Congress Is Being Urged to Redirect Existing Tax Code, Not Wait on New Funding, to Secure Water Utilities
A September 24, 2026 op-ed published by CyberScoop, authored by Joshua Levine and Lars Erik Schönander, argues that the fastest way to harden America's water systems against nation-state hackers is not a new federal grant program but a clarification of tax provisions that are already on the books. The piece contends that new cybersecurity funding mechanisms take years to authorize, appropriate, and disburse, while state and local water utilities are being actively targeted right now. Its proposed fix: have Congress explicitly confirm that bonus depreciation under the One Big Beautiful Bill (OBBB) and Section 174A expensing provisions cover cybersecurity software and hardware purchases, letting municipalities and their private-sector vendors write off security investments immediately instead of over multi-year depreciation schedules.
The op-ed lands amid a documented surge in attacks on the water sector. Water and wastewater ransomware incidents rose 500% between 2021 and 2025, according to FBI Internet Crime Complaint Center data, and in July and August 2026 a coordinated hacking campaign — attributed by federal officials to Iranian-affiliated actors — hit municipal water systems in at least 12 states, including Minnesota, Michigan, Alabama, Arkansas, Georgia, South Dakota, and New Jersey.
Details
| Attribute | Value |
|---|---|
| Source | CyberScoop op-ed, published September 24, 2026 |
| Authors | Joshua Levine, Lars Erik Schönander |
| Proposed mechanism | Clarify that OBBB bonus depreciation and Section 174A expensing cover cybersecurity software/hardware |
| Target sector | State and local water and wastewater utilities |
| Cited 2024 incident | Russian-affiliated actors breached a small Texas town's water system, causing a tank overflow; the municipality's entire 2023 budget was $3.37 million with no dedicated cybersecurity line item |
| Cited 2026 incident | Iranian-affiliated actors targeted Braham, Plymouth, South St. Paul, and Maple Plain, Minnesota; Braham alone identified $22.98 million in infrastructure needs against a $2.2 million annual budget |
| PLC advisory | CISA issued an advisory in August 2026 on active threats against internet-facing Siemens S7 programmable logic controllers |
| Budget context | A plurality of state CISOs reported stagnant or reduced cybersecurity budgets heading into 2026 |
| Sector baseline | The Center for Internet Security found roughly one-third of surveyed local agencies conducting minimal-to-no cybersecurity activity (2024) |
Why Water Systems Keep Getting Targeted
Thousands of Under-Resourced, Independently Governed Targets
The US water sector is not one network — it is roughly 50,000 community water systems, most run by small municipal governments, rural cooperatives, or regional authorities with no shared security operations center and no consolidated IT budget. Unlike large utilities with dedicated OT security teams, a town the size of the Texas municipality cited in the op-ed — annual revenue of $3.37 million — has no realistic path to fund a modern security program from its own tax base. That fragmentation is precisely what makes the sector an attractive, low-cost target: a single misconfigured, internet-exposed PLC can be enough.
Internet-Facing Industrial Controllers Remain Easy Entry Points
Both the 2024 Texas overflow incident and the July-August 2026 campaign against Minnesota and other states followed the same pattern federal agencies have warned about for years: threat actors scanning for exposed programmable logic controllers — Rockwell Automation/Allen-Bradley MicroLogix 1100/1400 units in the 2026 campaign, Siemens S7 controllers in the CISA advisory the op-ed cites — that were never meant to be reachable from the open internet, often left with default or weak credentials. These are not sophisticated intrusions; they are opportunistic sweeps that succeed because the underlying OT hardware was deployed without basic network segmentation.
Geopolitical Signaling Value
Federal officials have attributed the 2024 Texas incident to Russian-affiliated actors and the 2026 multi-state campaign to Iranian-affiliated actors — both cases where the disruption of a small town's water utility carries outsized geopolitical signaling value relative to the technical effort required. A tank overflow or a forced switch to manual operations makes headlines and demonstrates reach into US critical infrastructure, even when — as officials stressed after the 2026 campaign — no contamination or public health impact occurred.
