State Government - Information Technology - Cybersecurity Revisions
Summary
SB244 revises Maryland’s state cybersecurity framework by updating the duties of the Cyber Preparedness Unit in the Department of Emergency Management and the Office of Security Management in the Department of Information Technology. The bill shifts and clarifies responsibilities for supporting local governments, school systems, school boards, and local health departments with cybersecurity preparedness, including training resources, best practices, vulnerability assessments, response planning, regional exercises, and regional assistance groups.
The bill also updates the Secretary of Information Technology’s duties to emphasize implementing and maintaining statewide IT policies and a centralized cybersecurity strategy. It revises the required annual cybersecurity report to the Governor and legislative committees, changes what information must be included, and adds a new reporting requirement focused on cybersecurity spending relative to overall IT spending and recommendations for budget changes. The bill takes effect October 1, 2025.
Impact
SB244 amends provisions in the Public Safety Article and the State Finance and Procurement Article governing Maryland’s cybersecurity governance structure. It expands and refines the authority of the Cyber Preparedness Unit and the Office of Security Management, adds explicit support for local vulnerability and cyber assessments, and updates reporting and budget-related oversight requirements. The bill also changes the Secretary of Information Technology’s statutory responsibilities to include implementing, not just developing, IT policies and the statewide cybersecurity strategy, which may affect how cybersecurity priorities are managed across executive branch agencies and how funding decisions are made.
Sentiment
The bill appears to have been broadly supported and noncontroversial. It passed the Senate 44-0 and the House 132-0, indicating unanimous approval in both chambers. The committee report was favorable with amendments, suggesting the bill was generally accepted while still being refined during the legislative process.
Contention
There is little evidence of major opposition in the available record. The main substantive issues appear to have been administrative and structural rather than ideological: how responsibilities should be divided between the Department of Emergency Management and the Department of Information Technology, what support local governments should receive, and how cybersecurity spending and preparedness should be reported to the legislature. The amendments also suggest some adjustment over the scope of reporting and the exact duties of the affected offices, but no recorded committee debate or dissent is available.