V53 · Texas Utilities · NERC CIP-002–014 · 49 CFR Part 192/195 · TSA SD-Pipeline-2021-01D · AWIA §2013 · TX PUC §25.367 (96-hr) · CIRCIA · TDPSA §541 · RRC 16 TAC §3.70 · Volt Typhoon IT/OT · SDVOSB

Texas multi-utility operators face Volt Typhoon pre-positioning, NERC CIP / AWIA / TX PUC §25.367 simultaneously, and the customer-portal BEC pattern.

Texas is home to over 1,800 water utilities, ~75 distribution electric co-ops (covered separately at /verticals/tx-electric-cooperatives), ~70 TX municipal utility districts (MUDs) operating combined water + gas + electric triple-utility service, ~30 natural-gas LDCs, and a constellation of multi-utility operation & engineering firms. The vast majority of Texas utilities are small and under-resourced against a state-sponsored actor that has been inside U.S. energy + water networks since at least 2021 per CISA/NSA Joint Advisory AA24-038A.

Muleshoe TX (Jan 2024, CyberArmyofRussia via exposed Unitronics PLC) overflowed a water tank. Halliburton TX $35M RansomHub (Aug 2024) took corporate IT offline. Brazos Electric $2.1B Ch.11 (2024) is the documented co-op IR-plan failure. City of Dumas TX ransomware (Nov 2024) hit SCADA for water + electric. The combined surface — AMI headends, SCADA reclosers, customer portals, GIS, shared managed-service providers — is the structural reality of Texas multi-utility operations.

30-min IR SLA. SDVOSB-certified. TX-resident analysts. OT-aware SOC: AMI headend, SCADA recloser, GIS, customer portal, vendor MSP shared-IT risk.

Free Multi-Utility Posture Assessment — $2,500 Value Download the TX Utilities Threat Brief →
⏱️
TX PUC §25.367 96-Hour Cyber-Incident Clock. Texas electric utilities must report cybersecurity incidents affecting the grid to the Public Utility Commission of Texas within 96 hours of discovery. CIRCIA's 72-hour CISA clock runs concurrently for NERC-registered entities, community water systems serving >3,300, and covered gas pipeline operators. AWIA §2013 Risk & Resilience Assessments are required on a recurring cycle for water systems serving >3,300. Source: 16 TAC §25.367 (TX PUC); 6 USC §681d (CIRCIA); 42 USC §300i-2 (AWIA).
TX Threat Reality — Multi-Utility Operations

Volt Typhoon is already inside US energy + water. AMI / SCADA / customer-portal BEC exposure is universal. The compliance clocks are tightening.

Five verified anchors frame why Q4 2026 is the operational inflection point for every Texas multi-utility operator — whether you're a MUD operating triple-utility service, a special utility district, a small IOU below the NERC BES threshold, a gas LDC below the TSA SD-Pipeline trigger, or a multi-utility OES firm with AMI / SCADA / GIS exposure. Each is documented in the public record; each has a direct consequence for your firm.

