Skip to content
← Back to feed
Tom Cotton (R-AR)
Tom Cotton
Republican·Arkansas

Cotton to Bessent: Protect Critical Infrastructure from Cyberattacks

FOR IMMEDIATE RELEASE Contact: Tatum Wallace or Hannah McCarthy August 5, 2026 Cotton to Bessent: Protect Critical Infrastructure from Cyberattacks WASHINGTON — Senator Tom Cotton (R-Arkansas) sent a letter to Treasury Secretary Scott Bessent asking him to ensure federal tax guidance encourages investment in and modernization of American operational technology, which is the hardware and software that controls critical infrastructure. This technology is underfunded and outdated, leaving vital infrastructure like water systems, power facilities, and industrial plants, particularly in rural states like Arkansas, vulnerable to cyberattacks by our adversaries. In part, Senator Cotton wrote: “Attacks on civilian infrastructure have become a routine instrument of modern warfare, and American operational technology is a target. I write concerning federal tax guidance that discourages the investment needed to defend it. Operational technology is the hardware and software that directly controls physical systems, including the sensors that regulate the chemical mix safeguarding our drinking water and the controllers running a turbine or a processing line. These controllers were invented in the 1960s and still rely on protocols designed for isolated plants, not for today’s interconnected environment.” Full text of the letter may be found here and below. August 05, 2026 The Honorable Scott Bessent Secretary U.S. Department of the Treasury 1500 Pennsylvania Avenue, NW Washington, D.C. 20220 Dear Secretary Bessent: Attacks on civilian infrastructure have become a routine instrument of modern warfare, and American operational technology is a target. I write concerning federal tax guidance that discourages the investment needed to defend it. Operational technology is the hardware and software that directly controls physical systems, including the sensors that regulate the chemical mix safeguarding our drinking water and the controllers running a turbine or a processing line. These controllers were invented in the 1960s and still rely on protocols designed for isolated plants, not for today’s interconnected environment. The United States is already under attack. Chinese state-sponsored hackers spent nearly a year inside a New England utility and obtained its operational technology procedures and grid layout data. In April 2026, the Cybersecurity and Infrastructure Security Agency confirmed that Iranian actors exploited programmable logic controllers across American critical infrastructure. Most recently, a coordinated cyberattack disrupted operational technology at more than 30 community water systems in Minnesota. Preliminary assessments point to Iranian-linked hackers. Those who carry the greatest risk are least able to manage it. Arkansas has roughly 670 community water systems primarily serving small rural populations. Most cannot employ even one security engineer. With your assistance, we can make better use of existing incentives in the tax code that will strengthen our critical infrastructure. I therefore request the Department: Confirm that developing security software for industrial control systems qualifies as research under section 41. A company writing code to detect an intruder inside a water plant's controls is doing research in the ordinary sense of the word. The tax code rewards research, but it is unclear whether this research qualifies, which discourages the necessary investments in operational technology security. Establish a safe harbor for cybersecurity service agreements with publicly owned utilities under section 7701(e). Small public systems cannot hire their own security staff and must contract with outside firms. Under current rules, these contracts can be treated as equipment leases, forcing the vendor's equipment onto a fifty-year write-off, which pushes vendors away from servicing rural areas. The Department can end this uncertainty by clarifying that cybersecurity monitoring contracts with public utilities are treated as services, not long-term equipment leases. Extend the existing utility exception in Treasury Regulation §1.168(k)-2(b)(2)(ii)(F) to service providers as well as lessors. The current exception protects a company that leases security equipment to a utility, but a company that retains ownership and sells monitoring services receives no such protection, even though the work is essentially identical. The distinction steers small systems away from these arrangements. I look forward to working with you on this matter and stand ready to discuss further. Sincerely, Tom Cotton United States Senator ###

Source: https://www.cotton.senate.gov/news/press-releases/cotton-to-bessent-protect-critical-infrastructure-from-cyberattacks
Captured:
Last seen live:
Record ID: 5eec0a77-2415-4444-80a2-1c88b329371c

Issued within 24 hours

Other senators' releases published in the day before or after this one.