top of page
Logo with SHSU.JPG

Strengthening Texas Water Infrastructure Through Shared Cybersecurity Models

  • IHS Sam Houston State Uni
  • 1 day ago
  • 9 min read

Updated: 3 hours ago

By: Julia Chialastri

July 2026

Executive Summary


Water and wastewater (W/WW) districts provide non-negotiable lifeline services to Texas communities. These systems serve as the bedrock of communities, supporting public health, sanitation, emergency response, food production, schools, and local businesses. Every facet of community function relies on uninterrupted access to clean water and reliable sanitation, therefore, maintaining the operational continuity of these districts is a matter of vital public safety and economic stability.


In this environment, cybersecurity shifts from a backend IT issue to a fundamental continuity of operations problem. However, the cyber threat has evolved faster than local budgets can keep pace. Many districts confront an immense capacity gap, not from a lack of will, but from an ever-expanding list of institutional demands. Local administrative bandwidth is stretched to its limits by new requirements for 24/7 monitoring, formal incident response planning, and competitive cybersecurity salaries, all while trying to keep pace with shifting federal guidance. A state-supported, regional cybersecurity model closes this vulnerability gap by optimizing resource allocation, leveraging existing Texas Regional Security Operations Center (RSOC) frameworks, and delivering practical support while strictly preserving local control and autonomy. Crucially, the success of this model hinges on leveraging trusted industry advocates, including the Texas Rural Water Association (TRWA) and other major water associations, to act as vital trust bridges between utilities and RSOCS.


The Limits of Local Defense: Capacity vs. Reality


Identifying a risk does not translate into having the staff, tools, funding, and time to manage it independently. Texas water and wastewater districts recognize the importance of cybersecurity but are caught in a structural and resource squeeze. The core issue is not local willingness to protect, but modern cybersecurity expectations that have functionally outgrown what districts can reasonably sustain alone.


Relying on a “team of one”  for cyber security is equally impractical. Academic framework mapping cyber workforce profiles has emphasis that comprehensive defense requires a diverse mixture of certifications, technical skills, and continuous education that a single IT employee cannot realistically encompass. [1] Modern defensive operations require highly distinct, siloed expertise, including skill like threat hunting, cryptographic compliance, and Operational Technology (OT) system engineering. Expecting a single generalist to master these disparate domains creates what the Information Systems Security Association (ISSA) and Omdia term an unsustainable operational burden. [2]  Their June 2026 global study found that expanding attack surfaces combined with understaffed 'teams of one' have triggered an industry-wide burnout crisis, forcing practitioners into a perpetual state of emergency response. This operational friction is further compounded by what academic literature defines as 'cybersecurity fatigue', a state of mental and cognitive exhaustion proven to cause depersonalization and a mathematically higher likelihood of missing critical technical oversights.  [3]


However, scaling up to a dedicated internal defense team is equally out of reach, as market realities make full cyber security teams’ cost-prohibitive for individual utilities. In Texas, the average salary for an entry-level cybersecurity analyst sits at $44.52 per hour (approximately $92,606 annually).[4] For small-to-mid-sized districts, dedicating capital to hiring and maintaining a full cybersecurity team is structurally unfeasible. This dynamic aligns with findings from the Cybersecurity and Infrastructure Security Agency (CISA) regarding “Target Rich, Cyber Poor” in schools and local governments, which demonstrate that individual procurement of enterprise security tooling introduces redundant licensing costs and tool sprawl. [5] According to Deloitte's framework on 'Whole-of-State' cybersecurity, isolated defense strategies force resource-constrained local entities to operate at an economic disadvantage. [6] [7]Conversely, centralized, multi-tenant architecture allows the state to absorb the heavy baseline capital expenditures, distributing enterprise-level defense mechanisms to local nodes.


From Isolated Targets to Collective Defense: The RSOC Shared Service Model


Rather than expecting resource-constrained utilities to develop autonomous local cybersecurity capabilities, resilience in critical infrastructure relies on a pooled capability model. As advocated by the National Association of State Chief Information Officers (NASCIO), this shared service framework acts as a mechanism for 'fractional expertise.' [8] Participating water districts do not need to struggle to recruit rare, expensive specialists in threat forensics or industrial control systems; instead, they tap into a centralized pool of highly diverse talent housed within the regional hub. This provides immediate access to specialized tiers of defense during an incident, effectively neutralizing the local talent shortage while maximizing taxpayer and utility dollar efficiency.[9]


