In 2023 a small town’s entire revenue was $3.37 million — and it carried no dedicated line item for cybersecurity.
Siemens S7 PLCs: an “active threat” to field control
In August, the Cybersecurity and Infrastructure Security Agency issued a joint advisory describing an “active threat” against Siemens S7 series programmable logic controllers (PLCs). Those ruggedized industrial devices read field sensors, execute control logic on a fixed cycle, and drive equipment such as valves, motors, and pumps. The advisory said Siemens S7 PLCs, widely used across industries, were under attack from malicious actors seeking to sabotage infrastructure that supports sewers, hospitals, and other industrial operations.
Two breach vignettes: a Texas water overflow and Minnesota communities
In 2024, Russian-affiliated actors exploited a similar vulnerability and breached the water system for a small Texas town, causing a water tank to overflow. That incident was described in the source material as a “trial run” that educated the attackers on detection and response. Separately, several Minnesota municipalities — Braham, Plymouth, South St. Paul, and Maple Plain — were identified as having been targeted. The source reports that last month those cities were among many discovered to have been targeted by actors allegedly acting on behalf of Iran.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleBudget reality: municipal eyes on pipes, not patches
State and local governments, the organizations that often oversee critical natural resources, schools, and hospitals, are described as routinely targeted and breached while operating on budgets too slim to buy the digital tools necessary to defend against state-backed threat actors. A plurality of state chief information security officers reported stagnant or reduced cybersecurity budgets for 2026. At the local level the picture is worse: the Center for Internet Security in 2024 found that about one-third of the thousands of local agencies it surveyed were doing minimal to no cybersecurity activities. The source cites the example of Braham, Minnesota, which identified $22.98 million in water infrastructure needs against an annual city budget of $2.2 million; a state bond appropriation covered $10.22 million but was earmarked for physical upgrades — a wastewater treatment plant upgrade, water main replacement, and well replacement — and did not cover cybersecurity staff, security software, or network monitoring.
Tax-code fixes offered: bonus depreciation, full expensing, and Section 174A clarity
The source argues that federal tax incentives provide a faster route to increased cybersecurity purchases than creating new programs. It recommends clarifying that existing tax code already supports increased, iterative purchases of cybersecurity software and hardware. Specifically, the piece contends that bonus depreciation under the “One Big Beautiful Bill” should cover cybersecurity software and hardware, and that digital infrastructure should qualify for full expensing. It also calls for clarity on whether implementation and development costs for cybersecurity tools could apply to Section 174A expenses — an affirmative interpretation, the source says, could unlock private-sector cybersecurity solutions for businesses and infrastructure operators, particularly in rural areas.
What this means for technologists, policymakers, and local utilities
- Technologists and security teams: Pilot programs, bespoke integrations, and iterative testing are often necessary because operators do not fully know their asset inventories and must adapt protection to old equipment; the source says those discovery and development costs are currently cost-prohibitive for many operators.
- Policymakers and the Treasury: The source notes a recent letter from Sen. Tom Cotton to Treasury Secretary Scott Bessent requesting clarification on aspects of tax law that could facilitate cybersecurity purchases, signaling legislative interest in a tax-driven approach.
- Local utilities and procurement leaders: With many municipalities lacking dedicated cybersecurity budgets, the source suggests that tax incentives could make vendors more willing to field solutions for smaller customers and expand the cybersecurity software market beyond the largest organizations.
The source also warns that AI is already being used to attack critical infrastructure and that large private-sector cybersecurity efforts — Anthropic’s and OpenAI’s, for example — are directed at the upper echelons of the economy rather than smaller public utilities and municipalities. In that context, the piece concludes that an affirmative, fast-moving tax interpretation could convert an emergent national-security risk into an opportunity to harden the infrastructure Americans rely on every day.
Absent rapid clarification and action, the source argues, many new factories and infrastructure projects will come online effectively undefended; the current administration, the piece says, needs to provide as much support as quickly as possible to prevent American critical infrastructure from being reduced to scrap by enterprising malicious actors.
Original story: https://cyberscoop.com/how-federal-tax-incentives-can-protect-state-local-cybersecurity-op-ed/




