Relating to requiring the Department of Information Resources to conduct a study concerning the cybersecurity of small businesses.
Impact
The study required by HB1172 is expected to lead to significant implications for state-level initiatives aimed at enhancing the cybersecurity posture of small enterprises. By potentially establishing a grant program, the bill would facilitate much-needed financial aid for small businesses to improve their cybersecurity infrastructure and participate in essential training programs. This could be critical in a landscape where cyber threats are continuously evolving, especially for smaller organizations that may lack the resources to combat such risks effectively.
Summary
HB1172 mandates the Department of Information Resources to conduct a comprehensive study on cybersecurity for small businesses. The aim is to identify how these entities can improve their defenses against cybersecurity threats, particularly those impacting their supply chain. The bill emphasizes the necessity of understanding current best practices, challenges small businesses face regarding cybersecurity products, and ultimately aims to propose a structured approach for small businesses to mitigate and recover from cyber incidents.
Contention
While the bill is designed to provide better protective measures for small businesses, there may be concerns regarding the effectiveness and reach of a grant program, as well as the capacity of small businesses to adapt to recommended practices identified in the study. Critics might raise issues regarding the allocation of state resources, questioning whether support should be centralized or if additional frameworks should be established to ensure proper implementation of recommendations found in the study. Furthermore, transparency in how the program will function and ensure compliance among recipients of grants may also be a point of contention.
Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.
Requires the division of small business to conduct a study on certain stakeholder interest in a pilot program matching small businesses with content creators
Office of Information Technology, duties expanded to include cybersecurity and tasks previously performed by Division of Data Systems Management and Telecommunications Division of the Department of Finance
Relating to the continuation and functions of the Department of Information Resources, including the composition of the governing body of the department.
Removing the expiration on certain cybersecurity requirements, modifying the duties of chief information security officers and cybersecurity programs, requiring assessment of executive branch agency compliance with cybersecurity requirements, providing for consideration of such compliance by the legislature during the budget process and creating the judicial branch technology oversight council.
Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.
Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.