Skip to main content
CybersecurityInfrastructure

US Bolsters Water Infrastructure with Cybersecurity Pilot

People in business attire and utility workers stand in front of a small water treatment plant with industrial equipment.

“The agency revealed it had received incident reports from 27 providers in at least seven states.” That stark tally, disclosed by the FBI on July 30, helps explain why the White House and Texas officials moved quickly to roll out a concentrated cyber-defense experiment for water systems.

Project Watershed 250: a six‑month Texas pilot

Project Watershed 250 is a new White House-backed program that will be piloted in the State of Texas, Governor Greg Abbott and the White House national cyber director Sean Cairncross jointly announced on August 31 during a roundtable in San Antonio. The initiative will run as a six‑month pilot and is explicitly designed to deploy federal and private‑sector cyber‑defense resources to water and wastewater utilities at no cost. The scope includes rural water providers, which the announcement singled out as often lacking the resources to defend themselves from growing cyber threats.

Who is providing technology and operational help?

The pilot will pair the Office of the National Cyber Director with a roster of major private firms to bring expertise and tooling into utilities’ operations. Named partners include Microsoft, Google, AWS, Cloudflare, Palo Alto Networks, Forescout and Dragos. The program will use those resources to identify vulnerabilities and to implement stronger defenses across participating water and wastewater systems.

State support and the role of Texas Cyber Command

Project Watershed 250 will be supported by Texas Cyber Command, the statewide body established in 2025 to prepare for and respond to cyber threats across Texas. The announcement frames the pilot as a collaborative effort between federal authorities, state response assets and commercial vendors, with the immediate objective of hardening operational technology (OT) devices and other systems used by utilities.

FBI warnings and the background of recent attacks

The pilot follows a wave of cyber‑attacks that federal authorities have linked to nation‑state actors. On July 30 the FBI warned that malicious cyber actors have been targeting OT devices at water and wastewater utilities, producing operational disruptions; the agency reported it had received incident reports from 27 providers in at least seven states. The source material links those attacks to Iranian state‑backed groups. Separately, reporting in the UK in August 2026 stated that Iranian hackers managed to shut down a power plant for several days during July — an event that was claimed to have coincided with a large‑scale operation targeting U.S. water plants, though the specific plant in the UK was not revealed.

What this means for rural water providers, Texas Cyber Command, and the Office of the National Cyber Director

  • Rural water providers: These systems are explicitly included in the pilot and will receive no‑cost federal and private‑sector cyber‑defense resources, addressing a gap the announcement identifies between resource availability and growing threat activity.
  • Texas Cyber Command: As the state entity created in 2025 to respond to cyber threats, Texas Cyber Command will support deployment of the pilot’s tools and assessments across participating utilities.
  • Office of the National Cyber Director: Sean Cairncross said lessons from the Texas pilot will inform potential expansions of Project Watershed 250 to other states and rural communities, according to an Axios report; the office will therefore be collecting operational data and implementation findings during the six‑month test period.

Project Watershed 250 is focused, short‑term and specific: a six‑month, state‑level pilot that brings together federal authorities, a state cyber command and several leading technology vendors to harden water infrastructure. The effort is a direct response to recent OT targeting of utilities that, according to the FBI, has already produced operational impacts for dozens of providers. Whether the Texas pilot’s playbook will scale beyond the state will hinge on the harvest of technical lessons and implementation experience — the very material Cairncross said will guide possible expansion.

The pilot offers an explicit next step in a policy and operational arc set off by the July FBI warning and subsequent reporting of nation‑state activity. It also leaves at least one concrete question visible in the public record: reporting cited an August 2026 UK incident and a claimed simultaneous operation against U.S. water plants, but did not identify which plant was targeted. That unresolved detail will matter to defenders and investigators alike as they evaluate the nature and reach of the attacks Project Watershed 250 aims to counter.

Original story