A water system is not a typical IT environment.
A business can lose access to email or a CRM and still operate while systems are restored. A water utility has another layer of technology responsible for monitoring and controlling pumps, valves, treatment processes, storage levels, and distribution infrastructure. When that operational technology is disrupted or manipulated, the consequence can extend beyond data loss or business interruption.
That is why New York drinking water cybersecurity requirements increasingly focus on more than traditional IT controls. The state's cybersecurity requirements recognize the relationship between information technology (IT), operational technology (OT), process control systems, and public health.
New York's Appendix 5-E requirements apply to covered community water systems and specifically address cybersecurity programs, vulnerability analysis, incident response, training, and, for larger systems, network monitoring. The New York State Department of Health also recognizes documented separation between OT and IT, and between OT and external networks, in its exclusion provisions.
For water system executives and IT leaders, the important question is not simply whether the organization is "compliant."
It is whether the technology environment is structured so that a compromise in the business network does not unnecessarily become an operational problem.
Most organizations think about cybersecurity primarily through the lens of users, endpoints, applications, data, and identity.
Water systems have all of those, but they also have systems that interact with the physical environment.
New York's own Cybersecurity Vulnerability Analysis Checklist distinguishes between business enterprise systems and process control systems. The latter can include supervisory control and data acquisition (SCADA) systems used to operate and monitor pumps, valves, storage tanks, and other water treatment and distribution functions.
That creates two interconnected cybersecurity environments:
IT generally includes:
These are familiar territory for most IT teams.
OT includes technology that directly supports physical operations, such as:
The distinction matters because IT security practices cannot simply be copied into an OT environment without considering availability, safety, legacy equipment, vendor dependencies, and operational requirements.
The EPA's water sector cybersecurity guidance similarly treats OT and IT as connected but distinct areas that require specific cybersecurity considerations.
A cybersecurity program is difficult to manage if no one has a reliable picture of what exists.
That is particularly important in water systems, where equipment may have been deployed over many years by different vendors and may not be managed through the same tools used for conventional IT.
New York's cybersecurity assessment materials specifically call for inventories of process control assets, including applications, servers, workstations, field devices such as PLCs, communications equipment, and network equipment.
The EPA recommends the same foundational approach. Its guidance calls for maintaining an updated inventory of both OT and IT assets, including third-party and legacy equipment.
A useful IT/OT asset inventory should help answer:
This turns an asset inventory from a compliance document into an operational decision-making tool.
One of the most important concepts in water system cybersecurity is segmentation.
If a user's laptop, Microsoft 365 account, or business application is compromised, the objective should be to prevent that compromise from providing an easy path into systems controlling physical operations.
New York explicitly recognizes documented OT/IT separation and OT/external-network separation in its cybersecurity exclusion provisions. Those exclusions do not eliminate requirements related to training, emergency response planning, or reporting.
The underlying security principle is broader than regulatory compliance.
The fewer unnecessary pathways between IT and OT, the fewer opportunities there are for an IT compromise to become an operational compromise.
Depending on the environment, controls may include:
The EPA's cybersecurity guidance for drinking water and wastewater systems recommends that connections between OT and IT networks pass through an intermediary such as a firewall, bastion host, jump box, or DMZ that is monitored and logged. It also recommends MFA for remote access to OT and IT networks.
The goal is not to make OT inaccessible.
The goal is to make access intentional, limited, observable, and reversible.
Remote access can be operationally necessary. Water systems may depend on vendors, engineers, operators, or IT personnel who need to troubleshoot systems without being physically present.
The risk comes when remote access is treated as a permanent convenience rather than a controlled pathway into critical infrastructure.
An OT remote-access review should consider:
The EPA specifically recommends MFA for remote access to OT networks and controlled, monitored connections between OT and IT environments.
For organizations using Microsoft 365, this is where identity security becomes relevant to OT security.
Microsoft Entra ID, MFA, conditional access, privileged access controls, endpoint security, and centralized identity governance can strengthen the business side of the environment. But those controls should not create a false assumption that the SCADA or OT environment is therefore secure.