Texas has already pioneered this exact framework through its Regional Security Operations Center (RSOC) program. [10] Administered by the Texas Cyber Command (TXCC), following the transfer of statewide cybersecurity authority and RSOC administration from the Texas Department of Information Resources (DIR) pursuant to House Bill 150 (89th Legislature), in partnership with regional public universities, this 'Whole-of-State' model provides free network security monitoring and localized incident response to eligible public entities.[11] [12]Crucially, it simultaneously acts as a workforce incubator, training student analysts to augment active operations, thereby easing regional protection and talent shortage dilemmas. When critical infrastructure nodes operate as an interconnected community rather than isolated targets, they can share threat intelligence dynamically and coordinate rapid mutual aid during active network disruptions.[13]


Standard IT hygiene is vital, but the water sector operates in a unique cyber-physical environment where a digital breach can become a public health crisis. To move past generic compliance checklists, practical support must meet utilities exactly where they are. By positioning the RSOC as the central pillar of W/WW cybersecurity policy, the state can offer a "safe," non-punitive framing. Instead of imposing heavy-handed regulatory penalties that under-resourced districts cannot meet, this model introduces a state-supported partner dedicated to building local capability. The operational logic of the RSOC maps directly onto practical W/WW utility needs through six core functional pillars:


  • Monitoring Anomalous Web and Network Traffic: RSOCs provide 24/7 network detection and response (NDR) along with critical endpoint visibility. This specialized monitoring is vital for spotting early IT threat indicators before they can lateral into sensitive operational technology (OT) networks controlling pumps and valves. [14]


  • Providing Alerts and Escalation Guidance: When a threat is detected, the RSOC does not just issue a passive warning. It provides verified, actionable alerts paired with clear execution playbooks, ensuring utility operators know exactly how to isolate systems during the critical first minutes of an incident.[15]


  • Supporting Incident Preparedness: Moving utilities from a reactive posture to a proactive defense requires active cultivation. RSOCs assist local districts with incident response planning and host targeted tabletop exercises that simulate real-world utility threats[16]


  • Offering Staff Training: Because human error remains a primary vector for cybercriminals, RSOCs deliver cybersecurity educational services. These programs up skill local personnel on threat identification, phishing defense, and cyber-physical best practices without straining local training budgets. [17]


  • Helping Partners Make Sense of Cyber Guidance: Navigating state and federal compliance mandates can tax administrative departments. The RSOC can act as a local translator, helping operators turn cyber compliance frameworks and regulatory guidelines into actionable steps.[18]


  • Connecting Local Entities to State-Level Cyber Resources: Small utilities cannot survive on an island. The RSOC serves as a critical local pipeline, instantly linking individual water districts to broader state-level threat intelligence, Texas Cyber Command (TXCC) and DIR frameworks, and a shared security infrastructure that would otherwise be cost-prohibitive.[19] [20]


Policy Recommendations


To structurally secure Texas water and wastewater infrastructure without imposing unfeasible financial mandates on local communities, the state should adopt a phased, voluntary, and resource-backed approach. The following recommendations provide a practical roadmap for expanding the Texas RSOC model to the W/WW sector:


  • Conduct a Confidential W/WW Cyber Needs Assessment: Commission a statewide assessment to baseline the current IT/OT security posture of Texas utilities. To ensure participation, this must be legally structured as confidential and exempt from public disclosure laws, removing the fear of exploitation or regulatory penalties.[21]


  • Create a Voluntary Engagement Pathway and Trust-Bridge: Establish a clear, tiered opt-in framework allowing utilities to onboard into the state-supported network at their own pace. Transitioning away from top-down mandates incentivizes proactive partnership and facilitates local trust. To incentivize participation, Texas Cyber Command (TXCC) leadership and RSOC leadership should consider coordination with major water associations (e.g., TRWA). Utilizing these associations as trusted intermediaries ensures the onboarding pathway is communicated peer-to-peer, moving the needle from cautious skepticism to proactive partnership while preserving local trust.


  • Develop W/WW-Specific Training and Exercises: Design specialized IT/OT curricula focusing on industrial control systems (SCADA/PLCs). Fund and host regional tabletop exercises simulating realistic utility emergencies, such as unauthorized chemical feed adjustments or remote valve shutdowns.


  • Build Trusted, Localized Communication Channels: Form continuous information-sharing pipelines connecting local operators with regional cyber resources. By embedding information pipelines within the regular communication infrastructure of major water associations, the state can seamlessly push sanitized, actionable defense playbooks through channels that operators already read and trust. When a threat arises, regional hubs can immediately push sanitized, actionable defense playbooks to all neighboring districts, shifting the sector toward collective resilience.


