Security1 publisher2 min readPublished
Actors allegedly working for Iran targeted a Minnesota city. Its water needs are 10 times its budget
Braham, Minnesota has identified $22.98 million in water infrastructure needs on a $2.2 million annual city budget. The $10.22 million state bond it received cannot pay for security software, network monitoring or staff.
The Watch · Security desk

What happened
- CISA's joint advisory in August described an "active threat" against Siemens S7 series programmable logic controllers, the devices that read field sensors and drive valves, motors and pumps.
- Braham, Plymouth, South St. Paul and Maple Plain in Minnesota were among many municipalities discovered last month to have been targeted by actors allegedly acting on behalf of Iran.
- The Center for Internet Security found in 2024 that about one-third of the thousands of local agencies it surveyed were doing minimal to no cybersecurity activities.
- A plurality of state chief information security officers reported stagnant or reduced cybersecurity budgets for 2026.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Braham's next security purchase has to get written into an appropriation that currently names a wastewater plant, water mains and wells, so the choice between monitoring and a well replacement sits with whoever drafts the bond language.
- contradiction The relief on offer runs through the tax code, and the op-ed frames the Section 174A payoff as unlocking private sector solutions for businesses and infrastructure operators. In its own examples, the municipal utilities appear as victims.
- exposure A utility where one person owns asset inventory, patching and incident response cannot cover a shift pattern, so detection depends on that person being on duty and looking at the right console.
- precedent If the 2024 Texas overflow was reconnaissance, the attacker's takeaway was detection timing, and that intelligence stays useful long after the tank is drained.
Braham's figures set the floor for what a small utility can buy. The city put its water infrastructure needs at $22.98 million and runs on an annual budget of $2.2 million [12]. The state appropriated $10.22 million in bond money, earmarked for a wastewater treatment plant upgrade, water main replacement and well replacement [13]. That leaves $12.76 million of identified water need unfunded [15]. The ratio of need to budget is about 10.4 to 1 [16].
The Texas case is tighter still. In the op-ed's account, the town's entire 2023 revenue was $3.37 million, with no dedicated line item for cybersecurity [5]. In 2024, it says, Russian-affiliated actors exploited a vulnerability similar to the Siemens S7 issue, breached that water system and caused the tank to overflow [4]. "This was, in effect, a trial run," the op-ed says, and adds that how and when the detection occurred was an education for the Russians [6].
The federal remedy on offer is tax treatment. The piece argues that bonus depreciation under the One Big Beautiful Bill should cover cybersecurity software and hardware, and that digital infrastructure should qualify for full expensing [17]. It also wants Treasury to clarify Section 174A, on the argument that an affirmative interpretation could "unlock private sector cybersecurity solutions for businesses and infrastructure operators, particularly those in rural areas" [18]. Tax incentives, it says, are faster than creating new government programs [21].
The op-ed does not explain how a depreciation deduction or an expensing election reaches a city general fund [22]. Both of its worked examples are municipal: the Texas town at $3.37 million in total revenue and Braham at $2.2 million a year [5][12].
There is a sequencing problem inside the remedy as well. Organizations often do not know the scope of their own inventory, and the age of the equipment means bespoke software has to be developed [20]. New money has to buy an asset inventory before it can buy a monitoring license.
Sen. Tom Cotton has written to Treasury Secretary Scott Bessent asking for clarification of several aspects of tax law for this purpose [19].
What to watch
- Whether Treasury answers Cotton's letter with guidance that names cybersecurity software under Section 174A, and whether municipal buyers are in scope at all.
- Whether attribution of the Minnesota targeting moves from actors "allegedly acting on behalf of Iran" to a named group with published indicators.
- Whether Braham's next bond appropriation carries a security line, or whether the $12.76 million residual is spent entirely on pipes and wells.