Texas has become the testing ground for a new approach to protecting America’s water infrastructure.
Launched on August 31, 2026, Project Watershed 250 is a six-month pilot connecting Texas water and wastewater utilities with federal, state and private-sector cybersecurity support. Participating utilities will receive assistance at no cost, with a particular focus on smaller and rural providers that often lack dedicated cybersecurity staff.
The immediate task is to find and address weaknesses in Texas water systems. The wider goal is to test a model that could be expanded across the United States.
Its national value will depend on what happens after the six months. The pilot needs to test the funding, workforce and operating model alongside the technology.
Why water security needs a shared approach
Water utilities provide one of the country’s most essential services. They are also highly fragmented.
Thousands of providers operate with different technology, budgets and levels of cyber maturity. A large utility may have dedicated security staff and continuous monitoring. A small rural provider may have a handful of employees responsible for treatment, maintenance, billing, technology and emergency response.
Attackers do not adjust their methods according to the size of the utility.
Poorly secured remote-access systems can provide a route into the operational technology used to control water treatment and distribution. The FBI recently reported incidents involving 27 water providers across at least seven states. Water systems have also faced attacks associated with foreign actors, including groups linked to Iran.
Project Watershed 250 is designed to close part of this capability gap. It brings together the White House Office of the National Cyber Director, Texas Cyber Command and the Office of the Texas Governor. The Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency are participating as federal partners.
Private-sector partners are contributing red-team testing, vulnerability assessments, system-hardening support, threat intelligence and AI-enabled defensive tools. Reported participants include Microsoft, AWS, Google, Cloudflare, Palo Alto Networks, Fortinet, Forescout, Dragos, Reflection AI and Abnormal AI.
The Office of the Texas Governor says participating companies will provide cyber resources to Texas water and wastewater utilities at no cost.
Why Texas is the pilot
Texas offers a serious test of whether this approach can work at scale.
The state combines a large population, major cities, rural communities and vast geographic distances. Its water utilities vary significantly in size, ownership, technology and local capacity. Any model that works across that range could provide useful lessons for other states.
Texas has also created the institutional capacity to coordinate the work.
Texas Cyber Command was established in 2025 with $135 million in state funding. It is responsible for protecting state and local government systems, coordinating incident response and strengthening critical infrastructure.
Its five-year vision includes expanding the state’s regional security operations centers, developing a statewide cyber intelligence capability and growing its volunteer incident response force from around 200 members towards a long-term goal of 20,000 trained and credentialed volunteers.
Project Watershed 250 gives that wider strategy a clear use case. Water cybersecurity is specific enough to test measurable results and important enough to show whether the model could work across other areas of critical infrastructure.
What the pilot can test
The first task is establishing what technology is connected to participating utility networks.
Some smaller providers may not have complete visibility of their operational equipment, remote connections and software. The pilot can help identify exposed systems, insecure access, poor configurations and other weaknesses.
The next step is remediation.
That could include red-team exercises, stronger authentication, network segmentation, system hardening, monitoring and staff training. Some problems may be fixed through configuration changes. Others may require replacement equipment, specialist support or longer-term capital investment.
Finding vulnerabilities is only one measure of progress. The pilot also needs to establish:
- How many serious weaknesses were corrected.
- Whether utilities improved their ability to detect and respond to incidents.
- What skills and systems remain after the pilot.
- How much ongoing protection will cost.
- Whether the participating tools work together.
- Whether the model can be repeated across utilities with different levels of maturity.
These measures will give other states stronger evidence than a list of deployed products or completed assessments.
The unresolved funding question
The first clear gap is long-term funding.
Public launch materials do not identify a dedicated federal appropriation or financial-assistance program covering operations after the six-month pilot. Private partners are providing the initial technology, expertise and services at no cost, but no detailed plan has been published for continuing licenses, replacement equipment, monitoring, training or specialist staff.
This matters because a pilot can find problems faster than a small utility can afford to fix them.
A provider may be able to change a default password or close an exposed port quickly. Replacing obsolete operational equipment, separating networks and maintaining continuous monitoring require money, specialist skills and time.
Smaller utilities also face practical trade-offs. Cybersecurity competes for funding with pumps, pipes, treatment equipment, maintenance and frontline staff. Local ratepayers cannot reasonably absorb every cost associated with defending nationally important infrastructure against sophisticated criminal and state-backed attackers.
The Texas pilot therefore needs to test several funding options. These could include shared managed services, pooled purchasing, tiered support, state investment, federal assistance or a combination of these models.
A national program will struggle if its long-term affordability depends on each small utility negotiating and funding its own collection of products.
Texas already has useful shared models
Texas has experience using statewide services and purchasing power to support agencies with different levels of internal capacity.
