Technology; liability protections; counties; municipalities; cybersecurity frameworks; State Auditor and Inspector; effective date.
Summary
HB4132 creates a liability safe harbor for counties and municipalities that adopt and reasonably follow recognized cybersecurity frameworks. Specifically, a local government would not be held civilly liable for damages from a data breach or cybersecurity incident if, at the time of the incident, it had adopted one or more of three frameworks: the NIST Cybersecurity Framework, the CIS Critical Security Controls, or the ISO/IEC 27000 series standards.
To qualify for the protection, a county or municipality must complete an annual self-certification by its IT officer or designee, maintain records showing implementation of cybersecurity practices, and obtain an independent external assessment at least once every three years. The bill also allows local governments to voluntarily submit summary information about their self-certification or review to the State Auditor and Inspector for statewide benchmarking and education. The act is set to take effect November 1, 2026.
Impact
The bill would add a new section to Title 75A of the Oklahoma Statutes and change the legal exposure of counties and municipalities in cybersecurity-related civil lawsuits. It does not create a new cybersecurity mandate for all local governments, but it does establish a statutory safe harbor tied to documented compliance with recognized security standards and periodic third-party review. The bill also treats the independent review report as confidential under the Oklahoma Open Records Act, while permitting optional reporting to the State Auditor and Inspector for benchmarking purposes.
Sentiment
The available committee and floor votes suggest broad support for the measure. It passed the County and Municipal Government Committee unanimously, passed the Government Oversight Committee by a wide margin, and cleared House third reading 74-0. The limited transcript excerpts are procedural and do not show substantive opposition, which is consistent with the strong vote totals and the bill’s framing as a liability-protection and cybersecurity best-practices measure.
Contention
There is little visible contention in the available record, but the main policy issue is the balance between encouraging cybersecurity compliance and limiting legal accountability for local governments after a breach. Supporters appear to favor the bill as a way to incentivize adoption of recognized security frameworks and reduce litigation risk for counties and municipalities that follow them. Any potential concerns would likely center on whether the safe harbor is too broad, whether the self-certification and three-year external review are sufficient, and how much transparency should exist given the confidentiality of the assessment report.
State Auditor and Inspector; requiring the State Auditor and Inspector perform a special audit of the Oklahoma Turnpike Authority by certain date; effective date; emergency.
Ad valorem taxation; creating the Property Tax Transparency Act; requiring the State Auditor and Inspector to enforce the provisions of the act. Effective date. Emergency.