Texas has become the testing ground for a new cybersecurity model, and the experiment is starting in San Antonio.
On August 31, 2026, federal and Texas officials launched Project Watershed 250, a six-month cybersecurity pilot designed to help Texas water and wastewater utilities identify vulnerabilities and strengthen their defenses. The program connects participating utilities with federal agencies, Texas Cyber Command, and private cybersecurity companies at no cost to the utilities.
Water systems may seem far removed from a small dental office, accounting firm, contractor, nonprofit, or local retailer.
However, the cybersecurity problem Project Watershed 250 is attempting to solve should sound familiar to many small-business owners:
Important technology. Limited cybersecurity staff. Limited budgets. Growing threats.
That raises a useful question.
If Texas can build a shared cybersecurity model for smaller water utilities, could some of the same ideas work for small businesses?
The answer is yes, although not by copying the program directly.
The real lesson is how cybersecurity resources are organized.
What Is Project Watershed 250?
Project Watershed 250 brings together the White House Office of the National Cyber Director, Texas Cyber Command, the Environmental Protection Agency, CISA, Texas officials, water utilities, and private cybersecurity companies.
Texas is the first state participating in the program.
The pilot will run for six months and focus on identifying vulnerabilities, helping utilities correct problems, and determining which cybersecurity capabilities can eventually be standardized and expanded elsewhere.
Private-sector participants include organizations such as Microsoft, Fortinet, Palo Alto Networks, Amazon Web Services, Google Cloud, Cloudflare, Dragos, Forescout, Zscaler, and others.
The emphasis is particularly important for smaller utilities.
Many water systems do not have large cybersecurity departments. Yet they operate essential infrastructure that communities depend on every day.
That combination makes them a difficult security problem.
It also makes the pilot relevant beyond the water industry.
Why Are Water Systems Getting This Attention Now?
Cybersecurity threats against water systems are not theoretical.
In July 2026, CISA warned of increased cyber activity targeting programmable logic controllers and other operational technology used by water and wastewater organizations.
Attackers had changed passwords, altered IP addresses, locked operators out of equipment, and forced some organizations into manual operations. In some cases, incidents contributed to boil-water notices.
CISA emphasized that organizations of all sizes were being targeted.
That matters because cybercriminals do not select victims based solely on company size.
They look for opportunities.
An organization with outdated software, exposed systems, weak passwords, poor monitoring, or limited IT resources may become attractive precisely because defending it is harder.
Small businesses face the same basic economics.
Small Businesses Have Their Own Version of the Water-Utility Problem
Consider a Texas business with eight computers.
It may depend on:
- Microsoft 365 or Google Workspace
- QuickBooks or another accounting system
- Customer records
- Cloud storage
- Online banking
- A CRM
- Industry-specific applications
- Remote access
- Employee laptops
- A company website
That business may have tens of thousands of dollars invested in technology and years of important customer information.
Yet it probably does not have a cybersecurity department.
It may not even have one dedicated IT employee.
The owner, office manager, bookkeeper, or most technically comfortable employee often ends up handling technology decisions.
That is essentially the same structural challenge Project Watershed 250 is trying to address:
How do you provide meaningful cybersecurity to organizations that need protection but cannot build an enterprise security team themselves?
Lesson One: Start With an Assessment, Not Another Product
One of the strongest ideas behind Project Watershed 250 is straightforward.
Find the vulnerabilities first.
Then decide what needs fixing.
This sounds obvious, but many small businesses do cybersecurity backwards.
A company hears about ransomware and buys antivirus.
Then someone recommends a firewall.
Later, the owner adds cloud backup.
Eventually, employees start using MFA.
Each product may be useful. However, nobody has stopped to determine whether the complete system actually addresses the company’s biggest risks.
Texas cybersecurity guidance for water organizations recommends regular cybersecurity assessments, maintaining inventories of IT and operational technology, reducing unnecessary internet exposure, changing default passwords, and implementing stronger authentication.
A small business can apply the same logic.
Before spending more money, ask:
What devices do we have?
What software do we depend on?
Where is our important data?
Who can access it?
What happens if one computer is compromised?
Are backups actually working?
Which accounts still lack MFA?
Are former employees still able to access anything?
You cannot protect what you do not know exists.
Lesson Two: Cybersecurity Works Better as a Shared Service
Project Watershed 250 does not expect every small utility to hire its own security operations center.
Instead, the program brings expertise to the utility.
That model already exists for small businesses.
It is one of the reasons Managed Service Providers exist.
A five-person company may never justify hiring:
- A network administrator
- A cybersecurity analyst
- A backup specialist
- A Microsoft 365 administrator
- A help-desk technician
- A security trainer
But the business can share access to those capabilities through an outside IT provider.
That changes cybersecurity from:
“Call someone when something breaks.”
to:
“Have systems continuously managed before something breaks.”
For smaller organizations, that is often a more realistic model.
Lesson Three: Continuous Monitoring Matters
Another important lesson is the shift from reactive security toward proactive security.
Texas Cyber Command describes Project Watershed 250 as combining federal capabilities, private-sector technology, and local expertise to strengthen systems before problems become larger incidents.
Small businesses should think the same way.
Traditional IT support often begins after an employee reports a problem.
“My computer is slow.”
