The foundation for modern society in America is under attack. State and local governments, entities that often oversee critical natural resources, schools, and hospital systems, are routinely targeted and breached by state-backed threat actors. Their budgets are simply too slim to provide the digital bulwarks required to fend off such attacks.
The problem is growing. In August, the Cybersecurity and Infrastructure Security Agency issued a joint advisory detailing an “active threat” against Siemens S7 series programmable logic controllers (PLCs), ruggedized industrial devices that read field sensors, execute control logic on a fixed cycle, and drive equipment like valves, motors, and pumps. Siemens S7 PLCs, widely used across industries, are under attack from malicious actors looking to sabotage American infrastructure vital to the functioning of sewers, hospitals, and other industrial operations.
In 2024, Russian-affiliated actors exploited a similar vulnerability, breaching the water system for a small town in Texas, causing the water tank to overflow. The town’s entire revenue in 2023 was $3.37 million, with no dedicated line item for cybersecurity. This was, in effect, a trial run. How and when the detection occurred was an education for the Russians.
American state and local governments are unlikely to organically grow their budgets to the level needed to invest in software that can reliably secure their infrastructure. The U.S. government has a proven option here: clarify that existing tax code already supports increased, iterative purchases of necessary cybersecurity software.
State and local governments are increasingly responsible for cybersecurity, with the same, or even fewer, resources than they had in the past. A plurality of state chief information security officers reported stagnant or reduced cybersecurity budgets for 2026. The picture at the local level is often worse, where a single operator often owns asset inventory, patching, and incident response for an entire utility. The Center for Internet Security in 2024 found that, out of the thousands of local agencies it surveyed, about one-third were doing minimal to no cybersecurity activities. In Minnesota, specifically Braham, Plymouth, South St. Paul, and Maple Plain, threat actors used this to their advantage.
Braham in particular identified $22.98 million in water infrastructure needs, well over 10 times its annual city budget of $2.2 million. A state bond appropriation covered $10.22 million, but the money was earmarked for a wastewater treatment plant upgrade, water main replacement, and well replacement. None of these funds covered the cybersecurity infrastructure needed to secure a plant from a state-backed threat actor: no security software, no network monitoring, no cybersecurity staff. Last month, they were one of many cities and municipalities discovered to have been targeted by actors allegedly acting on behalf of Iran.
State-backed adversaries understand that most of America is like Braham. While Anthropic’s and OpenAI’s cybersecurity efforts are admirable, they are aimed at the upper echelons of the American economy, not the wider array of smaller organizations with similar cybersecurity profiles.
State and local governments cannot defend against state-backed actors alone. Federal tax incentives for cybersecurity software investment offer a faster solution than creating new government programs. This approach gives these organizations the tools to harden infrastructure while avoiding bureaucratic delays.
Bonus depreciation under the One Big Beautiful Bill should cover cybersecurity software and hardware. Digital infrastructure should also qualify for full expensing. Without these tax incentives, critical infrastructure remains vulnerable. A new factory without cybersecurity is essentially undefended.
Clarity on whether the implementation of cybersecurity software could apply to Section 174A expenses would also be useful. An affirmative interpretation could unlock private sector cybersecurity solutions for businesses and infrastructure operators, particularly those in rural areas. A recent letter from Sen. Tom Cotton to Treasury Secretary Scott Bessent asks for clarification of several aspects of tax law for such a purpose.
There are discoveries and risks when deploying new cybersecurity tools. Organizations often don’t know the scope of their own inventory, and given the age of the equipment, bespoke software needs to be developed so customers can use the cybersecurity software. Pilot programs, iterative testing, and development are currently cost-prohibitive for many infrastructure operators. Affirmative interpretations could make this emergent threat into an opportunity to secure the infrastructure that Americans depend on every day.
An affirmative interpretation would benefit all Americans. State and local governments would protect themselves from state-backed threat actors. Firms would be more willing to invest in cybersecurity software, as the cybersecurity software market would grow significantly. Rapid investment is needed now, as AI today is being used to attack critical infrastructure.
State and local governments now, more than ever, need cybersecurity software to face a world where they are on the front lines of cyberwarfare. The current administration needs to provide them with as much support as quickly as possible to ensure that American critical infrastructure is not reduced to scrap by enterprising malicious actors.