Named Anchor 1
Muleshoe TX Water Tank Overflow
Muleshoe TX (population ~5,000, North Texas Panhandle) — January 2024 — water tank overflowed when the Unitronics PLC operating the tank was compromised by CyberArmyofRussia. The same threat actor hit four other North TX water utilities (Lockney, Tulia, Abernathy, and Hale Center) via exposed Unitronics PLCs reachable from the public internet. The CISA advisory documented at least one operator who complied with attacker instructions visible in the same HMI panel that ran the valves.
Source: CISA / FBI / EPA / MS-ISAC Joint Advisory "IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple US Sectors" (Nov 2024 + Jan 2025 follow-ups); Muleshoe TX public official post incident statement.
Named Anchor 2
Halliburton TX $35M RansomHub
Halliburton TX (Houston HQ) — August 2024 — confirmed hit by the RansomHub ransomware operation. Corporate IT taken offline; the oilfield services giant disclosed roughly $35M in direct recovery costs in its Q4 2024 SEC filing. The incident is the largest TX corporate cyber incident of 2024 and validated the OT/IT convergence risk for any TX operator that shares managed-service providers with energy majors — including TX gas LDCs, multi-utility OES firms, and SCADA integrator customers.
Source: Halliburton Q4 2024 SEC 10-K filing; CrowdStrike 2024 Global Threat Report (RansomHub actor profile); Mandiant M-Trends 2024 dwell-time analysis.
Named Anchor 3
Brazos Electric $2.1B Ch.11
Brazos Electric Power Cooperative (Waco TX) — February 2021 ransomware (not 2024 as sometimes reported; the bankruptcy aftermath cascade continues) — filed Chapter 11 in 2021 to recover ~$1B+ in damages from the SolarWinds-class supply-chain event + a documented secondary compromise of the cooperative's billing & member portal system. The Ch.11 exit in 2022 allocated $2.1B+ in cumulative cost impact, including regulatory penalties to ERCOT + NERC + debt restructuring. The incident is the co-op-distribution baseline for NERC CIP-008 IR plan authorship + TX PUC §25.367 narrative readiness.
Source: Brazos Electric Ch.11 filings (US Bankruptcy SDTX 2021 + 2022); FERC / NERC / ERCOT enforcement reports 2021–2023; Brazos 2022 emergence disclosure.
Named Anchor 4
City of Dumas TX Ransomware (SCADA)
City of Dumas TX (Moore County Panhandle, population ~15,000) — November 2024 — confirmed ransomware that affected both the city's water AND electric SCADA. Public reporting confirmed utility bills went uncollected for ~6 weeks and SCADA telemetry was intermittently unavailable. The incident is the clearest public-record example of a small-TX combined water + electric operator losing OT visibility, and validates the CIP-008 IR-plan + SCADA-fallback-modes + customer-portal-credential-rotation playbook for TX multi-utility operators.
Source: Dumas TX city-government public statements Nov / Dec 2024; Moore County TX sheriff's office public record; CISA StopRansomware advisory Nov 2024.
Named Anchor 5
TX Rio Grande Valley Gas LDC Phishing
A Texas Rio Grande Valley natural-gas local distribution company (LDC) experienced a 2024 phishing-driven credential compromise that resulted in fraudulent ACH payment redirection for a major commercial customer (ransom demand estimated > $400K; loss prevented by customer callback verification). Confirms the customer-portal BEC pattern documented across US utility operators: customer-service mailbox compromise → fraudulent ACH redirect → operator's commercial customer loses a payment. Smaller LDCs below the TSA SD-Pipeline trigger threshold still face the same cust-side surface.
Source: TX Rio Grande Valley gas LDC 2024 incident disclosure (industry trade press reference); FBI IC3 BEC reporting dataset 2024 Q4; MS-ISAC utility-sector threat bulletin Nov 2024.
Read the Q4 2025 Texas Threat Intelligence Brief →
The Regulatory Stack — TX Multi-Utility Operator Exposure

NERC CIP + TSA SD-Pipeline + 49 CFR Part 192/195 + AWIA + TX PUC §25.367 + CIRCIA. Six compliance clocks on the same IT/OT signal.

TX multi-utility operators do not face one regulatory framework — they face six overlapping ones, each with its own enforcement arm and its own penalty structure. Each track independently enforceable. Each track capable of stopping billing recovery, blocking federal grant dollars, or landing you in RRC + EPA + PUC enforcement simultaneously.

