TX Utilities Cybersecurity 2026
Texas multi-utility operators (gas + electric + water combined MUDs, special utility districts, gas LDCs, multi-utility OES firms) face NERC CIP-002 through CIP-014 (CIP-008 IR plan tri-clock + CIP-014 physical security + CIP-013 supply-chain), AWIA §2013 Risk & Resilience Assessment + Emergency Response Plan on 5-yr cycle, TSA SD-Pipeline-2021-01D (top 100+ gas LDCs + LNG), 49 CFR Part 192/195 (gas distribution + transmission), EPA RRAN-aligned RRA/ERP, AWWA G430/J100/DWFR, RRC 16 TAC §3.70 pipeline damage prevention, TX PUC Substantive Rule §25.367 (96-hr electric cyber-incident clock to PUCT — concurrent with CIRCIA 72-hr for NERC-registered entities), TDPSA §541 (utility customer billing + usage data enumeration), Volt Typhoon IT/OT pre-positioning in U.S. energy + water since 2021 (CISA/NSA AA24-038A), Muleshoe TX water-tank overflow (Jan 2024, CyberArmyofRussia/Unitronics PLC), Halliburton TX $35M RansomHub (Aug 2024), Brazos Electric $2.1B Ch.11 (2021 aftermath), City of Dumas TX SCADA ransomware (Nov 2024). Shared-MSP / vendor-IT / AMI headend / SCADA recloser / GIS / customer-portal BEC attack surface. CoreRecon tri-clock parallel-narrative SOC deliverable at $89–$129/endpoint + $2,500+/mo Command tier with AWIA RRA/ERP authorship + CIP-014 audit support + CIP-013 supply-chain plan + TDPSA enumeration coverage. SDVOSB-certified, 30-min CIP-008 SLA, TX-resident analysts, federal-grant procurement eligible (DWSRF/BRIC/RUS/DOE OE-000).