HB 1293 would substantially revise Florida’s cybersecurity and state technology governance framework. The bill expands the Florida Digital Service’s role in enterprise IT oversight, cybersecurity planning, procurement standards, and data stewardship, while also creating a state chief technology officer position to help align technology investments with statewide strategic objectives. It updates definitions related to cloud services and “enterprise digital data,” and it broadens the Digital Service’s authority over project management, interoperability, cloud-first modernization, and standards for state IT contracts.
The bill also tightens incident reporting and response requirements for both state agencies and local governments. It shortens reporting deadlines for ransomware and higher-severity cybersecurity incidents, requires immediate notification to the Cybersecurity Operations Center and law enforcement, and mandates prompt notice to legislative leaders for serious incidents in a secure setting. It adds requirements for quarterly consolidated incident reports, cybersecurity briefings to legislative committees, annual designation of agency chief information security officers, and expanded duties for information security managers. The bill further revises the Florida Cybersecurity Advisory Council to add a local government representative and a critical infrastructure representative from a utility or water treatment facility.
In terms of state law impact, HB 1293 would amend multiple sections of chapter 282, Florida Statutes, affecting state agencies, Cabinet agencies, local governments, the Department of Management Services, the Florida Digital Service, the Department of Law Enforcement, and the Legislature. It raises the project-cost thresholds for certain oversight and procurement actions, changes reporting timelines, and authorizes stronger state-level access to and direction over infrastructure hosting enterprise digital data. It also removes a prior restriction on the department retrieving or disclosing certain data absent a shared-data agreement, while still preserving public-records limitations and confidentiality rules where applicable.
The general sentiment reflected by the bill text is one of stronger cybersecurity centralization and modernization, with an emphasis on faster reporting, clearer accountability, and more active state oversight of technology projects. Because there were no committee transcripts or recorded votes provided, there is no direct evidence of debate or support/opposition in the available materials. The bill’s structure suggests a policy priority on improving incident response, reducing risk, and standardizing IT governance across government.
Notable points of potential contention include the expanded authority of the Florida Digital Service over agency and local government cybersecurity matters, the shortened incident-reporting deadlines, and the requirement for secure legislative briefings on confidential incidents. Another possible issue is the bill’s change to data access rules and its broader oversight of large IT projects, which could raise concerns about agency autonomy, operational burden, and confidentiality. The bill died in the Information Technology Budget & Policy Subcommittee, indicating it did not advance despite its broad cybersecurity reforms.
HB 1293 would amend Florida Statutes sections 282.0041, 282.0051, 282.00515, 282.318, 282.3185, and 282.319 to expand the Florida Digital Service’s authority over enterprise IT, cybersecurity governance, project oversight, procurement standards, and data stewardship. It would create a state chief technology officer role, increase oversight thresholds for major IT projects, require faster reporting of ransomware and cybersecurity incidents, and add new notification and briefing obligations for state agencies, local governments, and legislative leaders. It would also revise the membership of the Florida Cybersecurity Advisory Council and affect confidentiality and public-records handling for certain cybersecurity-related briefings.
The bill appears generally favorable toward stronger cybersecurity controls, modernization, and centralized oversight, with an emphasis on rapid incident reporting and coordinated response. No committee transcripts or vote records were provided, so there is no direct evidence of floor or committee debate in the available materials. Its failure in the Information Technology Budget & Policy Subcommittee suggests it did not secure enough support to move forward, but the text itself reflects a policy consensus-oriented approach to cybersecurity risk management.
The main points of contention likely involve the bill’s expansion of state oversight and reporting obligations. State and local agencies may view the tighter deadlines, mandatory reporting, and broader Florida Digital Service authority as burdensome or intrusive, especially the provisions allowing immediate access to infrastructure hosting enterprise digital data and the removal of a prior restriction on data retrieval/disclosure absent a shared-data agreement. Legislative confidentiality procedures and secure briefings on sensitive incidents may also raise concerns about transparency versus security. The bill’s death in subcommittee suggests unresolved concerns about scope, implementation, or policy priorities.