Bill

Bill > S3100


NJ S3100

NJ S3100
Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.


summary

Introduced
04/15/2024
In Committee
06/13/2024
Crossed Over
Passed
Dead
01/12/2026

Introduced Session

2024-2025 Regular Session

Bill Summary

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

AI Summary

This bill requires businesses in the financial, essential infrastructure, and healthcare industries, referred to as "sensitive businesses," to develop and implement comprehensive cybersecurity programs. These programs must include identifying a responsible individual for cyber risk management, conducting risk assessments, implementing controls, and creating incident response and recovery plans. Sensitive businesses must also adhere to recognized cybersecurity frameworks, such as those from the National Institute of Standards and Technology (NIST), and submit their plans and annual certifications of compliance to the New Jersey Cybersecurity and Communications Integration Cell, a state entity responsible for cybersecurity and communications. Furthermore, these businesses must promptly report any "cybersecurity incident"—an event that compromises the integrity, confidentiality, or availability of computer systems or data—to the same state cell. The bill exempts financial institutions already subject to federal regulations like the Gramm-Leach-Bliley Act.

Committee Categories

Budget and Finance, Justice

Sponsors (2)

Last Action

Referred to Senate Budget and Appropriations Committee (on 06/13/2024)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...