Water Cybersecurity Just Entered a New Phase. A water treatment facility with a Direnzic water tower and a live threat-monitoring display. Capability, Decision, Evidence.
Executive Analysis Direnzic Technology Water Security

Water Cybersecurity Just Entered a New Phase

Project Watershed 250 and OpenAI’s Daybreak are pushing new cyber capability toward under-resourced utilities. The harder problem increasingly begins after the findings arrive: turning them into safe, authorized and provable action.

Key takeaways

Government and industry have begun subsidizing the parts of cyber defense that utilities have struggled to fund: assessment, remediation support, training and advanced tooling.

As more capability becomes available, execution increasingly becomes the binding constraint. Findings still need an owner, an authorization boundary, a safe change window, a verification step and a record.

The final AWIA ERP certification date for the 3,301 to 49,999 population tier creates a near-term forcing function for affected community water systems.

The most important water-cybersecurity story of the past ten days is not that utilities are being offered more tools. It is that government and industry are beginning to subsidize parts of cyber defense that many utilities have struggled to fund themselves: assessment, analysis, remediation support, training, advanced defensive capability and technical assistance.

That is real progress. It also creates a new operating challenge.

A utility can accept a free assessment, a subsidized AI capability or a donated security tool and still be left with the same difficult questions the next morning.

Who owns the finding?

Which vendor actually performs the work?

Can the proposed fix be made safely on an operating plant?

How do we verify that it worked?

Who has authority to approve the change?

Where is the evidence six months later, when a regulator, insurer, auditor, council or board asks what happened?

That is where the next phase of water-sector cybersecurity begins.

Two programs point in the same direction

On August 31, Governor Greg Abbott and White House National Cyber Director Sean Cairncross launched Project Watershed 250 in Texas, with Texas Cyber Command playing a central state role alongside the Office of the National Cyber Director.1, 2 Texas Cyber Command says Texas is the first state selected for the pilot, which combines federal capabilities, private-sector technology and the frontline expertise of water utilities. Participating utilities will gain access to comprehensive cyber assessments, hands-on remediation support and emerging defensive measures.1

The ambition extends beyond one state. Texas Cyber Command describes Texas as a proof of concept for protecting essential services nationwide, with the goal of moving utilities from reactive incident response toward proactive risk reduction and resilience.1

Three days later, OpenAI announced Daybreak for Frontline Defenders, committing $1 billion in subsidized access to cyber models and products, training, technical support and partnerships.3 OpenAI says the subsidy is targeted for consumption over the next six months, with water and wastewater systems named among the essential-service operators being prioritized.

OpenAI also announced a public-sector and water-focused pilot with MS-ISAC. Initial participants will receive Daybreak access, guided training and hands-on assistance intended to help defenders validate and prioritize findings, coordinate remediation and develop a repeatable operating approach.3

The scale is already significant. OpenAI says thousands of defenders across 2,000 approved organizations and workspaces use Daybreak. Its second utility convening included organizations representing 40 states and the District of Columbia. The Daybreak Defense Network now includes more than 35 partner products and partner-operated services.3, 4

The funding environment is moving the same way. Also on August 31, EPA announced $11.75 million for ten drinking-water resilience projects at midsize and large systems, addressing cybersecurity and extreme-weather risk. In the same announcement, EPA noted that cyberattacks this year have targeted more than 100 drinking water and wastewater systems across 12 states.5

By the numbers · The new water-cyber landscape
$1B
OpenAI Daybreak subsidy for frontline defenders, targeted for use over six months
40 + DC
States represented at OpenAI’s second utility convening
$11.75M
EPA drinking-water resilience grants across ten projects
100+
Water and wastewater systems targeted by cyberattacks this year, across 12 states, per EPA
Sources: OpenAI (Sept. 3, 2026); EPA (Aug. 31, 2026). See endnotes.

The constraint is shifting

The common signal is hard to miss: more capability is moving toward water utilities. For years, the water-sector cybersecurity problem has been framed as a resource problem. Too little staff. Too little budget. Too little specialized cyber expertise. Too many aging systems.

Those constraints remain. But programs such as Watershed 250 and Daybreak can begin relieving part of the capability shortage. That shifts attention to a different question: can the utility operationalize what it receives?

A vulnerability report does not decide whether a programmable logic controller can be patched while treatment remains online.

An AI-generated remediation recommendation does not have authority to change a plant.

A donated tool does not decide whether the utility’s SCADA integrator, IT provider, equipment manufacturer or internal operator owns the fix.

A grant does not automatically create the governance needed to prioritize findings against operational consequences.

And a pilot does not create a sustainment model for the day after the pilot ends.

The more cyber capability a utility receives, the more important those questions become.

“An AI-generated remediation recommendation does not have authority to change a plant.”

Ieshea Hollins

Five things utility leadership should do now

1

Establish who owns the decision process.

