
The Water Still Moves Through Pipes. The Threat Can Come Through a Wire.
Seven years after SJRA showed Dock Line readers the computer network behind local water, real attacks on utilities explain why Texas launched Project Watershed 250 — a new statewide cybersecurity effort aimed at the systems that keep water moving.
Seven years after SJRA showed Dock Line readers the computer network behind local water, real attacks on utilities explain why Texas has launched a new cybersecurity effort.
In December 2019, the San Jacinto River Authority showed Dock Line readers something most of us never think about when we turn on a faucet: the water system behind the water system. SJRA called it SCADA — Supervisory Control and Data Acquisition. It was the network of servers, operator workstations, programmable controllers, field instruments and communications equipment helping people monitor and operate facilities spread across a large area.
At the time, SJRA said its SCADA systems contained more than 1,200 network devices. A staff of three highly trained employees specialized in networking, programming, communications and cybersecurity.
Those are 2019 figures, not a current inventory or staffing count. But they reveal something important. Even seven years ago, a modern local water system was already much more than reservoirs, treatment plants, pipes and pumps. It was also a sizeable computer network.
In 2019, that was mainly a story about how the system worked. In 2026, it is a story about how to keep it working.
The Water System Behind the Water

The technology SJRA described could perform jobs that once required someone to be physically present at every facility. A programmable controller could recognize that a tank level was low and start a pump. Operators could monitor pumps, valves, blowers and other equipment from a central location. If an automatic process did not respond correctly, an operator could see what was happening and intervene.
None of that means SJRA's equipment was exposed to the public internet or insecure. A device can be part of a protected internal network without being reachable from outside it. No public source reviewed for this article identifies SJRA as a victim of the recent attacks or as a participant in the new Texas program.
SJRA's 2019 explanation matters for a different reason. It gives Montgomery County readers a look at the scale and complexity hiding behind an ordinary utility service. The computer at the water plant is not necessarily one computer sitting on one desk. It can be a web of controllers, sensors, communications links and workstations spread across miles of physical infrastructure.
Every connection that helps an operator see farther and respond faster is also something the utility must understand, maintain and protect.
Somebody Has Already Reached the Controls

The danger is not hypothetical. On July 30, the FBI and Environmental Protection Agency warned that water and wastewater utilities in at least seven states had reported cyber incidents beginning July 27. Some of those incidents degraded water operations.
The attackers targeted specific programmable logic controllers — small industrial computers used to monitor and control physical equipment. According to the federal alert, attackers changed controller internet addresses and passwords, causing utilities to lose monitoring and control. The physical consequences included loss of water pressure and flooding. The systems' ability to switch to manual operation helped determine how serious the disruption became.
That detail pulls the story out of the digital world and puts it back in the pump house. This was not simply stolen information or a frozen office computer. A change made through a network connection affected equipment that moved water.
The July incidents followed an April warning from the EPA, FBI, Cybersecurity and Infrastructure Security Agency and National Security Agency about an urgent and ongoing threat from Iranian-affiliated cyber actors. Federal officials said organizations, including water and wastewater systems, had experienced disruption involving commonly used operational technology.
The lesson is not that every computerized water system is about to fail. It is that the line between a cyber incident and a physical problem has become very short.
Why Texas Is Going First
On August 31, Governor Greg Abbott and White House National Cyber Director Sean Cairncross launched Project Watershed 250 in San Antonio. The project is designed to connect Texas water utilities with federal, state and private-sector cybersecurity resources at no cost. Texas Cyber Command is involved, and state officials emphasized the needs of rural providers that may not have the money or specialized staff to build sophisticated cyber defenses on their own.
That focus makes sense because the country's water infrastructure is unusually spread out. There is no single company operating every water plant and wastewater facility. Large utilities, river authorities, municipal systems, rural providers and small districts all carry pieces of the same essential responsibility.
A large organization may have dedicated technology employees, security specialists and outside consultants. A small provider may have a handful of people responsible for treatment, testing, maintenance, emergency calls, billing and everything else required to keep the water moving. The smaller system does not get a smaller consequence if its controls stop working.
Project Watershed 250 is an attempt to close part of that gap by bringing outside expertise and defensive tools to the people already running the systems. The public announcement does not promise that cyberattacks will disappear. It describes a more practical goal: find weaknesses, improve protection and give under-resourced utilities help they could not easily assemble alone.
The Old Backup Is Still a Good One

Modern technology gives utility operators remarkable reach. Sensors can report tank levels. Controllers can start and stop equipment. Alarms can warn that a process has moved outside its normal range. A person in one control room can understand what is happening at facilities miles apart.
But the recent attacks reinforced something reassuringly old-fashioned. People still need to know how to run the system when the computer cannot.
The FBI and EPA urged utilities to disconnect vulnerable controllers from the public internet, use strong unique passwords, restrict access and practice manual operation. Federal agencies also recommend identifying every piece of operational technology, maintaining backups and planning for the moment when normal digital controls are unavailable.
Some of those steps require technical expertise. Others require time, discipline and repetition. Know what is connected. Know who can reach it. Know how to restore it. Know what to do by hand. The same system that can automate a pump should still have people prepared for the day automation is not available.
What the Local Picture Tells Us
SJRA's old Dock Line article did not describe a vulnerability report. It described the people and technology that kept a complex system operating. That distinction matters. The number of devices tells us about scale, not insecurity. The three-person staff figure tells us how specialized the work already was in 2019, not how SJRA is staffed today. And the article's examples — checking a tank level, starting a pump, operating valves and responding when equipment did not stop as expected — show why utilities adopted these systems in the first place. They help people do the job better.
Cybersecurity is not an argument for going back to a time before sensors and remote monitoring. It is the work required to keep those benefits without allowing an outsider to turn convenience into control.
That is the local value of looking back at SJRA's explanation now. Most of us will never walk through a water plant control room. We will not see the screens, cables, controllers or radio links. We will not hear an alarm or watch an operator respond to a failing pump. We see the result. We turn the handle, and water comes out.
The Fence Now Extends Beyond the Gate
Protecting a water facility once brought a fairly physical picture to mind. A locked gate. A fence around the property. A secured door. Someone watching the treatment process and maintaining the equipment. All of those things still matter.
But the fence around a modern water system now has to extend beyond the property line. It has to include passwords, remote connections, software, backups, controllers and every authorized path into the network.
That is the world Project Watershed 250 enters. Texas is not testing whether computers belong in water systems. They are already there, doing essential work every day. The state is testing how government and private industry can help more utilities defend the technology they already depend upon.
Seven years ago, SJRA gave Dock Line readers a useful tour of that unseen system. Today, the tour reads differently. The water still travels through pipes. The people still run the plants. But the fence around a modern water system now has to reach farther than the property line. Because the threat can arrive through a wire.
Sources and Further Reading
San Jacinto River Authority — What in the World Is SCADA? (December 13, 2019)
Office of the Texas Governor — Project Watershed 250 Launch (August 31, 2026)
FBI and EPA — Cyber Actors Target U.S. Water and Wastewater Systems (July 30, 2026)
EPA — Joint Advisory on Iranian-Affiliated Threats to Water Systems (April 7, 2026)
More Politics & Government Stories
YesterdayThe Woodlands Approves Tax Rate; Residents Voice Concerns over Mounted Patrol Decisions; "The Woodlands Independence Day" | Recap of The Woodlands Township Board Meeting, September 2026
This WeekMontgomery County Commissioners Decide How Far Their Authority Reaches Into Other Elected Officials’ Offices | September 2026 Meeting Recap
Last Week