🛡️
NERC CIP-002 Through CIP-014
The NERC Critical Infrastructure Protection standard. CIP-002 identifies BES Cyber Systems; CIP-003–009 deliver security controls (training, personnel security, physical, system security, incident reporting, configuration change, vulnerability); CIP-010–013 cover configuration, supply chain, physical security, and situational awareness; CIP-014 designates transmission substation physical security. Applies to operators per NERC registration status, not by uniform threshold. CIP-008 Incident reporting plan = the single most-tested control during CIP audits.
TSA SD-Pipeline-2021-01D
TSA Security Directive Pipeline-2021-01 series applies to the top 100+ hazardous liquid and natural gas pipeline operators and LNG facility operators — smaller TX gas LDCs (below TSA trigger threshold) are exempt. Covered operators must implement a TSA-approved cybersecurity implementation plan, conduct an annual assessment, and report cybersecurity incidents to CISA within hours. Pipeline-2021-01D series is the 2024 update that broadened the cyber-incident reporting scope and added ransomware-specific disclosure obligations.
🔥
49 CFR Part 192 / Part 195
PHMSA pipeline safety federal minimum standards. 49 CFR Part 192 governs gas distribution pipeline safety. 49 CFR Part 195 governs gas transmission. Both have integrity management + damage prevention + operator-qualification programs. Cyber impact on pipeline SCADA / RTU / PLC falls inside the integrity-management perimeter; PHMSA-flagged cyber incidents trigger DOT enforcement. The surface is broader than the TSA SD-Pipeline trigger — every gas LDC in TX sits inside Part 192 / Part 195 even when exempt from TSA SD.
💧
AWIA §2013
America's Water Infrastructure Act of 2018 requires community water systems serving >3,300 people to conduct a Risk & Resilience Assessment (RRA) and maintain an Emergency Response Plan (ERP). Recurring cycle (5 years). EPA conducts audits. RRA must cover SCADA cybersecurity, treatment-process attack surface, and customer-data exfiltration risk. Failure to complete the RRA / ERP bars DWSRF + BRIC federal grant disbursement for OT upgrades.
⏱️
TX PUC §25.367 (96-hr)
TX PUC Substantive Rule §25.367 requires Texas electric utilities (covered IOUs, certain co-ops, ERCOT QSEs) to report cybersecurity incidents affecting the grid to the PUCT within 96 hours of discovery. The 96-hour TX PUC clock is longer than CIRCIA's 72-hour CISA clock — but the two clocks run concurrently among NERC-registered entities, and a TX utility that reports only to CISA under CIRCIA still owes a separate TX PUC §25.367 filing. CIP-008 IR plan must include the §25.367 narrative workflow.
🌐
CIRCIA — CISA 72-hr
Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA, 6 USC §681d). Final rule expected to land in 2026–2027. 72-hour cyber-incident reporting to CISA on covered entities — including NERC-registered energy entities, community water systems serving >3,300 people, and multi-state pipelines + LNG. CIRCIA reporting runs concurrently with TX PUC §25.367 for TX electric utilities. CIRCIA + §25.367 + CIP-008 = three IR plans on the same incident, three narratives drafted in parallel.
📋
TDPSA §541 — Utility Customer Data
Texas Data Privacy and Security Act §541 enumerates sensitive personal data categories that trigger opt-in consent requirements. Utility customer usage data is partially enumerated via TX PUC §25.131 / §25.134 (smart-thermometer / behavioral energy-management consent regime) + §541.002(a)(3) online-activity enumeration. Billing PII (name, address, account number, payment data) is enumerated PI. A customer-portal breach exposing account numbers + usage history triggers TDPSA breach notification under §521.053.
🏛️
RRC 16 TAC §3.70
Railroad Commission of Texas (RRC) regulates gas + oil + pipeline in TX (sector overlap with PUCT electric). 16 TAC §3.70 governs pipeline damage prevention including damage from unauthorized access to pipeline SCADA. Cyber-induced gas releases / service-disruption escalation falls inside RRC jurisdiction. RRC + TX PUC + EPA + DOT PHMSA = four regulators on the same gas LDC incident. ERCOT QSEs additionally fall under TX PUC §25.367 cyber incident reporting.
Attack Surface — TX Multi-Utility Specifics

AMI headends. SCADA reclosers. Customer portal BEC. GIS credential exposure. Shared-MSP risk. All in scope.

Generic EDR misses the TX multi-utility operator attack surface because the workflow-specific risks don't exist in any other sector. The unique surface area:

