New Jersey 2022-2023 Regular Session

New Jersey Assembly Bill A1979

Introduced
1/11/22  

Caption

Requires businesses in financial, essential infrastructure, and health care industries to report cybersecurity incidents.

Impact

Under A1979, affected businesses will be required to notify the NJCCIC immediately after becoming aware of a cybersecurity incident. Additionally, the bill stipulates that these businesses must undergo an audit within 30 days of reporting an incident, conducted by an independent cybersecurity firm at their own expense. This introduces a new layer of regulatory scrutiny around cybersecurity practices in sectors deemed critical, contributing to a more secure business environment in New Jersey.

Summary

Assembly Bill A1979 mandates that certain businesses, specifically those operating within the financial, essential infrastructure, and healthcare sectors, must promptly report any cybersecurity incidents to the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC). This legislation aims to enhance the state’s cybersecurity framework by ensuring that sensitive businesses are held accountable for any breaches that may jeopardize sensitive information. The bill defines a 'cybersecurity incident' broadly, capturing a variety of events that compromise the integrity and confidentiality of business operations.

Contention

Potential points of contention may arise regarding the financial responsibilities placed on businesses due to the requirement for audits, especially for smaller entities that might struggle to bear these additional costs. Moreover, some stakeholders could argue that the bill places an undue burden on businesses by further complicating compliance obligations and creating challenges in the case of reporting incidents without potential legal repercussions. Critics may call for more support for businesses in enhancing their cybersecurity measures rather than imposing fines or penalties for incidents that could stem from vulnerabilities beyond their control.

Companion Bills

No companion bills found.

Previously Filed As

NJ S1262

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

NJ A3231

Requires businesses in financial, essential infrastructure, and health care industries to report cybersecurity incidents.

NJ A3283

Requires businesses in financial, essential infrastructure, and health care industries to develop cybersecurity plans.

NJ S2940

Establishes Office of Cybersecurity Infrastructure.

NJ A4198

Requires New Jersey Cybersecurity and Communications Integration Cell to study cybersecurity infastructure and establish cybersecurity guidelines.

NJ A2024

Requires each government entity in this State to conduct review of cybersecurity infrastructure and make recommendations.

NJ S1225

Requires New Jersey Cybersecurity and Communications Integration Cell to study cybersecurity infastructure and establish cybersecurity guidelines.

NJ A3959

Establishes Office of Cybersecurity Infrastructure.

NJ S07672

Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.

NJ A06769

Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.

Similar Bills

NJ A3959

Establishes Office of Cybersecurity Infrastructure.

NJ S1262

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

CA AB979

California Cybersecurity Integration Center: artificial intelligence.

NJ A1550

Requires adoption and implementation of cybersecurity standards by casinos and sportsbooks; establishes safe gaming certification program.

NM SB254

Cybersecurity Act & Office Changes

NJ S2940

Establishes Office of Cybersecurity Infrastructure.

NJ A1549

Establishes Gaming Cybersecurity Intelligence and Response Council.

TX HB150

Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.