Water and wastewater systems are among the most important pieces of critical infrastructure in the United States. They are also increasingly connected to digital technologies, making cybersecurity a critical component of operational resilience.
That challenge is the focus of Project Watershed 250, a six-month cybersecurity pilot launched in Texas in August 2026.
The program brings together government agencies, Texas water utilities, and private-sector cybersecurity companies to identify vulnerabilities and strengthen defenses. Participating utilities will receive cybersecurity and artificial intelligence resources at no cost during the pilot.
For organizations responsible for protecting critical infrastructure, Project Watershed 250 represents more than a new government cybersecurity initiative. It reflects a broader shift toward proactive security testing, operational technology (OT) security, and attacker-focused assessments.
It also highlights a fundamental cybersecurity lesson: protecting critical infrastructure requires organizations to understand not only whether vulnerabilities exist, but how a threat actor could use them to affect real-world operations.
What is Project Watershed 250?
Project Watershed 250 is a six-month water utility cybersecurity pilot launched in Texas on August 31st, 2026.
Texas was selected as the first state to participate in the federal initiative. Texas Cyber Command is overseeing implementation, with federal support from the Environmental Protection Agency (EPA) and the Cybersecurity and Infrastructure Security Agency (CISA).
The program connects water and wastewater utilities with private-sector cybersecurity companies that can provide technology, expertise, testing, and other defensive capabilities.
The goal is to help utilities:
Identify cybersecurity vulnerabilities
Assess their existing security posture
Strengthen defenses
Remediate identified weaknesses
Improve resilience against cyberattacks
Explore the use of artificial intelligence for cybersecurity
Develop a model that could eventually be expanded beyond Texas
Texas Cyber Command describes the initiative as an effort to shift critical infrastructure cybersecurity from reactive incident response toward proactive risk reduction and resilience.
Why Water Utility Cybersecurity Matters
Water utilities operate an unusual combination of information technology and operational technology.
IT systems may include:
Employee workstations
Email systems
Cloud applications
Identity infrastructure
Databases
Business applications
Internet-facing services
OT environments can include:
Industrial control systems
Supervisory control and data acquisition systems
Programmable logic controllers
Human-machine interfaces
Sensors
Pumps
Treatment systems
Remote monitoring equipment
These environments can have very different security and availability requirements.
A compromised employee workstation is a serious security issue. A compromised system involved in controlling a physical process can potentially create consequences that extend into the real world.
That is why OT cybersecurity is an increasingly important component of critical infrastructure protection.
The EPA has specifically warned about vulnerabilities involving internet-exposed human-machine interfaces in water and wastewater systems. Unauthorized users who gain access to these systems could potentially view or modify real-time operational settings. For water utilities, cybersecurity is therefore not simply about protecting data. It is about protecting the systems that communities depend on.
Why Small Water Utilities Are Particularly Vulnerable
One of the challenges Project Watershed 250 attempts to address is the disparity in cybersecurity resources among water providers.
Large utilities may have dedicated security personnel, security operations teams, specialized technology, and significant cybersecurity budgets.
Smaller and rural utilities may not. This creates an uncomfortable reality: a smaller organization can face sophisticated cyber threats without having the resources necessary to maintain an equally sophisticated defense.
The Texas pilot is designed in part to address that gap by making private-sector cybersecurity capabilities available at no cost during the program.
Texas Cyber Command says the state has more than 7,400 public water systems and more than 3,000 wastewater treatment facilities, demonstrating the scale and diversity of the infrastructure involved.
The security needs of a large metropolitan utility and a small rural provider may look very different. However, both can become targets.
Project Watershed 250 Uses a Proactive Cybersecurity Model
One of the most significant aspects of Project Watershed 250 is its emphasis on identifying weaknesses before they become incidents.
A traditional incident response model is inherently reactive. An organization discovers suspicious activity, investigates it, contains the threat, removes the attacker, and attempts to recover.
