America’s water infrastructure is becoming a new front line in the cybersecurity battle, and federal officials are turning to technology companies for help. Tenable has joined Project Watershed, a White House-led initiative designed to help U.S. water and wastewater utilities identify and address cyber vulnerabilities before attacks disrupt essential services.
The partnership comes after a series of cyber incidents targeting water systems across the country, highlighting how software vulnerabilities can quickly become operational threats for communities that depend on uninterrupted water and wastewater services.
Tenable Brings Exposure Management to Water Utilities
Under Project Watershed, Tenable will contribute its exposure-management expertise to help participating utilities improve visibility across both information technology and operational technology environments.
That distinction is increasingly important. Modern water facilities rely on connected systems to monitor pumps, control equipment, manage water quality and oversee treatment operations. As those systems become more digitally connected, the number of potential entry points for attackers also increases.
Tenable says its role will focus on helping operators identify cyber exposures, prioritize the most significant risks and automate remediation where possible. The company is also emphasizing the challenge posed by increasingly sophisticated threats in the era of agentic artificial intelligence.
Project Watershed is being piloted in Texas and brings together federal and state officials with private-sector cybersecurity partners. The broader objective is to provide water utilities with practical cybersecurity capabilities and expertise, particularly where local operators may not have large security teams or extensive technology budgets.
The Timing Reflects a Growing Threat
The initiative arrives as attacks against U.S. water infrastructure have become a growing national security concern.
Recent incidents have affected water and wastewater systems in multiple states. Tenable’s own research team has tracked a coordinated cyberattack that disrupted operations across more than 30 Minnesota communities, while activity targeting internet-exposed programmable logic controllers has been observed across the water, energy and government sectors.
Programmable logic controllers, or PLCs, are particularly important because they control physical processes. An attacker who gains access to such systems may be able to interfere with equipment, alter settings or disrupt operations.
That makes water cybersecurity fundamentally different from protecting an ordinary corporate network. A compromised email account may create financial or data risks, but an attack against an industrial control system can affect the physical operation of a public utility.
Software Is Becoming Part of the Infrastructure Defense
The growing reliance on software is changing how water utilities approach cybersecurity.
Federal cybersecurity guidance has increasingly emphasized the need to protect both traditional IT networks and operational technology. The National Institute of Standards and Technology has noted that digital transformation is making water systems more dependent on connected technologies while simultaneously creating additional opportunities for malicious actors.
For smaller utilities, however, implementing advanced security programs can be difficult. Many operate with limited budgets, aging infrastructure and relatively small technical teams.
That is one reason initiatives such as Project Watershed could become important. Instead of expecting every utility to independently build a sophisticated cyber-defense operation, the program seeks to connect operators with government resources, private-sector expertise and security technologies.
AI Adds Another Layer of Urgency
The emergence of artificial intelligence is adding another dimension to the threat.
Security researchers have warned that AI can reduce the technical expertise and time required to discover and exploit vulnerabilities. At the same time, defenders can use AI to identify weaknesses, analyze large volumes of security data and accelerate remediation.
That creates an escalating technology race in which software itself becomes both a potential weapon and a defensive tool.
For water utilities, the priority is therefore shifting from simply responding to cyber incidents toward continuously identifying weaknesses before attackers exploit them.
A Broader Critical-Infrastructure Test
Tenable’s participation in Project Watershed signals how cybersecurity companies are becoming increasingly integrated into national critical-infrastructure protection.
The water sector is only one part of a much larger challenge involving energy, transportation, healthcare and communications systems. As physical infrastructure becomes more dependent on connected software, cybersecurity is increasingly becoming an operational requirement rather than a separate IT concern.
For U.S. water utilities, the stakes are particularly high. A successful cyberattack does not have to shut down an entire city to create serious consequences. Disruptions to treatment, pumping or monitoring systems can affect public confidence and force operators into manual processes.
Project Watershed’s Texas pilot will therefore serve as an important test of whether government and private-sector technology providers can help utilities move from reactive cybersecurity toward continuous exposure management.
As digital systems become embedded deeper into America’s water infrastructure, protecting the software controlling those systems could become just as important as protecting the pipes, pumps and treatment facilities themselves.
Source Angle: Tenable’s August 31, 2026 announcement of its participation in White House-led Project Watershed, supported by recent cybersecurity incidents and federal water-sector security guidance.
