Project Watershed 250 tests AI cyber tools for water-utility risk reduction


Operational technology (OT)
Hardware and software that monitor or control physical processes, such as pumps, valves, chemical treatment systems and industrial controllers.
SCADA
Supervisory control and data acquisition systems used to monitor and control industrial processes across sites such as water plants and pump stations.
Red teaming
Authorized adversary-style testing that attempts to find and exploit weaknesses so defenders can close attack paths before real attackers use them.
Exposure management
A risk-based approach to finding, prioritizing and reducing weaknesses across assets, identities, vulnerabilities and externally reachable systems.
Axios
news
Trump officials launch program to secure water systems after Iran cyberattacks
“Confirms a six-month Texas pilot delivering free cybersecurity and AI tools to under-resourced water systems and lists participating vendors and implementation roles.”
Nextgov/FCW
news
White House launches water cybersecurity pilot in Texas
“Frames Project Watershed 250 as a six-month stress test using private-sector cybersecurity and AI tools, with ONCD, Texas Cyber Command, EPA, CISA and vendors involved.”
CyberScoop
news
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
“Reports that officials described the pilot as testing red teaming, system hardening, AI tooling, proactive weakness-finding and whether the model can scale.”
Tenable
Tenable Joins White House-Led Project Watershed to Bolster U.S. Water Systems Cybersecurity
Parsons
Parsons Participates in Trump Administration’s Project Watershed 250
Office of the Texas Governor via EIN Presswire
Governor Abbott, National Cyber Director Launch Project Watershed 250 To Defend Texas Water Supply
Six-month pilot
Project Watershed 250 is a six-month Texas test connecting water and wastewater utilities with private-sector cyber and AI tools.
AI-assisted defense
Vendors are expected to help utilities detect suspicious activity, respond to attacks and harden systems with AI-enabled cyber capabilities.
OT focus
The pilot includes work on SCADA, PLCs, pump stations and treatment-plant environments where availability and safety constrain traditional security testing.
The White House and Texas launched Project Watershed 250 on August 31 as a six-month test of private-sector cybersecurity and artificial intelligence tools for under-resourced water and wastewater utilities. Texas is the first proving ground for a model officials say could expand nationally.126
The pilot is designed to put operational tools in front of utility operators, not just improve coordination. Those tools include red teams to test defenses, exposure-management platforms to identify reachable assets and risky weaknesses, OT vulnerability assessments for SCADA and control environments, system-hardening support, threat intelligence, and AI-assisted detection and response.3458
Officials have framed the effort as a way to determine “what works” before scaling the approach across U.S. water and wastewater infrastructure.38 For technologists, the core question is measurable: whether the pilot can show that private-sector tools reduce the conditions that enable operational disruption, not simply that more products were deployed.
Project Watershed 250 will connect Texas utilities with federal, state and private-sector resources at no cost to participating providers, according to the Texas governor’s office.6 Axios reported that EPA and CISA are federal partners and that Texas Cyber Command is overseeing implementation. Vendors including Microsoft, Google, AWS, Cloudflare, Palo Alto Networks, Reflection AI, Abnormal AI, Parsons, Fortinet, Forescout, Tenable, Zscaler and Dragos are providing services during the Texas pilot.1
Nextgov/FCW described the program as a six-month stress test using Texas as the testing ground for private-sector cybersecurity and AI tools. ONCD, Texas Cyber Command, the governor’s office and vendors are working together to find and address utility vulnerabilities.2 CyberScoop reported that officials specifically pointed to red teaming, system hardening, AI tooling and proactive weakness-finding as planned capabilities.3
The capabilities fall into five engineering workstreams.
First, red teaming will simulate attacker behavior against utility networks to identify exploitable paths before adversaries do.37 In a water environment, the useful output is not a generic penetration-test report. It is a ranked set of attack paths showing how an exposed remote-access service, weak identity control or flat network segment could reach operational systems.