Organizations protecting critical infrastructure also need to understand where attackers could gain access before an incident occurs. This is where security assessments and penetration testing can provide valuable insight.
Why Penetration Testing Matters for Critical Infrastructure
A vulnerability scan can tell an organization that a particular vulnerability exists.
A penetration test can help answer a more consequential question: What could an attacker actually do with it?
Penetration testing uses controlled, authorized attack techniques to identify weaknesses in an organization's defenses.
Rather than treating vulnerabilities as isolated technical findings, a skilled penetration testing team can examine how multiple weaknesses might be combined.
For example, an attacker might:
Identify an internet-facing service.
Exploit a vulnerability.
Obtain credentials.
Escalate privileges.
Move laterally through the environment.
Access sensitive systems.
Attempt to reach an operational environment.
The individual weaknesses might appear relatively manageable when viewed separately. The attack path could reveal a much more serious risk.
Penetration Testing vs. Vulnerability Scanning
Penetration testing and vulnerability scanning are complementary, but they are not the same thing.
Vulnerability scanning
Vulnerability scanning generally uses automated tools to identify known security weaknesses.
It can help organizations establish visibility across large environments and prioritize obvious issues.
Penetration testing
Penetration testing goes further by attempting to exploit vulnerabilities within an authorized scope.
The objective is to determine whether weaknesses can be practically leveraged and what impact they could have. A mature security program can use both.
Scanning provides breadth. Penetration testing provides depth and context. For critical infrastructure organizations, that context can be essential when determining which vulnerabilities represent the greatest operational risk.
The Importance of IT and OT Security
The convergence of IT and OT has fundamentally changed the cybersecurity landscape for industrial organizations.
Historically, many operational systems were isolated from conventional corporate networks.
Modern organizations increasingly depend on remote access, cloud services, connected devices, centralized management, and other technologies that create additional connectivity.
That connectivity can improve efficiency. It can also expand the attack surface.
A threat actor who compromises an IT environment may attempt to use that access as a stepping stone toward more sensitive systems.
This makes network architecture and segmentation particularly important.
Critical infrastructure organizations should understand:
Which systems communicate with one another
Which assets are internet-facing
Which users have privileged access
Which remote access pathways exist
Which third parties can connect to operational environments
Where IT and OT networks intersect
Whether unnecessary connectivity can be removed
Whether security controls can detect lateral movement
These questions should be answered before an attacker forces the organization to answer them during an incident.
Red Teaming Can Expose Gaps in Defensive Assumptions
Project Watershed 250 also puts attention on attacker-focused security testing. Red teaming is designed to simulate aspects of a real-world attack against an organization under controlled conditions.
The purpose is not simply to collect as many vulnerabilities as possible.
Instead, a red team can evaluate whether an organization's defensive assumptions hold up when someone actively attempts to bypass them.
This can include testing:
External attack surfaces
Identity controls
Privileged accounts
Network segmentation
Endpoint security
Security monitoring
Detection and response capabilities
Remote access
Social engineering defenses
Attack paths between IT and OT environments
For critical infrastructure, testing should be carefully designed around operational requirements.
An assessment that is appropriate for a traditional corporate environment may not be appropriate for sensitive OT systems.
Testing methodology, scope, safety controls, authorization, and communication procedures all matter.
AI is Becoming Part of the Critical Infrastructure Security Conversation
Artificial intelligence is another major component of Project Watershed 250.
The initiative reflects a broader cybersecurity trend: both attackers and defenders are exploring how AI can accelerate security operations.
Defenders can potentially use AI to:
Analyze security data
Identify suspicious behavior
Accelerate threat investigation
Support security analysts
Prioritize alerts
Automate repetitive tasks
Improve response workflows
Attackers can similarly use AI to accelerate reconnaissance, automate portions of their operations, and identify potential weaknesses.
