The White House launched a six month, no cost red-teaming pilot across Texas water systems on August 31, with EPA, CISA and Texas Cyber Command. It is a genuinely good program. It also ends, covers one state, and leaves behind findings rather than the ability to see the next intrusion.

Water is the soft target everyone in this industry has been pointing at for a decade, and it stays soft for an unglamorous reason: the utilities most exposed are the ones least able to pay for defence. A system serving a few thousand connections has operators who know the plant intimately, equipment spanning three decades, and no security staff at all.
Project Watershed 250 is a serious attempt at part of that problem. It is worth understanding precisely what part.
On Monday, August 31, the administration launched Project Watershed 250, a six month pilot that puts red teams inside Texas water utilities to find weaknesses before an adversary does. National Cyber Director Sean Cairncross framed it as part of a broader push to secure critical infrastructure against determined adversaries.
The structure is worth reading carefully, because the details are what matter to anyone who runs a water system:
Officials were explicit that the program is not a reaction to a specific breach, while acknowledging that attacks against more than thirty Minnesota water systems reinforced the urgency. The shape of the problem was stated plainly in the briefing: the threats are active and documented, and they fall hardest on small utilities that have no robust defences to begin with.
We read this announcement the way you read a competitor validating your roadmap, which is to say with some satisfaction and no surprise.
RedEye has been doing this work with municipal water and utility districts in Tennessee: finding what is exposed, mapping what actually talks to what, and getting continuous monitoring onto plants that were never going to buy an enterprise SIEM. The federal government has now said out loud, with EPA and CISA behind it, what water operators have been told by their budgets to ignore for a decade. Small systems are targets, the threats are documented, and the utilities least able to fund a defence are the ones carrying the most risk.
So this is not a program we are watching from the outside and picking at. It is the same play, run at federal scale in one state, and it is good that it exists. If you run a Texas water system and can get into the pilot, get into it.
What follows is the part the pilot is not scoped to solve, which is where we spend our time.
A red team tells you what was wrong on the days they looked. That is valuable and it is finite. When they leave, the utility holds a report and a list of fixes. What it does not hold is the ability to notice that something is wrong next Tuesday.
That gap is not a criticism of the pilot. It is the difference between assessment and monitoring, and they are separate disciplines with separate budgets. The trouble is that the second one is where the money runs out, and it is the one that has to be paid for every year rather than once.
Three specifics make it sharper for water:
We sell into municipal water and utility districts, so this is not theoretical. The pattern is consistent.
The operators are competent and stretched. The OT network is a mix of equipment from three decades, some of which cannot be patched and none of which can be taken offline for a maintenance window that suits a vendor. There is usually no SOC. There is frequently no full time IT person, let alone a security one.
And when these utilities do look at monitoring, they discover the economics were designed for someone else. Traditional platforms price on ingest, so the more of the plant you watch, the more you pay, and the rational response is to collect less. That is precisely backwards for OT, where the signal that matters is a small anomaly inside a large volume of ordinary process traffic. A utility that samples its historian to control cost has bought a monitoring system that is blind in the exact place it needed to see.
That is the constraint we built against. Storage economics are not a marketing line for this buyer, they are what decides whether the plant is monitored at all.
Caver is our security data platform, and the OT work in it exists because of conversations with utilities like these rather than a market study.
It runs on storage the utility already owns, keeps full fidelity rather than sampled data, and is queryable in the language the operator already knows. There are two ways to adopt it: migrate fully, or run it in parallel with what you have until you trust it.
A pilot proves a thesis. It does not staff a plant.
When the six months are up, the utility is holding a report and a list of remediations, and it is back to whatever it had before, which for most small systems is nothing watching the OT network at all. The same is true today for every water system outside Texas, which is nearly all of them.
That is the question worth asking now rather than in March: when the assessment is finished and the team has moved on, what is left running that would notice an intruder in your SCADA network on an ordinary Tuesday? If the answer is nothing, that gap is not closed by another assessment. It is a monitoring problem with a budget problem attached, and it is the one we built for.
Three things worth doing this month, regardless of who you buy anything from:
We are in Tennessee and we work with utility districts on exactly this. If you want a second opinion on what your plant would and would not see, that conversation is free and does not come with a pipeline.