New Jersey 2022-2023 Regular Session

New Jersey Assembly Bill A1981

Introduced
1/11/22  

Caption

Requires businesses in financial, essential infrastructure, and health care industries to develop cybersecurity plans.

Impact

The legislation directs the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC), along with the Attorney General, to develop rules and regulations that define accountability and responsibility for cybersecurity risk management. Businesses will need to conduct risk assessments, produce incident response plans, and provide annual certifications of compliance. The NJCCIC is empowered to supervise these businesses, conduct audits if necessary, and ensure that organizations adhere to the regulations put forth, thus potentially leading to improved cybersecurity standards within these key industries.

Summary

Assembly Bill 1981, introduced in the New Jersey legislature, mandates that businesses operating within the financial services, essential infrastructure, and healthcare sectors develop comprehensive cybersecurity plans. This requirement is aimed at enhancing the cybersecurity posture of organizations that handle sensitive information and critical operations. The bill outlines a structured approach for these businesses to implement and maintain cybersecurity programs reflective of industry best practices, as well as the need for continuous evaluation and improvement of security measures in response to evolving threats.

Contention

However, the bill may raise concerns regarding the financial burden on smaller enterprises that may struggle to implement extensive cybersecurity infrastructures. Critics may argue that the costs associated with compliance and audits could hinder the operational capabilities of smaller businesses. Furthermore, there are concerns about the adequacy of the NJCCIC's resources to effectively monitor and audit a diverse array of businesses under its jurisdiction. Balancing the need for heightened security without overburdening businesses is a critical point of contention in the discussions surrounding this bill.

Companion Bills

No companion bills found.

Similar Bills

NJ S3100

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

NJ A2200

Requires businesses in financial, essential infrastructure, and health care industries to develop cybersecurity plans.

MS SB2471

Cyber breach; limit liability for certain entities.

WV HB5338

Relating to Safe Harbor for Cybersecurity Programs

IL HB3576

WATER UTILITY CYBERSECURITY

IA HF553

A bill for an act relating to affirmative defenses for entities using cybersecurity programs. (Formerly HSB 154.) Effective date: 07/01/2023.

IA SF495

A bill for an act relating to affirmative defenses for entities using cybersecurity programs.(Formerly SSB 1095.)

NJ S1860

Creates affirmative defense for certain breaches of security.