How AE Tax Advisors Evaluates Whether a Client Should Convert to a C-Corporation

The C-Corporation has been receiving more strategic attention in tax planning conversations since the 2017 Tax Cuts and Jobs Act reduced the federal corporate rate to 21%. For decades before that, the C-Corp was generally avoided by closely-held businesses because of double taxation, corporate-level tax on profits, plus personal-level tax on distributions. The 21% corporate rate changed the math for businesses that don’t need to distribute current earnings out, and the post-2017 tax landscape has seen more closely-held businesses evaluating whether C-Corp structure might be appropriate.

AE Tax Advisors works through the C-Corp conversion analysis with appropriate clients as part of the firm’s entity structuring service line. The analysis is technical, the decision has long-term consequences, and the right answer depends on specific factors that vary across businesses.

The framework for evaluating C-Corp conversion involves several distinct considerations. The first consideration is the retained earnings need. Businesses that need to retain

significant earnings inside the corporation for working capital, capital investment, or growth funding benefit from the 21% corporate rate that applies to those retained earnings. A business that distributes all current-year earnings to owners gets less benefit from the corporate rate because the double-taxation issue becomes more pronounced.

The second consideration is the owner’s marginal tax rate. The C-Corp 21% rate becomes more attractive relative to pass-through structures when the owner’s individual marginal rate is significantly higher. For owners in the top federal bracket plus high-tax states, the differential can be substantial.

The third consideration is the §199A deduction interaction. Pass-through structures (S Corps, partnerships, sole proprietorships) often benefit from the §199A Qualified Business Income deduction, which can reduce the effective pass-through rate significantly. The comparison between the C-Corp 21% rate and the pass-through rate with §199A deduction needs to be done specifically for the client’s situation rather than assumed.

The fourth consideration is the IRC §1202 Qualified Small Business Stock opportunity. C Corporation stock that qualifies for §1202 treatment and is held for more than five years can produce a federal capital gains exclusion of up to $10 million or 10 times basis (whichever is greater) per shareholder. For business owners with potential future exit events that could qualify for §1202, the C-Corp structure can produce dramatic after-tax outcomes that pass-through structures cannot match.

The fifth consideration is the state tax overlay. Different states tax C-Corps and pass-through entities differently. Some states have favorable C-Corp regimes; others penalize them. The state tax analysis is integral to the federal evaluation.

The sixth consideration is the dividend strategy. C-Corps that distribute earnings as dividends create the double-taxation issue, but distributing some earnings as reasonable compensation (deductible at the corporate level) and retaining others can produce significantly better outcomes than either extreme.

The seventh consideration is the exit and succession plan. Different entity types have different implications for sale transactions, generational transitions, and wind-down scenarios. The C-Corp conversion decision should align with the longer-term exit and succession objectives for the business.

The eighth consideration is the operational complexity. C-Corps require more formal corporate governance, separate corporate tax filings, more rigorous documentation, and other operational overhead beyond what S-Corp or LLC structures require. The operational burden is real and should be factored into the decision.

AE Tax Advisors models the C-Corp conversion outcome against the current structure for each client where the question is being evaluated. The modeling includes the multi-year

projection of after-tax outcomes under each structure, the specific assumptions used in the projection, the sensitivity analysis showing how the outcomes change under different scenarios, and the qualitative factors (exit plans, succession objectives, operational complexity) that affect the decision beyond the pure tax math.

Where the analysis supports C-Corp conversion, AE Tax Advisors handles the conversion process, including the necessary entity restructuring, the tax planning around the conversion itself (which can have specific tax implications depending on the original structure), and the implementation of the ongoing C-Corp operational requirements.

The conversion is not always the right answer. Many businesses are correctly structured as pass-throughs, and the C-Corp conversion would be a step backward. The firm’s role is to identify which clients have the profile that would benefit from a C-Corp structure and execute the conversion correctly for those clients, while confirming for others that their current structure is appropriate.

The annual $7,800 advisory engagement at AE Tax Advisors includes the ongoing monitoring of the entity structure decision as the business evolves. A structure that was right at engagement start may become suboptimal as income grows, exit timelines change, or tax law evolves. The quarterly check-ins revisit the structure question as appropriate.

The team, IRS Enrolled Agents and licensed CPAs led by Christina Nortman, has executed entity restructurings across multiple business categories. The work requires specific technical expertise and careful procedural execution, and the firm has built the operational depth to handle the conversions correctly.