The important question is how identity and access controls connect to the actual operational architecture.
SCADA is often the most recognizable component of a water system's OT environment, but it is not an isolated application.
A typical operational environment can include:
Operator → HMI → SCADA server → PLC → equipment
with sensors, communications infrastructure, engineering workstations, remote-access tools, and other dependencies surrounding it.
A weakness anywhere in that chain can affect the security of the overall system.
For example, an exposed HMI can provide an unauthorized user with visibility into operational information and, depending on the configuration, the ability to make changes to system settings. EPA and CISA have specifically warned about internet-exposed HMIs in water and wastewater environments.
That means an OT security review should not stop at asking whether the SCADA platform itself is patched.
It should examine the surrounding architecture.
These questions turn cybersecurity from an abstract IT exercise into an operational risk assessment.
Segmentation reduces unnecessary pathways.
Monitoring helps determine whether those pathways are being used.
New York's requirements include additional network monitoring and logging provisions for community water systems serving more than 50,000 people.
But visibility is valuable regardless of system size.
A practical monitoring strategy should help identify:
This is where managed security capabilities can be particularly useful for smaller IT teams. A water system does not necessarily need a large internal security operation to establish meaningful monitoring, but it does need defined ownership, escalation procedures, and someone responsible for reviewing and acting on meaningful signals.
The objective is not to collect the maximum amount of data.
It is to ensure that important changes in the environment are visible to someone who can act on them.
A conventional incident response plan might focus on isolating endpoints, disabling accounts, restoring applications, and recovering data.
A water system needs to go further.
What happens if the SCADA environment is unavailable?
What happens if an operator cannot authenticate?
What happens if remote access has to be disabled?
What happens if a PLC or HMI is suspected of being compromised?
What happens if the organization has to operate without normal network connectivity?
New York requires covered water systems to maintain a written cybersecurity incident response plan describing tasks during and following a cybersecurity incident to maintain or restore compliance with applicable drinking water requirements.
The EPA's water sector resources similarly emphasize incident response and recovery planning for scenarios involving disabled or manipulated process control systems.
One of the most valuable exercises a water system can conduct is a scenario-based tabletop exercise.
For example:
"At 8:00 a.m., the IT team discovers suspicious activity involving an account that has access to both the business environment and an OT management system. At 8:15 a.m., operators report that remote access to SCADA is unavailable."
The exercise should answer:
The EPA's water sector cybersecurity resources provide incident response and asset inventory resources specifically designed for water and wastewater system operators.
This is ultimately what makes water cybersecurity different.
A compromised business application may create financial, operational, or privacy consequences.
A compromised operational system can potentially affect the physical processes used to produce and distribute drinking water.
That does not mean every cyber vulnerability represents an immediate public-health threat. It means cybersecurity risk has to be evaluated in the context of what a system can influence.
Consider the difference between:
A compromised employee laptop
and
A compromised workstation with a pathway into a process control environment.
The first may require an endpoint investigation, credential reset, and remediation.
The second may require operational isolation, validation of physical processes, review of system configurations, coordination with plant personnel, and potentially regulatory notification.
That is why New York's cybersecurity requirements focus on vulnerabilities that may affect compliance with drinking water requirements or create a public-health risk.
Cybersecurity is therefore not simply an IT responsibility.
It is an operational resilience responsibility.
The strongest cybersecurity programs translate technical controls into measurable outcomes.
Rather than reporting only that a firewall exists or MFA is enabled, leadership should be able to see whether risk is actually being reduced.
Useful measures include:
These metrics give executives a much clearer picture than a simple statement that the organization is "secure."
For many organizations, the right starting point is not a major technology overhaul.
It is establishing visibility and control over the environment that already exists.
Document critical systems, devices, communications pathways, vendors, dependencies, and ownership.
Identify every connection between business systems, external networks, remote-access tools, and operational environments.
Eliminate unnecessary access, require strong authentication, restrict privileges, and establish clear procedures for vendor access.
Confirm that IT compromise does not automatically provide a pathway into critical operational systems.
Look specifically for internet-exposed HMIs, legacy equipment, unsupported systems, unnecessary services, and unmanaged connections.