AI works best when it complements fundamentals such as:
Strong identity security
Network segmentation
Vulnerability management
Secure configuration
Endpoint protection
Continuous monitoring
Incident response
Security testing
Technology can accelerate a security program. It cannot compensate indefinitely for fundamental architectural weaknesses.
Why Continuous Security Testing Matters
A single penetration test provides a point-in-time assessment. That does not mean it provides permanent protection.
Infrastructure changes. Employees join and leave organizations. Credentials change. Applications are deployed. Cloud environments expand. Vulnerabilities are discovered. Vendors gain new access. Network configurations are modified.
As the environment changes, the attack surface changes with it.
This is why critical infrastructure organizations should think about cybersecurity as a continuous process rather than a one-time compliance exercise.
Regular assessments can help organizations determine whether previously addressed vulnerabilities have returned, whether new attack paths have emerged, and whether defensive controls remain effective.
For organizations with highly dynamic environments, continuous penetration testing can provide an additional layer of visibility into how their security posture changes over time.
What Project Watershed 250 Means for Critical Infrastructure Security
Project Watershed 250 is significant because it combines three elements that are often difficult for under-resourced organizations to access independently:
Government coordination.
Federal and state organizations can provide intelligence, guidance, coordination, and infrastructure expertise.
Private-sector cybersecurity expertise.
Cybersecurity companies can contribute specialized technologies, testing capabilities, threat intelligence, and technical expertise.
Operational knowledge.
Utilities understand their own infrastructure, processes, equipment, and operational constraints.
Bringing these capabilities together can produce a more comprehensive approach to critical infrastructure cybersecurity.
The Texas pilot includes companies such as Microsoft, Google Cloud, Amazon Web Services, Cloudflare, Palo Alto Networks, Fortinet, Forescout, Dragos, Zscaler, Abnormal AI, Parsons, and Reflection AI, among other participants.
The diversity of organizations involved also demonstrates that protecting critical infrastructure requires multiple cybersecurity disciplines.
No single security product can eliminate an organization's cyber risk.
What Other Critical Infrastructure Organizations Can Learn
Although Project Watershed 250 focuses on Texas water utilities, its lessons can apply across critical infrastructure sectors.
Organizations responsible for energy, transportation, manufacturing, healthcare, telecommunications, and other essential services can ask similar questions.
1. Know your attack surface
Organizations cannot protect assets they do not know exist.
Asset inventory should include internet-facing systems, cloud environments, endpoints, network infrastructure, third-party connections, and relevant OT assets.
2. Prioritize critical systems
Not every vulnerability presents the same level of risk.
Organizations should understand which systems are essential to operations and prioritize security efforts accordingly.
3. Test security controls
Security tools may perform differently in practice than they do on paper.
Authorized penetration testing can help organizations determine whether their controls withstand realistic attack techniques.
4. Examine attack paths
Individual vulnerabilities do not always tell the whole story.
Organizations should understand whether attackers can chain multiple weaknesses together.
5. Protect IT and OT environments
The boundary between corporate IT and operational environments should be deliberately designed and monitored.
6. Prepare for failure
Organizations should determine how essential services would continue if a critical system became unavailable.
Cyber resilience requires more than preventing attacks. It requires the ability to detect, respond, recover, and maintain essential operations.
How Penetration Testing Supports Water Utility Cybersecurity
For water utilities and other critical infrastructure organizations, penetration testing should be viewed as part of a broader risk management strategy.
A strong engagement can help answer questions such as:
Can an external attacker gain unauthorized access?
Can a compromised account escalate its privileges?
Can attackers move laterally through the network?
Are exposed services adequately secured?
Can security controls detect realistic attack activity?
Are segmentation controls working as intended?
Could an attacker reach sensitive systems from an initial foothold?
What attack paths represent the greatest operational risk?
The answers can help security teams move beyond theoretical vulnerability lists and toward practical risk reduction.
That distinction is increasingly important as organizations face threats from cybercriminals, nation-state actors, hacktivists, and other adversaries.
