Bill

Bill > A06769


NY A06769

NY A06769
Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.


summary

Introduced
03/13/2025
In Committee
03/24/2025
Crossed Over
03/24/2025
Passed
Dead

Introduced Session

2025-2026 General Assembly

Bill Summary

AN ACT to amend the general municipal law and the executive law, in relation to requiring municipal cybersecurity incident reporting and exempting such reports from freedom of information requirements; and to amend the state technology law, in relation to requiring cybersecurity awareness training for government employees, data protection standards, and cybersecurity protection

AI Summary

This bill requires municipal corporations and public authorities to report cybersecurity incidents and ransom payments to the Division of Homeland Security and Emergency Services within 72 hours of discovering such incidents. The bill provides detailed definitions for key cybersecurity terms like "cybersecurity incident," "cyber threat," and "ransomware attack," and mandates that these reports include information about the incident and whether the reporting entity is seeking technical assistance. It also requires state and local government employees who use technology in their jobs to complete annual cybersecurity awareness training starting January 1, 2026, with the training to be conducted during regular work hours and compensated at the employee's normal rate of pay. Additionally, the bill requires state agencies to develop comprehensive cybersecurity protection standards, including creating inventories of information systems, developing incident response plans, and conducting annual incident response plan exercises. All cybersecurity incident reports and related documents will be exempt from public disclosure to protect sensitive information. The bill aims to improve cybersecurity preparedness and response capabilities across New York state and local government entities by establishing clear reporting requirements, training standards, and protection protocols.

Committee Categories

Government Affairs

Sponsors (2)

Last Action

substituted by s7672a (on 05/19/2025)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...