Bill

Bill > A711


NJ A711

NJ A711
Requires public institution of higher education to establish plans concerning cyber security and prevention of cyber attacks.


summary

Introduced
01/13/2026
In Committee
01/13/2026
Crossed Over
Passed
Dead

Introduced Session

2026-2027 Regular Session

Bill Summary

This bill requires public institutions of higher education to establish plans and procedures to enhance cyber security and prevent cyber attacks against the institution's information technology systems. Pursuant to the bill, the plans and procedures are required to address, at a minimum: system monitoring to identify potential cyber security risks and vulnerabilities; cyber threat assessment; techniques for mitigating risk and preventing cyber breaches; and response and recovery for cyber security incidents. The bill requires public institutions of higher education to regularly update their cyber security plans and procedures in order to reflect current technologies and information security techniques. In connection with developing their cyber security plans, a public institution of higher education may consult with the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) regarding information and best practices on cyber security and data protection. The NJCCIC was established in 2015 by executive order as the State's central organization for cyber security information sharing and threat analysis. Lastly, the bill requires a public institution of higher education to notify the New Jersey Office of Homeland Security and Preparedness of any cyber attack against the institution's information technology systems in a manner consistent with current law governing reporting of cybersecurity incidents. Pursuant to the bill, a phishing attempt, as defined in the bill, is not considered a cyber attack for the purposes of this notification. The bill generally defines a cyber attack as unauthorized access to electronic files, media, or data containing personal information. The bill stipulates that good faith acquisition of personal information by an employee or agent of the public institution of higher education for a legitimate purpose, or for a purpose authorized under State or federal law, is not considered a cyber attack, provided that this information is not used for a purpose unrelated to the institution or subject to further unauthorized disclosure.

AI Summary

This bill mandates that public colleges and universities in New Jersey must create and maintain comprehensive plans to bolster their cybersecurity and defend against cyber attacks, which are defined as unauthorized access to electronic files or data containing personal information that compromises its security, confidentiality, or integrity, unless the information is encrypted or rendered unusable, or if an employee or agent lawfully acquires it for a legitimate purpose without further unauthorized disclosure. These plans must include monitoring systems for risks and vulnerabilities, assessing threats, implementing strategies to prevent breaches, and outlining procedures for responding to and recovering from security incidents. The institutions are encouraged to consult with the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC), a state organization established in 2015 for sharing cybersecurity information and analyzing threats, for guidance and best practices. The bill also requires these institutions to regularly update their plans to keep pace with evolving technologies and security methods, and to report any cyber attacks to the New Jersey Office of Homeland Security and Preparedness, though phishing attempts, which are defined as fraudulent attempts to obtain personal information by impersonating a trustworthy entity, are specifically excluded from this reporting requirement.

Committee Categories

Education

Sponsors (7)

Last Action

Introduced, Referred to Assembly Higher Education Committee (on 01/13/2026)

bill text


bill summary

Loading...

bill summary

Loading...

bill summary

Loading...