New York 2025-2026 Regular Session

New York Senate Bill S07672

Introduced
4/28/25  
Refer
4/28/25  
Engrossed
5/12/25  
Refer
5/12/25  
Engrossed
5/19/25  
Enrolled
6/26/25  
Chaptered
6/26/25  

Caption

Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.

Impact

The bill introduces significant changes to existing municipal laws by requiring public authorities to maintain detailed records of cybersecurity incidents, which are to be kept confidential and exempt from public disclosure under the state's freedom of information laws. This provision aims to protect sensitive information regarding the state's response to cyber threats. Furthermore, the legislation emphasizes the necessity of developing incident response plans within eighteen months of its enactment, thereby standardizing how municipal corporations manage and recover from cybersecurity breaches.

Summary

Bill S07672 aims to enhance cybersecurity measures across municipal corporations and public authorities in New York State. It establishes a framework that requires these entities to report any cybersecurity incidents, particularly those involving ransom demands, to the Division of Homeland Security and Emergency Services within 72 hours. The bill intends to improve incident response capabilities and protect state-maintained information systems from potential vulnerabilities. It also mandates annual cybersecurity awareness training for government employees starting in 2026, ensuring that personnel are well-equipped to handle cyber threats.

Contention

Notably, the bill has sparked discussions regarding privacy and transparency. Critics argue that exempting incident reports from public scrutiny could hinder accountability and oversight of municipal data management. There are concerns that, while aiming to fortify cybersecurity, the legislation could potentially create a lack of transparency about how effectively these municipalities handle cyber threats and ransom situations. Proponents defend the bill, asserting that the confidentiality of these reports is essential to safeguard sensitive operational details and minimize risks of further attacks.

Companion Bills

NY A06769

Same As Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.

Previously Filed As

NY A02833

Directs that state agencies require that procurement of personal computing goods, services and solutions meet the National Institute of Standards and Technology (NIST) Cybersecurity Framework.

NY S05615

Directs that state agencies require that procurement of personal computing goods, services and solutions meet the National Institute of Standards and Technology (NIST) Cybersecurity Framework.

NY S08977

Requires law enforcement officers to conduct a lethality assessment as part of the standardized domestic incident report form when responding to incidents of domestic violence.

NY A09892

Requires law enforcement officers to conduct a lethality assessment as part of the standardized domestic incident report form when responding to incidents of domestic violence.

NY A09337

Requires the state fire administrator to establish hazardous materials emergency response training for incidents involving lithium-ion batteries.

NY S08742

Requires the state fire administrator to establish hazardous materials emergency response training for incidents involving lithium-ion batteries.

NY S01699

Requires health care facilities to report incidents of a sexual offense to the departments of health and education.

NY A02991

Requires health care facilities to report incidents of a sexual offense to the departments of health and education.

NY S02737

Directs the division of homeland security and emergency services to conduct a review and analysis of security measures at rail yards and to issue related reports and recommendations.

NY A09480

Directs the division of homeland security and emergency services to conduct a review and analysis of security measures at rail yards and to issue related reports and recommendations.

Similar Bills

PA HB1139

In organization of departmental administrative boards and commissions and of advisory boards and commissions, providing for Cybersecurity Coordination Board.

RI H7281

Amends the statutory provisions regarding domestic and foreign insurers and insurer examinations to provide provisions with regard to cybersecurity events involving Rhode Island consumers.

RI S2802

Amends the statutory provisions regarding domestic and foreign insurers and insurer examinations to provide provisions with regard to cybersecurity events involving Rhode Island consumers.

HI HB946

Relating To Insurance Data Security.

MD SB691

Healthcare Ecosystem Stakeholder Cybersecurity Workgroup

ND SB2088

Implementation dates for certain data security requirements for insurance producers.

MD HB333

Healthcare Ecosystem Stakeholder Cybersecurity Workgroup

CT SB00903

An Act Concerning Insurance Data And Information Security.