> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Dragos CEO Robert M. Lee Has Warned About Water Cybersecurity for Years. Now Comes Project Watershed 250
- URL: https://www.cybrsecmedia.com/dragos-ceo-robert-m-lee-has-warned-about-water-cybersecurity-for-years-now-comes-project-watershed-250/
- Published: 2026-08-31T14:36:59.000Z
- Updated: 2026-08-31T14:39:06.000Z
- Description: Dragos CEO Robert M. Lee has repeatedly warned that under-resourced water utilities cannot defend themselves against growing cyber threats alone. A new federal-state-industry initiative in Texas aims to start closing that gap.
- Author: Bill Brenner
- Tags: Critical Infrastructure Security, OT Security, Article

Robert M. Lee has been sounding the alarm about the cybersecurity of America's water systems for years. His message has been consistent: The threat is real, the consequences can reach far beyond computers and networks, and many of the utilities expected to defend themselves simply don't have the resources to do it.

Now Lee and Dragos are getting a chance to help put that message into practice.

The Trump administration on Monday launched [Project Watershed 250](https://www.foxnews.com/politics/first-fox-texas-becomes-testing-ground-new-defense-against-attacks-americas-water-systems?ref=cybrsecmedia.com), a six-month pilot program in Texas that brings together federal agencies, Texas Cyber Command and private-sector cybersecurity companies to strengthen the defenses of water utilities. Dragos is among the companies participating in the effort.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

The program comes amid mounting concern over cyberattacks against U.S. water systems, including recent attacks affecting more than 30 water systems in Minnesota. But for Lee, the underlying problem predates the latest incidents.

And in recent weeks, he has been [making the case with increasing urgency](https://lnkd.in/p/gkeDXszY?ref=cybrsecmedia.com):

![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/2026/08/Screenshot-2026-08-31-at-10.21.50---AM.png)

## Stop blaming the water utilities

Lee recently took to LinkedIn to push back against one of the recurring responses whenever another water utility is compromised: Why didn't they just practice better cyber hygiene? Why was that PLC connected to the internet? Why didn't they secure the system properly?

Those questions, Lee argued, miss the point.

Roughly 97% of utilities, he wrote, lack the resources necessary to adequately address the problem. Even utilities that understand the cyber risks can face budgets controlled by public utility commissions, municipalities and other entities. Some don't have dedicated cybersecurity staff. Some don't even have a dedicated IT person.

Dragos has seen the problem firsthand through its Community Defense Program, which provides qualifying small water, electric and natural gas utilities with free access to its OT security software, training and other resources. Even when the software is free, Lee noted, some utilities lack the staff or hardware needed to deploy it.

"This is an economics issue not a lack of caring," Lee wrote.

His larger point was even harder to ignore: These utilities are victims. Telling them to simply do better without providing the money, personnel and expertise to do it amounts to little more than the cyber equivalent of "thoughts and prayers."

That distinction matters because the cybersecurity problem facing water utilities is fundamentally different from the security challenge at a Fortune 500 company.

A small municipal water authority isn't choosing between competing multimillion-dollar security platforms or deciding how many analysts to add to a mature SOC. It may be trying to keep aging operational technology running while dealing with staffing shortages, maintenance costs, regulatory requirements and a budget ultimately paid for by local residents.

Meanwhile, the adversaries targeting those environments can include ransomware operators and nation-state actors.

That's not an even fight.

**Related:**

[Cyberwar’s New Red Line: Why Attacks on Civilians Must Be StoppedDragos CEO and National Guard Lt. Col. Rob Lee warns that cyber operations targeting civilian infrastructure, from hospitals to water systems, are crossing a dangerous line the cybersecurity community must confront directly.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-b6016679-8ed6-4f2f-a536-fac18297fde5.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/da7b9bd6-98c3-4b2b-8fe5-fa70472414ad-ad175f9e-0940-405c-aeb1-6da0a242e36f.png)](https://www.cybrsecmedia.com/cyberwars-new-red-line-why-attacks-on-civilians-must-be-stopped/)