Budgets That Can't Keep Pace With the Threat
The op-ed's central data point is structural, not technical: Braham, Minnesota identified $22.98 million in infrastructure needs against a town budget of $2.2 million a year. No amount of security awareness training closes a gap that size. State CISOs surveyed for 2026 reported budgets that are, at best, flat — while the threat landscape they're defending against has escalated to nation-state-linked campaigns spanning a dozen states in a single summer.
Impact Assessment
| Impact Area | Description |
|---|---|
| Public safety | Water treatment and distribution systems are safety-critical; disruption risks contamination, service outages, or forced manual operation with reduced safety margins |
| Municipal finances | Small utilities face incident response, remediation, and potential liability costs far exceeding their annual operating budgets |
| National security posture | Nation-state-linked actors (Russian- and Iranian-affiliated groups cited in the op-ed) treat water systems as low-cost, high-visibility targets for demonstrating reach into US infrastructure |
| Policy timeline risk | New appropriated grant programs can take multiple budget cycles to authorize and disburse, leaving a multi-year gap during which utilities remain exposed |
| Private-sector security market | Ambiguity in how OBBB bonus depreciation and Section 174A apply to cybersecurity spend discourages vendors and utilities from committing to security purchases now |
| Precedent for other sectors | A tax-based fix for water-sector cybersecurity could become a template for similarly under-resourced sectors — rural hospitals, small electric cooperatives — facing the same budget-versus-threat mismatch |
Recommendations
For Congress and Federal Policymakers
- Issue explicit Treasury/IRS guidance clarifying that cybersecurity software and hardware purchases by state and local infrastructure operators and their vendors qualify for OBBB bonus depreciation.
- Clarify Section 174A expensing rules to permit full, immediate expensing of cybersecurity implementation costs rather than multi-year capitalization.
- Continue advancing sector-specific legislative efforts already in motion — including bills aimed at establishing baseline cybersecurity requirements for drinking water and wastewater systems — as a complement to, not a substitute for, faster tax-based incentives.
- Treat tax-code clarification as a bridge measure: it can move markedly faster than a new appropriated grant program, buying time while longer-term funding mechanisms are negotiated.
For State and Local Water Utility Operators
- Inventory every internet-facing PLC and OT device today; the 2026 campaign and the CISA S7 advisory both exploited controllers that should never have been directly reachable from the internet.
- Apply basic network segmentation between IT and OT environments, and remove default or shared credentials from industrial controllers immediately — the entry point in the cited incidents was rarely sophisticated.
- Engage a tax professional or managed security provider now to understand how existing (and any newly clarified) depreciation and expensing provisions could offset planned security purchases.
- Participate in EPA and CISA vulnerability assessment programs; EPA's Office of Water has proactively identified and helped remediate issues at hundreds of systems this year at no direct cost to the utility.
For Security Teams Supporting the Sector
- Prioritize low-cost, high-impact controls (network segmentation, credential hygiene, removing unnecessary internet exposure) over expensive platform purchases when advising resource-constrained municipal clients.
- Build proposals utilities can bring to their councils and boards that explicitly reference available tax treatment, not just security benefit, to improve the odds of budget approval.
Key Takeaways
- The op-ed's central proposal — clarifying that OBBB bonus depreciation and Section 174A expensing cover cybersecurity purchases — uses existing tax code rather than new appropriated funding, which the authors argue can move far faster.
- A 2024 Texas water system breach, attributed to Russian-affiliated actors, occurred in a town with a $3.37 million annual budget and no cybersecurity line item.
- A July-August 2026 campaign attributed to Iranian-affiliated actors hit water systems in at least 12 states; Braham, Minnesota alone faces $22.98 million in infrastructure needs against a $2.2 million budget.
- Water-sector ransomware incidents rose 500% from 2021 to 2025, according to FBI data, while a plurality of state CISOs report stagnant or reduced cybersecurity budgets for 2026.
- Attackers have repeatedly exploited internet-facing industrial controllers — Rockwell Automation/Allen-Bradley MicroLogix units and Siemens S7 PLCs — rather than sophisticated intrusion techniques.
- The proposal is positioned as a near-term bridge measure, meant to complement (not replace) longer-term legislative efforts to set baseline cybersecurity requirements for the water sector.