Determine which events need to be detected, who reviews them, and how the organization responds when something changes.
Exercise scenarios involving loss of SCADA, compromised credentials, unavailable communications, vendor compromise, and manual operations.
New York requires covered systems to review and update their Cybersecurity Vulnerability Analysis annually. The state notes that many water systems already perform cybersecurity vulnerability analysis as part of their emergency response planning.
The opportunity is to make that process operational rather than treating it as an annual compliance exercise.
The distinction between IT and OT is important, but the two environments cannot be managed in isolation.
A compromised Microsoft 365 identity may become an IT security issue.
A compromised remote-access account may become an OT security issue.
A compromised OT system may become an operational issue.
And an operational issue involving water treatment or distribution can become a public-health concern.
The most effective New York water cybersecurity compliance programs therefore connect these layers.
That means understanding the environment, documenting assets, controlling pathways, securing identities, monitoring meaningful activity, preparing for incidents, and testing recovery.
The New York State Department of Health's cybersecurity resources provide the regulatory requirements, templates, reporting resources, and cybersecurity guidance for covered water systems.
For executives and IT leaders, the larger question is straightforward:
If an attacker compromised the business network today, how difficult would it be for that compromise to reach the systems that keep the water system operating?
Answering that question accurately is a much more useful starting point for cybersecurity improvement than simply asking whether the organization has met its compliance requirements.
New York's Appendix 5-E establishes cybersecurity requirements for covered community water systems, including a cybersecurity program, Cybersecurity Vulnerability Analysis, incident and vulnerability reporting, operator training, and incident response capabilities. Additional requirements apply to systems serving more than 50,000 people, including network monitoring and a designated cybersecurity individual.
OT cybersecurity protects technology used to monitor and control physical water system operations. Examples include SCADA systems, PLCs, HMIs, sensors, pumps, valves, and related communications infrastructure. New York's cybersecurity assessment materials specifically distinguish these process control systems from business enterprise IT systems.
IT/OT separation limits the ability of a compromise in a business or external network to reach systems responsible for physical operations. New York recognizes documented OT/IT and OT/external-network separation within its cybersecurity exclusion provisions, while EPA guidance recommends controlled and monitored connections between IT and OT environments.
Internet exposure should be carefully evaluated and minimized. EPA and CISA have specifically warned that internet-exposed HMIs can allow unauthorized users to view operational information and potentially make changes that affect water treatment or wastewater processes.
Microsoft 365 security controls can strengthen identity, endpoint, email, and business IT security, but they do not by themselves secure an OT environment. Water systems should separately evaluate SCADA, PLCs, HMIs, remote access, network segmentation, vendor connections, and other operational technology.
The inventory should cover both IT and OT assets, including SCADA systems, PLCs, HMIs, servers, workstations, network equipment, communications systems, third-party equipment, and legacy technology. EPA guidance recommends maintaining an updated inventory that also documents how assets are configured and connected.
New York requires covered water systems to review and update their Cybersecurity Vulnerability Analysis annually and when significant changes occur. The state's cybersecurity overview explains that annual review is intended to address newly discovered vulnerabilities as they arise.
The incident response and recovery plan should define how the organization maintains or restores critical operations, including who makes decisions, how IT and operations coordinate, how systems are isolated, how vendors are engaged, and whether manual operating procedures are available. EPA water-sector resources specifically address incident response scenarios involving disabled or manipulated process control systems.
Useful measures include OT asset visibility, number of undocumented assets, privileged access using MFA, internet-exposed OT assets, monitored IT/OT connections, unresolved vulnerabilities, time to isolate incidents, time to restore critical operations, and completion of recovery exercises. These metrics connect cybersecurity activity to operational outcomes rather than simply measuring whether security tools have been deployed.
Start with visibility. Build an accurate inventory of IT and OT assets, map how those assets communicate, identify remote-access pathways, and determine which systems could affect critical water operations. From there, the organization can prioritize segmentation, identity controls, monitoring, vulnerability remediation, and recovery planning based on actual operational risk.