ics-ottrade-pressNewsThe Broadside1 min read

Cotton asks Treasury to clarify OT security R&D tax treatment

The tax code already rewards research, but no one can say whether writing intrusion-detection code for a water plant's 1960s-era controllers counts, and that ambiguity is its own deterrent.


TL;DR

Senate Intelligence Committee Chairman Tom Cotton (R-Ark.) wrote Treasury Secretary Scott Bessent on Wednesday asking the department to clarify that OT cybersecurity R&D (including intrusion-detection software for industrial control systems) qualifies for the Section 41 research credit. Cotton also wants a Section 7701(e) safe harbor so cybersecurity monitoring contracts with public utilities are treated as services, not equipment leases, and an extension of the lessor exemption to monitoring-service providers who retain equipment ownership. The letter draws a direct line from ambiguous tax guidance to underinvestment in critical infrastructure defense at a moment when attacks on civilian systems have become routine.

Cotton's letter frames the problem with a specificity that's unusual for congressional tax-correspondence. The controllers running turbines and processing lines across U.S. critical infrastructure were invented in the 1960s "and still rely on protocols designed for isolated plants, not for today's interconnected environment." The tax code offers incentives for research and for equipment leasing, but neither category has been clearly mapped to the cybersecurity work actually being done.

"A company writing code to detect an intruder inside a water plant's controls is doing research in the ordinary sense of the word," Cotton wrote. "The tax code rewards research, but it is unclear whether this research qualifies, which discourages the necessary investments in operational technology security." That's the core asymmetry: the activity plainly meets a lay definition of R&D, but Treasury hasn't said whether it meets the statutory one.

The leasing-versus-services distinction is similarly sharp. Under current rules, a company that leases security equipment to a utility gets tax protection; a company that retains ownership and sells monitoring services for the same equipment doesn't. "The distinction steers small systems away from these arrangements," Cotton noted, and small systems, particularly municipal water utilities, are precisely the ones being targeted.

The letter lands against a backdrop of well-documented attacks: the Minnesota water-system intrusions and an Iran-backed campaign exploiting programmable logic controllers across U.S. infrastructure. Cotton's argument is that the tax code, as applied, is making the defender's job harder than it needs to be. No deadline was set for a response.


Published ·Deep Fathom

Cotton asks Treasury to clarify OT security R&D tax treatment — The Broadside