Skip to main content
COSMICBYTEZ LABS
NewsSecurityHOWTOsTools
ProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

3,036+ Articles
170+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Tools
  • Checklists
  • Projects

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • Hire Me
  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

  1. Home
  2. News
  3. How Tax Incentives Could Shield US Water Utilities From Cyberattacks
NEWS

How Tax Incentives Could Shield US Water Utilities From Cyberattacks

A new op-ed argues federal tax incentives under the One Big Beautiful Bill could fund water utility cybersecurity faster than new federal programs.

Dylan H.

News Desk

September 24, 2026
8 min read
How Tax Incentives Could Shield US Water Utilities From Cyberattacks

A Tax Code Fix for a Cybersecurity Funding Gap

A September 24, 2026 op-ed published by CyberScoop, authored by Joshua Levine and Lars Erik Schönander, argues that the fastest way to protect America's small water and wastewater utilities from nation-state and ransomware intrusions is not a new federal cybersecurity program, but a clarification of tax incentives that already exist. The piece — titled "How tax policy can stop threat actors from breaching US water systems" — contends that new federal cybersecurity initiatives typically take years to authorize, appropriate, and disburse, while the threat to municipal water systems is immediate. The authors point to the "One Big Beautiful Bill" (OBBB), the 2025 federal tax and reconciliation package, as a vehicle already on the books that Congress could sharpen to let cash-strapped local governments write off cybersecurity software and hardware purchases now, rather than waiting on a future grant cycle.


Details

AttributeValue
Op-Ed Title"How tax policy can stop threat actors from breaching US water systems"
AuthorsJoshua Levine, Lars Erik Schönander
PublishedSeptember 24, 2026, CyberScoop
Proposed VehicleTax provisions in the One Big Beautiful Bill (OBBB)
Key Mechanisms CitedBonus depreciation, full expensing, Section 174A expense clarification
Primary TargetState and local government water/wastewater utilities
Cited Incidents2024 Texas water tank overflow (Russian-affiliated actors); 2026 Minnesota multi-city targeting (Iranian-affiliated actors)
Related AdvisoryCISA, August 2026 — active-threat advisory for Siemens S7 series PLCs
Reported Funding Gap DataState CISO budget survey (2026); Center for Internet Security local-agency survey (2024)

The Argument: Legislation Is Too Slow, the Threat Is Not

The op-ed's core claim is a mismatch of timelines. Standing up a new federal cybersecurity grant program — from authorization, to appropriations, to agency rulemaking, to funds actually landing in a utility's bank account — routinely spans multiple budget cycles. Threat actors, by contrast, are already inside the perimeter of some of the smallest public water systems in the country. The authors argue that tax policy sidesteps this lag entirely: it does not require creating a new agency, a new grant office, or a new compliance regime. It only requires Congress, or Treasury guidance, to confirm that cybersecurity software and hardware purchases qualify under provisions the OBBB already put in place.

Recurring Target: Water Systems Under Fire

The op-ed frames its policy argument around two incidents that illustrate how thin the cybersecurity margin is at the municipal level:

  • 2024, Texas — Russian-affiliated actors exploited a vulnerability in a small Texas town's water system, causing a water tank to overflow. The town's total 2023 revenue was $3.37 million, and it had no dedicated cybersecurity budget line item at all.
  • 2026, Minnesota — Iranian-affiliated actors targeted multiple Minnesota cities, including Braham, Plymouth, South St. Paul, and Maple Plain. Braham is a stark example of the funding mismatch: the city had identified $22.98 million in water infrastructure needs — more than 10 times its $2.2 million annual budget — and received a $10.22 million state bond to replace its wastewater plant, water main, and wells. None of that bond funding was earmarked for cybersecurity.
  • August 2026 — CISA issued a joint advisory warning of an active threat targeting Siemens S7 series programmable logic controllers (PLCs), hardware used across sewer systems, hospitals, and other industrial operations — underscoring that the exposure extends well beyond water utilities alone.

Proposed Mechanism: Three Tax Levers

The op-ed identifies three specific tax provisions Congress could clarify or extend to cybersecurity purchases:

  1. Bonus depreciation — extending eligibility to cybersecurity software and hardware, letting utilities immediately deduct a large share of the purchase cost rather than depreciating it over years.
  2. Full expensing for digital infrastructure — allowing the entire cost of qualifying cybersecurity technology to be written off in the year it is purchased.
  3. Section 174A expense clarification — explicitly confirming that cybersecurity software implementation costs qualify for immediate expensing rather than being treated as a capitalized, multi-year expenditure.

None of these require new spending authority. The pitch is regulatory clarity: confirm that existing OBBB language covers cybersecurity purchases, and municipal budgets — and the vendors who sell to them — can act on it immediately.

The Underlying Funding Gap

The op-ed cites two data points to establish scale. A survey of state chief information security officers found a plurality reporting stagnant or reduced cybersecurity budgets for 2026 — even as the threat landscape for critical infrastructure intensifies. Separately, a 2024 Center for Internet Security survey of thousands of local government agencies found that roughly one-third conducted "minimal to no cybersecurity activities" at all. Against that backdrop, the authors argue, a tax-code fix that costs the federal government little in direct outlay is a pragmatic bridge until larger structural funding is available.


