Estates and Trusts - Jurisdiction Over Property of Minors or Disabled Persons - Authorized Transactions
HB1062 establishes a new cybersecurity framework for Maryland’s community water systems and community sewerage systems. The bill directs the Department of the Environment, working with the Department of Information Technology and the Maryland Department of Emergency Management, to coordinate cybersecurity efforts in the water and wastewater sector, update regulations, set minimum cybersecurity standards, and require planning for cyber disruptions such as ransomware and root-level compromise. It also requires cybersecurity awareness training for operators and superintendents, creates approved training programs, and calls for a zero-trust approach for larger or technology-dependent systems.
The bill further requires affected providers to designate a cybersecurity point of contact, attend annual training, and, for systems serving more than 3,300 customers or using information technology and operational technology, undergo recurring third-party maturity assessments. It also creates a reporting structure for cybersecurity incidents to the State Security Operations Center, with annual public reporting of incident counts and types in aggregate form, and periodic reports to the General Assembly on compliance and implementation progress. In addition, it expands confidentiality protections by barring inspection of public records that reveal security information about information systems, operational technology, or critical infrastructure, including records related to community water and sewerage systems.
HB1062 would add a new subtitle to the Environment Article governing cybersecurity for community water and sewerage systems and amend the Public Information Act and Public Safety Article to support that framework. It would impose new duties on the Department of the Environment, the Department of Information Technology, the Maryland Department of Emergency Management, and affected utilities, while also limiting public access to certain security-related records. The bill would create ongoing compliance, reporting, training, and assessment obligations for water and wastewater providers, especially larger systems and those using operational technology.
The bill appears to have been treated as a serious infrastructure-security measure, with the committee report marked favorable with amendments and the House adopting the bill. The text emphasizes coordination, preparedness, training, and use of federal cybersecurity standards, suggesting broad policy support for strengthening protections around essential water and wastewater services. No vote breakdown or transcript is available in the provided materials, so the record does not show organized opposition, but the amendments indicate the bill was refined during committee review.
The main points of potential contention are the scope and cost of compliance for community water and sewerage systems, especially smaller providers that may need to adopt new standards, conduct third-party assessments, and participate in recurring training and reporting. Another likely issue is the bill’s confidentiality provision, which restricts inspection of records concerning information-system, operational-technology, and critical-infrastructure security; that could raise transparency concerns even as it is intended to protect sensitive infrastructure details. The bill also places significant coordination and implementation responsibilities on state agencies, which may have prompted the amendments referenced in the committee report.