HB 235 revises Maryland’s state cybersecurity framework by changing the duties of the Cyber Preparedness Unit in the Department of Emergency Management and the Office of Security Management in the Department of Information Technology. The bill shifts and clarifies responsibilities for supporting local governments, including local school systems, school boards, and local health departments, in cybersecurity preparedness, response, and recovery. It also updates the kinds of resources the Cyber Preparedness Unit must provide, such as online training materials, continuity-of-operations templates, and consequence management plans, while preserving its role in coordinating regional exercises and assistance groups.
The bill also expands and refines the Office of Security Management’s authority over statewide cybersecurity policy, standards, and incident response. It requires the Office to continue setting information and system categorization standards, security requirements, training, and guidance, while adding explicit support for local governments in developing vulnerability and cyber assessments and obtaining resources to complete them. The bill updates reporting requirements to the Governor and legislative committees, including annual reporting on cybersecurity activities, preparedness, and key performance indicators, and it removes some prior reporting items while adding a separate report on cybersecurity spending relative to overall IT spending and recommendations for budget changes. It also clarifies the Secretary of Information Technology’s role in implementing and maintaining IT policies and a statewide cybersecurity strategy.
The bill’s impact on state law is primarily administrative and structural rather than creating new criminal or regulatory penalties. It amends provisions in the Public Safety Article and the State Finance and Procurement Article to reassign, clarify, and expand cybersecurity coordination duties across state agencies, especially in relation to local government support, emergency response, and statewide cybersecurity governance. It also changes the timing and content of required reports and reinforces the Department of Information Technology’s central role in executive branch cybersecurity strategy and budget planning.
Overall, the bill appears to have been noncontroversial and technical in nature, focused on modernizing and clarifying cybersecurity responsibilities rather than advancing a disputed policy change. No committee transcript or vote data was provided showing opposition or debate, and the enacted chapter suggests it moved through the process successfully. The main policy emphasis is on improving preparedness, coordination, and reporting, with particular attention to helping local governments meet cybersecurity risks.
Notable points of potential contention, based on the text alone, would likely involve the scope of state oversight versus local autonomy, the added administrative burden of reporting and assessments, and how cybersecurity funding priorities are set. However, the available record does not show specific objections or named opponents, so any contention appears limited or absent in the materials provided.
HB 235 amends Maryland law in the Public Safety Article and the State Finance and Procurement Article to revise the duties of the Cyber Preparedness Unit, the Office of Security Management, and the Secretary of Information Technology. It strengthens the state’s cybersecurity coordination structure by requiring more explicit support for local governments, updating statewide cybersecurity policy and strategy responsibilities, and modifying annual reporting requirements to focus on preparedness, incident response, and cybersecurity spending. The bill takes effect October 1, 2025.
The available materials suggest broad support or at least little visible opposition. The bill is framed as a cybersecurity modernization measure, and the absence of recorded committee testimony or vote controversy indicates a generally favorable or routine legislative reception. Its enacted status also suggests it was viewed as a practical administrative update to state cybersecurity operations.
No specific contention is documented in the provided transcripts or vote history. Based on the bill text, the most likely areas of debate would be whether the state should further centralize cybersecurity oversight, how much assistance should be mandated for local governments, and whether the revised reporting and assessment requirements create additional workload or cost. The text also removes some prior budget-analysis language from the annual report, which could be relevant to stakeholders concerned about transparency in cybersecurity spending.