The proprietary 3-Year Tax Lookback evaluates whether the current structure has been optimal across the prior period. Where prior years would have produced better outcomes under a different structure, the lookback identifies the issue and considers whether catch-up positioning or current-year restructuring should occur.

For business owners who have not formally evaluated whether their current entity structure is the right one for the post-2017 tax landscape, the AE Tax Advisors C-Corp analysis is one of the more substantive moves available in the strategic planning category. The structures matter. The decision is consequential. And the firm’s expertise in evaluating and executing the conversion correctly is exactly the kind of operational depth that produces consistent outcomes for clients across the multi-year horizon.

Disclaimer: This article is provided for general informational and educational purposes only and does not constitute tax, legal, accounting, financial, or investment advice. Tax laws and regulations are complex, subject to change, and may apply differently depending on a taxpayer’s individual circumstances. References to potential tax benefits, including those under Internal Revenue Code Sections 199A and 1202, are subject to detailed eligibility requirements and do not guarantee any particular tax treatment, savings, or outcome. Business owners should consult qualified tax and legal professionals before selecting, converting, or restructuring a business entity.

Two Georgia Water Systems Hacked Through Programmable Logic Controllers as Federal Investigation Widens

Two Georgia water systems have confirmed they were targeted in cyberattacks that exploited programmable logic controllers (PLCs), the industrial minicomputers that automate water treatment, pressure regulation, and chemical dosing at utility facilities across the country. Clayton County Water Authority, which serves communities south of Atlanta, said a service disruption that temporarily knocked out water to parts of the county is under investigation as a possible cyberattack. Columbus Water Works confirmed a separate breach but said its drinking water supply was never compromised.

Key Takeaways

  • Clayton County Water Authority (metro Atlanta) confirmed that hackers targeted its system, causing pump station outages and triggering a boil water advisory for parts of the county.
  • Columbus Water Works also confirmed a cyberattack but said drinking water was never affected and its team detected the intrusion before operations were compromised.
  • The FBI issued a public service announcement warning that water and wastewater utilities in at least seven states have reported cyber incidents since July 27, 2026.
  • Attackers targeted Rockwell Automation/Allen-Bradley PLCs (MicroLogix 1100 and 1400 series), changing IP addresses and passwords to lock out operators and disable monitoring.
  • CISA expanded its advisory scope to include Schneider Electric, Siemens, and other PLC manufacturers as potential targets.
  • Georgia Tech researchers have identified more than 7,000 PLCs accessible on the open internet across water treatment plants, hospitals, airports, and military facilities nationwide.

Clayton County Pump Stations Went Down Before the Cause Was Identified

The first signs of trouble in Clayton County appeared as a routine service disruption. Residents received a boil water advisory and experienced low water pressure. It was not until days later that the Clayton County Water Authority publicly disclosed that the disruption may have resulted from unauthorized cyber activity. Spokesperson Erin Thomas confirmed that the investigation centers on programmable logic controllers, the devices that automate equipment ranging from pumps to water treatment and purification operations throughout the system.

“What we realized is that some of our pump stations went down,” Thomas told WSB-TV. The authority described the PLCs as the “last step between you and the equipment,” noting that manipulation of these devices “could get really dangerous.” Thomas said there is no evidence that customers’ billing or payment information was compromised and that the authority immediately began coordinating with state and federal partners, including the FBI and the Cybersecurity and Infrastructure Security Agency (CISA), to investigate the incident and secure affected systems.

Columbus Water Works, located approximately 100 miles southwest of Atlanta, confirmed a separate breach. The utility said its team detected the intrusion and that the city’s drinking water was never compromised during the incident. Both Georgia incidents are now part of a broader federal investigation spanning multiple states.

The FBI Says Water Utilities in at Least Seven States Have Been Hit

The Georgia incidents are not isolated. The FBI issued a public service announcement, jointly with the Environmental Protection Agency, warning that water and wastewater utilities in at least seven states have reported cyber incidents to federal authorities since July 27, 2026. Some of those incidents “degraded water operations,” the FBI stated. The number of affected states has since grown; ABC News reported the count had reached 12 as of early August.

The FBI said attackers targeted Rockwell Automation/Allen-Bradley PLCs, specifically the MicroLogix 1100 and 1400 series, which are widely deployed across small and mid-sized water utilities. After remotely accessing internet-facing devices, the attackers changed IP addresses and passwords, effectively locking operators out of their own systems and resulting in a loss of monitoring and control functionality. The FBI cautioned that while it has so far observed this specific behavior only against Rockwell devices, organizations using PLCs from other manufacturers should follow the same hardening guidance.

