Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.
This bill expands New York’s cybersecurity reporting and preparedness requirements across municipal corporations, public authorities, and state agencies. It creates a new article in the General Municipal Law requiring local governments and public authorities to report cybersecurity incidents, including ransomware demands, to the Division of Homeland Security and Emergency Services within 72 hours of reasonably believing an incident occurred. If a ransom is paid, the entity must provide notice within 24 hours and a written explanation within 30 days describing why payment was necessary, the amount paid, the payment method, alternatives considered, and diligence performed to comply with applicable state and federal rules.
The bill also directs the commissioner of homeland security and emergency services to review incident reports, assess their impact on public health, safety, welfare, and security, and coordinate with state and federal agencies to share trends, threat indicators, and defensive measures. It requires these incident reports, ransom-related records, and related review materials to be exempt from disclosure under the Freedom of Information Law. In addition, the bill adds cybersecurity awareness training requirements for state and certain local government employees who use technology in their jobs, beginning January 1, 2026, with training generally occurring during work hours and at regular pay.
The bill would amend the General Municipal Law, Executive Law, and State Technology Law to create a more formal statewide cybersecurity incident reporting and response framework. It imposes new mandatory reporting duties on municipal corporations and public authorities, establishes confidentiality protections for incident-related records, and authorizes state review and coordination of reported incidents. For state agencies, it requires the development of cybersecurity policies and standards, information system inventories, incident response plans, annual exercises, and confidentiality protections for those plans and inventories. It also establishes workforce training and data protection obligations for state-maintained information systems, affecting state agencies, public benefit corporations headed by gubernatorial appointees, and local government employees covered by the training provisions.
The available voting history shows strong support for the bill, with unanimous approval in the Assembly Local Governments Committee and unanimous final passage in the Assembly. That pattern suggests broad agreement that the state should strengthen cybersecurity preparedness, improve incident visibility, and formalize response procedures for public entities. The bill’s framing around ransomware, incident reporting, and data protection indicates a generally security-focused and preventive policy approach rather than a controversial regulatory expansion.
No committee transcript is available, and the recorded votes show no opposition, so there is no documented floor or committee controversy in the provided materials. The most likely points of policy sensitivity are the new reporting deadlines, the requirement to disclose ransom-payment details to the state, the confidentiality carveouts from FOIL, and the training and compliance burdens placed on local governments and state agencies. Another possible area of concern is the bill’s broad confidentiality treatment of incident reports and agency security inventories, which may raise transparency questions even as it is intended to protect sensitive cybersecurity information.