New Jersey 2022-2023 Regular Session

New Jersey Assembly Bill A1981

Introduced
1/11/22  

Caption

Requires businesses in financial, essential infrastructure, and health care industries to develop cybersecurity plans.

Impact

The legislation directs the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC), along with the Attorney General, to develop rules and regulations that define accountability and responsibility for cybersecurity risk management. Businesses will need to conduct risk assessments, produce incident response plans, and provide annual certifications of compliance. The NJCCIC is empowered to supervise these businesses, conduct audits if necessary, and ensure that organizations adhere to the regulations put forth, thus potentially leading to improved cybersecurity standards within these key industries.

Summary

Assembly Bill 1981, introduced in the New Jersey legislature, mandates that businesses operating within the financial services, essential infrastructure, and healthcare sectors develop comprehensive cybersecurity plans. This requirement is aimed at enhancing the cybersecurity posture of organizations that handle sensitive information and critical operations. The bill outlines a structured approach for these businesses to implement and maintain cybersecurity programs reflective of industry best practices, as well as the need for continuous evaluation and improvement of security measures in response to evolving threats.

Contention

However, the bill may raise concerns regarding the financial burden on smaller enterprises that may struggle to implement extensive cybersecurity infrastructures. Critics may argue that the costs associated with compliance and audits could hinder the operational capabilities of smaller businesses. Furthermore, there are concerns about the adequacy of the NJCCIC's resources to effectively monitor and audit a diverse array of businesses under its jurisdiction. Balancing the need for heightened security without overburdening businesses is a critical point of contention in the discussions surrounding this bill.

Companion Bills

No companion bills found.

Previously Filed As

NJ S1262

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

NJ A3283

Requires businesses in financial, essential infrastructure, and health care industries to develop cybersecurity plans.

NJ A3231

Requires businesses in financial, essential infrastructure, and health care industries to report cybersecurity incidents.

NJ S2940

Establishes Office of Cybersecurity Infrastructure.

NJ A3959

Establishes Office of Cybersecurity Infrastructure.

NJ A4945

Requires BPU to conduct study on environmental, infrastructural, and financial impacts of data center development in State.

NJ A2024

Requires each government entity in this State to conduct review of cybersecurity infrastructure and make recommendations.

NJ A4198

Requires New Jersey Cybersecurity and Communications Integration Cell to study cybersecurity infastructure and establish cybersecurity guidelines.

NJ S1225

Requires New Jersey Cybersecurity and Communications Integration Cell to study cybersecurity infastructure and establish cybersecurity guidelines.

NJ A3304

Requires development of State data and technology infrastructure investment plan for public health emergencies.

Similar Bills

NJ A3959

Establishes Office of Cybersecurity Infrastructure.

NJ S1262

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

CA AB979

California Cybersecurity Integration Center: artificial intelligence.

NJ A1550

Requires adoption and implementation of cybersecurity standards by casinos and sportsbooks; establishes safe gaming certification program.

NM SB254

Cybersecurity Act & Office Changes

NJ S2940

Establishes Office of Cybersecurity Infrastructure.

NJ A1549

Establishes Gaming Cybersecurity Intelligence and Response Council.

TX HB150

Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.