  • Expand Regional Monitoring Capacity: Scale the technical infrastructure of designated regional centers to handle continuous threat detection for participating water systems. Centralizing advanced network monitoring tools provides small utilities with 24/7 enterprise-grade protection without on-site overhead.


  • Identify Sustainable Funding Mechanisms: Identify Sustainable Funding Mechanisms: Secure long-term financial viability by leveraging federal grant opportunities like the FEMA State and Local Cybersecurity Grant Program (SLCGP). At the state level, the legislature should explore dedicated funding through the Texas Water Development Board (TWDB) or direct appropriations to Texas Cyber Command (TXCC) to scale the RSOC operational footprint.[22] [23]


Conclusion


Securing Texas water and wastewater infrastructure is a fundamentally structural one that requires shifting the burden of defense away from isolated, under-resourced utilities and into a model of pooled capability. Expecting a small municipality to independently defend public health assets against sophisticated, global threat actors while absorbing the prohibitive costs of a dedicated cybersecurity team is economically and operationally unsustainable. When looked at through the lens of this reality, integrating the water sector into the existing Texas Regional Security Operations Center (RSOC) framework emerges as the most logical, natural conclusion to the crisis. By leveraging a battle-tested blueprint that already exists within state borders, Texas can centralize expensive threat-monitoring tools, mitigate local workforce shortages through regional university-led talent pipelines, and operationalize a collective defense network. This state-supported, regional approach allows solutions to remain locally responsive and trust-based without imposing punitive, unfunded mandates that strain local utility budgets, aligning Texas's public health realities with its defensive capabilities to ensure its most critical lifeline infrastructure remains secure.


Bibliography


Angelo State University. "ASU Selected to Pilot DIR Regional Security Operations Center." May 4, 2022. https://www.angelo.edu/live/news/18760-asu-selected-to-pilot-dir-regional-security.

Chance, J., et al. "Strengthening Cyber Resilience by Building Critical Infrastructure Communities: The C-CIC Pilot Study." The Cyber Defense Review 10, no. 2 (2025).

Code for America. "How Texas Is Building Cyber Resilience While Growing Talent." YouTube video, 15:32. Posted November 2025. Accessed July 8, 2026. https://www.youtube.com/watch?v=oE16wX4h-9U.

Cybersecurity and Infrastructure Security Agency (CISA). "Target Rich, Cyber Poor: Strengthening Our Nation's Critical Infrastructure Sectors." CISA News & Events. https://www.cisa.gov/news-events/news/target-rich-cyber-poor-strengthening-our-nations-critical-infrastructure-sectors.

Deloitte Insights. "Whole-of-state cybersecurity: Protecting the public information ecosystem." https://www.deloitte.com/us/en/insights/industry/government-public-sector-services/whole-of-state-cybersecurity.html.

[1] Lata Nautiyal and Awais Rashid, "A Framework for Mapping Organizational Workforce Knowledge Profile in Cyber Security," Computers & Security 145 (2024): 103925, https://doi.org/10.1016/j.cose.2024.103925.

[2] Information Systems Security Association (ISSA) and Omdia, "The Life and Times of Cybersecurity Professionals, Volume VIII," June 2026, https://issa.org/life-and-times-of-cybersecurity-professionals-volume-viii/.

[3] Filiz Mizrak et al., "Digital Detox: Exploring the Impact of Cybersecurity Fatigue on Employee Productivity and Mental Health," Discover Mental Health 5 (2025): 20, PMCID: PMC11861440, https://doi.org/10.1007/s44192-025-00149-x.

[4] "Entry Level Cyber Security Analyst Salary in Texas," ZipRecruiter, updated 2026, https://www.ziprecruiter.com/Salaries/Entry-Level-Cyber-Security-Analyst-Salary--in-Texas.

[5] Cybersecurity and Infrastructure Security Agency (CISA), "Target Rich, Cyber Poor: Strengthening Our Nation's Critical Infrastructure Sectors," CISA, https://www.cisa.gov/news-events/news/target-rich-cyber-poor-strengthening-our-nations-critical-infrastructure-sectors.

[6] Deloitte Insights, "Whole-of-state cybersecurity: Protecting the public information ecosystem," Deloitte, https://www.deloitte.com/us/en/insights/industry/government-public-sector-services/whole-of-state-cybersecurity.html.

[7] Angelo State University. 2022. "ASU Selected to Pilot DIR Regional Security Operations Center." April 14, 2022. https://www.angelo.edu/live/news/18760-asu-selected-to-pilot-dir-regional-security.

[8] Les Druitt et al., State CIO as Broker: A New Model, Issue brief (Lexington, KY: National Association of State Chief Information Officers, 2018), https://www.nascio.org/wp-content/uploads/2019/11/NASCIO_StateCIOasBrokerModel.pdf.

