Texas 2025 - 89th Regular

Texas Senate Bill SB1034 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 89R9459 ANG-F
22 By: Sparks, Perry S.B. No. 1034
33
44
55
66
77 A BILL TO BE ENTITLED
88 AN ACT
99 relating to cybersecurity for retail public utilities that provide
1010 water or sewer service.
1111 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
1212 SECTION 1. Section 2054.0525, Government Code, is amended
1313 to read as follows:
1414 Sec. 2054.0525. CUSTOMERS ELIGIBLE FOR DEPARTMENT
1515 SERVICES. If the executive director determines that participation
1616 is in the best interest of this state, the following entities are
1717 eligible customers for services the department provides:
1818 (1) a state agency;
1919 (2) a local government;
2020 (3) the legislature or a legislative agency;
2121 (4) the supreme court, the court of criminal appeals,
2222 or a court of appeals;
2323 (5) a public hospital owned or operated by this state
2424 or a political subdivision or municipal corporation of this state,
2525 including a hospital district or hospital authority;
2626 (6) an independent organization certified under
2727 Section 39.151, Utilities Code, for the ERCOT power region;
2828 (7) the Texas Permanent School Fund Corporation;
2929 (8) an assistance organization, as defined by Section
3030 2175.001;
3131 (9) an open-enrollment charter school, as defined by
3232 Section 5.001, Education Code;
3333 (10) a private school, as defined by Section 5.001,
3434 Education Code;
3535 (11) a private or independent institution of higher
3636 education, as defined by Section 61.003, Education Code;
3737 (12) a public safety entity, as defined by 47 U.S.C.
3838 Section 1401;
3939 (13) a volunteer fire department, as defined by
4040 Section 152.001, Tax Code; [and]
4141 (14) a governmental entity of another state; and
4242 (15) a retail public utility, as defined by Section
4343 13.002, Water Code.
4444 SECTION 2. Section 2059.058, Government Code, is amended to
4545 read as follows:
4646 Sec. 2059.058. AGREEMENT TO PROVIDE NETWORK SECURITY
4747 SERVICES TO ENTITIES OTHER THAN STATE AGENCIES. In addition to the
4848 department's duty to provide network security services to state
4949 agencies under this chapter, the department by agreement may
5050 provide network security services to:
5151 (1) each house of the legislature and a legislative
5252 agency;
5353 (2) a local government;
5454 (3) the supreme court, the court of criminal appeals,
5555 or a court of appeals;
5656 (4) a public hospital owned or operated by this state
5757 or a political subdivision or municipal corporation of this state,
5858 including a hospital district or hospital authority;
5959 (5) the Texas Permanent School Fund Corporation;
6060 (6) an open-enrollment charter school, as defined by
6161 Section 5.001, Education Code;
6262 (7) a private school, as defined by Section 5.001,
6363 Education Code;
6464 (8) a private or independent institution of higher
6565 education, as defined by Section 61.003, Education Code;
6666 (9) a volunteer fire department, as defined by Section
6767 152.001, Tax Code; [and]
6868 (10) an independent organization certified under
6969 Section 39.151, Utilities Code, for the ERCOT power region; and
7070 (11) a retail public utility, as defined by Section
7171 13.002, Water Code.
7272 SECTION 3. Chapter 13, Water Code, is amended by adding
7373 Subchapter O to read as follows:
7474 SUBCHAPTER O. CYBERSECURITY REQUIREMENTS
7575 Sec. 13.601. DEFINITIONS. In this subchapter:
7676 (1) "Center" means the Cyber Center for Security and
7777 Analytics at The University of Texas at San Antonio.
7878 (2) "Department" means the Department of Information
7979 Resources.
8080 Sec. 13.602. CONNECTION BETWEEN SUPERVISORY CONTROL AND
8181 DATA ACQUISITION SYSTEM AND INTERNET PROHIBITED. (a) A retail
8282 public utility may not connect the retail public utility's
8383 supervisory control and data acquisition system, or another
8484 equivalent operational information technology infrastructure, to
8585 the Internet.
8686 (b) Notwithstanding Subsection (a), a supervisory control
8787 and data acquisition system or other equivalent operational
8888 information technology infrastructure may be operated by an
8989 intranet, site-to-site virtual private network.
9090 (c) The commission, in consultation with the department,
9191 shall adopt rules as necessary to implement this section.
9292 Sec. 13.603. REQUIREMENTS AND CONTROLS. (a) The
9393 commission, in consultation with and as recommended by the
9494 department and the center, by rule shall adopt cybersecurity
9595 requirements for retail public utilities to require the
9696 authentication of a retail public utility employee's
9797 identification before granting the employee access to a retail
9898 public utility's network or information systems.