Someone must own the movement from finding to decision to implementation to verification. That does not mean one person performs every technical task. It means accountability cannot disappear between departments and vendors.

2

Define authorization boundaries before new technology arrives.

Decide which systems can be reviewed, scanned or analyzed; what data may leave the environment; what requires operator approval; and which types of changes require a maintenance window. Those decisions belong to the utility.

3

Create one place where findings become managed work.

Assessments, incident reports, vendor recommendations, AI-generated findings and penetration-test results should not live in disconnected reports. Every material finding should have an owner, an operational consequence, a decision, a target action, a status, verification evidence and an escalation path.

4

Plan sustainment before accepting temporary support.

Ask what continues when the pilot, grant, credit, vendor engagement or donated service ends. Cyber risk does not expire with the funding period.

5

Use the current compliance cycle as a forcing function.

For community water systems serving 3,301 to 49,999 people, EPA lists December 31, 2026 as the final ERP certification date in the current five-year cycle. Under AWIA, ERP certification is due six months after the utility certifies its Risk and Resilience Assessment; December 31 corresponds to utilities that certified their RRA on the June 30, 2026 deadline.6 That makes the current period an opportunity to do more than update a document. Utilities can use the ERP cycle to ask whether roles, escalation, manual operations, communications, vendor coordination and cyber-response decisions would actually work under pressure.

Before accepting any free or subsidized cyber resource
  1. Who authorizes the work, against which systems, and within what boundaries?
  2. When findings arrive, who prioritizes them by operational consequence rather than simply by technical severity?
  3. Who determines whether remediation can occur while treatment and distribution remain operational?
  4. Where will decisions, approvals, remediation results and verification evidence be retained?
  5. What capability must remain in place after the external program ends?

These questions are not arguments against free resources. They are how a utility extracts lasting value from them.

The bottom line

Water cybersecurity is entering an unusual window. Government agencies, technology companies, cybersecurity providers and funding programs are simultaneously pushing more capability toward the organizations protecting essential services. Utilities should evaluate that opportunity deliberately.

But the strongest utilities will not measure success by how many assessments they received, how many findings an AI model generated or how many tools were installed. They will measure success by whether the highest-consequence risks were understood, decisions were made by the right people, work was completed without disrupting essential services, results were verified, and evidence remained after the outside support was gone.

That is the difference between receiving cyber assistance and becoming more resilient.

About the Author

Ieshea Hollins, Founder, CEO and CISO of Direnzic Technology Consulting Group, a critical-infrastructure cybersecurity and AI-governance firm founded in 2008. Her work focuses on helping water utilities, municipalities and other essential-service organizations move from documented compliance to defensible operational readiness.

WaterReady™

WaterReady starts where the assessment stops

WaterReady helps water and wastewater leadership connect operations, IT, OT/SCADA, providers, plans, findings and evidence into one managed cyber-operational readiness system. For utilities preparing for the 2026 ERP certification cycle or evaluating new cyber-assistance programs, this is where the work begins.

  • Finding to decision: who authorizes what, and on what evidence
  • Owner and remediation: safe execution inside existing operations
  • Validation and executive evidence: proof that the fix held
Request a WaterReady Readiness Briefing Explore WaterReady
Related Analysis Previous Analysis

The Minnesota Water-System Cyberattacks: A Lesson in Readiness, Not Fear

July 31, 2026 · Water Security

What the Minnesota incidents reveal about visibility, resilience and response.

Sources and official resources

  1. Texas Cyber Command, “Texas to Lead Project Watershed 250 Cybersecurity Pilot to Defend the Water Systems Millions Depend On,” Sept. 1, 2026. txcc.texas.gov/news/project-watershed-250
  2. Office of the Texas Governor, “Governor Abbott, National Cyber Director Launch Project Watershed 250 To Defend Texas Water Supply,” Aug. 31, 2026. gov.texas.gov/news/post/governor-abbott-national-cyber-director-launch-project-watershed-250-to-defend-texas-water-supply
  3. OpenAI, “Daybreak for Frontline Defenders: $1B to protect essential services,” Sept. 3, 2026. openai.com/index/daybreak-for-frontline-defenders/
  4. OpenAI, “Daybreak Defense Network,” accessed Sept. 9, 2026. openai.com/daybreak/partners/
  5. U.S. Environmental Protection Agency, “EPA Announces $11.75 Million to Help Protect Drinking Water from Cyberattacks and Extreme Weather Events,” Aug. 31, 2026. epa.gov/newsreleases/epa-announces-1175-million-help-protect-drinking-water-cyberattacks-and-extreme
  6. U.S. Environmental Protection Agency, “AWIA Section 2013/SDWA Section 1433: Risk and Resilience Assessments and Emergency Response Plans,” certification deadlines for the second five-year cycle. epa.gov/waterresilience/awia-section-2013
>