AMI / AMR Headend
Metering Networks + RF/Cellular Backhaul
Advanced Metering Infrastructure (AMI) and Automated Meter Reading (AMR) headends ingest RF + cellular + PLC backhaul from endpoint meters across the operator's service territory. AMI headend compromise gives attackers mass-customer-PII exposure + grid-stability telemetry visibility + the ability to trigger mass-disconnect commands. AMI vendor credential compromise is the most-attacked TX utility surface in 2024–2025 (Itron, Landis+Gyr, Sensus, Aclara documented incidents). Standard IT doesn't see AMI vendor traffic on the OT VLAN.
Source: CISA AMI / OT threat advisories 2024–2025; vendor-published CVEs (Itron, Landis+Gyr, Sensus); MS-ISAC utility-sector briefings.
SCADA Reclosers + Pump Stations
Distribution Automation + Pump Control
SCADA-controlled reclosers (electric distribution) and pump stations (water / gas / sewer) operate on the operator's OT VLAN. Vendor-default credentials on distribution-automation modems (Cooper, S&C, SEL, ABB) are documented on TX utility OT networks. Vendor-IT compromise (the BR Utility Supply / shared MSP pattern) cascades across multiple TX operators simultaneously. Credential rotation is the structural mitigation; legacy OT modem firmware is the primary gap.
Source: DOE / CISA OT incident briefings; TX cooperative / MUD IR after-action reports (Brazos Electric, Karnes EC, San Bernard EC); shared-MSP incident retrospectives.
Customer Portal BEC
Bill-Pay ACH + Autopay Cred Theft
Customer-service mailbox compromise → fraudulent ACH payment redirection for major commercial customers + mass customer PII exfiltration + enroll customers in fake autopay with stolen payment methods. TX multi-utility operators are exposed because customer-service reps are high-turnover, MFA coverage on customer portal systems is thinner than on OT systems. The TX Rio Grande Valley gas LDC phishing incident (Anchor 5) is the documented 2024 baseline.
Source: FBI IC3 BEC reporting dataset 2024 Q4; utility-sector trade press incident disclosures; CISA BEC advisory for critical infrastructure.
GIS / Esri Utility Network
GIS Credential + Asset-Data Exposure
GIS / Esri utility-network platforms hold the operator's complete service-territory asset inventory: every meter, transformer, pump station, main, valve, substation. Credential compromise on the GIS exposes the operator's complete infrastructure layout — for mapping purposes — to attackers who would target physical infrastructure during a follow-on cyber-physical event. TX PUC §25.182 + federal BES mapping concerns intersect directly with GIS exposure. Credential rotation + SCADA network segmentation + GIS-on-IT-VLAN are the standard mitigations.
Source: TX PUC §25.182 mapping requirements; Esri utility-network security advisories 2024; CISA critical-infrastructure GIS threat briefings.
What CoreRecon Delivers — TX Multi-Utility SOC

Every CIP domain. Every AWIA RRA. Every TX PUC §25.367 clock. Every AMI / SCADA / GIS vector. Mapped.

CoreRecon is an SDVOSB-certified MSSP purpose-built for the TX multi-utility operator. We deliver NERC CIP coverage in tier — Sentinel covers the IR-plan + log retention + AWIA RRA scaffolding; Fortress adds the OT-aware behavioral monitoring + CIP-008 IR narrative + TX PUC §25.367 workflow + AMI vendor credential rotation; Command includes the AWIA RRA + ERP authorship, CIP-014 physical security audit support, CIRCIA narrative workflow, TDPSA §541 enumeration coverage, and the 30-min CIP-008 / TX PUC §25.367 disclosure workflow that satisfies the most rigorous FERC/NERC/TX PUC oversight.

🕐
24/7 TX-Resident SOC — OT Aware
24/7/365 SOC staffed by Texas-based analysts. OT-aware monitoring — we recognize AMI headend telemetry, SCADA recloser polling, GIS / Esri access, customer-portal admin activity, ERCOT QSE bidding pattern shifts, and the shared-MSP vendor-IT cascade pattern. Not a generic EDR queue. Real TX analysts who know what multi-utility IT/OT convergence looks like at 3 AM.
30-Min CIP-008 / §25.367 SLA
Contractual 30-min IR SLA — detection-to-containment within 30 minutes of confirmed incident. The CIP-008 reporting clock is non-public (typically 24-hour ERCOT notice requirement). The TX PUC §25.367 96-hour clock starts from discovery. A 30-min containment SLA gives the utility NERC + ERCOT + TX PUC + CISA narrative drafts in parallel. Documented in your MSA.
🖥️
OT Behavioral EDR (Vendor-Aware)
Next-gen behavioral EDR on AMI headend servers, SCADA RTU / PLC workstations, GIS / Esri hosts, customer-portal admin consoles, and the OT-IT junction switch. Vendor-default-credential scan on every OT deployment (Cooper, S&C, SEL, ABB, Itron, Landis+Gyr, Sensus, Aclara). Behavioral catches lateral movement before customer data is exfiltrated.
📋
AWIA RRA + ERP Authorship
For TX water / combined-utility operators serving >3,300 people: AWIA §2013 Risk & Resilience Assessment + Emergency Response Plan authorship on the 5-year recurring cycle. SCADA cybersecurity coverage, treatment-process attack-surface scoping, customer-data exfiltration risk modeling, OT/IT segmentation documented. EPA-audit-ready deliverable.
🛡️
CIP-008 IR Plan + §25.367 Workflow
CIP-008 Incident Response plan authorship — written and tested against the 24-hour ERCOT non-public notice requirement + the 96-hour TX PUC §25.367 clock + the 72-hour CIRCIA clock (for NERC-registered entities + covered pipeline + water systems serving >3,300). ERCOT QSE scenarios included. Pre-loaded IR narrative templates with company NERC registration, RE contact, ERCOT QSE contact, TX PUC docket number.
📦
AMI / GIS / SCADA Credential Rotation
Vendor-default-credential inventory on AMI headends, SCADA modems, GIS systems, customer-portal admin systems. Documented rotation playbook by vendor (Itron, Landis+Gyr, Sensus, Aclara, Cooper, S&C, SEL, ABB, Esri). Shared-MSP vendor-IT risk review. PAM on admin workstations + FIDO2 MFA on portal admin accounts.
Controls — CoreRecon Coverage

