A BILL to amend the Code of Virginia by adding a section numbered 2.2-2012.2, relating to Virginia Information Technologies Agency; powers of the CIO; creation of Cyber Civilian Corps.
HB83 would create the Virginia Cyber Civilian Corps within the Virginia Information Technologies Agency (VITA) to provide rapid-response cybersecurity assistance to municipal, educational, nonprofit, and critical infrastructure organizations that experience a cybersecurity incident. The bill authorizes VITA’s Chief Information Officer (CIO), working with a new advisory board, to recruit and manage volunteers and non-deployable advisors, set expertise standards, approve tools, publish operating guidelines, and establish training and client-contract requirements.
The bill sets out eligibility and screening rules for Corps participants, including confidentiality obligations, conflict-of-interest disclosures, compliance with VITA security policies, background screening, and State Police criminal history checks. It also defines deployment procedures, generally limiting volunteer deployments to seven days unless extended in writing, and allows VITA to reimburse travel and subsistence expenses and charge clients fees designed only to recover costs, not generate profit. The bill further exempts certain sensitive cybersecurity-related information from disclosure under the Virginia Freedom of Information Act.
HB83 would add a new section to the Code of Virginia, § 2.2-2012.2, expanding VITA’s authority to organize a state-run cybersecurity volunteer response program. It would create new administrative duties for the CIO and an advisory board, establish screening and deployment procedures, provide limited immunity and indemnification-related provisions for volunteers, advisors, VITA, and the Commonwealth, and protect specified cybersecurity information from FOIA disclosure. The bill would affect public-sector cybersecurity response and could also impact municipalities, schools, nonprofits, critical infrastructure entities, and volunteer cybersecurity professionals.
The available legislative history shows limited recorded debate, but the bill was continued to the next session by voice vote in the Communications, Technology and Innovation committee. That suggests the proposal was not rejected outright, but also did not advance immediately. Based on the bill’s structure, it appears to have been framed as a cybersecurity preparedness and mutual-aid measure, with an emphasis on controlled deployment, oversight, and confidentiality.
The main points of potential contention are the scope of VITA’s authority, liability protections, and the use of volunteers in sensitive cybersecurity incidents. The bill gives the CIO broad discretion over eligibility, deployment, tools, and client prioritization, which could raise oversight concerns. Its immunity and indemnification provisions for volunteers, advisors, VITA, and the Commonwealth may also draw scrutiny, especially where negligence, gross negligence, or criminal allegations are involved. In addition, the background-check requirements and FOIA exemptions reflect a tension between security and transparency.