9999 (b) Not later than September 1 of each even-numbered year,
100100 the commission, in consultation with the department and the center,
101101 shall review and amend as necessary rules adopted under this
102102 section to ensure that the cybersecurity requirements continue to
103103 provide effective cybersecurity protection for retail public
104104 utilities.
105105 Sec. 13.604. TRAINING. At least annually, a retail public
106106 utility shall:
107107 (1) identify any employees and officials who:
108108 (A) have access to the retail public utility's
109109 computer system or databases; or
110110 (B) use a computer to perform any of the
111111 employee's or official's required duties; and
112112 (2) require the employees and officials identified
113113 under Subdivision (1) to complete a cybersecurity training program
114114 certified under Section 2054.519, Government Code.
115115 Sec. 13.605. SECURITY ASSESSMENT AND COMPLIANCE AUDIT. (a)
116116 The commission, the utility commission, or the department may
117117 require a retail public utility to conduct, in accordance with
118118 commission and department rules:
119119 (1) a security assessment of the retail public
120120 utility's:
121121 (A) information resource systems;
122122 (B) network systems;
123123 (C) digital data storage systems;
124124 (D) digital data security measures; or
125125 (E) information resources vulnerabilities; or
126126 (2) an audit of the retail public utility's compliance
127127 with this subchapter.
128128 (b) Not later than the 90th day after the date a retail
129129 public utility completes a security assessment or audit under
130130 Subsection (a), the retail public utility shall report the results
131131 of the assessment or audit to:
132132 (1) the commission;
133133 (2) the utility commission; and
134134 (3) the department.
135135 (c) A standing committee of the legislature with
136136 jurisdiction over cybersecurity or water service may request that
137137 the commission, the utility commission, or the department require
138138 an assessment or audit under Subsection (a) from a retail public
139139 utility.
140140 (d) The department shall provide to the center, and if
141141 applicable the standing committee of the legislature that requested
142142 the assessment or audit, access to each assessment or audit
143143 conducted under Subsection (a).
144144 (e) The department or the center may conduct a security
145145 assessment or audit required by this section on behalf of a retail
146146 public utility.
147147 (f) A retail public utility may contract with a person who
148148 is not the department or the center to conduct a security assessment
149149 or audit under this section.
150150 (g) Information contained in a report prepared under this
151151 section is confidential and not subject to disclosure under Chapter
152152 552, Government Code.
153153 (h) The commission, in consultation with the department and
154154 the center, shall adopt rules as necessary to implement this
155155 section.
156156 Sec. 13.606. SECURITY INCIDENT NOTIFICATION. (a) In this
157157 section:
158158 (1) "Confidential information" means information the
159159 disclosure of which is regulated by law.
160160 (2) "Sensitive personal information" has the meaning
161161 assigned by Section 521.002(a)(2)(A), Business & Commerce Code.
162162 (b) A retail public utility that owns, licenses, or
163163 maintains computerized data that includes sensitive personal
164164 information or other confidential information shall notify the
165165 commission, the utility commission, the department, and the center
166166 of a security incident, not later than 48 hours after the discovery
167167 of the incident, during which:
168168 (1) a person other than the retail public utility made
169169 an unauthorized acquisition of computerized data that compromises
170170 the security, confidentiality, or integrity of sensitive personal
171171 information or other confidential information maintained by the
172172 retail public utility, including data that is encrypted if the
173173 person who acquired the data has the key required to decrypt the
174174 data;
175175 (2) ransomware, as defined by Section 33.023, Penal
176176 Code, was introduced into a computer, computer network, or computer
177177 system; or
178178 (3) unauthorized access of a computer information
179179 system or network led to a substantial loss of availability of the
180180 system or network or otherwise disrupted a retail public utility's
181181 ability to engage in business or deliver services.
182182 (c) Subsection (b)(1) does not apply to a good faith
183183 acquisition of data by an employee or agent of the retail public
184184 utility for the purposes of the retail public utility if the
185185 employee or agent does not use or disclose the data in an
186186 unauthorized manner.
187187 SECTION 4. Not later than September 1, 2026, the Texas
188188 Commission on Environmental Quality and the Department of
189189 Information Resources shall adopt the rules necessary to implement
190190 the changes in law made by this Act.
191191 SECTION 5. A retail public utility shall comply with
192192 Section 13.602, Water Code, as added by this Act, not later than
193193 September 1, 2027.
194194 SECTION 6. This Act takes effect September 1, 2025.