{"database": "press", "table": "releases", "rows": [["https://www.cotton.senate.gov/news/press-releases/cotton-to-bessent-protect-critical-infrastructure-from-cyberattacks", "Cotton to Bessent: Protect Critical Infrastructure from Cyberattacks", "2026-08-05", "2026", "2026-08", "Republican", "Senate", "AR", "Tom Cotton", "C001095", "www.cotton.senate.gov", "cotton", "https://www.cotton.senate.gov/news/press-releases", "scraper", "FOR IMMEDIATE RELEASE\n\nContact: Tatum Wallace or Hannah McCarthy\n\nAugust 5, 2026\n\nCotton to Bessent: Protect Critical Infrastructure from Cyberattacks\n\nWASHINGTON \u2014 Senator Tom Cotton (R-Arkansas) sent a letter to Treasury Secretary Scott Bessent asking him to ensure federal tax guidance encourages investment in and modernization of American operational technology, which is the hardware and software that controls critical infrastructure. This technology is underfunded and outdated, leaving vital infrastructure like water systems, power facilities, and industrial plants, particularly in rural states like Arkansas, vulnerable to cyberattacks by our adversaries.\n\nIn part, Senator Cotton wrote:\n\n\u201cAttacks on civilian infrastructure have become a routine instrument of modern warfare, and American operational technology is a target. I write concerning federal tax guidance that discourages the investment needed to defend it.\n\nOperational technology is the hardware and software that directly controls physical systems, including the sensors that regulate the chemical mix safeguarding our drinking water and the controllers running a turbine or a processing line. These controllers were invented in the 1960s and still rely on protocols designed for isolated plants, not for today\u2019s interconnected environment.\u201d\n\nFull text of the letter may be found here and below.\n\nAugust 05, 2026\n\nThe Honorable Scott Bessent\n\nSecretary\n\nU.S. Department of the Treasury\n\n1500 Pennsylvania Avenue, NW\n\nWashington, D.C. 20220\n\nDear Secretary Bessent:\n\nAttacks on civilian infrastructure have become a routine instrument of modern warfare, and American operational technology is a target. I write concerning federal tax guidance that discourages the investment needed to defend it.\n\nOperational technology is the hardware and software that directly controls physical systems, including the sensors that regulate the chemical mix safeguarding our drinking water and the controllers running a turbine or a processing line. These controllers were invented in the 1960s and still rely on protocols designed for isolated plants, not for today\u2019s interconnected environment.\n\nThe United States is already under attack. Chinese state-sponsored hackers spent nearly a year inside a New England utility and obtained its operational technology procedures and grid layout data. In April 2026, the Cybersecurity and Infrastructure Security Agency confirmed that Iranian actors exploited programmable logic controllers across American critical infrastructure. Most recently, a coordinated cyberattack disrupted operational technology at more than 30 community water systems in Minnesota. Preliminary assessments point to Iranian-linked hackers.\n\nThose who carry the greatest risk are least able to manage it. Arkansas has roughly 670 community water systems primarily serving small rural populations. Most cannot employ even one security engineer. With your assistance, we can make better use of existing incentives in the tax code that will strengthen our critical infrastructure. I therefore request the Department:\n\nConfirm that developing security software for industrial control systems qualifies as research under section 41. A company writing code to detect an intruder inside a water plant's controls is doing research in the ordinary sense of the word. The tax code rewards research, but it is unclear whether this research qualifies, which discourages the necessary investments in operational technology security.\n\nEstablish a safe harbor for cybersecurity service agreements with publicly owned utilities under section 7701(e). Small public systems cannot hire their own security staff and must contract with outside firms. Under current rules, these contracts can be treated as equipment leases, forcing the vendor's equipment onto a fifty-year write-off, which pushes vendors away from servicing rural areas. The Department can end this uncertainty by clarifying that cybersecurity monitoring contracts with public utilities are treated as services, not long-term equipment leases.\n\nExtend the existing utility exception in Treasury Regulation \u00a71.168(k)-2(b)(2)(ii)(F) to service providers as well as lessors. The current exception protects a company that leases security equipment to a utility, but a company that retains ownership and sells monitoring services receives no such protection, even though the work is essentially identical. The distinction steers small systems away from these arrangements.\n\nI look forward to working with you on this matter and stand ready to discuss further.\n\nSincerely,\n\nTom Cotton\n\nUnited States Senator\n\n###", 1, "2026-08-06T07:37:31Z", "2026-08-06T07:38:34Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.cotton.senate.gov/news/press-releases/cotton-to-bessent-protect-critical-infrastructure-from-cyberattacks"], "units": {}, "query_ms": 0.7618891540914774, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}