Impact Assessment

Impact AreaDescription
Funding SpeedTax incentives could let utilities acquire cybersecurity tooling within a single fiscal year, versus multi-year federal grant timelines
Budget ReliefCould partially offset the stagnant-to-reduced cybersecurity budgets state CISOs report for 2026
OT/ICS ExposureDoes not directly remediate PLC-level vulnerabilities like those in the Siemens S7 advisory, but could fund the monitoring and detection tools needed to catch exploitation attempts
Adoption EquityBenefits skew toward utilities with tax liability and capital budgets large enough to leverage depreciation — the smallest municipal systems, like the $3.37 million-revenue Texas town, may see limited practical benefit without additional guidance
Policy UncertaintyThe incentives are only useful once Congress or Treasury issues explicit clarifying guidance; ambiguity in current OBBB language is itself the bottleneck the op-ed is trying to solve
Infrastructure vs. Security TradeoffBond and infrastructure funding (e.g., Braham's $10.22 million bond) continues to be allocated for physical plant needs with no parallel cybersecurity line item, a pattern the op-ed says tax policy could correct without competing for the same dollars

Recommendations

For State and Local Officials

  • Inventory current OT/ICS assets (SCADA, PLCs, remote telemetry) at every water and wastewater facility, and identify which are internet-facing or remotely accessible.
  • Do not assume infrastructure bonds or state grants cover cybersecurity — explicitly request or budget a cybersecurity line item separate from physical plant upgrades.
  • Track OBBB guidance from Treasury and the IRS; if depreciation and expensing provisions are clarified to cover cybersecurity purchases, be ready to act within the same budget cycle.

For Water Utility Operators and OT/ICS Teams

  • Segment PLCs and other OT devices from IT networks and the public internet; devices like the Siemens S7 series named in the August 2026 CISA advisory should not be directly internet-accessible.
  • Apply CISA advisories for industrial control system products as a standing operational checklist, not a one-time read.
  • Where budget allows, prioritize basic monitoring and multi-factor authentication for remote access to water system controls — the Texas and Minnesota incidents both involved intrusion into systems with minimal safeguards.

For Congress and Policymakers

  • Issue explicit guidance confirming cybersecurity software and hardware qualify for bonus depreciation, full expensing, and Section 174A treatment under the OBBB.
  • Pair tax-code clarification with continued support for direct grant programs — the op-ed frames tax incentives as a faster bridge, not a replacement for structural federal investment in state and local cybersecurity.
  • Consider size-adjusted incentives or refundable credit mechanisms so that the smallest municipal utilities, which often have little or no tax liability to offset, are not left out of a depreciation-based approach.

Key Takeaways

  1. A CyberScoop op-ed by Joshua Levine and Lars Erik Schönander proposes using existing One Big Beautiful Bill tax provisions — bonus depreciation, full expensing, and Section 174A clarification — to fund state and local water utility cybersecurity faster than new federal programs could.
  2. US water systems remain a recurring target: Russian-affiliated actors caused a Texas water tank overflow in 2024, and Iranian-affiliated actors targeted four Minnesota cities in 2026, including Braham.
  3. Braham, Minnesota illustrates the structural funding gap — a $10.22 million state bond covered physical infrastructure but included no cybersecurity funding, despite $22.98 million in identified needs.
  4. A CISA advisory from August 2026 flagged active exploitation targeting Siemens S7 series PLCs used across sewers, hospitals, and industrial facilities, broadening the exposure beyond water utilities alone.
  5. Survey data cited in the op-ed shows a plurality of state CISOs reporting stagnant or reduced 2026 cybersecurity budgets, and roughly one-third of local agencies (per a 2024 Center for Internet Security survey) conducting minimal to no cybersecurity activity.
  6. The proposal requires no new federal spending program — only regulatory clarity — but its benefit is skewed toward utilities with enough capital budget or tax liability to use depreciation-based incentives, leaving the smallest systems potentially underserved without further adjustment.

Sources

  • CyberScoop: How tax policy can stop threat actors from breaching US water systems
#Critical Infrastructure#Policy#Water Systems#Tax Incentives#State & Local Government#OT Security

Related Articles

Senate Democrats Introduce Water Cyber Shield Act to Fund $300M Annual Water System Cybersecurity

Senators Schiff and Klobuchar introduce legislation directing $300 million per year to secure U.S. water and wastewater infrastructure following coordinated Iranian-linked attacks on municipal systems across 12 states.

5 min read

Iran, Russia, and China Target Water Systems for Sabotage

Nation-state attackers from Iran, Russia, and China are breaching water utility systems through weak passwords, exposed PLCs, and poor network...

5 min read

After Water Attacks, Congress Pitches Its Own AI Cyber Defense Pilot

Gottheimer's $100M CISA bill would give water utilities free AI tools, rivaling the White House's Texas pilot.

7 min read
Back to all News