A Tax Code Fix for a Cybersecurity Funding Gap
A September 24, 2026 op-ed published by CyberScoop, authored by Joshua Levine and Lars Erik Schönander, argues that the fastest way to protect America's small water and wastewater utilities from nation-state and ransomware intrusions is not a new federal cybersecurity program, but a clarification of tax incentives that already exist. The piece — titled "How tax policy can stop threat actors from breaching US water systems" — contends that new federal cybersecurity initiatives typically take years to authorize, appropriate, and disburse, while the threat to municipal water systems is immediate. The authors point to the "One Big Beautiful Bill" (OBBB), the 2025 federal tax and reconciliation package, as a vehicle already on the books that Congress could sharpen to let cash-strapped local governments write off cybersecurity software and hardware purchases now, rather than waiting on a future grant cycle.
Details
| Attribute | Value |
|---|---|
| Op-Ed Title | "How tax policy can stop threat actors from breaching US water systems" |
| Authors | Joshua Levine, Lars Erik Schönander |
| Published | September 24, 2026, CyberScoop |
| Proposed Vehicle | Tax provisions in the One Big Beautiful Bill (OBBB) |
| Key Mechanisms Cited | Bonus depreciation, full expensing, Section 174A expense clarification |
| Primary Target | State and local government water/wastewater utilities |
| Cited Incidents | 2024 Texas water tank overflow (Russian-affiliated actors); 2026 Minnesota multi-city targeting (Iranian-affiliated actors) |
| Related Advisory | CISA, August 2026 — active-threat advisory for Siemens S7 series PLCs |
| Reported Funding Gap Data | State CISO budget survey (2026); Center for Internet Security local-agency survey (2024) |
The Argument: Legislation Is Too Slow, the Threat Is Not
The op-ed's core claim is a mismatch of timelines. Standing up a new federal cybersecurity grant program — from authorization, to appropriations, to agency rulemaking, to funds actually landing in a utility's bank account — routinely spans multiple budget cycles. Threat actors, by contrast, are already inside the perimeter of some of the smallest public water systems in the country. The authors argue that tax policy sidesteps this lag entirely: it does not require creating a new agency, a new grant office, or a new compliance regime. It only requires Congress, or Treasury guidance, to confirm that cybersecurity software and hardware purchases qualify under provisions the OBBB already put in place.
Recurring Target: Water Systems Under Fire
The op-ed frames its policy argument around two incidents that illustrate how thin the cybersecurity margin is at the municipal level:
- 2024, Texas — Russian-affiliated actors exploited a vulnerability in a small Texas town's water system, causing a water tank to overflow. The town's total 2023 revenue was $3.37 million, and it had no dedicated cybersecurity budget line item at all.
- 2026, Minnesota — Iranian-affiliated actors targeted multiple Minnesota cities, including Braham, Plymouth, South St. Paul, and Maple Plain. Braham is a stark example of the funding mismatch: the city had identified $22.98 million in water infrastructure needs — more than 10 times its $2.2 million annual budget — and received a $10.22 million state bond to replace its wastewater plant, water main, and wells. None of that bond funding was earmarked for cybersecurity.
- August 2026 — CISA issued a joint advisory warning of an active threat targeting Siemens S7 series programmable logic controllers (PLCs), hardware used across sewer systems, hospitals, and other industrial operations — underscoring that the exposure extends well beyond water utilities alone.
Proposed Mechanism: Three Tax Levers
The op-ed identifies three specific tax provisions Congress could clarify or extend to cybersecurity purchases:
- Bonus depreciation — extending eligibility to cybersecurity software and hardware, letting utilities immediately deduct a large share of the purchase cost rather than depreciating it over years.
- Full expensing for digital infrastructure — allowing the entire cost of qualifying cybersecurity technology to be written off in the year it is purchased.
- Section 174A expense clarification — explicitly confirming that cybersecurity software implementation costs qualify for immediate expensing rather than being treated as a capitalized, multi-year expenditure.
None of these require new spending authority. The pitch is regulatory clarity: confirm that existing OBBB language covers cybersecurity purchases, and municipal budgets — and the vendors who sell to them — can act on it immediately.