How Packetlabs Helps Organizations Test Their Defenses
Critical infrastructure organizations need more than a checklist.
They need to understand how their defenses perform against realistic attack scenarios.
Packetlabs provides penetration testing services designed to help organizations identify exploitable weaknesses, validate security controls, and better understand their real-world attack surface.
Our approach focuses on what attackers can actually accomplish, not simply how many vulnerabilities an automated scanner can identify.
For organizations operating complex IT environments, cloud infrastructure, applications, or other critical systems, penetration testing can provide the insight needed to prioritize remediation and strengthen defensive controls.
Whether the goal is validating an existing security program, preparing for a compliance requirement, assessing an emerging technology environment, or understanding exposure to realistic attack paths, an attacker-focused assessment can provide valuable context.
Conclusion
Project Watershed 250 will run for six months, making the program an important test of whether public-private collaboration can produce a scalable model for critical infrastructure cybersecurity.
Texas Cyber Command has described the initiative as a potential model for other states.
The outcome will depend on more than how many vulnerabilities are identified. The real test will be whether participating organizations can translate findings into lasting security improvements.
Project Watershed 250 recognizes that reality by bringing cybersecurity expertise directly to an industry where a digital compromise can potentially create physical consequences.
For other critical infrastructure organizations, the broader lesson is equally important.
Penetration testing, red teaming, vulnerability management, continuous monitoring, and strong security architecture can help organizations identify those paths before adversaries do.
FAQs
What is Project Watershed 250?
Project Watershed 250 is a six-month cybersecurity pilot focused on Texas water and wastewater utilities. The initiative provides participating utilities with access to cybersecurity and AI resources at no cost while testing a model that could potentially be expanded to other states and critical infrastructure sectors.
Why was Texas selected for Project Watershed 250?
Texas was selected as the first state for the pilot because of the scale and importance of its critical infrastructure and the capabilities of Texas Cyber Command. The state has thousands of public water and wastewater facilities.
Why are water utilities targeted by cybercriminals?
Water utilities operate essential infrastructure and increasingly rely on connected IT and OT systems. Smaller utilities may also have limited cybersecurity resources, making some organizations more difficult to defend against sophisticated threats.
What is OT cybersecurity?
OT cybersecurity focuses on protecting systems that monitor or control physical processes. In water utilities, OT can include industrial control systems, programmable logic controllers, sensors, pumps, and human-machine interfaces.
How does penetration testing help critical infrastructure organizations?
Penetration testing can identify vulnerabilities and demonstrate how attackers could potentially exploit weaknesses and chain multiple findings together. This helps organizations prioritize remediation based on realistic attack paths rather than vulnerability severity alone.
Is penetration testing the same as vulnerability scanning?
No. Vulnerability scanning primarily identifies known weaknesses through automated processes. Penetration testing involves authorized attempts to exploit weaknesses and can provide greater insight into how vulnerabilities could affect an organization.
Why is IT and OT segmentation important?
Segmentation can help limit an attacker's ability to move between systems and environments. Strong separation and access controls can reduce the potential impact of a compromise.
Can AI improve water utility cybersecurity?
AI can potentially help security teams analyze data, identify threats, prioritize alerts, and accelerate investigations. However, AI should complement rather than replace foundational controls such as identity security, network segmentation, vulnerability management, monitoring, and penetration testing.
Will Project Watershed 250 become a national program?
The Texas pilot is intended to evaluate a model that could potentially be expanded to other states and critical infrastructure sectors.
How can organizations improve their critical infrastructure cybersecurity?
Organizations can start by identifying critical assets, understanding their attack surface, strengthening identity and access controls, segmenting IT and OT environments, continuously monitoring for threats, conducting penetration testing, and maintaining tested incident response and recovery plans.
Security tools and penetration testing serve different purposes. Security tools help prevent, detect, and respond to threats, while penetration testing can evaluate whether an authorized attacker can bypass or work around those controls. Testing can therefore help validate whether security investments are working as intended.