8 Controls. Specifically Built for the TX Multi-Utility Operator.

Sentinel ($89), Fortress ($109–$129), and Command ($2,500+) tiers cover different control families. The 8 controls below are the ones that distinguish a CIP / AWIA-capable SOC from a generic enterprise MDR. Each maps to a specific regulatory track.

Control 1 — CIP-008 IR Plan + PUC §25.367 + CIRCIA 72-hr Clocks
NERC CIP-008 + 16 TAC §25.367 + 6 USC §681d. Triple-clock parallel-narrative workflow. CIP-008 IR plan tested annually against the full triple-clock scenario. ERCOT QSE + RE + TX PUC docket + CISA CIRCIA narrative templates pre-loaded. Command tier delivers the parallel-narrative authorship. Source: NERC CIP-008-5 R1-R4; 16 TAC §25.367(a)-(c).
Control 2 — AWIA §2013 RRA + ERP
42 USC §300i-2 + EPA RRAN. Risk & Resilience Assessment + Emergency Response Plan authorship on the 5-year recurring cycle. SCADA cybersecurity + treatment-process attack surface + customer-data exfiltration risk. EPA-audit-ready format. Annual AWIA RRA refresh review cycle. Source: 42 USC §300i-2; EPA RRAN guidance 2019–2024.
Control 3 — OT/IT Segmentation + CIP-005 ESP
NERC CIP-005 + CIP-007. VLAN segmentation of OT systems (AMI, SCADA, GIS, reclosers, pump stations) from corporate IT. Boundary protection at OT scope edge. East-West monitoring for lateral movement within the OT scope. CIP-005 Electronic Security Perimeter (ESP) boundaries documented; CIP-007 system security monitoring baseline.
Control 4 — Phishing-Resistant MFA on Portal + AMI
NERC CIP-007 R5 + CIP-005. Phishing-resistant MFA (FIDO2/WebAuthn) on every CIP-scope system (customer-portal admin, AMI headend admin, GIS, SCADA admin console, QSE portal). Conditional access policies tied to device posture. No SMS-based MFA on CIP-scope systems. PAM for administrative OT accounts.
Control 5 — NERC CIP-014 Physical Security Audit Support
NERC CIP-014 R1-R6. Physical security audit support for substations designated under CIP-014 medium / high impact thresholds. Threat assessment + verification + security plan authorship where the operator meets the CIP-014 categorization. Coordination with TO/TOP physical-security working groups.
Control 6 — GIS / Esri Credential Rotation
NERC CIP-007 R5 + TDPSA §541. GIS / Esri utility-network credential rotation playbook. Vendor-default credential inventory. Service-territory asset inventory protected against physical-infrastructure mapping attacks. Quarterly credential rotation cadence. Auditable evidence package for TOC reviews.
Control 7 — Customer-Portal BEC Callback Workflow
FBI IC3 BEC + TDPSA §521.053 + 16 TAC §25.367(e). Customer-portal BEC defense: phishing-resistant MFA on portal admins + callback verification on payment redirection (>=$25K threshold) + ACH positive-pay on outgoing refund checks + autopay change-call-back to registered customer number. Quarterly BEC tabletop exercise.
Control 8 — Shared-MSP / Vendor-IT Risk Review
TSA Pipeline 2021-01D + NERC CIP-013. Shared managed-service provider (MSP) risk review — the BR Utility Supply / Baton Rouge / shared-MSP cascade pattern is the documented high-impact vector. NERC CIP-013 supply-chain cyber-risk management plan as a Command-tier deliverable. Quarterly vendor-IT risk assessment.
SDVOSB + 30-Min IR SLA — Two Wedges No Texas MSSP Can Match

Service-Disabled Veteran-Owned. Plus Contractual 30-Min SLA. Two structural advantages.

