VYPR
advisoryPublished Sep 24, 2026· 1 source

Federal Tax Incentives Proposed to Bolster Cybersecurity for US Water Systems

A new op-ed suggests federal tax incentives for cybersecurity hardware and software purchases to help underfunded state and local governments defend critical infrastructure like water systems from state-backed adversaries.

State and local governments, responsible for vital public services such as water systems, schools, and hospitals, are increasingly becoming targets for sophisticated, state-backed threat actors. These entities often operate with insufficient budgets, leaving their critical infrastructure vulnerable to cyberattacks. A recent advisory from the Cybersecurity and Infrastructure Security Agency (CISA) highlighted an active threat against Siemens S7 series programmable logic controllers (PLCs), which are widely used in industrial operations to control equipment like pumps and valves. These PLCs are crucial for the functioning of essential services, making them prime targets for malicious actors seeking to cause disruption.

In 2024, threat actors, including those affiliated with Russia, have exploited vulnerabilities to breach water systems in several U.S. states. One notable incident involved a small town in Texas where attackers compromised its water system, leading to an overflow of a water tank. The town's limited annual revenue underscores the financial challenges faced by many local governments in affording robust cybersecurity measures. These attacks are not isolated incidents but rather serve as "trial runs" for adversaries to learn about detection capabilities and system vulnerabilities.

The article argues that state and local governments are unlikely to organically increase their cybersecurity budgets to the necessary levels. A significant portion of state chief information security officers have reported stagnant or reduced cybersecurity budgets, and the situation is often more dire at the local level, where a single individual may be responsible for all aspects of IT security. A survey by the Center for Internet Security found that about one-third of surveyed local agencies were engaged in minimal to no cybersecurity activities.

This lack of resources leaves critical infrastructure exposed. In Minnesota, for example, several municipalities, including Braham, were targeted by actors allegedly acting on behalf of Iran. Braham's significant water infrastructure needs far outstripped its annual city budget, and even funds allocated for upgrades were earmarked for physical infrastructure, not cybersecurity. This leaves essential systems without security software, network monitoring, or dedicated cybersecurity staff, making them easy targets for well-resourced state-sponsored groups.

The proposed solution centers on leveraging existing federal tax policy. The op-ed suggests clarifying that the U.S. tax code already supports increased, iterative purchases of necessary cybersecurity software and hardware. Specifically, it advocates for cybersecurity software and hardware to qualify for bonus depreciation under the One Big Beautiful Bill and for digital infrastructure to be eligible for full expensing. Such measures would provide a more immediate and effective solution than the creation of new, potentially bureaucratic government programs.

Furthermore, clarity on whether the implementation of cybersecurity software can apply to Section 174A expenses could unlock private sector solutions for businesses and infrastructure operators, particularly in rural areas. A letter from Senator Tom Cotton to Treasury Secretary Scott Bessent has already sought clarification on these tax law aspects. The ability to pilot, iteratively test, and develop bespoke cybersecurity solutions is currently cost-prohibitive for many infrastructure operators, and tax incentives could alleviate this burden.

Implementing these tax incentives would not only help state and local governments defend themselves against state-backed threat actors but also stimulate the cybersecurity market. As AI is increasingly used to attack critical infrastructure, rapid investment in security is paramount. By making cybersecurity investments more financially accessible, the U.S. can better protect the essential services Americans depend on daily from evolving cyber threats.

The article concludes by emphasizing the urgent need for the current administration to provide support to state and local governments, who are on the front lines of cyber warfare. Without swift action and financial assistance through tax incentives, critical American infrastructure remains at risk of being compromised by malicious actors.

Synthesized by Vypr AI