Opportunity

New York State Contract Reporter #2139581

Cybersecurity Risk Assessment for Ogdensburg Water and Wastewater Systems

Posted

October 02, 2026

Respond By

November 20, 2026

Identifier

2139581

NAICS

541512

The City of Ogdensburg is seeking a consultant to assess cybersecurity risks across its drinking water and wastewater systems. - Government buyer: City of Ogdensburg, New York; Office of the City Manager. The attachment also identifies Planning/Engineering. - Procurement: One integrated cybersecurity risk assessment for the City’s municipally owned drinking water and wastewater systems, supported by the New York State Environmental Facilities Corporation (EFC) SECURE Assessment Grant. - OEMs and vendors: No product manufacturers, OEMs, or consulting vendors are named in the materials. - Services requested: Review IT and operational technology/industrial control systems, including SCADA, PLCs, remote telemetry, and remotely accessible systems; gather information and review relevant policies, diagrams, and prior assessments; assess current risks; develop current and target profiles using NIST CSF 2.0 and CIA Triad principles; and analyze gaps against applicable New York State DOH and DEC requirements. - Deliverables: Prioritized remediation actions and an implementation roadmap with order-of-magnitude cost considerations; draft and final assessment reports; system-specific executive summaries; and a findings presentation. - Quantity and price: One integrated assessment; the all-inclusive combined price must not exceed $45,000. - Notable requirements: Address all six NIST CSF functions; protect sensitive vulnerability and system information; and demonstrate relevant water/wastewater or OT/ICS cybersecurity experience, including at least three similar engagements, with appropriately qualified staff.

Description

The City of Ogdensburg is requesting proposals for a comprehensive cybersecurity risk assessment of its municipally owned drinking water and wastewater systems under the New York State Environmental Facilities Corporation SECURE Program Assessment Grant. The assessment must evaluate current cybersecurity posture using NIST Cybersecurity Framework 2.0 and CIA Triad principles, assess compliance with applicable New York State DOH and DEC cybersecurity regulations, and identify gaps and prioritized remediation actions. Required work includes project initiation and data collection, current and target profiles, regulatory gap analysis, a remediation roadmap, and final reports and presentations. Proposals must cover both systems together and stay within the $45,000 all-inclusive not-to-exceed budget; they are due November 20, 2026, at 4:00 PM.

View original listing