Creates a cyber security enhancement fund to be used for the purpose of upgrading cyber security in local governments, including but not limited to, villages, towns and cities with a population of one million or less; restricts the use of taxpayer moneys in paying ransoms in response to ransomware attacks.
Summary
This bill creates a new Cyber Security Enhancement Fund and directs the Division of Homeland Security and Emergency Services to establish a program to help local governments upgrade their cybersecurity systems. The program is aimed at local governments, including villages, towns, and cities with populations of one million or less. The fund would be housed in the state finance law and initially capitalized with a $5 million transfer from the general fund, along with any grants or other eligible contributions.
The bill also adds a policy restriction on ransomware response spending. Beginning January 1, 2028, local and state taxpayer moneys could not be used to pay ransoms in response to ransomware attacks. The measure is intended to both strengthen prevention and limit the use of public funds in cyber extortion situations.
Impact
The bill would amend the executive law and state finance law by creating a dedicated state fund for local cybersecurity upgrades and assigning DHSES responsibility for administering the program. It would shift $5 million from the general fund into a new restricted account and allow the fund to receive grants and other authorized contributions. It would also impose a statewide prohibition, effective in 2028, on using taxpayer funds to pay ransomware demands, affecting state and local governments that might otherwise consider ransom payments as part of incident response.
Sentiment
The bill’s overall tone is preventive and security-focused, reflecting concern about increasing ransomware threats to public entities. The caption and structure suggest support for helping local governments harden their systems while discouraging ransom payments that can incentivize future attacks. No committee transcripts or recorded votes were provided, so there is no direct evidence of formal support or opposition in the available record.
Contention
The main point of potential contention is the ban on using taxpayer money to pay ransoms, which could be viewed as limiting flexibility for governments facing urgent cyber incidents. Supporters are likely to argue that ransom payments encourage criminal activity and that public funds should instead go toward prevention and recovery. Another possible issue is the $5 million transfer from the general fund, which may raise budgetary concerns, though the bill does not include any recorded debate or vote history showing specific objections.
Same As
Creates a cyber security enhancement fund to be used for the purpose of upgrading cyber security in local governments, including but not limited to, villages, towns and cities with a population of one million or less; restricts the use of taxpayer moneys in paying ransoms in response to ransomware attacks.
Creates a cyber security enhancement fund to be used for the purpose of upgrading cyber security in local governments, including but not limited to, villages, towns and cities with a population of one million or less; restricts the use of taxpayer moneys in paying ransoms in response to ransomware attacks.
Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.