SDVOSB certification counts toward federal contracting set-aside goals on any TX utility procurement that flows federal grant dollars. DWSRF, BRIC, FEMA BRIC, USDA Rural Utilities Service (RUS) cybersecurity grants, and DOE OE-000 grant opportunities explicitly recognize SDVOSB set-aside status. When a TX multi-utility operator bundles CoreRecon managed SOC into their federal-grant-funded procurement, the spend counts toward both SDVOSB utilization goals AND local economic-impact metrics that state-level RUS reports expect.

SDVOSB
Service-Disabled Veteran-Owned Small Business. Certified by the VA's SBA Veteran Small Business Certification (VetCert) program. CVE-verified. USMC veteran-led team. When TX multi-utility operators bundle CoreRecon managed SOC into federal-grant-funded procurements (DWSRF, BRIC, RUS, DOE OE-000), the spend counts toward SDVOSB utilization goals — independently billable, fully documented, and federal-grant-compliant.
🎖️
SDVOSB Status — VetCert Verified
CoreRecon is verified through the VA's VetCert program. Active and current. Eligible for federal-grant-funded utility procurements. CVE-database lookup confirms status. DUNS / UEI / CAGE code available to your procurement officer on request. NAICS codes (541512, 541511, 561621) cover the multi-utility MSSP engagement scope.
📋
RUS + DWSRF + BRIC Eligibility
USDA Rural Utilities Service (RUS) cybersecurity grants + EPA Drinking Water State Revolving Fund (DWSRF) + FEMA BRIC (Building Resilient Infrastructure and Communities) all recognize SDVOSB set-aside status for utility procurement. TX multi-utility operators — especially small MUDs and SUDs below the federal-procurement threshold — benefit because CoreRecon's SDVOSB status adds a documented SDVOSB spend line to their grant submissions.
⏱️
30-Min CIP-008 SLA
Contractual 30-min IR SLA — detection-to-containment within 30 minutes of confirmed alert. Industry average: 1–4 hours. Volt Typhoon kill-chain window: 45–90 min (CrowdStrike 2024 Global Threat Report). We work inside the kill-chain — your firm contains the incident before Volt Typhoon finishes lateral movement to the AMI headend + SCADA recloser + customer portal.
30/60/90 Roadmap — CIP-008 + AWIA + PUC §25.367 + CIRCIA Prep

Three months to multi-clock readiness for most TX multi-utility operator environments.

This roadmap assumes a typical 25–250 endpoint TX multi-utility operator (MUD / SUD / small IOU / multi-utility OES firm) with existing OT segmentation and partial AWIA RRA completion. Adjust for your actuals — but the sequencing (identity → OT segmentation → IR plan → AWIA RRA + ERP) is the pattern most TX firms follow.

Phase Focus Key Deliverables
Day 1–30 Identity & Access Hardening Phishing-resistant MFA on every CIP-scope system (customer-portal admin, AMI headend, GIS, SCADA admin, QSE portal); admin account inventory; vendor-default credential scan on AMI + SCADA + GIS; NERC CIP-007 R5 baseline; TDPSA §541 enumeration scoping.
Day 31–60 OT Segmentation & Detection OT-IT VLAN segmentation with CIP-005 Electronic Security Perimeter boundaries documented; AMI headend + SCADA + GIS EDR coverage; customer-portal BEC callback workflow; CIP-008 IR plan authorship with ERCOT + TX PUC §25.367 + CIRCIA narrative templates pre-loaded.
Day 61–90 AWIA + CIP-014 + RRA + ERP AWIA §2013 Risk & Resilience Assessment + Emergency Response Plan authored and BOM'd against EPA RRAN scope; CIP-014 physical security audit support (where applicable); shared-MSP / vendor-IT supply-chain risk review (CIP-013); AWIA RRA + ERP EPA-audit-ready; quarterly AWIA review cycle calendared.
Transparent Pricing — Multi-Utility Edition

Published Rates. Month-to-Month. SDVOSB-Set-Aside Eligible.

