Texas 2023 - 88th Regular

Texas House Bill HB4996 Compare Versions

OldNewDifferences
11 88R8305 SCP-F
22 By: Bell of Montgomery, Anchía, Capriglione H.B. No. 4996
33
44
55 A BILL TO BE ENTITLED
66 AN ACT
77 relating to a statewide cyber insurance program.
88 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
99 SECTION 1. DEFINITIONS. In this Act:
1010 (1) "Department" means the Department of Information
1111 Resources.
1212 (2) "Office" means the State Office of Risk
1313 Management.
1414 (3) "Risk framework" means key security domains
1515 identified by cyber insurance underwriters based on current
1616 security controls.
1717 (4) "Security controls" include:
1818 (A) use of multiple security levels;
1919 (B) managing user access;
2020 (C) user authentication;
2121 (D) network and server vulnerability;
2222 (E) malware defense;
2323 (F) operational technology;
2424 (G) remote work;
2525 (H) third-party vendor management;
2626 (I) e-mail filtering;
2727 (J) response planning;
2828 (K) data encryption and backup;
2929 (L) use of wireless devices and connections;
3030 (M) monitoring users or devices;
3131 (N) continuity of service;
3232 (O) incident response;
3333 (P) appropriate insurance coverage; and
3434 (Q) governance.
3535 SECTION 2. STUDY. Not later than October 1, 2023, the
3636 department shall contract with a cyber risk model vendor to conduct
3737 a study on the development of a statewide risk framework in order to
3838 determine the need for and feasibility of implementing a statewide
3939 cyber insurance program. The department shall enter into a
4040 memorandum of understanding with the office to support this
4141 assessment.
4242 SECTION 3. INSURANCE PROGRAM. Based on the results of the
4343 study required by Section 2 of this Act, the office may develop and
4444 maintain a statewide cyber insurance program meeting the
4545 specifications identified in the study.
4646 SECTION 4. REPORT. Not later than April 1, 2024, the
4747 department, in conjunction with the office, shall prepare and
4848 submit to the governor and the legislature a report containing the
4949 results of the study and any recommendations for legislative or
5050 other action to address the need for and feasibility of requiring
5151 cyber insurance.
5252 SECTION 5. EXPIRATION. This Act expires September 1, 2025.
5353 SECTION 6. EFFECTIVE DATE. This Act takes effect
5454 immediately if it receives a vote of two-thirds of all the members
5555 elected to each house, as provided by Section 39, Article III, Texas
5656 Constitution. If this Act does not receive the vote necessary for
5757 immediate effect, this Act takes effect September 1, 2023.