"The United States is already under attack," Sen. Tom Cotton wrote, citing recent assaults on community water systems in Minnesota and an Iran-backed campaign to exploit programmable logic controllers across American critical infrastructure.
Sen. Tom Cotton's appeal to Treasury Secretary Scott Bessent
In a Wednesday letter to Treasury Secretary Scott Bessent, Sen. Tom Cotton, R-Ark., asked the Treasury Department to use existing tax-code tools to spur investment in operational technology (OT) — the hardware and software that underpins U.S. critical infrastructure. Cotton, who has led the Senate Intelligence Committee since the beginning of the second Trump administration, argued federal tax guidance currently “discourages” the investments needed to defend OT as attacks on civilian infrastructure “have become a routine instrument of modern warfare.”
What Cotton says is wrong with operational technology
Cotton framed the problem chiefly as one of underinvestment and obsolescence: OT is “underfunded, outdated and increasingly vulnerable to cyberattacks,” and some controllers “were invented in the 1960s and still rely on protocols designed for isolated plants, not for today’s interconnected environment.” The senator described those who “carry the greatest risk” as the least able to manage it, a dynamic he said is made worse by unclear tax treatment of relevant activity.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadTax-code changes Cotton proposes: Section 41, section 7701(e), and lease exceptions
Cotton asked Treasury to take three concrete steps. First, he requested confirmation that developing security software for industrial control systems qualifies as research under Section 41 of the tax code, on the grounds that “a company writing code to detect an intruder inside a water plant’s controls is doing research in the ordinary sense of the word.”
Second, he urged Treasury to use section 7701(e) to create a “safe harbor” for cybersecurity agreements with public utilities, clarifying that monitoring contracts would be treated as services rather than long-term equipment leases. Finally, he asked Treasury to extend a current exception that protects lessors of security equipment to also cover service providers. Cotton noted that under current law, “lessors are protected, ‘but a company that retains ownership and sells monitoring services receives no such protection, even though the work is essentially identical.’” He added: “The distinction steers small systems away from these arrangements.”
How public utilities, cybersecurity service providers, and the Treasury are implicated
- Public utilities: Utilities running aging controllers and other OT stand to gain clearer tax incentives for modernization and for contracting monitoring services if Treasury accepts Cotton’s suggested interpretations.
- Cybersecurity service providers: Firms that write detection code or offer retained-ownership monitoring services would seek clarity that their work counts as research or as protected services, because Cotton argues current ambiguity “discourages” investment.
- The Treasury Department: Treasury has the administrative authority Cotton asks it to use — including confirmations under Section 41 and application of section 7701(e) safe harbors — and will be asked to decide whether to change guidance or interpretive positions that affect how investments and contracts are taxed.
Next step: an unanswered administrative decision
Cotton did not set a deadline in his letter; he wrote that he “looked forward to working on the matter and stands ‘ready to discuss further.’” That leaves the next concrete step in the hands of Treasury Secretary Scott Bessent and his agency: whether to confirm the Section 41 treatment, to apply section 7701(e) safe-harbor guidance to utility cybersecurity contracts, and to broaden the exception that currently covers equipment lessors to include service providers. Those administrative choices would determine whether the tax code’s present incentives are interpreted in a way that, according to the senator, will encourage the investment he says is needed to secure critical OT.




