Maryland Cybersecurity Council - Alterations
SB294 revises the structure and duties of the Maryland Cybersecurity Council. The bill changes how the Council’s chair is selected, moving from a chair designated by the Attorney General to a chair and vice chair elected by the Council beginning October 1, 2025, with one officer required to be a State employee and the other a non-State employee. It also updates Council membership by shifting several appointments to the Governor or other designated entities, adding or clarifying representation from business, higher education, critical infrastructure, privacy, and technology stakeholders, and inviting additional federal participation.
The bill expands the Council’s mandate beyond general cybersecurity coordination to specifically assess and address cybersecurity threats and associated risks from artificial intelligence and quantum computing. It directs the Council to work with NIST, federal agencies, private businesses, nonprofits, and cybersecurity experts to review critical infrastructure risks, assist entities in following federal guidance, identify critical cyber infrastructure, examine state-federal legal inconsistencies, and recommend legislative changes. It also adds responsibilities related to resident privacy interests and emerging AI threats such as adversarial AI, cyberattacks, deepfakes, unethical use, and fraud.
SB294 amends Section 9-2901 of the State Government Article, altering the composition, appointment process, and leadership structure of the Maryland Cybersecurity Council and expanding its statutory duties. It adds new categories of members and stakeholders, including representatives from the Maryland Chamber of Commerce, the Cybersecurity Association of Maryland, financial, health, water, and electric sectors, privacy and technology organizations, and higher education institutions with expertise in cybersecurity, AI, and quantum computing. The bill also requires the Council to review and adjust its subcommittee structure and bylaws by December 1, 2025, and takes effect October 1, 2025.
The bill appears to have broad bipartisan support and little visible opposition. The recorded floor votes were unanimous or near-unanimous, with third reading passage in both chambers showing no dissenting votes. The lack of committee transcript material suggests no major public controversy surfaced in the available record, and the bill’s focus on cybersecurity modernization, critical infrastructure protection, and emerging technology risks likely contributed to its favorable reception.
The main policy questions raised by the bill are structural rather than ideological: who should control Council leadership, which entities should appoint members, and how much representation should be given to government, industry, academia, and privacy advocates. The shift from Attorney General control to Council-elected leadership may matter to those concerned about executive branch oversight, while the expanded membership list could raise concerns about size, balance, and stakeholder influence. Another point of interest is the bill’s explicit focus on artificial intelligence and quantum computing, which may prompt debate over whether the Council’s expanded mandate is sufficiently specific or too broad, but no recorded opposition is evident in the available materials.