Maryland 2022 Regular Session

Maryland House Bill HB1339

Introduced
2/11/22  
Refer
2/11/22  

Caption

Cybersecurity - Critical Infrastructure and Public Service Companies (Critical Infrastructure Security Act of 2022)

Impact

The bill imposes new requirements on public service companies, mandating them to adopt cybersecurity best practices, including zero trust principles and the protection of personally identifiable information (PII). It also compels these companies to include specific cybersecurity provisions in contracts with third-party vendors. By doing so, the bill underscores the significance of maintaining stringent security protocols to safeguard both consumer data and critical operational information, thereby aligning utility management with modern cybersecurity expectations.

Summary

House Bill 1339, titled the Critical Infrastructure Security Act of 2022, aims to strengthen the cybersecurity framework surrounding critical infrastructure and public service companies in Maryland. The bill designates the Department of Emergency Management as the authority to initiate actions that minimize disaster risks associated with cybersecurity breaches. A key feature of the bill is the establishment of a Critical Infrastructure Cybersecurity Grant Program, which is intended to support enhancements in cybersecurity through various funding sources, thereby allowing critical facilities to implement necessary security measures and technologies.

Contention

While the bill supports enhanced cybersecurity measures, there are points of contention among stakeholders regarding the feasibility and implications of the proposed changes. Opponents may argue that the added requirements could lead to increased operational costs for public service companies, potentially impacting service rates for consumers. Moreover, ensuring compliance with new cybersecurity standards might stretch resources—especially for smaller utilities that may struggle with the financial implications of implementing the required changes. Overall, the legislation is positioned as a proactive approach to cybersecurity, yet it raises discussions about economic impacts and the balance between stringent security practices and operational viability.

Companion Bills

MD SB810

Crossfiled Cybersecurity - Critical Infrastructure and Public Service Companies (Critical Infrastructure Security Act of 2022)

Previously Filed As

MD SB810

Cybersecurity - Critical Infrastructure and Public Service Companies (Critical Infrastructure Security Act of 2022)

MD HB969

Public Service Commission – Cybersecurity Staffing and Assessments (Critical Infrastructure Cybersecurity Act of 2023)

MD SB800

Public Service Commission - Cybersecurity Staffing and Assessments (Critical Infrastructure Cybersecurity Act of 2023)

MD HB1420

Cybersecurity - Office of People's Counsel, Public Service Companies, Public Service Commission, and Maryland Cybersecurity Council

MD SB474

Certificate of Public Convenience and Necessity and Related Approvals - Definition of Generating Station (Critical Infrastructure Streamlining Act of 2024)

MD HB1205

State Government – Information Technology and Cybersecurity–Related Infrastructure (Modernize Maryland Act of 2022)

MD AB1359

Cybersecurity: critical infrastructure business: breach notification.

MD SB811

State Government - Information Technology and Cybersecurity-Related Infrastructure (Modernize Maryland Act of 2022)

MD SB265

Cybersecurity preparedness: critical infrastructure sectors.

MD HB444

Criminal Law – Interference With Critical Infrastructure or a Public Safety Answering Point – Penalties

Similar Bills

MD HB1420

Cybersecurity - Office of People's Counsel, Public Service Companies, Public Service Commission, and Maryland Cybersecurity Council

MD SB871

Department of the Environment - Community Water and Sewerage Systems - Cybersecurity Planning and Assessments

MD HB1062

Department of the Environment - Community Water and Sewerage Systems - Cybersecurity Planning and Assessments

MD HB969

Public Service Commission – Cybersecurity Staffing and Assessments (Critical Infrastructure Cybersecurity Act of 2023)

MD SB810

Cybersecurity - Critical Infrastructure and Public Service Companies (Critical Infrastructure Security Act of 2022)

MD HB1123

Maryland Health Care Commission – Health Care Facilities – Cybersecurity for Hospitals

MD SB800

Public Service Commission - Cybersecurity Staffing and Assessments (Critical Infrastructure Cybersecurity Act of 2023)

MD HB333

Healthcare Ecosystem Stakeholder Cybersecurity Workgroup