DIR cooperative contracts give public bodies access to pre-established purchasing routes. Contract prices are ceilings, and agencies are encouraged to negotiate below them, particularly where purchasing volumes are known. Texas leaders are also considering broader enterprise pricing approaches that could give agencies more consistent rates.
Texas Cyber Command and DIR have described a “single front door” approach to cybersecurity, helping agencies and local bodies understand where to seek support. State leaders have also called for greater sharing of network and cyber-tool data, with Texas Cyber Command expected to protect that information and return useful threat intelligence to participating organizations.
These structures could help Project Watershed 250 move from a collection of vendor-supported pilots into an ongoing shared capability.
The work will still require clear rules. Utilities need to know which data will be collected, who can access it, how it will be protected and what information they will receive in return.
Cyber risk needs to be explained as service risk
The discussions around Texas Cyber Command framed cybersecurity as a threat to government operations and public safety.
For a water utility, the relevant consequence is disruption to treatment, distribution and public access to safe water. For other agencies, the risk could involve emergency response, licensing, transportation or public health.
This framing helps executives and legislators make informed decisions. It connects a technical weakness to a public service and allows leaders to fund mitigation or knowingly accept the remaining risk.
Private partners should use the same standard.
A product description or threat dashboard does not show why an agency should invest. Providers need to explain which operational risks they reduce, how the improvement will be measured and what happens if the system fails.
They also need to be transparent about cost. Government needs the total price, including implementation, integration, monitoring, training, data movement, AI consumption and future licensing.
The wider financial pressure
Project Watershed 250 launches as Texas agencies prepare for tighter financial conditions.
In July 2026, Governor Greg Abbott, Lieutenant Governor Dan Patrick and House Speaker Dustin Burrows directed agencies and institutions of higher education to prepare their 2028–29 Legislative Appropriations Requests with a 3% reduction in baseline spending as a starting point for budget deliberations.
Texas technology leaders were already reporting pressure from rising software, hardware and AI consumption costs. Agencies are reviewing license numbers, contracts and product use before approving new commitments.
This makes no-cost support useful during the pilot. It also raises the bar for any long-term model.
If the program produces a service that only large utilities can afford, it will miss the providers with the greatest need. Industry partners should disclose expected continuing costs before the pilot ends, giving Texas time to design a sustainable approach.
Lessons from other Texas technology programs
The state’s wider technology agenda offers useful lessons for Watershed 250.
TxDOT has applied AI to invoice reconciliation, engineering plans, traffic-camera monitoring, crash analysis and road-hazard detection. Reported outcomes include eliminating penalty-interest payments, saving more than 20 hours on some engineering projects, reducing incident response time by around 10 minutes and identifying 3,400 active work zones.
These projects start with a defined operational problem and a measurable baseline. That allows the agency to assess the result rather than relying on a broad promise of productivity.
The Texas Department of Criminal Justice is dealing with a different form of complexity. Its core offender management system dates from 1974 and reportedly includes around 64,000 tables. The department works across more than 68 connected data sources and has developed approximately 1,600 cleansing rules to create a more trusted data foundation.
The relevance to water security is direct. Many utilities also operate ageing technology with poorly documented connections and limited internal knowledge. New security tools need to work with that reality.
Government leaders repeatedly asked vendors to research agencies, understand existing systems, bring proven public-sector use cases and disclose downstream costs. Workshops and real pilots were valued more highly than generic presentations.
What national expansion should preserve
If the Texas pilot succeeds, a national program should preserve six features:
- Priority for smaller providers. Support should reach utilities with limited internal security capacity.
- Clear public outcomes. Each intervention should connect to water safety, continuity or operational resilience.
- Shared responsibility. Local knowledge, state coordination, federal intelligence and private-sector capability all have distinct roles.
- Common measures. States need comparable evidence showing whether vulnerabilities and operational risks were reduced.
- A sustainable funding model. Continuing protection cannot depend indefinitely on donated technology and goodwill.
- Choice and interoperability. Utilities should retain control of their data and avoid unnecessary dependence on one provider.
The national model should also remain flexible. Other states have different procurement systems, utility structures and cybersecurity capabilities. The partnership principles can be consistent while implementation reflects local conditions.
The real test begins after launch
Project Watershed 250 is a credible attempt to address a known weakness in American critical infrastructure.
It has government backing, private-sector participation and a defined six-month test in a state large and diverse enough to produce useful evidence.
The unresolved questions concern what happens next. How much risk will the pilot remove? What capability will remain within participating utilities? Who will fund continuing protection? Can the approach work across other states without creating a new collection of disconnected products?
Texas will provide the first answers.
The strongest result would be an affordable operating model that smaller utilities can continue using after the initial support ends. That would give the United States something more valuable than a successful pilot: a practical national framework for protecting the water systems every community depends on.
Want to learn more? Join our Texas Community Forum for access to more interviews, presentations, intelligence and insights.
Published by
Help your peers
Share what you've learned with fellow public servants