Creates a cyber security enhancement fund to be used for the purpose of upgrading cyber security in local governments, including but not limited to, villages, towns and cities with a population of one million or less; restricts the use of taxpayer moneys in paying ransoms in response to ransomware attacks.
Summary
Bill S00193 aims to enhance cyber security for local governments in New York, specifically targeting villages, towns, and cities with populations of one million or less. The bill establishes a Cyber Security Enhancement Fund, which will be financed by an initial transfer of five million dollars from the state general fund and additional grants or financial contributions. This fund will be managed by the state comptroller and the commissioner of taxation and finance, and it will be used to upgrade cyber security measures across the specified local governments.
In addition to establishing the fund, the bill includes a significant provision that prohibits the use of taxpayer money for paying ransoms in the event of ransomware attacks, effective from January 1, 2028. This aims to discourage the practice of paying ransoms and encourages local governments to invest in preventive measures instead.
The bill's impact on state laws includes the formal establishment of a dedicated fund for cyber security improvements and the restriction on the use of public funds for ransom payments, which could reshape how local governments respond to cyber threats. This legislation is expected to promote better cyber security practices and resource allocation at the local level, potentially reducing the risk of successful cyber attacks.
The general sentiment around the bill appears to be supportive, as it addresses a growing concern regarding cyber security vulnerabilities among local governments. However, there may be some apprehension regarding the implications of restricting ransom payments, as this could leave local governments in difficult positions during cyber incidents. Overall, the bill seems to be well-received as a proactive measure to enhance cyber resilience.
Impact
The bill establishes a Cyber Security Enhancement Fund to support local governments in upgrading their cyber security infrastructure. It also introduces a prohibition on the use of taxpayer funds for ransom payments in response to ransomware attacks, which could lead to changes in how local governments manage cyber security threats and allocate resources. This legislation aims to strengthen the overall cyber security posture of local governments in New York.
Sentiment
The sentiment surrounding Bill S00193 is largely positive, as it addresses critical issues related to cyber security for local governments. Lawmakers and stakeholders recognize the importance of enhancing cyber defenses, especially in light of increasing cyber threats. However, there may be concerns regarding the restriction on ransom payments, with some arguing that it could hinder local governments' ability to respond effectively to cyber attacks.
Contention
Notable points of contention include the provision that prohibits the use of taxpayer money for ransom payments. Some lawmakers and local government representatives may express concern that this could leave them vulnerable in the event of a ransomware attack, potentially forcing them to choose between paying ransoms and risking data loss or operational disruptions. The balance between encouraging proactive cyber security measures and providing adequate response options during crises is a key point of debate.
Same As
Creates a cyber security enhancement fund to be used for the purpose of upgrading cyber security in local governments, including but not limited to, villages, towns and cities with a population of one million or less; restricts the use of taxpayer moneys in paying ransoms in response to ransomware attacks.
Creates a cyber security enhancement fund to be used for the purpose of upgrading cyber security in local governments, including but not limited to, villages, towns and cities with a population of one million or less; restricts the use of taxpayer moneys in paying ransoms in response to ransomware attacks.
Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.