Second, exposure management will inventory assets across IT and OT, identify externally reachable systems, prioritize vulnerabilities by risk and support remediation workflows. Tenable said its contribution centers on unified visibility across IT and OT domains, risk prioritization and automated remediation support for water and wastewater systems.4
Third, OT vulnerability assessment will focus on control-system environments, which are typically harder to scan and patch than enterprise IT. Parsons said its participation includes vulnerability assessments, remediation and mitigation, and OT expertise covering programmable logic controllers, SCADA networks, valves, pump stations and treatment plants.5
Fourth, hardening will translate findings into configuration changes, segmentation, access-control improvements and mitigation steps that utility operators can sustain. Fox News reported that the program will test existing defenses and strengthen vulnerable systems with private-sector cyber and AI tools.7
Fifth, AI-assisted defense will help detect suspicious activity, support response and extend scarce utility cyber staff. The San Antonio Express-News reported that vendors will help utilities find weak spots, test defenses, look for suspicious activity and respond to attacks with AI tools and technical support.8
Officials have not published a detailed public scorecard for Project Watershed 250. But their stated plan to “find out what works” and scale proven approaches implies a deployment test with evidence requirements: baseline risk, intervention, verification and repeatability.38
The strongest telemetry would start with a pre-deployment baseline. That includes an asset inventory of internet-facing systems, remote-access paths, identity providers, endpoints, servers, engineering workstations, HMIs, PLCs and SCADA components. It also includes known vulnerabilities, unsupported systems, weak credentials, exposed services and network paths from business IT into OT.
After vendor tooling is deployed, officials and utilities should be able to compare before-and-after evidence: fewer externally exposed services, fewer critical vulnerabilities on reachable assets, reduced privileged-account risk, stronger remote-access controls, segmented OT pathways, documented compensating controls for unpatchable systems and shorter mean time to remediate high-risk findings.
Red-team results offer another test. If an initial exercise shows a path from phishing or exposed remote access into operational technology, the pilot’s value depends on whether that path is closed and whether a retest confirms the fix. A clean retest is more meaningful than a list of alerts generated during the exercise.
Detection telemetry is central to the AI claim. AI-assisted defense should produce measurable improvements in suspicious-activity detection, triage speed and response quality. Useful metrics would include high-confidence alerts tied to validated behaviors, analyst time saved, false-positive rates, response playbooks executed and incidents contained before operational impact.
For under-resourced utilities, remediation evidence matters as much as discovery. A pilot that finds hundreds of weaknesses but leaves operators without patch windows, compensating controls or budgeted fixes would not meaningfully reduce operational risk. Tenable’s emphasis on prioritization and automated remediation, and Parsons’ emphasis on remediation and mitigation, point to the need for closure data rather than discovery counts alone.45
Water providers vary widely in size, maturity and staffing. Many smaller and rural utilities operate legacy equipment, rely on vendors or part-time IT support, and must balance cybersecurity work against safety, regulatory and availability requirements. Axios and Nextgov/FCW both noted that many systems lack the money, personnel and technical depth available to larger critical-infrastructure operators.12
That environment makes OT assessment difficult. Scanning a business laptop fleet is not the same as testing treatment-plant controls, pump stations or telemetry links. Aggressive scanning can disrupt fragile devices, and some systems cannot be patched quickly because downtime affects service delivery.
The pilot’s engineering challenge is operational fit. Tools must be light enough for utilities with limited staff, precise enough to avoid overwhelming operators with findings, and safe enough for environments where availability and process integrity are paramount.
The White House and participating companies have described Texas as a test bed for a broader national model.27 CyberScoop reported that officials want to identify what works, learn lessons and scale from the six-month pilot.3 The San Antonio Express-News reported the stated goal of expanding successful approaches across national water and wastewater infrastructure.8
Scaling will require more than duplicating a vendor roster. Texas Cyber Command is coordinating the state implementation, giving the pilot a centralized state-level cyber partner that not every state currently has.18 A national rollout would need a repeatable onboarding process for utilities, a common data model for findings, minimum evidence requirements for remediation, clear rules for sensitive OT telemetry and a support model that does not assume local cyber expertise.
Cost is another constraint. The Texas launch emphasizes no-cost resources for utilities, but CyberScoop reported skepticism from one water-security professional who questioned whether the program has enough funding behind it.3 If free vendor support is temporary, officials will need to show whether utilities can sustain the controls after the pilot ends.
The six-month test will be most credible if it produces comparable engineering outputs across participating utilities: initial exposure maps, red-team findings, mitigation actions, retest results, detection metrics and operator feedback. Those artifacts would show whether AI-enabled defense can reduce real operational risk in water systems — and whether the model is portable beyond Texas.
Fox News
FIRST ON FOX: Texas becomes testing ground for new defense against attacks on America’s water systems
Comments