SB1363 amends the Illinois State Officials and Employees Ethics Act to require annual cybersecurity training for each officer, member, and employee covered by the Act. New officeholders or employees who fill a vacancy would have to complete the initial training within 30 days of starting service. The bill specifies minimum training topics, including malware, phishing, social engineering, ransomware, password security, multi-factor authentication, data privacy and secure file sharing, recognizing suspicious links and websites, and steps to protect and report lost or stolen devices.
The bill also requires each ultimate jurisdictional authority to file an annual report with the appropriate Ethics Commission documenting the cybersecurity training. In practical terms, it creates a recurring compliance and reporting obligation for state officials and employees and adds a cybersecurity education requirement to existing ethics-related training and oversight structures. The measure does not appear to create new criminal penalties or substantive privacy rules, but it does formalize cybersecurity awareness as part of government ethics compliance.
Impact
SB1363 would add a new Section 5-10.10 to the State Officials and Employees Ethics Act, expanding the Act’s training requirements to include cybersecurity. It would affect state officers, members, and employees subject to the Act, as well as the ultimate jurisdictional authorities responsible for ensuring training compliance and reporting to the Ethics Commission. The bill would likely require agencies and offices to adopt or update training programs, track completion, and prepare annual reports, but it does not amend substantive cybersecurity or data privacy statutes beyond the training mandate.
Sentiment
Based on the bill text and the absence of recorded committee testimony or votes, the overall sentiment appears neutral to favorable toward improving government cybersecurity readiness. The proposal is framed as a preventive, administrative measure rather than a controversial policy shift, suggesting it is intended to strengthen awareness and reduce risk across state government. No formal opposition, amendments, or recorded vote history is available in the provided materials.
Contention
No specific points of contention are documented in the provided context because there are no committee transcripts or votes. Potential areas of debate, if any arise later, would likely concern the administrative burden of annual training and reporting, the cost of implementing training programs across agencies, and whether the requirements duplicate existing ethics or information-security training. The bill’s supporters would likely emphasize risk reduction, while any skeptics might focus on compliance workload and implementation details.