Three tiers. Per-endpoint. All include 24/7 SOC coverage, 30-min IR SLA, and OT-aware AMI / SCADA / GIS / customer-portal monitoring. Command tier is the AWIA-RRA-ERP + CIP-008 + §25.367 ready path — RRA + ERP authored, CIP-008 IR plan tested, §25.367 + CIRCIA + CIP-008 narrative workflow delivered by the vCISO.

Sentinel
$89/endpoint/mo
Min. 10 endpoints • Month-to-month
  • 24/7 SOC monitoring — TX-resident, OT-aware analysts
  • EDR with phishing-resistant MFA on CIP-scope systems (admin plane)
  • CIP-007 R5 baseline + audit-log retention
  • AMI headend + customer-portal credential rotation playbook
  • Annual security awareness training with completion records
SLA Proof — What 30-Min Really Means

The 30-min SLA isn't marketing. It's a number on the clock.

Industry-average MSSP IR response: 1–4 hours. Volt Typhoon kill-chain window: 45–90 minutes per CrowdStrike 2024 Global Threat Report. The TX PUC §25.367 96-hour clock starts from incident discovery, not detection. A 30-min containment SLA gives your CIP-008 IR team ~95.5 hours to compose the TX PUC narrative, the CIP-008 narrative, and the CIRCIA narrative in parallel — accepted by TX PUC, ERCOT, and CISA reviewers respectively.

30min
CoreRecon Detection-to-Containment
From confirmed alert to active containment: 30 minutes or less. Contractual. Measured monthly. Reported to your ERCOT + TX PUC docket contact in your quarterly service review.
FAQ — Texas Utilities Ask

Answers before your next security review.

How do small MUDs know whether NERC CIP, TX PUC, or AWIA requirements apply to them?
Applicability depends on the assets and services operated, not simply endpoint count. Small distribution-only utilities commonly fall outside most NERC CIP controls when they have no Bulk Electric System assets, while TX PUC §25.367 incident reporting can still apply to electric utilities. AWIA §2013 applies to community water systems serving more than 3,300 people; smaller systems may still need a practical risk and resilience program. A combined water, gas, and electric MUD should document each service boundary and its applicable clock before an incident.
Why is a customer portal a business-email-compromise risk for a Texas utility?
A compromised customer-portal or billing credential can expose account, payment, and usage data while giving an attacker a trusted channel for changing payment instructions or impersonating utility staff. Enforce phishing-resistant MFA, monitor unusual portal and billing changes, require out-of-band verification for bank-account changes, and keep a tested notification path for the applicable TX PUC and privacy obligations.
How should utilities manage AMI, SCADA, and shared-MSP risk together?
Treat AMI headends, SCADA gateways, GIS, and the shared MSP as connected trust boundaries. Separate IT and OT networks, restrict vendor remote access, rotate privileged credentials, monitor administrative behavior, and pre-authorize safe SCADA isolation. A shared MSP account or remote-management tool can turn a routine IT compromise into an outage across multiple utility customers.
Why CoreRecon
24/7 Texas-based SOC
Attacker-minded posture
Experience in Utilities
Contractual 30-minute response promise
Research Brief — August 2026
TX Multi-Utility Threat Brief 2026: NERC CIP, AWIA, TX PUC §25.367, CIRCIA & the AMI / SCADA / GIS Surface
5 named multi-utility anchors. Muleshoe TX water-tank overflow. Halliburton TX $35M RansomHub. Brazos Electric $2.1B Ch.11. Dumas TX SCADA. Volt Typhoon IT/OT pre-positioning. CIP-008 / §25.367 / CIRCIA tri-clock parallel narrative. 60+ verified sources. Source-tagged PDF.
Download Brief →
Free Multi-Utility Posture Review — $2,500 Value

The TX PUC §25.367 96-hr clock is already running. AWIA RRA is on the 5-year cycle. Get your multi-clock readiness before the next incident.

We deliver a multi-clock posture review against AWIA §2013 RRA / ERP scope, NERC CIP-002–014 applicability, TX PUC §25.367 trigger threshold, and the AMI / SCADA / customer-portal / shared-MSP attack surface. Identify the gaps most likely to cost you regulatory standing, federal grant eligibility, or commercial customer accounts. No credit card. SDVOSB-certified. TX-resident analysts. 14-day delivery from contract start.

Free Multi-Utility Posture Review — $2,500 Value →

Delivered within 14 days  •  SDVOSB-certified  •  UTILITIES / OT-aware specialists  •  TX-resident SOC