Mississippi 2023 Regular Session

Mississippi Senate Bill SB2717

Introduced
1/16/23  
Refer
1/16/23  
Engrossed
2/7/23  
Refer
2/13/23  
Enrolled
2/28/23  

Caption

Department of Information Technology Services; require to report ransomware incidents and revise provisions related thereto.

Impact

The implementation of SB 2717 will significantly impact the protocols for cybersecurity across state government sectors, mandating state agencies to adhere to centralized management under MDITS. This centralized approach is expected to create standardized procedures for dealing with cybersecurity threats, enhancing overall data protection and security measures at the state level. By requiring a yearly summary of ransomware incidents to be reported to legislative leaders, the bill promotes accountability and transparency in handling cyber threats.

Summary

Senate Bill 2717 aims to enhance the cybersecurity posture of the state by mandating that all state agencies report any ransomware incidents to the Mississippi Department of Information Technology Services (MDITS). The bill defines ransomware and establishes procedures for reporting demands for payment as a result of ransomware attacks. Beginning July 1, 2023, agencies are required to notify MDITS of incidents by the end of the next business day after discovery. This legislative measure aims to promote a coordinated response to cybersecurity threats and ensure a uniform approach across all state governmental entities.

Sentiment

The sentiment surrounding SB 2717 appears to be largely supportive, as evidenced by its unanimous passage in the House with 117 votes in favor. There seems to be a general consensus on the need for improved cybersecurity measures within the state's infrastructure to combat the rising threats of cyberattacks and ransomware. However, as with any legislation, there may be concerns regarding the bureaucratic implications and resource allocation required to implement these changes effectively.

Contention

Despite the positive sentiment, some points of contention could arise regarding the feasibility of requiring all state agencies to report incidents promptly. The requirement for agencies to develop new reporting formats and adhere to strict timelines may present logistical challenges. Additionally, the bill's effectiveness relies on the cooperation of all state agencies in maintaining and reporting cybersecurity measures, which may not be uniformly achievable across various departments.

Companion Bills

No companion bills found.

Similar Bills

MS SB2530

Department of Information Technology Services; require to report ransomware incidents and revise provisions related thereto.

MS SB2703

Cybersecurity; prohibit agencies from paying ransoms.

MS HB1380

Cybersecurity; governmental and certain commercial entities substantially complying with standards not liable for incidents relating to.

MS HB958

Department of Information Technology Services; revise certain provisions relating to acquisition of technology services.

MS HB1333

Department of Information Technology Services; require all state agencies to use for computer equipment and services.

FL H1293

Cybersecurity

FL H1555

Cybersecurity

FL H1511

Cybersecurity