Texas And White House Launch Free Cyber Defense Pilot For State Water Utilities

Texas Governor Greg Abbott and White House National Cyber Director Sean Cairncross launched Project Watershed 250 on August 31, 2026, in San Antonio, a six-month pilot that gives Texas drinking water and wastewater utilities access to commercial cybersecurity tools, red team testing and AI-assisted defense at no charge. The program is run jointly by the Office of the National Cyber Director and Texas Cyber Command, with roughly a dozen technology and engineering firms contributing services. It is aimed primarily at small and rural systems among the more than 7,000 public water systems the Texas Commission on Environmental Quality regulates, and the administration intends to replicate the model in other states if it works.

Why Texas Was Chosen As The First State Testbed

Project Watershed 250 is the first of the state-level, industry-funded critical infrastructure pilots the Office of the National Cyber Director signalled after publishing its national cybersecurity strategy earlier this year. Texas offered a ready state counterpart in the form of a standing cyber agency, which most states do not have.

The pilot also lands in a policy vacuum. The previous administration’s attempt to impose cybersecurity audit requirements on water systems through the U.S. Environmental Protection Agency was withdrawn after legal challenges from several states, leaving voluntary measures as the main federal lever.

“For too long, at least on the federal level, the government has admired the problem of cybersecurity in water systems,” said Sean Cairncross, National Cyber Director at the Office of the National Cyber Director, speaking at the Project Watershed 250 rollout event in San Antonio on August 31, 2026, as reported by CyberScoop.

What Utilities Actually Receive During The Six Months

The service package is built around four functions: red team exercises that attempt to breach live utility networks, vulnerability assessments, remediation and hardening work, and AI-assisted monitoring intended to flag anomalous activity in operational technology environments.

The emphasis on red teaming is notable because it goes beyond the paper-based risk assessments that most small utilities have completed to satisfy America’s Water Infrastructure Act requirements. Adversarial testing of live SCADA and PLC estates is expensive and rarely purchased by systems serving a few thousand connections.

Reflection AI has framed part of its contribution around open-weight models running locally on a utility’s own hardware, an architecture choice that matters for operators unwilling to route control system telemetry to third-party clouds.

The Vendor Roster And The Absence Of A Price Tag

Twelve companies appeared at the launch: Parsons, Microsoft, Fortinet, Google Cloud, Palo Alto Networks, Amazon Web Services, Reflection AI, Cloudflare, Zscaler, Forescout, Abnormal AI and Dragos. Axios additionally listed Tenable among the participating firms.

Parsons said it will supply red teaming, vulnerability assessments, remediation and AI-enabled cyber defense, and noted in its August 31 release that it currently supports more than 400 electric and water utilities across the United States. That existing engineering footprint is the closest thing the pilot has to a delivery backbone for field work at dispersed rural sites.

Neither the governor’s office nor the Office of the National Cyber Director has published a budget, a target number of participating utilities, or the commercial value of the donated services. One water security practitioner quoted anonymously by CyberScoop dismissed the effort as lacking real money behind it and argued that the federal government was asking industry to fund work the government should partly pay for itself.

Texas Cyber Command As The Delivery Layer

Texas Cyber Command was created by House Bill 150 during the 89th Legislative Session after Abbott designated it an emergency item, and he signed the bill in San Antonio in June 2025. The agency handles threat intelligence, security operations and incident response for state and local systems and critical infrastructure, and is led by Chief of the Texas Cyber Command Vice Admiral (Ret.) TJ White.

Its role in the pilot is coordination rather than tooling: matching utilities to vendors, handling threat intelligence flow, and acting as the state point of contact alongside the EPA and the Cybersecurity and Infrastructure Security Agency as federal partners.

That intermediary function is the part most likely to determine whether the model transfers. States without an equivalent agency would need to route the same work through emergency management offices or state drinking water primacy agencies with far less cyber capacity.

The Incident Record Driving The Timeline

Abbott cited the January 2024 intrusion at the water system in Muleshoe, Texas, which caused a tank to overflow and was later linked to a Russian-aligned group, and a more recent Iranian-linked campaign against water systems in other states.

The Federal Bureau of Investigation said in a July 30, 2026, announcement that malicious actors had targeted programmable logic controllers at water and wastewater systems in at least seven states, with some incidents degrading water operations. Minnesota IT Services reported malicious activity against more than 30 community water systems, and Michigan reported attacks on nine of its systems.

The pattern in those cases was internet-exposed controllers with weak or absent authentication rather than sophisticated intrusion tradecraft, which is why the pilot’s asset discovery and remote access hardening components matter more than its AI framing.

EPA Grant Money Is Moving On A Separate Track

On the same day as the Texas launch, the EPA announced $11.75 million in grants for ten projects across six states under its Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability program. Eligibility is restricted to systems serving 10,000 people or more.

Individual awards illustrate the split between cyber and weather resilience. The City of Lake City, Florida, received $189,875 to modernize its SCADA and pump control system, while Denver Water received $1,125,000 and Coffeyville, Kansas, received $687,240.

The structural gap is visible in the eligibility threshold. The federal grant program excludes exactly the small systems the Texas pilot is targeting, which is why the donated-services model exists at all.

Benchmarking Free Against What OT Security Normally Costs

Commercial operational technology security programs at water and wastewater utilities are multi-year capital commitments. Kurrantly News previously reported that Jacobs won a $13.4 million OT cybersecurity contract with the Hampton Roads Sanitation District, a Virginia wastewater utility serving 1.9 million residents, covering assessments, OT design and integration, continuous monitoring and network engineering.

Against that benchmark, a six-month donated engagement is a diagnostic exercise, not a security program. Red teaming and vulnerability assessment produce findings; remediation, monitoring and staffing produce risk reduction, and those are recurring operating costs.

The unresolved question for participating utilities is what happens in month seven. Unless the pilot is paired with a sustainment path through state revolving funds, rate cases or a successor federal program, small systems will hold a remediation backlog they cannot fund.

What To Watch Over The Pilot Period

Three metrics will indicate whether the model scales: how many of the roughly 4,600 community water systems in Texas actually enrol, what share of findings reach verified remediation rather than reporting, and whether vendors commit to any post-pilot pricing for small systems.

Congress is separately weighing water sector cybersecurity legislation in the wake of the summer attacks, and the outcome of that debate will shape whether Watershed 250 remains a voluntary showcase or becomes the template for a funded national program.