
Texas Water Cybersecurity: Inside Texas Cyber Command’s Project Watershed 250
Texas Cyber Command’s 6-Month Water Cybersecurity Pilot, Explained – What Project Watershed 250 Covers And What It Leaves Out
Texas Cyber Command's 6-month pilot hardens rural utilities. Houston businesses running the same industrial gear are on their own.
Texas water cybersecurity became a federal test case on August 31, 2026, when the Office of the National Cyber Director and Texas Governor Greg Abbott announced Project Watershed 250, a 6-month pilot overseen by Texas Cyber Command that puts 12 cyber and AI companies to work on Texas water utilities at no charge to those utilities.
CyberScoop reporter Tim Starks counted 12 participating companies: Microsoft, Google Cloud, Amazon Web Services, Palo Alto Networks, Fortinet, Cloudflare, Zscaler, Forescout, Dragos, Parsons, Reflection AI, and Abnormal AI. The Office of the National Cyber Director and Texas Cyber Command are running it, with the Environmental Protection Agency and CISA as federal partners. The work itself is red team testing, hardening systems with donated tooling, and AI assistance so utility defenders can find and fix holes faster.
That is genuinely useful for a town of 5,000 with one part-time operator. It does nothing for the Houston metal fabricator, the pipeline services company in Katy, or the engineering firm in Sugar Land running the same remote-access software on the same flat network. CinchOps builds IT/OT network segmentation and monitoring for oil and gas, manufacturing, and utility contractors across the Houston metro at a flat $100 to $250 per user per month, with a help desk that answers in under 15 minutes.
What Project Watershed 250 Actually Includes
A 6-month, Texas-only pilot built on donated private sector labor and tooling.
Project Watershed 250 is a 6-month pilot overseen by the Office of the National Cyber Director and Texas Cyber Command in which 12 private cyber and artificial intelligence companies provide red team testing, system hardening, and AI-assisted vulnerability remediation to Texas water utilities at no cost.
National Cyber Director Sean Cairncross framed it as an experiment rather than a finished program: "We are going to find out what works. We're going to target that, and we're going to scale off of this." Abbott was blunter about why Texas volunteered as the test bed. "The need for cyber resilience is overwhelming," he said. "Many rural providers simply don't have the resources they need."
- Red team testing. Outside operators attack the utility's systems the way a real adversary would, then report what worked.
- Hardening with donated tooling. Vendor products get deployed into environments that could not otherwise license them.
- AI-assisted defense. Tools that help a one-person IT shop triage and remediate findings instead of drowning in a 200-line report.
- 6 months, Texas only. The pilot is scoped to Texas before any decision about scaling it nationally.
- State-run implementation. Texas Cyber Command handles delivery on the ground, which makes this a state program with federal sponsorship rather than the reverse.
One practical note before the criticism starts. If you operate a water or wastewater system anywhere from Katy to The Woodlands, this is a red team and a hardening engagement you would otherwise have to buy, offered at no cost inside a limited window. Get in front of Texas Cyber Command and get on the list. There is no version of waiting that ends better.
Watershed 250 did not land alone. On the same day, OpenAI and a group including Dragos, Microsoft, Google, Palo Alto Networks, Fortinet, Cloudflare, AWS, and Tenable published a collective cyber defense initiative asking governments to fund defenses for hospitals, water utilities, and local governments, and asking AI companies to put defensive tooling in the hands of under-resourced operators. Several of those names are the same ones staffing the Texas pilot. Watershed 250 is the working prototype of an argument the security industry made in public that week.
Not everyone is convinced the prototype solves the right problem. Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs, pointed out that the operators in question are still struggling to inventory what they have connected to the internet, shut down insecure remote access, hire security staff, and fix vulnerabilities they already know about. "Offering increasingly sophisticated AI defensive capabilities without fixing those fundamentals is like giving someone a Tesla when what they need is a road," he wrote. A cyber professional quoted anonymously by CyberScoop made a narrower complaint: this is the government asking industry to fund work the government should be paying for.
Both critiques land, and neither one makes the work worthless. The road-before-the-Tesla point is the useful one for any business reading this, because the fundamentals Krell lists are the same 5 items in the checklist further down this page.
