Maryland 2025 Regular Session

Maryland House Bill HB235

Introduced
1/8/24  
Introduced
1/8/25  
Refer
1/8/24  
Refer
1/8/25  
Report Pass
2/17/25  
Engrossed
2/20/25  
Refer
2/21/25  
Report Pass
4/3/25  
Enrolled
4/5/25  
Chaptered
4/22/25  

Caption

State Government - Information Technology - Cybersecurity Revisions

Summary

HB235 revises Maryland’s state cybersecurity framework by updating the duties of the Cyber Preparedness Unit in the Maryland Department of Emergency Management, the Office of Security Management in the Department of Information Technology, and the Secretary of Information Technology. The bill keeps the basic structure of state cybersecurity coordination in place, but refines how those agencies support local governments, respond to incidents, and report on cybersecurity readiness. It also updates terminology and reporting deadlines, and clarifies that the Office’s role includes implementing and maintaining information technology policies and a statewide cybersecurity strategy. A major focus of the bill is support for local governments. The Cyber Preparedness Unit and the Office of Security Management are directed to help local governments develop vulnerability and cyber assessments, provide best-practice resources, connect them to assistance, and coordinate regional exercises and assistance groups. The bill also expands the annual reporting requirements to the Governor and legislative committees, including information on cybersecurity spending, budget recommendations, performance indicators, and remediation needs, while continuing to prohibit disclosure of sensitive vulnerabilities in the report.

Impact

HB235 amends provisions in the Public Safety Article and the State Finance and Procurement Article to broaden and clarify the cybersecurity responsibilities of state agencies. It changes the duties of the Cyber Preparedness Unit and the Office of Security Management, adds explicit support for local governments’ vulnerability and cyber assessments, and revises the annual reporting structure and content. It also updates the Secretary of Information Technology’s responsibilities to expressly include implementing and maintaining IT policies and a statewide cybersecurity strategy, reinforcing centralized executive-branch cybersecurity management.

Sentiment

The bill appears to have been broadly supported and noncontroversial. It passed the House 134-0 and the Senate 43-0, indicating unanimous approval in both chambers. The absence of committee transcript debate suggests the measure was viewed as a technical and administrative cybersecurity update rather than a contested policy shift.

Contention

There is little evidence of substantive opposition. The main policy emphasis is on how much responsibility should be placed on state cybersecurity offices versus local governments, and on the scope of reporting to the legislature. The bill also removes some prior language about specific assessment support and budget analysis while adding new reporting on cybersecurity spending and budget recommendations, but these changes do not appear to have generated disagreement in the recorded votes.

Companion Bills

MD SB244

Crossfiled State Government - Information Technology - Cybersecurity Revisions

Similar Bills

No similar bills found.