“I can’t open this file.”
“My email account looks strange.”
“I clicked something.”
Those symptoms may appear after an attack has already begun.
Monitoring gives businesses another layer.
Instead of waiting for the employee to notice the problem, security software and monitoring systems can look for unusual activity, malware, missing patches, system failures, or other warning signs.
The goal is not perfect prevention.
Perfect cybersecurity does not exist.
The goal is earlier detection and faster response.
Lesson Four: Passwords Still Matter
For all the discussion surrounding AI-powered security tools, one of the recommendations for water systems remains remarkably ordinary:
Change default passwords and strengthen authentication.
Texas cybersecurity guidance specifically recommends unique, strong passwords and MFA where possible.
Small businesses should not overlook this.
Attackers do not need an advanced cyber weapon if they already have a working password.
Password-first security remains one of the most practical improvements a small organization can make.
That means:
- Unique passwords for every account
- A business password manager
- MFA wherever available
- Removing old accounts promptly
- Separating personal and business credentials
- Reviewing who has access to sensitive systems
Advanced cybersecurity still depends on basic security being done correctly.
Lesson Five: Backups Are Part of Cybersecurity
Water utilities need operational resilience.
Businesses do too.
A company that prevents 99 attacks but cannot recover from the 100th still has a serious problem.
Backups should therefore be treated as part of cybersecurity rather than simply storage.
Businesses should know:
When did the last backup succeed?
Where is it stored?
Is it protected from the same attack that could damage the original files?
Has anyone tested a restore?
How quickly could critical information be recovered?
“Backup enabled” is not the same thing as “recovery ready.”
What About the AI Part of Project Watershed 250?
The project also includes access to cybersecurity and AI resources from participating technology companies.
That deserves attention, but small businesses should avoid drawing the wrong conclusion.
AI is not replacing cybersecurity professionals.
The more useful role is helping professionals identify patterns, analyze large amounts of security information, prioritize vulnerabilities, automate repetitive work, and respond faster.
That same principle should guide small-business AI adoption.
Education first. Safe implementation second. Workflow improvement third. Ongoing support fourth.
AI should improve a security process, not become an excuse to operate without one.
Could the San Antonio Model Work for Small Businesses?
Not literally.
Small businesses are not going to receive the same federal program designed for critical water infrastructure.
However, the operating model translates remarkably well.
Project Watershed 250 combines:
Assessment → expertise → technology → monitoring → remediation → shared resources
A small business can follow essentially the same sequence:
Evaluate → prioritize → protect → monitor → back up → train → review
That is a much stronger cybersecurity strategy than buying random tools whenever a new threat makes the news.
San Antonio May Be Testing Something Bigger Than Water Security
Project Watershed 250 is important because Texas water infrastructure matters.
But the broader idea deserves attention too.
Thousands of organizations across Texas operate important systems without dedicated cybersecurity departments.
Water utilities are one example.
So are dental practices.
Accounting offices.
Law firms.
Nonprofits.
Construction companies.
Local governments.
Medical offices.
Retailers.
Family businesses.
The question is not whether these organizations deserve enterprise-grade cybersecurity.
They do.
The challenge is delivering appropriate protection without requiring each organization to build an enterprise-sized IT department.
San Antonio’s new cybersecurity pilot is testing one approach: combine resources, share expertise, identify risks early, and fix vulnerabilities before attackers exploit them.
That is a model worth watching.
For small businesses, the takeaway is even simpler:
You do not need a massive IT department to take cybersecurity seriously. You need to know what you have, understand where you are vulnerable, put the right protections in place, and make sure someone is watching the systems that keep your business running.
If you are unsure where your current cybersecurity gaps are, start with an IT security review. Knowing what needs attention is the first step toward fixing it.
FAQ
Project Watershed 250 is a six-month cybersecurity pilot launched in San Antonio on August 31, 2026. Texas water and wastewater utilities can access cybersecurity expertise and technology through federal, state, and private-sector partners.
Texas is serving as the first testing ground for the program. The goal is to determine which cybersecurity capabilities can work effectively for under-resourced utilities and potentially be scaled to other states.
No. The pilot specifically focuses on water and wastewater utilities. However, its shared-resource and proactive-security model offers useful lessons for smaller organizations that lack dedicated cybersecurity teams.
There is no single protection that solves every problem. A good starting point is a cybersecurity assessment followed by basic controls such as updated systems, endpoint protection, MFA, password management, monitored systems, secure backups, and employee training.
Not necessarily. Small businesses can use managed IT providers and other outside specialists to obtain monitoring, cybersecurity, backup, support, and technical expertise without maintaining a full internal IT department.
Find the Gaps Before an Attacker Does
Project Watershed 250 starts with identifying weaknesses before they become incidents. Small businesses should take the same approach.
SofTouch Systems helps Texas businesses review their current IT security, identify practical risks, and prioritize the protections that matter most. From password security and endpoint protection to backups, monitoring, and employee training, we focus on clear recommendations without unnecessary complexity.
Start with a free 15-minute IT security check. We’ll help you understand what is working, what may need attention, and what your next practical step should be.
Schedule your free IT security check with SofTouch Systems.
Discover more from SofTouch Systems
Subscribe to get the latest posts sent to your email.