Why Texas Cyber Command Launched Watershed 250 In August 2026
A coordinated July attack on Minnesota water utilities, on top of a Texas incident record going back to 2024.
Project Watershed 250 follows a coordinated cyberattack that disrupted more than 30 Minnesota water and wastewater utilities across roughly 48 hours in late July 2026, after which utilities in at least 7 states reported incidents and some of that activity degraded water operations.
Between July 26 and July 27, 2026, Minnesota IT reported a coordinated campaign against water and wastewater systems statewide. Four cities disclosed publicly: Braham, Plymouth, South St. Paul, and Maple Plain. In Braham, a city of roughly 1,700 people, the attack disabled computerized operating controls and took the well and water treatment plant offline. Public works crews brought it back in about 2 hours, tower storage kept water flowing, and officials said quality and safety were never affected. The FBI identified the targeted devices as Rockwell Automation MicroLogix 1100 and 1400 series PLCs reachable from the internet.
Texas already had its own file on this. On January 18, 2024, an attacker reached a remote-access industrial software interface at the Muleshoe municipal water system, manipulated a tank level value, and caused an overflow that ran 30 to 45 minutes before city staff pulled the device off the network and switched to manual operation. A Telegram channel calling itself the Cyber Army of Russia Reborn claimed it and posted video. In April 2024, Mandiant tied that channel to Sandworm, the GRU's Unit 74455. The same day as Muleshoe, suspicious activity showed up on the SCADA system in Lockney, and Hale Center logged 37,000 firewall login attempts over 4 days.
The Congressional Research Service put the July wave in front of Congress on August 27, 2026, 4 days before the pilot was announced. Analyst Elena H. Humphreys opened that report by noting that attacks reported in at least 7 states "have increased attention on the security of the nation's municipal water infrastructure." Watershed 250 arrived into that attention.
Why A 6-Month Donation Was The Only Tool Texas Had
The federal mandate was withdrawn in 2023 and the grant money was never appropriated.
Project Watershed 250 is structured as donated private sector work because the federal rules that would have required water system cybersecurity were rescinded in October 2023, and Congress has not appropriated funding for the Safe Drinking Water Act cybersecurity assistance programs it already authorized.
The Congressional Research Service laid out the scale on August 27, 2026. The Safe Drinking Water Act covers nearly 144,000 public water systems, of which about 49,500 are community water systems serving more than 324 million people. America's Water Infrastructure Act of 2018 requires risk-and-resilience assessments and emergency response plans, but only for community systems serving more than 3,300 people. Those assessments are voluntary for small systems, and 81% of community water systems are small by EPA's definition. That is the exact population Abbott described as lacking resources, and it is the population the pilot targets.
Compliance is thin even where the requirement is mandatory. CRS cites a 2024 EPA enforcement notice stating that more than 70% of systems EPA inspected since September 2023 were in violation of basic SDWA Section 1433 requirements, with at least 100 enforcement actions between 2020 and 2024. Separately, the EPA Office of Inspector General scanned 1,062 water systems serving 50,000 or more people and found 97 systems serving roughly 26.6 million users with critical or high-risk cybersecurity vulnerabilities.
EPA did try the direct route. In March 2023 it issued an interpretive memorandum requiring states to evaluate water system operational technology cybersecurity during the routine on-site inspections known as sanitary surveys. Stakeholders petitioned for judicial review, arguing EPA had not followed the Administrative Procedure Act and had exceeded its statutory authority. EPA rescinded the memorandum in October 2023. On the money side, CRS notes Congress has never specified appropriations for the SDWA Section 1433(g) technical assistance program or the Section 1459G advanced technology grants.
So the mandate got pulled and the money never showed up. In that setting, 12 companies volunteering for 6 months is not a weak substitute for policy. It is the only instrument anybody actually had. Water utilities also do not get the treatment the electric grid gets, and CRS explains why: local power distribution connects to a shared transmission network, so FERC can hold NERC standards over the whole thing, while water systems are not interconnected and a disruption stays inside one community. Smaller blast radius, weaker regulator, same PLCs.
