Former ONCD official pitches water-sector cyber workforce pilot
The "Watershed 250" program starts in Texas for a reason (ONCD can't afford for it to fail) which means lower-resourced states wait while the model proves itself.
TL;DR
Phil Stupak, former ONCD assistant national cyber director and now advocacy lead at ISC2, outlined a workforce rotation model for the water sector: embed early-career cyber professionals at quasi-governmental water entities for one- to two-year stints, then cycle in new cohorts. The ONCD-led "Watershed 250" pilot launched August 31 with an initial focus on Texas utilities, partnering with CISA, EPA, the FBI, and Texas Cyber Command. Stupak acknowledged Texas was chosen deliberately ("you want to do the initial pilots in somewhere like Texas where you know it is going to succeed") and wants the program to expand to states with fewer resources once the model is proven.
The workforce model Stupak described is straightforward: bring in entry-level cyber talent, place them at water utilities that can't afford dedicated security staff, and accept that they'll leave after a year or two for higher-paying roles elsewhere. The continuity comes from the intake pipeline, each departing cohort is replaced by the next.
"They can work there for a year or two, and then they will go elsewhere and make more money. But they have gained experience by bringing in the next cohort," Stupak told Inside Cybersecurity. The question he says the sector faces: "How do you make sure that you have some level of cybersecurity professionals working within the sector?"
The pilot's Texas-first design is practical. Texas Cyber Command, created by a 2025 state law, provides an existing infrastructure backbone (a threat intelligence center, incident response unit, and digital forensics lab) that many other states lack. Stupak said ONCD "can't have [the pilot program] fail, so you want to do the initial pilots in somewhere like Texas where you know it is going to succeed." The result, he suggested, is that Texas becomes "a gold standard to measure other states against" when the program expands.
The resource gap the pilot is trying to close
Stupak's candor about the baseline is what gives the proposal its weight. "The biggest thing is that we don't have cybersecurity in the water sector at all," he said, adding that water-sector operators "absolutely do" appreciate the risk but "are very hamstrung by resources."
GAO has documented this same gap repeatedly. In May 2026 testimony, GAO noted that water systems face workforce shortages, manage older technologies difficult to update with modern protections, and must prioritize limited funds toward meeting Safe Drinking Water Act requirements (where compliance is mandatory) over cybersecurity investments that remain largely voluntary [2]. A 2024 GAO report found that EPA had not conducted a comprehensive sector-wide risk assessment and recommended it develop a national cybersecurity strategy [5].
What the pilot doesn't yet address
Stupak also flagged a broader problem: the absence of regulatory baseline for critical infrastructure cybersecurity. "What we have seen with pre-positioning in critical infrastructure, some countries are taking on new legislation to handle that. We are not," he said. He predicted that whether "adequate regulatory controls" emerge will be "the real story over the next two to three years."
That warning lands against the backdrop of July's coordinated attacks on programmable logic controllers at water utilities, which prompted joint advisories from CISA, EPA, and the FBI. The attacks were linked to Iran-affiliated actors by threat intelligence firm Tenable but remain unattributed by the U.S. government. The workforce pilot is a capacity play; the regulatory question (whether voluntary cybersecurity expectations are sufficient for the sector) remains open.
Published ·Deep Fathom