The launch of Project Watershed 250 in Texas has sparked a wave of questions from boards, audit committees, and executive teams across critical infrastructure sectors. When the White House announces a federal pilot program to defend water systems against Iranian and Chinese state actors, it's not just a water industry issue anymore.
Here's what GRC leaders are asking right now, based on conversations in risk committees and cross-sector forums.
Context: The Source of These Questions
On August 31, 2025, the White House launched Project Watershed 250 in Texas, a six-month pilot deploying federal and private sector cyber-defense resources to water and wastewater utilities at no cost. The program responds to FBI warnings about cyber-attacks on operational technology devices across 27 water providers in at least seven states, linked to Iranian state-backed groups.
The questions below reflect what GRC teams are considering as they watch this pilot unfold and ponder its implications for their own critical infrastructure risk programs.
Q1: "Our water utility is in Texas. How do we get into this pilot?"
Contact Texas Cyber Command directly. The program is coordinated through the state's cyber command structure, established in 2025 to prepare for and respond to cyber threats.
The pilot prioritizes rural water providers lacking resources to defend against nation-state threats, but it's not limited to small systems. If you're a water or wastewater utility in Texas, reach out now. The program runs for six months, and the deployment schedule isn't public yet.
Private sector partners include Microsoft, Google, AWS, Cloudflare, Palo Alto Networks, Forescout, and Dragos. You'll likely receive vulnerability assessments and defensive tool deployment from one or more of these vendors, coordinated by federal resources.
Q2: "We're not in water, and we're not in Texas. Why does this matter to us?"
Because the threat model and response model apply beyond water systems.
The FBI reported attacks on operational technology devices, not just IT networks. If you operate OT environments in energy, manufacturing, transportation, or healthcare, you're facing the same adversary playbook. Iranian and Chinese state actors don't limit their reconnaissance to one sector.
White House national cyber director Sean Cairncross said lessons from the Texas pilot will inform expansions to other states and rural communities. This signals a template: federal coordination, state-level execution, private sector resources, zero cost to participants.
Start asking: If a similar program launched in your state for your sector, would your organization be ready to participate? Do you have an inventory of OT assets? Can you articulate your current defensive posture to a federal assessor?
Q3: "How do we structure a public-private partnership that actually works?"
Look at what Project Watershed 250 is doing structurally, not just tactically.
It combines federal oversight (Office of the National Cyber Director), state operational capacity (Texas Cyber Command), and private sector technical execution (seven named vendors). That's a three-layer model: policy direction, regional coordination, and hands-on defense.
For your organization, the parallel is: board-level risk appetite, enterprise risk oversight, and business unit execution. Public-private partnerships fail when one layer tries to do all three jobs. They succeed when each layer has clear authority and accountability.
The "no cost" element matters. It removes the procurement barrier that kills most security upgrades in underfunded infrastructure. If you're building a partnership model internally or with regulators, find the friction point (usually budget approval or vendor selection) and design around it.
Q4: "What vulnerabilities should we expect them to find in OT environments?"
The FBI's warning focused on attacks targeting operational technology devices, meaning adversaries are going after the systems that control physical processes, not just data networks.
Common OT vulnerabilities include: outdated firmware on programmable logic controllers, lack of network segmentation between IT and OT environments, default credentials on human-machine interfaces, and insufficient logging on supervisory control and data acquisition systems.
In the UK, Iranian hackers shut down a power plant for several days in July 2026, reportedly during a coordinated campaign targeting US water plants. That's not a sophisticated zero-day exploit. That's an adversary with time and patience exploiting known weaknesses in legacy industrial control systems.
Don't wait for a federal assessment. Run your own OT vulnerability scan now. If you find devices with default passwords or unpatched firmware from 2018, you've got the same exposure these water systems had.
Q5: "Our board wants to know if we need similar federal support. What do I tell them?"
Tell them you're monitoring the six-month pilot to see what defensive measures prove most effective, and you're assessing whether your current OT security program addresses the same threat vectors.
The honest answer: If you're in critical infrastructure and you don't have dedicated OT security resources, you probably do need external support. The question is whether you wait for a federal program or build capability now.
Project Watershed 250 exists because rural water providers can't afford dedicated cybersecurity staff. If your organization is larger or better resourced, the board's question should shift from "Do we need federal support?" to "What would a federal assessment find if they showed up tomorrow?"
Q6: "How do we justify budget for OT security when there's no regulatory mandate?"
Use the threat intelligence coming out of this pilot as your justification.
The FBI confirmed attacks on 27 providers in at least seven states. That's not hypothetical risk, it's documented incidents. When Iranian state actors are actively targeting a sector, your audit committee can't claim the risk is speculative.
Frame it as enterprise risk oversight, not compliance. You're not asking for budget to check a regulatory box. You're asking for budget to defend operational technology that, if compromised, could disrupt service to customers or create safety hazards.
Reference the public-private partnership model: major vendors are contributing resources to defend critical infrastructure because the threat is real and the consequences are severe. If Microsoft and Google are deploying tools to protect Texas water systems, your board should ask why your organization isn't making similar investments.
Where to Go for More
Monitor announcements from the Office of the National Cyber Director and Texas Cyber Command for updates on the pilot's progress. Watch for published findings after the six-month period ends.
If you're in critical infrastructure outside Texas, engage with your state's cybersecurity office now. Ask whether they're tracking Project Watershed 250 and whether they're considering similar programs.
For OT security frameworks, start with NIST SP 800-82 (Guide to Industrial Control Systems Security) and IEC 62443 (Security for Industrial Automation and Control Systems). These standards will give you a baseline to assess your current posture before any federal assessor does.





