network traffic
  • Devices communicating outside expected patterns

This is where managed security capabilities can be particularly useful for smaller IT teams. A water system does not necessarily need a large internal security operation to establish meaningful monitoring, but it does need defined ownership, escalation procedures, and someone responsible for reviewing and acting on meaningful signals.

The objective is not to collect the maximum amount of data.

It is to ensure that important changes in the environment are visible to someone who can act on them.

 

Incident Response Has to Account for Operations

A conventional incident response plan might focus on isolating endpoints, disabling accounts, restoring applications, and recovering data.

A water system needs to go further.

What happens if the SCADA environment is unavailable?

What happens if an operator cannot authenticate?

What happens if remote access has to be disabled?

What happens if a PLC or HMI is suspected of being compromised?

What happens if the organization has to operate without normal network connectivity?

New York requires covered water systems to maintain a written cybersecurity incident response plan describing tasks during and following a cybersecurity incident to maintain or restore compliance with applicable drinking water requirements.

The EPA's water sector resources similarly emphasize incident response and recovery planning for scenarios involving disabled or manipulated process control systems.

 

Recovery should be tested, not assumed

One of the most valuable exercises a water system can conduct is a scenario-based tabletop exercise.

For example:

"At 8:00 a.m., the IT team discovers suspicious activity involving an account that has access to both the business environment and an OT management system. At 8:15 a.m., operators report that remote access to SCADA is unavailable."

The exercise should answer:

  1. Who declares the incident?
  2. Who owns the operational response?
  3. Who can disable the affected account?
  4. Who can isolate the relevant network?
  5. How do operators communicate if normal systems are unavailable?
  6. Can the facility operate manually?
  7. Who contacts vendors?
  8. Who determines whether regulatory reporting is required?
  9. How are systems restored?
  10. How is the root cause documented?

The EPA's water sector cybersecurity resources provide incident response and asset inventory resources specifically designed for water and wastewater system operators.

 

How IT/OT Vulnerabilities Can Become Public-Health Risks

This is ultimately what makes water cybersecurity different.

A compromised business application may create financial, operational, or privacy consequences.

A compromised operational system can potentially affect the physical processes used to produce and distribute drinking water.

That does not mean every cyber vulnerability represents an immediate public-health threat. It means cybersecurity risk has to be evaluated in the context of what a system can influence.

Consider the difference between:

A compromised employee laptop

and

A compromised workstation with a pathway into a process control environment.

The first may require an endpoint investigation, credential reset, and remediation.

The second may require operational isolation, validation of physical processes, review of system configurations, coordination with plant personnel, and potentially regulatory notification.

That is why New York's cybersecurity requirements focus on vulnerabilities that may affect compliance with drinking water requirements or create a public-health risk.

Cybersecurity is therefore not simply an IT responsibility.

It is an operational resilience responsibility.

 

What Water System Leaders Should Measure

The strongest cybersecurity programs translate technical controls into measurable outcomes.

Rather than reporting only that a firewall exists or MFA is enabled, leadership should be able to see whether risk is actually being reduced.

Useful measures include:

 

Asset visibility

  • Percentage of known OT assets inventoried
  • Percentage of assets with identified owners
  • Percentage of critical assets with current configurations documented
  • Number of unknown or unauthorized devices

 

Access control

  • Percentage of privileged accounts using MFA
  • Number of shared or generic accounts
  • Number of active vendor accounts
  • Percentage of vendor access reviewed on schedule

 

Network security

  • Number of documented IT/OT communication pathways
  • Number of internet-exposed OT assets
  • Percentage of critical OT connections monitored
  • Number of unauthorized connection attempts

 

Vulnerability management

  • Number of critical OT vulnerabilities identified
  • Number with documented mitigation plans
  • Average time from identification to mitigation
  • Percentage of corrective actions completed within the defined timeframe

 

Response and recovery

  • Time to identify a cybersecurity incident
  • Time to isolate affected systems
  • Time to restore critical operations
  • Percentage of incident response plans tested
  • Number of recovery exercises completed

 

These metrics give executives a much clearer picture than a simple statement that the organization is "secure."

 

A Practical IT/OT Security Roadmap for New York Water Systems

For many organizations, the right starting point is not a major technology overhaul.

It is establishing visibility and control over the environment that already exists.

 

1. Build a complete IT and OT asset inventory

Document critical systems, devices, communications pathways, vendors, dependencies, and ownership.

 

2. Map the IT-to-OT pathways

Identify every connection between business systems, external networks, remote-access tools, and operational environments.

 

3. Review remote access

Eliminate unnecessary access, require strong authentication, restrict privileges, and establish clear procedures for vendor access.

 

4. Validate segmentation

Confirm that IT compromise does not automatically provide a pathway into critical operational systems.