[9] N. Graham, "Rural Water Cybersecurity: Shared Defense for Critical Infrastructure," Raventek, 2026, https://www.raventek.com/rural-water-cybersecurity-shared-defense/.

[10] Deloitte Insights, "Whole-of-state cybersecurity."

[11] Code for America, "How Texas Is Building Cyber Resilience While Growing Talent," YouTube video, 15:32, posted November 2025, accessed July 8, 2026, https://www.youtube.com/watch?v=oE16wX4h-9U.

[12] Angelo State University, "ASU Selected to Pilot."

[13] J. Chance et al., "Strengthening Cyber Resilience by Building Critical Infrastructure Communities: The C-CIC Pilot Study," The Cyber Defense Review 10, no. 2 (2025).

[14] "RSOC Services," UT Regional Security Operations Center, The University of Texas at Austin, accessed June 25, 2026, https://rsoc.utexas.edu/services.

[15] "Regional Security Operations Center," University of Texas Rio Grande Valley Regional Security Operations Center, accessed June 26, 2026, https://www.rsoc.utrgv.edu/.

[16]UT Rio Grande Valley, “Regional Security Operations Center.”

[17] "Texas Department of Information Resources and Angelo State University Pilot," eGov Review, accessed June 26, 2026, https://www.egovreview.com/article/cybersecurity/675/texas-department-information-resources-and-angelo-state-university-pilot.

[18] “Regional Security Operations Center,” The University of Texas Rio Grande Valley, accessed June 26, 2026, https://www.rsoc.utrgv.edu/.

[19]"RSOC Services," UT Austin.

[20] "ASU Selected to Pilot DIR Regional Security Operations Center," Angelo State University, May 4, 2022, https://www.angelo.edu/live/news/18760-asu-selected-to-pilot-dir-regional-security.

[22] Texas Office of the Governor, Public Safety Office, "State and Local Cybersecurity Grant Program (SLCGP) - Governance and Planning Projects," Texas eGrants, accessed July 8, 2026, https://egrants.gov.texas.gov/.

[23] Texas Department of Information Resources, "Regional Security Operations Centers," accessed July 8, 2026, https://dir.texas.gov/.

"Digital Detox: Exploring the Impact of Cybersecurity Fatigue on Employee Productivity and Mental Health." PubMed Central, PMC11861440.

Druitt, Les, Patrick Moore, Craig Orgeron, Eric Boyette, William Rials, and Eric Sweden. State CIO as Broker: A New Model. Issue brief. Lexington, KY: National Association of State Chief Information Officers, 2018. https://www.nascio.org/wp-content/uploads/2019/11/NASCIO_StateCIOasBrokerModel.pdf.

eGov Review. "Texas Department of Information Resources and Angelo State University Pilot." Accessed June 26, 2026. https://www.egovreview.com/article/cybersecurity/675/texas-department-information-resources-and-angelo-state-university-pilot.

Graham, N. "Rural Water Cybersecurity: Shared Defense for Critical Infrastructure." Raventek. 2026. https://www.raventek.com/rural-water-cybersecurity-shared-defense/.

Information Systems Security Association (ISSA) & Omdia. "The Life and Times of Cybersecurity Professionals, Volume VIII." June 2026. https://issa.org/life-and-times-of-cybersecurity-professionals-volume-viii/.

Nautiyal, Lata, and Awais Rashid. "A Framework for Mapping Organizational Workforce Knowledge Profile in Cyber Security." Computers & Security 145 (2024): 103925. https://doi.org/10.1016/j.cose.2024.103925.

Texas Department of Information Resources. "Regional Security Operations Centers." Texas Government Code § 2054.5121. Accessed July 8, 2026. https://dir.texas.gov/.

Texas Government Code. § 552.139.

Texas Office of the Governor. Public Safety Office. "State and Local Cybersecurity Grant Program (SLCGP) - Governance and Planning Projects." Texas eGrants. Accessed July 8, 2026. https://egrants.gov.texas.gov/.

University of Texas at Austin. "RSOC Services." UT Regional Security Operations Center. Accessed June 25, 2026. https://rsoc.utexas.edu/services.

University of Texas Rio Grande Valley. "Regional Security Operations Center." Regional Security Operations Center website. Accessed June 26, 2026. https://www.rsoc.utrgv.edu/.

ZipRecruiter. "Entry Level Cyber Security Analyst Salary in Texas." Updated 2026. https://www.ziprecruiter.com/Salaries/Entry-Level-Cyber-Security-Analyst-Salary--in-Texas.

 
 
bottom of page