CISA issued a separate alert on July 30 urging water and wastewater system operators to remove publicly exposed PLCs from the internet immediately. CISA noted that threat actors have modified passwords to lock out operators, disconnected PLCs by changing IP addresses, and caused boil water notices and sustained manual operations at affected utilities. The agency emphasized that water organizations “of all sizes” are being targeted, including systems where cellular modems installed by operators, vendors, or system integrators may not be documented or included in routine security scans.

Researchers Found Over 7,000 PLCs Exposed on the Open Internet

The vulnerability that makes these attacks possible is not a software flaw in the PLCs themselves. It is the fact that thousands of these devices are connected directly to the internet without adequate security protections. Georgia Tech cybersecurity professor Saman Zonouz, whose research focuses on industrial control system security, compared PLCs to home thermostats. Both detect environmental conditions and trigger automated responses. A thermostat measures temperature and turns on an air conditioner. A PLC in a water treatment plant monitors water pressure, chlorine levels, and flow rates, then adjusts pumps, valves, and chemical dosing systems accordingly.

Zonouz and his research team found more than 7,000 PLCs accessible on the open internet across water treatment plants, airports, hospitals, energy facilities, and military installations. The exposure exists largely for convenience. Operators and maintenance teams connect PLCs to the internet to enable remote monitoring and troubleshooting, particularly at smaller utilities that may not have full-time on-site technical staff. That convenience creates a direct attack surface that adversaries can exploit without needing to breach any firewall or internal network.

“The reason,” Zonouz noted, is that operators prioritize functionality and accessibility over security, a trade-off that is especially common at small and mid-sized utilities with limited cybersecurity budgets. The research underscores a structural vulnerability that extends far beyond the water sector: the same PLCs used in water treatment are deployed across power grids, manufacturing facilities, oil and gas refineries, and building automation systems.

Small and Mid-Sized Utilities Face the Steepest Cybersecurity Gap

The pattern of attacks highlights a disparity in cybersecurity capacity between large metropolitan water systems and smaller utilities. Large systems like Atlanta’s Department of Watershed Management typically maintain dedicated cybersecurity teams, network segmentation between operational technology and information technology, and regular vulnerability assessments. Smaller systems, particularly those serving rural communities or mid-sized counties, often operate with lean staff and limited budgets for technology upgrades.

Clayton County Water Authority serves approximately 300,000 residents across unincorporated Clayton County and portions of southern Fulton and Henry counties. Columbus Water Works serves the city of Columbus and surrounding Muscogee County. Neither is a small rural system, but both are representative of the mid-tier utilities that federal agencies have identified as particularly vulnerable to PLC-based attacks.

State Rep. Sandra Scott, a Democrat whose district includes parts of Clayton County, said she has heard from constituents concerned about the incident. Scott emphasized that the investigation must be thorough because “we know that we all need water.” The political pressure to address water infrastructure cybersecurity is likely to grow as the number of affected states increases and as the federal investigation produces findings about the scope of the campaign.

CISA has recommended that water utilities immediately remove all PLCs from direct internet exposure, implement network segmentation between operational technology and corporate networks, require multi-factor authentication for remote access, and monitor for unauthorized changes to PLC configurations. The EPA’s Cybersecurity Technical Assistance Program for the Water Sector is available to assist utilities that lack in-house cybersecurity expertise.

FAQs

What Is a Programmable Logic Controller?

A programmable logic controller (PLC) is an industrial minicomputer that automates equipment operations in water treatment plants, manufacturing facilities, power systems, and other critical infrastructure. PLCs monitor conditions like water pressure and chemical levels and automatically adjust pumps, valves, and dosing systems in response.

Was Drinking Water in Georgia Contaminated?

Neither Clayton County Water Authority nor Columbus Water Works has reported any contamination of the drinking water supply. Clayton County issued a precautionary boil water advisory during the service disruption, which has since been lifted. Columbus said its team detected the breach before operations were affected.

What Should Water Utilities Do to Protect Against These Attacks?

CISA recommends removing all PLCs from direct internet exposure, implementing network segmentation, requiring multi-factor authentication for remote access, and monitoring for unauthorized configuration changes. The EPA’s Cybersecurity Technical Assistance Program offers free support for water utilities.