Oil and Gas SCADA Cybersecurity Houston: What The Pilot Leaves Out
The pilot covers Texas water utilities. Private industrial operators running identical gear get nothing.
Oil and gas SCADA cybersecurity in Houston sits outside the scope of Project Watershed 250, which means private operators running the same HMIs, PLCs, and remote-access software as the utilities in the pilot receive no donated assessment, no donated tooling, and no red team.
The equipment does not care who owns it. The Rockwell MicroLogix 1100 and 1400 controllers the FBI named in Minnesota are the same low-cost, long-lived PLCs sitting in packaged skids, lift stations, and small process lines all over the Houston metro. A pump station controller in a small Texas water district and a tank battery controller on a Houston-area lease are frequently the same hardware, reached the same way, with the same integrator account still enabled. In 35+ years doing this, the thing that has not changed is that industrial gear gets bought by operations, installed by a contractor, and then patched by nobody, because no one on the org chart owns it.
CinchOps measures this locally rather than guessing at it. The CinchOps Houston Area Security Index scored 953 Houston manufacturers at a 1.57 GPA, the lowest of the 3 industries measured, with 46.6% failing and only 24.9% passing. Sugar Land manufacturers came in at a 1.15 GPA with 65% failing across the 20 businesses scored there. Legal practices and CPA firms both landed at 1.61, which is less a compliment to them than an indictment of the whole set.
| Security work | Texas water utility in the pilot | Private Houston business |
|---|---|---|
| Outside red team test | Donated for 6 months | You buy it or it does not happen |
| IT/OT network segmentation | Vendor engineers assigned | Your MSP, your integrator, or nobody |
| AI-assisted vulnerability triage | Donated tooling | Licensed per seat, out of your budget |
| Credential and remote-access cleanup | In scope | In scope only if somebody assigns it |
| Day 181 | Unfunded by design | Same exposure, no headline |
We see this twice a month with Houston businesses: a flat network where the office file server, the accounting workstation, and the control system all sit in the same broadcast domain, plus a vendor VPN account that has not been rotated since the system was commissioned. Energy operators running WellView, OpenWells, P2 Energy Solutions, or Enertia alongside plant control systems carry an extra problem. A ransomware event in the business network can stop field work even when the control network is technically untouched, because the people who run the field cannot see their own data.
5 Things Houston Businesses Can Copy From Watershed 250 This Quarter
The pilot's playbook is not secret, and most of it does not require a vendor donation.
The defensive work inside Project Watershed 250 is inventory, segmentation, credential hygiene, outside testing, and a manual-operations plan, and a Houston business with 10 to 200 employees can run all 5 without waiting for a federal program.
- Inventory everything reachable from the internet. Braham was hit through internet-facing PLCs and Muleshoe through a remote-access industrial interface. Pull an external scan and account for every open port, every remote-support tool, and every cellular modem sitting on a skid.
- Separate the business network from the control network. IT/OT segmentation is the single control that turns a total outage into a contained one. Office ransomware should not be able to reach a PLC.
- Kill default and shared credentials. Vendor accounts, integrator logins, and the shared operator password taped inside the panel are the 3 most common ways in. Rotate them and put multi-factor authentication on every remote path.
- Get tested by somebody who does not work for you. The pilot's headline feature is a red team. A scoped external assessment gives you the same class of answer, and it is the only way to learn whether your controls actually hold.
- Write the manual-operations runbook. Braham's public works crew restored service in about 2 hours by hand, and Muleshoe stopped its overflow by disconnecting the device and running the system manually. If your people cannot operate for 4 hours without the HMI, that is a business continuity gap, not an IT gap.
None of that is exotic. It is the boring half of security that gets skipped because nothing breaks when you skip it, right up until something does. It is also, item for item, the road Krell says operators need before anybody hands them a Tesla.
Twelve vendors showing up free for 6 months is a good gesture. It is not a security program. The utilities that come out of this ahead will be the ones who wrote down exactly what got fixed and then kept paying somebody to keep it fixed on day 181. Same goes for every Houston business reading about it and assuming their plant floor is fine.
