Bill

Bill > S07672


NY S07672

NY S07672
Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.


summary

Introduced
04/28/2025
In Committee
05/12/2025
Crossed Over
05/19/2025
Passed
06/26/2025
Dead
Signed/Enacted/Adopted
06/26/2025

Introduced Session

2025-2026 General Assembly

Bill Summary

AN ACT to amend the general municipal law and the executive law, in relation to requiring municipal cybersecurity incident reporting and exempting such reports from freedom of information requirements; and to amend the state technology law, in relation to requiring cybersecurity awareness training for government employees, data protection standards, and cybersecurity protection

AI Summary

This bill establishes comprehensive cybersecurity reporting and protection requirements for municipal corporations, public authorities, and state agencies. It mandates that municipal corporations and public authorities report any cybersecurity incidents and ransom payment demands to the Division of Homeland Security and Emergency Services within 72 hours of discovering the incident, with detailed reporting requirements including whether they seek technical assistance. The bill defines key terms like "cybersecurity incident," "ransomware attack," and "cyber threat," and provides specific guidelines for reporting such events. It also requires state and local government employees who use technology in their jobs to complete annual cybersecurity awareness training beginning in January 2026, with the training to be conducted during regular working hours and compensated at the employee's standard pay rate. Additionally, the bill requires state agencies to develop robust data protection standards, create inventories of their information systems, and establish incident response plans, with provisions to keep these sensitive documents confidential. The legislation aims to enhance cybersecurity preparedness, response, and protection across New York's government entities, while providing a framework for managing and mitigating potential cyber threats.

Committee Categories

Government Affairs

Sponsors (1)

Last Action

SIGNED CHAP.177 (on 06/26/2025)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...