Bill
Bill > A06769
NY A06769
NY A06769Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.
summary
Introduced
03/13/2025
03/13/2025
In Committee
03/24/2025
03/24/2025
Crossed Over
03/24/2025
03/24/2025
Passed
Dead
Introduced Session
2025-2026 General Assembly
Bill Summary
AN ACT to amend the general municipal law and the executive law, in relation to requiring municipal cybersecurity incident reporting and exempting such reports from freedom of information requirements; and to amend the state technology law, in relation to requiring cybersecurity awareness training for government employees, data protection standards, and cybersecurity protection
AI Summary
This bill requires municipal corporations and public authorities to report cybersecurity incidents and ransom payments to the Division of Homeland Security and Emergency Services within 72 hours of discovering such incidents. The bill provides detailed definitions for key cybersecurity terms like "cybersecurity incident," "cyber threat," and "ransomware attack," and mandates that these reports include information about the incident and whether the reporting entity is seeking technical assistance. It also requires state and local government employees who use technology in their jobs to complete annual cybersecurity awareness training starting January 1, 2026, with the training to be conducted during regular work hours and compensated at the employee's normal rate of pay. Additionally, the bill requires state agencies to develop comprehensive cybersecurity protection standards, including creating inventories of information systems, developing incident response plans, and conducting annual incident response plan exercises. All cybersecurity incident reports and related documents will be exempt from public disclosure to protect sensitive information. The bill aims to improve cybersecurity preparedness and response capabilities across New York state and local government entities by establishing clear reporting requirements, training standards, and protection protocols.
Committee Categories
Government Affairs
Sponsors (2)
Last Action
substituted by s7672a (on 05/19/2025)
Official Document
bill text
bill summary
Loading...
bill summary
Loading...
bill summary
Loading...