[Cyber Fortress: The War Game Preparing the U.S. for Cyberattacks on Critical InfrastructureDragos CEO and Army National Guard Lt. Col. Rob Lee explains how Cyber Fortress brings together military units, infrastructure operators, and international partners to train for real-world cyberattacks against operational technology systems.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-6505501c-b029-40b4-ba59-a051089f8741.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/Screenshot-2026-03-17-at-10.39.22---AM-37e4a77f-c994-4d7a-936c-6eab1755170a.png)](https://www.cybrsecmedia.com/cyber-fortress-the-war-game-preparing-the-u-s-for-cyberattacks-on-critical-infrastructure/)

[CYBR.SEC.CAST Episode 64: Rob LeeDragos CEO and U.S. National Guard Lt. Col. Rob Lee on why he returned to military service and the role exercises like Cyber Fortress play in preparing both government and private sector operators for real-world cyber incidents, including those tied to the Iran War.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-24691a15-d1f8-4e05-92bc-9fdabff9dfda.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/Rob-Lee-32280ffe-7fc6-49b1-b156-48587b05a34b.png)](https://www.cybrsecmedia.com/cybr-sec-cast-episode-64-rob-lee/)

## Project Watershed 250 puts resources behind the warnings

Project Watershed 250 is designed to test a different approach.

The six-month Texas pilot will connect water utilities with federal, state and private-sector cybersecurity resources. According to the White House, participating organizations will use red-team exercises to stress-test utility networks, identify weaknesses attackers could exploit and then strengthen those systems with cybersecurity and AI technologies.

The Environmental Protection Agency and CISA will participate at the federal level, while Texas Cyber Command will work with local governments and private-sector companies including Dragos, Microsoft, Reflection AI and Palo Alto Networks.

The administration ultimately wants to determine whether the model can be scaled beyond Texas.

Lee told Fox News that U.S. water infrastructure faces active, documented cyber threats, with smaller utilities particularly exposed because they often lack mature cybersecurity defenses. Watershed 250, he said, provides an opportunity to get technology, training and support into those environments before an attacker gets there first.

For Lee, that makes the initiative a logical extension of the argument he has been making for years.

Water cybersecurity doesn't improve simply because another advisory tells operators to patch systems, remove internet exposure or follow security best practices. Those things matter, but somebody still needs the time, expertise, technology and money to make them happen.

Project Watershed 250 attempts to bring those pieces together.

## The water cybersecurity problem has been building for years

None of this appeared overnight.

Dragos launched its Community Defense Program as a pilot in 2022 and later expanded it to provide qualifying smaller utilities with ongoing free access to the Dragos Platform, Neighborhood Keeper collective defense capability, OT-CERT resources and training.

The reason was straightforward: Small utilities are responsible for critical services while increasingly confronting the same national-security, ransomware, supply-chain and vulnerability-management challenges faced by much larger organizations.

They just don't have the same resources.

Lee has also carried that argument to Congress. In 2024, he testified about the need to strengthen operational technology cybersecurity in U.S. water systems, warning that escalating cyber threats were colliding with limited resources across the sector.

Recent attacks have made the problem harder to dismiss.

A White House official told Fox News that Watershed 250 was already under development and was not created in response to the recent attacks against Minnesota water systems. But those incidents, the official acknowledged, reinforced the need for greater modernization and attention to water security.

That's an important distinction.

Water utilities aren't suddenly vulnerable because attackers recently discovered them. The vulnerabilities, staffing problems and resource constraints have been visible for years. What's changing is the willingness of adversaries to exploit them—and the potential consequences when they do.

## From warning to action

That is what makes Lee's involvement in Project Watershed 250 worth watching.

Cybersecurity has no shortage of warnings about critical infrastructure. Every major incident produces another round of calls for better visibility, stronger segmentation, faster patching and improved threat detection.

Lee's argument has increasingly focused on what comes next.

If a utility doesn't have a security team, give it access to expertise. If it can't afford the technology, find a way to provide it. If local economics make cybersecurity investments difficult, recognize that protecting water infrastructure is a broader national-security problem rather than simply telling individual utilities to solve it themselves.

Project Watershed 250 won't solve the cybersecurity problems facing America's water infrastructure in six months.

But it does test something the industry badly needs: whether federal agencies, state governments, cybersecurity companies and local utilities can work from the same playbook and get actual resources into the hands of the people operating the systems.

Lee has spent years warning about what happens if we don't.

Now he and Dragos are participating in an effort to show what doing something about it might look like.

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)