 

5. Review SCADA and OT exposure

Look specifically for internet-exposed HMIs, legacy equipment, unsupported systems, unnecessary services, and unmanaged connections.

 

6. Establish meaningful monitoring

Determine which events need to be detected, who reviews them, and how the organization responds when something changes.

 

7. Test incident response

Exercise scenarios involving loss of SCADA, compromised credentials, unavailable communications, vendor compromise, and manual operations.

 

8. Connect cybersecurity to the annual vulnerability analysis

New York requires covered systems to review and update their Cybersecurity Vulnerability Analysis annually. The state notes that many water systems already perform cybersecurity vulnerability analysis as part of their emergency response planning.

 

The opportunity is to make that process operational rather than treating it as an annual compliance exercise.

 

The Goal Is Not IT Security or OT Security. It Is Operational Resilience.

The distinction between IT and OT is important, but the two environments cannot be managed in isolation.

A compromised Microsoft 365 identity may become an IT security issue.

A compromised remote-access account may become an OT security issue.

A compromised OT system may become an operational issue.

And an operational issue involving water treatment or distribution can become a public-health concern.

The most effective New York water cybersecurity compliance programs therefore connect these layers.

That means understanding the environment, documenting assets, controlling pathways, securing identities, monitoring meaningful activity, preparing for incidents, and testing recovery.

The New York State Department of Health's cybersecurity resources provide the regulatory requirements, templates, reporting resources, and cybersecurity guidance for covered water systems.

For executives and IT leaders, the larger question is straightforward:

If an attacker compromised the business network today, how difficult would it be for that compromise to reach the systems that keep the water system operating?

Answering that question accurately is a much more useful starting point for cybersecurity improvement than simply asking whether the organization has met its compliance requirements.

 

FAQ

What are the New York drinking water cybersecurity requirements?

New York's Appendix 5-E establishes cybersecurity requirements for covered community water systems, including a cybersecurity program, Cybersecurity Vulnerability Analysis, incident and vulnerability reporting, operator training, and incident response capabilities. Additional requirements apply to systems serving more than 50,000 people, including network monitoring and a designated cybersecurity individual.

What is OT cybersecurity for a water system?

OT cybersecurity protects technology used to monitor and control physical water system operations. Examples include SCADA systems, PLCs, HMIs, sensors, pumps, valves, and related communications infrastructure. New York's cybersecurity assessment materials specifically distinguish these process control systems from business enterprise IT systems.

Why is IT/OT separation important for water systems?

IT/OT separation limits the ability of a compromise in a business or external network to reach systems responsible for physical operations. New York recognizes documented OT/IT and OT/external-network separation within its cybersecurity exclusion provisions, while EPA guidance recommends controlled and monitored connections between IT and OT environments.

Should SCADA systems be connected to the internet?

Internet exposure should be carefully evaluated and minimized. EPA and CISA have specifically warned that internet-exposed HMIs can allow unauthorized users to view operational information and potentially make changes that affect water treatment or wastewater processes.

Does Microsoft 365 security protect a water system's OT environment?

Microsoft 365 security controls can strengthen identity, endpoint, email, and business IT security, but they do not by themselves secure an OT environment. Water systems should separately evaluate SCADA, PLCs, HMIs, remote access, network segmentation, vendor connections, and other operational technology.

What should a water system include in its cybersecurity asset inventory?

The inventory should cover both IT and OT assets, including SCADA systems, PLCs, HMIs, servers, workstations, network equipment, communications systems, third-party equipment, and legacy technology. EPA guidance recommends maintaining an updated inventory that also documents how assets are configured and connected.

How often should a water system review its Cybersecurity Vulnerability Analysis?

New York requires covered water systems to review and update their Cybersecurity Vulnerability Analysis annually and when significant changes occur. The state's cybersecurity overview explains that annual review is intended to address newly discovered vulnerabilities as they arise.

What should a water system do if SCADA becomes unavailable during a cyber incident?

The incident response and recovery plan should define how the organization maintains or restores critical operations, including who makes decisions, how IT and operations coordinate, how systems are isolated, how vendors are engaged, and whether manual operating procedures are available. EPA water-sector resources specifically address incident response scenarios involving disabled or manipulated process control systems.

How can water systems measure cybersecurity risk reduction?

Useful measures include OT asset visibility, number of undocumented assets, privileged access using MFA, internet-exposed OT assets, monitored IT/OT connections, unresolved vulnerabilities, time to isolate incidents, time to restore critical operations, and completion of recovery exercises. These metrics connect cybersecurity activity to operational outcomes rather than simply measuring whether security tools have been deployed.

What is the first step in improving water system cybersecurity?

Start with visibility. Build an accurate inventory of IT and OT assets, map how those assets communicate, identify remote-access pathways, and determine which systems could affect critical water operations. From there, the organization can prioritize segmentation, identity controls, monitoring, vulnerability remediation, and recovery planning based on actual operational risk.