The White House along with the Texas Government has launched Project Watershed 250, a six-month cybersecurity pilot that will provide Texas water and wastewater utilities with private-sector cybersecurity and AI resources at no cost.
The program will use red teaming to test utilities’ existing defenses, identify vulnerabilities and harden systems, with a particular focus on smaller and rural water providers that often lack dedicated cybersecurity resources.
The initiative will be overseen by the Office of the National Cyber Director and Texas Cyber Command, with companies including Microsoft, Google Cloud, AWS, Cloudflare, Palo Alto Networks, Fortinet, Forescout and Dragos contributing technology and expertise.
The pilot follows a wave of attacks against U.S. water infrastructure, including a recent campaign affecting 30 water systems across 12 states. Officials said the goal is to determine which defenses are effective during the six-month test and then scale successful approaches to water and wastewater systems across the country.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“You can’t harden what you don’t know is connected. Incomplete asset inventories are one of the most common findings I see across engagements, and critical infrastructure environments have some of the worst visibility gaps. Forescout, one of Watershed 250’s twelve participating vendors, recently found 4,400 internet-exposed Rockwell and Allen-Bradley controllers. Twenty-two sit in cities already hit by the recent water attacks, and 19 of those run firmware vulnerable to a flaw Rockwell patched many years ago.
“Twelve companies are contributing technology and expertise at no cost, but bringing more tools into environments that lack staff to configure and maintain them just grows the unmanaged attack surface. A firewall with default rules or a monitoring console nobody watches becomes another blind spot in an inventory that was already incomplete. These utilities need governance and dedicated security personnel before they need enterprise-grade technology.
“Month seven is the real test. Iranian campaigns against U.S. water systems and FBI-documented Chinese access to critical infrastructure are persistent threats, not six-month engagements. Replacing an exposed Programmable Logic Controller (PLC) might mean swapping a 15-year-old controller that was never designed to be networked, and the utility that can’t fund a dedicated security hire can’t fund that replacement either. If “scale what works” is the exit plan, it needs to include who pays for ongoing staffing and governance after the pilot ends.”
Damon Small, Board of Directors, Xcape, Inc.:
“Federal support for critical infrastructure represents a welcome partnership between the public and private sectors, offering underfunded municipal utilities a no-cost opportunity to reduce operational technology risk. While Project Watershed 250 establishes an important first step, utility executives must question who benefits most over time: whether this effort drives long-term resilience or simply lines vendor pockets with short-lived service agreements. Temporary tool donations and red teaming cannot fix legacy hardware and deficient network architecture design without sustained capital investment. The broader challenge remains defending the entirety of the nation’s critical infrastructure beyond rural water systems.
“To turn this initial momentum into permanent defense, security leaders must isolate control networks from the public Internet, enforce multi-factor authentication on remote access gateways, and baseline legacy environments before deploying complex artificial intelligence tools.
“Critical Takeaways
- Federal support and private-sector partnerships provide essential temporary coverage, but pilot programs cannot substitute for long-term capital investments in legacy hardware.
- Utility executives must evaluate whether vendor-backed initiatives drive systemic resilience or merely create vendor lock-in.
- Immediate operational technology defense requires foundational controls, including network isolation from the public Internet and enforced multi-factor authentication, before layering on advanced tools.
“Upgrading national security requires durable capital allocation, not just a six-month software trial with big-tech name drops.”
Hopefully this isn’t just a one time investment because quite honestly, that’s not what the US needs. Now more than ever.
Related
This entry was posted on September 1, 2026 at 3:44 pm and is filed under Commentary with tags White House. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
White House & Texas Government launch Texas pilot to find and fix cyber weaknesses in water systems
The White House along with the Texas Government has launched Project Watershed 250, a six-month cybersecurity pilot that will provide Texas water and wastewater utilities with private-sector cybersecurity and AI resources at no cost.
The program will use red teaming to test utilities’ existing defenses, identify vulnerabilities and harden systems, with a particular focus on smaller and rural water providers that often lack dedicated cybersecurity resources.
The initiative will be overseen by the Office of the National Cyber Director and Texas Cyber Command, with companies including Microsoft, Google Cloud, AWS, Cloudflare, Palo Alto Networks, Fortinet, Forescout and Dragos contributing technology and expertise.
The pilot follows a wave of attacks against U.S. water infrastructure, including a recent campaign affecting 30 water systems across 12 states. Officials said the goal is to determine which defenses are effective during the six-month test and then scale successful approaches to water and wastewater systems across the country.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“You can’t harden what you don’t know is connected. Incomplete asset inventories are one of the most common findings I see across engagements, and critical infrastructure environments have some of the worst visibility gaps. Forescout, one of Watershed 250’s twelve participating vendors, recently found 4,400 internet-exposed Rockwell and Allen-Bradley controllers. Twenty-two sit in cities already hit by the recent water attacks, and 19 of those run firmware vulnerable to a flaw Rockwell patched many years ago.
“Twelve companies are contributing technology and expertise at no cost, but bringing more tools into environments that lack staff to configure and maintain them just grows the unmanaged attack surface. A firewall with default rules or a monitoring console nobody watches becomes another blind spot in an inventory that was already incomplete. These utilities need governance and dedicated security personnel before they need enterprise-grade technology.
“Month seven is the real test. Iranian campaigns against U.S. water systems and FBI-documented Chinese access to critical infrastructure are persistent threats, not six-month engagements. Replacing an exposed Programmable Logic Controller (PLC) might mean swapping a 15-year-old controller that was never designed to be networked, and the utility that can’t fund a dedicated security hire can’t fund that replacement either. If “scale what works” is the exit plan, it needs to include who pays for ongoing staffing and governance after the pilot ends.”
Damon Small, Board of Directors, Xcape, Inc.:
“Federal support for critical infrastructure represents a welcome partnership between the public and private sectors, offering underfunded municipal utilities a no-cost opportunity to reduce operational technology risk. While Project Watershed 250 establishes an important first step, utility executives must question who benefits most over time: whether this effort drives long-term resilience or simply lines vendor pockets with short-lived service agreements. Temporary tool donations and red teaming cannot fix legacy hardware and deficient network architecture design without sustained capital investment. The broader challenge remains defending the entirety of the nation’s critical infrastructure beyond rural water systems.
“To turn this initial momentum into permanent defense, security leaders must isolate control networks from the public Internet, enforce multi-factor authentication on remote access gateways, and baseline legacy environments before deploying complex artificial intelligence tools.
“Critical Takeaways
“Upgrading national security requires durable capital allocation, not just a six-month software trial with big-tech name drops.”
Hopefully this isn’t just a one time investment because quite honestly, that’s not what the US needs. Now more than ever.
Share this:
Like this:
Related
This entry was posted on September 1, 2026 at 3:44 pm and is filed under Commentary with tags White House. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.