An act relating to the Cybersecurity Advisory Council
H.560 amends Vermont law governing the Cybersecurity Advisory Council. The bill expands the council’s membership by adding two legislative members: the chair of the House Committee on Energy and Digital Infrastructure and the chair of the Senate Committee on Institutions. It also adds a representative from the Judiciary, appointed by the Chief Justice of the Vermont Supreme Court. The stated purpose is to strengthen the council’s ability to advise on the state’s cybersecurity infrastructure, best practices, communications protocols, standards, training, and safeguards.
The council already includes executive branch officials and representatives from critical infrastructure sectors such as utilities, municipal water systems, hospitals, emergency management, homeland security, the National Guard, the Attorney General’s office, and Vermont Information Technology Leaders. By adding legislative and judicial representation, the bill broadens the council’s cross-branch and cross-sector participation without changing its advisory role or creating new regulatory powers. The bill is set to take effect on July 1, 2026.
If enacted, H.560 would amend 20 V.S.A. § 4662 to change the composition of the Cybersecurity Advisory Council. The practical effect would be to give the General Assembly and the Judiciary formal seats on a body that advises the state on cybersecurity planning and coordination. The bill does not appear to alter substantive cybersecurity standards, enforcement authority, or reporting requirements; instead, it changes who participates in the advisory process and may influence how state cybersecurity policy is developed and coordinated across branches of government and critical infrastructure stakeholders.
Based on the bill text and the absence of recorded committee transcripts or votes, the available record suggests a neutral-to-supportive posture toward the measure. The proposal is framed as an administrative and governance update rather than a controversial policy shift, and its stated goal is to improve coordination on cybersecurity issues. No opposition, amendments, or divided votes are reflected in the provided materials.
The main potential point of discussion is institutional representation: the bill adds legislative chairs and a Judiciary representative to a council that already includes executive branch and sector-specific members. Supporters would likely view this as improving oversight, coordination, and information-sharing across branches of government. Any concerns would likely center on whether the council should remain primarily an executive-branch advisory body or whether adding legislative and judicial members could complicate its structure, blur branch boundaries, or affect confidentiality in cybersecurity planning. No specific objections are documented in the provided materials.