The Underlying Funding Gap
The op-ed cites two data points to establish scale. A survey of state chief information security officers found a plurality reporting stagnant or reduced cybersecurity budgets for 2026 — even as the threat landscape for critical infrastructure intensifies. Separately, a 2024 Center for Internet Security survey of thousands of local government agencies found that roughly one-third conducted "minimal to no cybersecurity activities" at all. Against that backdrop, the authors argue, a tax-code fix that costs the federal government little in direct outlay is a pragmatic bridge until larger structural funding is available.
Impact Assessment
| Impact Area | Description |
|---|---|
| Funding Speed | Tax incentives could let utilities acquire cybersecurity tooling within a single fiscal year, versus multi-year federal grant timelines |
| Budget Relief | Could partially offset the stagnant-to-reduced cybersecurity budgets state CISOs report for 2026 |
| OT/ICS Exposure | Does not directly remediate PLC-level vulnerabilities like those in the Siemens S7 advisory, but could fund the monitoring and detection tools needed to catch exploitation attempts |
| Adoption Equity | Benefits skew toward utilities with tax liability and capital budgets large enough to leverage depreciation — the smallest municipal systems, like the $3.37 million-revenue Texas town, may see limited practical benefit without additional guidance |
| Policy Uncertainty | The incentives are only useful once Congress or Treasury issues explicit clarifying guidance; ambiguity in current OBBB language is itself the bottleneck the op-ed is trying to solve |
| Infrastructure vs. Security Tradeoff | Bond and infrastructure funding (e.g., Braham's $10.22 million bond) continues to be allocated for physical plant needs with no parallel cybersecurity line item, a pattern the op-ed says tax policy could correct without competing for the same dollars |
Recommendations
For State and Local Officials
- Inventory current OT/ICS assets (SCADA, PLCs, remote telemetry) at every water and wastewater facility, and identify which are internet-facing or remotely accessible.
- Do not assume infrastructure bonds or state grants cover cybersecurity — explicitly request or budget a cybersecurity line item separate from physical plant upgrades.
- Track OBBB guidance from Treasury and the IRS; if depreciation and expensing provisions are clarified to cover cybersecurity purchases, be ready to act within the same budget cycle.
For Water Utility Operators and OT/ICS Teams
- Segment PLCs and other OT devices from IT networks and the public internet; devices like the Siemens S7 series named in the August 2026 CISA advisory should not be directly internet-accessible.
- Apply CISA advisories for industrial control system products as a standing operational checklist, not a one-time read.
- Where budget allows, prioritize basic monitoring and multi-factor authentication for remote access to water system controls — the Texas and Minnesota incidents both involved intrusion into systems with minimal safeguards.
For Congress and Policymakers
- Issue explicit guidance confirming cybersecurity software and hardware qualify for bonus depreciation, full expensing, and Section 174A treatment under the OBBB.
- Pair tax-code clarification with continued support for direct grant programs — the op-ed frames tax incentives as a faster bridge, not a replacement for structural federal investment in state and local cybersecurity.
- Consider size-adjusted incentives or refundable credit mechanisms so that the smallest municipal utilities, which often have little or no tax liability to offset, are not left out of a depreciation-based approach.
Key Takeaways
- A CyberScoop op-ed by Joshua Levine and Lars Erik Schönander proposes using existing One Big Beautiful Bill tax provisions — bonus depreciation, full expensing, and Section 174A clarification — to fund state and local water utility cybersecurity faster than new federal programs could.
- US water systems remain a recurring target: Russian-affiliated actors caused a Texas water tank overflow in 2024, and Iranian-affiliated actors targeted four Minnesota cities in 2026, including Braham.
- Braham, Minnesota illustrates the structural funding gap — a $10.22 million state bond covered physical infrastructure but included no cybersecurity funding, despite $22.98 million in identified needs.
- A CISA advisory from August 2026 flagged active exploitation targeting Siemens S7 series PLCs used across sewers, hospitals, and industrial facilities, broadening the exposure beyond water utilities alone.
- Survey data cited in the op-ed shows a plurality of state CISOs reporting stagnant or reduced 2026 cybersecurity budgets, and roughly one-third of local agencies (per a 2024 Center for Internet Security survey) conducting minimal to no cybersecurity activity.
- The proposal requires no new federal spending program — only regulatory clarity — but its benefit is skewed toward utilities with enough capital budget or tax liability to use depreciation-based incentives, leaving the smallest systems potentially underserved without further adjustment.