Tom Cotton

08/05/2026 | Press release | Distributed by Public on 08/05/2026 08:36

Cotton to Bessent: Protect Critical Infrastructure from Cyberattacks

FOR IMMEDIATE RELEASE
Contact: Tatum Wallace or Hannah McCarthy
August 5, 2026

Cotton to Bessent: Protect Critical Infrastructure from Cyberattacks

WASHINGTON - Senator Tom Cotton (R-Arkansas) sent a letter to Treasury Secretary Scott Bessent asking him to ensure federal tax guidance encourages investment in and modernization of American operational technology, which is the hardware and software that controls critical infrastructure. This technology is underfunded and outdated, leaving vital infrastructure like water systems, power facilities, and industrial plants, particularly in rural states like Arkansas, vulnerable to cyberattacks by our adversaries.

In part, Senator Cotton wrote:

"Attacks on civilian infrastructure have become a routine instrument of modern warfare, and American operational technology is a target. I write concerning federal tax guidance that discourages the investment needed to defend it.

Operational technology is the hardware and software that directly controls physical systems, including the sensors that regulate the chemical mix safeguarding our drinking water and the controllers running a turbine or a processing line. These controllers were invented in the 1960s and still rely on protocols designed for isolated plants, not for today's interconnected environment."

Full text of the letter may be found here and below.

August 05, 2026

The Honorable Scott Bessent
Secretary
U.S. Department of the Treasury
1500 Pennsylvania Avenue, NW
Washington, D.C. 20220

Dear Secretary Bessent:

Attacks on civilian infrastructure have become a routine instrument of modern warfare, and American operational technology is a target. I write concerning federal tax guidance that discourages the investment needed to defend it.

Operational technology is the hardware and software that directly controls physical systems, including the sensors that regulate the chemical mix safeguarding our drinking water and the controllers running a turbine or a processing line. These controllers were invented in the 1960s and still rely on protocols designed for isolated plants, not for today's interconnected environment.

The United States is already under attack. Chinese state-sponsored hackers spent nearly a year inside a New England utility and obtained its operational technology procedures and grid layout data. In April 2026, the Cybersecurity and Infrastructure Security Agency confirmed that Iranian actors exploited programmable logic controllers across American critical infrastructure. Most recently, a coordinated cyberattack disrupted operational technology at more than 30 community water systems in Minnesota. Preliminary assessments point to Iranian-linked hackers.

Those who carry the greatest risk are least able to manage it. Arkansas has roughly 670 community water systems primarily serving small rural populations. Most cannot employ even one security engineer. With your assistance, we can make better use of existing incentives in the tax code that will strengthen our critical infrastructure. I therefore request the Department:

  1. Confirm that developing security software for industrial control systems qualifies as research under section 41. A company writing code to detect an intruder inside a water plant's controls is doing research in the ordinary sense of the word. The tax code rewards research, but it is unclear whether this research qualifies, which discourages the necessary investments in operational technology security.
  2. Establish a safe harbor for cybersecurity service agreements with publicly owned utilities under section 7701(e). Small public systems cannot hire their own security staff and must contract with outside firms. Under current rules, these contracts can be treated as equipment leases, forcing the vendor's equipment onto a fifty-year write-off, which pushes vendors away from servicing rural areas. The Department can end this uncertainty by clarifying that cybersecurity monitoring contracts with public utilities are treated as services, not long-term equipment leases.
  3. Extend the existing utility exception in Treasury Regulation §1.168(k)-2(b)(2)(ii)(F) to service providers as well as lessors. The current exception protects a company that leases security equipment to a utility, but a company that retains ownership and sells monitoring services receives no such protection, even though the work is essentially identical. The distinction steers small systems away from these arrangements.

I look forward to working with you on this matter and stand ready to discuss further.

Sincerely,

Tom Cotton
United States Senator

###

Tom Cotton published this content on August 05, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 05, 2026 at 14:36 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]