Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • AI Agents Engaged in Malicious Cyber Activity During U.K. Tests
    • Appeals Court Agrees to Quickly Rule on Fired Privacy Board Members
    • Bipartisan House Report: FCC Needs More Power to Expel Chinese Carriers From U.S.
    • C.D. Ill.: Court allows class action to proceed against hospital, whose website allegedly intercepted, disclosed patient data to third parties without authorization
    • Cotton Wants to Use Tax Incentives to Boost Cyber Defenses of Water Utilities
    • Privacy Advocate Advises App Developers to Protect Location Data
    • Senate Approves Foreign Robocall Elimination Act
    • Senate Commerce Committee Advances Online, AI Safety Bills
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Cotton Wants to Use Tax Incentives to Boost Cyber Defenses of Water Utilities, (Aug 5, 2026)

    By Tom Leithauser

    The Treasury Department should help rural water utilities improve their cyber defenses by issuing federal tax guidance that would save the utilities money when they hire cybersecurity contractors, Sen. Tom Cotton (R., Ark.) said today.

    In a letter to ...

    By Tom Leithauser

    The Treasury Department should help rural water utilities improve their cyber defenses by issuing federal tax guidance that would save the utilities money when they hire cybersecurity contractors, Sen. Tom Cotton (R., Ark.) said today.

    In a letter to Treasury Secretary Scott Bessent, Sen. Cotton, chairman of the Senate Intelligence Committee, noted that a recent wave of attacks on the operational technologies used by water utilities had disrupted municipal water systems (CPR, July 31).

    “Those who carry the greatest risk are least able to manage it. Arkansas has roughly 670 community water systems primarily serving small rural populations. Most cannot employ even one security engineer. With your assistance, we can make better use of existing incentives in the tax code that will strengthen our critical infrastructure,” he told Mr. Bessent.

    He recommended that the Treasury Department confirm that development of security software for industrial control systems qualified as “research.”

    “A company writing code to detect an intruder inside a water plant's controls is doing research in the ordinary sense of the word. The tax code rewards research, but it is unclear whether this research qualifies, which discourages the necessary investments in operational technology security,” he said.

    In addition, contracts between water utilities and providers of cybersecurity monitoring services should not be treated as “long-term equipment leases” for tax purposes, Sen. Cotton advised.

    “Small public systems cannot hire their own security staff and must contract with outside firms. Under current rules, these contracts can be treated as equipment leases, forcing the vendor's equipment onto a fifty-year write-off, which pushes vendors away from servicing rural areas,” he said.

    “The Department can end this uncertainty by clarifying that cybersecurity monitoring contracts with public utilities are treated as services, not long-term equipment leases,” he told Mr. Bessent.

    A third change to help utilities’ cyber defenses, Sen. Cotton said, would be the expansion of “the existing utility exception in Treasury Regulation §1.168(k)-2(b)(2)(ii)(F) to service providers as well as lessors.”

    “The current exception protects a company that leases security equipment to a utility, but a company that retains ownership and sells monitoring services receives no such protection, even though the work is essentially identical. The distinction steers small systems away from these arrangements,” he explained.

    “Attacks on civilian infrastructure have become a routine instrument of modern warfare, and American operational technology is a target,” he told Mr. Bessent. “I look forward to working with you on this matter and stand ready to discuss further.”

    News: FederalLegislation DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use