New York 2025-2026 Regular Session

New York Senate Bill S07672

Introduced
4/28/25  
Refer
4/28/25  
Engrossed
5/12/25  

Caption

Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.

Impact

The bill introduces significant changes to existing municipal laws by requiring public authorities to maintain detailed records of cybersecurity incidents, which are to be kept confidential and exempt from public disclosure under the state's freedom of information laws. This provision aims to protect sensitive information regarding the state's response to cyber threats. Furthermore, the legislation emphasizes the necessity of developing incident response plans within eighteen months of its enactment, thereby standardizing how municipal corporations manage and recover from cybersecurity breaches.

Summary

Bill S07672 aims to enhance cybersecurity measures across municipal corporations and public authorities in New York State. It establishes a framework that requires these entities to report any cybersecurity incidents, particularly those involving ransom demands, to the Division of Homeland Security and Emergency Services within 72 hours. The bill intends to improve incident response capabilities and protect state-maintained information systems from potential vulnerabilities. It also mandates annual cybersecurity awareness training for government employees starting in 2026, ensuring that personnel are well-equipped to handle cyber threats.

Contention

Notably, the bill has sparked discussions regarding privacy and transparency. Critics argue that exempting incident reports from public scrutiny could hinder accountability and oversight of municipal data management. There are concerns that, while aiming to fortify cybersecurity, the legislation could potentially create a lack of transparency about how effectively these municipalities handle cyber threats and ransom situations. Proponents defend the bill, asserting that the confidentiality of these reports is essential to safeguard sensitive operational details and minimize risks of further attacks.

Companion Bills

NY A06769

Same As Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.

Similar Bills

HI HB946

Relating To Insurance Data Security.

MD SB691

Healthcare Ecosystem Stakeholder Cybersecurity Workgroup

ND SB2088

Implementation dates for certain data security requirements for insurance producers.

CT SB00903

An Act Concerning Insurance Data And Information Security.

MD HB333

Healthcare Ecosystem Stakeholder Cybersecurity Workgroup

KY HB474

AN ACT relating to insurance data security.

MD HB969

Public Service Commission – Cybersecurity Staffing and Assessments (Critical Infrastructure Cybersecurity Act of 2023)

NJ S3222

Requires instruction on cybersecurity in grades nine through 12; requires Office of Secretary of Higher Education to develop cybersecurity model curricula; establishes loan redemption programs for individuals in certain cybersecurity occupations.