Florida 2025 1st Special Session

Florida House Bill HB1293

Caption

Cybersecurity:

Summary

HB 1293 would substantially revise Florida’s cybersecurity and state technology governance framework. The bill expands the Florida Digital Service’s role in enterprise IT oversight, cybersecurity planning, procurement standards, and data stewardship, while also creating a state chief technology officer position to help align technology investments with statewide strategic objectives. It updates definitions related to cloud services and “enterprise digital data,” and it broadens the Digital Service’s authority over project management, interoperability, cloud-first modernization, and standards for state IT contracts. The bill also tightens incident reporting and response requirements for both state agencies and local governments. It shortens reporting deadlines for ransomware and higher-severity cybersecurity incidents, requires immediate notification to the Cybersecurity Operations Center and law enforcement, and mandates prompt notice to legislative leaders for serious incidents in a secure setting. It adds requirements for quarterly consolidated incident reports, cybersecurity briefings to legislative committees, annual designation of agency chief information security officers, and expanded duties for information security managers. The bill further revises the Florida Cybersecurity Advisory Council to add a local government representative and a critical infrastructure representative from a utility or water treatment facility. In terms of state law impact, HB 1293 would amend multiple sections of chapter 282, Florida Statutes, affecting state agencies, Cabinet agencies, local governments, the Department of Management Services, the Florida Digital Service, the Department of Law Enforcement, and the Legislature. It raises the project-cost thresholds for certain oversight and procurement actions, changes reporting timelines, and authorizes stronger state-level access to and direction over infrastructure hosting enterprise digital data. It also removes a prior restriction on the department retrieving or disclosing certain data absent a shared-data agreement, while still preserving public-records limitations and confidentiality rules where applicable. The general sentiment reflected by the bill text is one of stronger cybersecurity centralization and modernization, with an emphasis on faster reporting, clearer accountability, and more active state oversight of technology projects. Because there were no committee transcripts or recorded votes provided, there is no direct evidence of debate or support/opposition in the available materials. The bill’s structure suggests a policy priority on improving incident response, reducing risk, and standardizing IT governance across government. Notable points of potential contention include the expanded authority of the Florida Digital Service over agency and local government cybersecurity matters, the shortened incident-reporting deadlines, and the requirement for secure legislative briefings on confidential incidents. Another possible issue is the bill’s change to data access rules and its broader oversight of large IT projects, which could raise concerns about agency autonomy, operational burden, and confidentiality. The bill died in the Information Technology Budget & Policy Subcommittee, indicating it did not advance despite its broad cybersecurity reforms.

Impact

HB 1293 would amend Florida Statutes sections 282.0041, 282.0051, 282.00515, 282.318, 282.3185, and 282.319 to expand the Florida Digital Service’s authority over enterprise IT, cybersecurity governance, project oversight, procurement standards, and data stewardship. It would create a state chief technology officer role, increase oversight thresholds for major IT projects, require faster reporting of ransomware and cybersecurity incidents, and add new notification and briefing obligations for state agencies, local governments, and legislative leaders. It would also revise the membership of the Florida Cybersecurity Advisory Council and affect confidentiality and public-records handling for certain cybersecurity-related briefings.

Sentiment

The bill appears generally favorable toward stronger cybersecurity controls, modernization, and centralized oversight, with an emphasis on rapid incident reporting and coordinated response. No committee transcripts or vote records were provided, so there is no direct evidence of floor or committee debate in the available materials. Its failure in the Information Technology Budget & Policy Subcommittee suggests it did not secure enough support to move forward, but the text itself reflects a policy consensus-oriented approach to cybersecurity risk management.

Contention

The main points of contention likely involve the bill’s expansion of state oversight and reporting obligations. State and local agencies may view the tighter deadlines, mandatory reporting, and broader Florida Digital Service authority as burdensome or intrusive, especially the provisions allowing immediate access to infrastructure hosting enterprise digital data and the removal of a prior restriction on data retrieval/disclosure absent a shared-data agreement. Legislative confidentiality procedures and secure briefings on sensitive incidents may also raise concerns about transparency versus security. The bill’s death in subcommittee suggests unresolved concerns about scope, implementation, or policy priorities.

Companion Bills

No companion bills found.

Previously Filed As

FL H1293

Cybersecurity

FL H7013

OGSR/Cybersecurity

FL H1183

Cybersecurity Incident Liability

FL S7020

OGSR/Agency Cybersecurity Information

FL H1379

Cybersecurity Risks from Unmanned Aircraft Systems

FL H1321

Higher Education

FL H1309

Reading Interventions and Instruction

FL H1397

Transportation

FL H7033

Taxation

FL H1535

Emergencies

Similar Bills

NJ A3959

Establishes Office of Cybersecurity Infrastructure.

NJ S1262

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

CA AB979

California Cybersecurity Integration Center: artificial intelligence.

NJ A1550

Requires adoption and implementation of cybersecurity standards by casinos and sportsbooks; establishes safe gaming certification program.

NM SB254

Cybersecurity Act & Office Changes

NJ S2940

Establishes Office of Cybersecurity Infrastructure.

NJ A1549

Establishes Gaming Cybersecurity Intelligence and Response Council.

TX HB150

Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.