How CinchOps Can Help Houston Businesses Running Industrial Systems
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.
- Through managed cybersecurity, CinchOps runs external exposure scanning, credential and remote-access cleanup, and monitored endpoint defense across both the business network and the systems that touch operations.
- Through managed IT support, CinchOps handles patching, vendor account governance, and the help desk work that keeps segmentation from quietly getting undone 6 months after it is built.
- Through business continuity and disaster recovery, CinchOps keeps geo-redundant backups outside the Gulf Coast flood zone so a ransomware event and a hurricane cannot take the same copy of your data.
- Industrial and field operators get sector-specific work through oil and gas IT, manufacturing IT, energy services and utilities IT, and engineering firm IT.
- Local coverage runs across Houston, Katy, Sugar Land, Cypress, and The Woodlands, at a flat monthly rate per user with no contracts, no hidden fees, and no cancellation penalties.
Texas Cyber Command is about to spend 6 months proving what a small utility can fix when somebody competent finally looks. If you run one of those systems, take the free help and take it early. The findings will not surprise anybody who does this work: exposed devices, stale vendor accounts, flat networks. If that describes your operation and nobody is donating 6 months of engineering to you, start with an external scan and an honest inventory, then talk to CinchOps about what to fix first.
Frequently Asked Questions
What is Project Watershed 250?
Project Watershed 250 is a 6-month cybersecurity pilot for Texas water utilities announced on August 31, 2026. The Office of the National Cyber Director and Texas Cyber Command oversee it, with 12 private cyber and AI companies donating red team testing, system hardening, and AI-assisted remediation to participating utilities.
What happened to Minnesota water systems in July 2026?
Between July 26 and 27, 2026, a coordinated cyberattack disrupted more than 30 Minnesota water and wastewater utilities. In Braham, computerized controls were disabled and the well and treatment plant went offline for about 2 hours. The FBI identified internet-facing Rockwell Automation MicroLogix 1100 and 1400 PLCs as the targeted devices.
Does Project Watershed 250 cover private businesses in Houston?
No. The pilot is scoped to Texas water utilities, not private industry. A Houston manufacturer, oil and gas operator, or engineering firm running the same PLCs, HMIs, and remote-access software receives no donated assessment or tooling, and has to fund equivalent work itself.
What does OT and SCADA cybersecurity cost in Houston?
CinchOps prices managed cybersecurity and IT/OT segmentation work at a flat $100 to $250 per user per month depending on scope, with no contracts, no hidden fees, and no cancellation penalties. Project work such as an external exposure scan or a segmentation build is quoted separately after the initial assessment.
Why is water utility cybersecurity not already required by law?
It is required only for community water systems serving more than 3,300 people, and it stays voluntary for the 81% of community systems EPA classifies as small. EPA tried to extend operational technology checks in March 2023, faced a legal challenge, and rescinded the requirement in October 2023.
Discover More
Resource
Sources
- Tim Starks, CyberScoop - "Watershed 250 test program in Texas looks to private sector for water cybersecurity help" (August 31, 2026)
- Elena H. Humphreys, Congressional Research Service - "July 2026 Water System Cyber Incidents: Considerations for Congress" (IF13298, August 27, 2026)
- Anna Ribeiro, Industrial Cyber - "US water systems face persistent cybersecurity gaps as July attacks renew scrutiny of federal protections, CRS says" (August 31, 2026)
- Industrial Cyber - "OpenAI-backed initiative targets critical infrastructure cyber gaps with AI-powered defenses, coordinated global response" (August 31, 2026)
- MPR News - "Braham officials say cyberattack knocked water system offline" (July 27, 2026)
- Tenable - "Coordinated Cyberattack on Minnesota Water Utilities: What You Need to Know" (CISA advisory AA26-097A)
- EPA Office of Inspector General - Management Implication Report: Cybersecurity Concerns Related to Drinking Water Systems (November 13, 2024)
- CyberScoop - "Mandiant: Notorious Russian hacking unit linked to breach of Texas water facility" (April 2024)
- CinchOps Houston Area Security Index - Houston Manufacturing Cybersecurity Scores