Loading chat...

NY A05739

Bill

Status

Introduced

2/20/2025

Primary Sponsor

Michaelle Solages

Click for details

Origin

Assembly

2025-2026 General Assembly

AI Summary

  • Requires the Office of Information Technology Services to develop cybersecurity standards within one year, including protections against security breaches, immutable data backups, data retention policies, and annual workforce training

  • Mandates monthly vulnerability assessments of mission critical information systems beginning January 1, 2026, with full system-wide testing required by December 1, 2026

  • Requires each state entity to create inventories of personal information and information systems within one year, documenting data sources, purposes, and whether systems are protected by immutable backups

  • Establishes incident response plan requirements by 18 months after enactment, with mandatory annual exercises beginning January 1, 2028 to test restoration and recovery processes

  • Applies to state boards, departments, public authorities, and other state entities, but excludes the judiciary and local governments; does not create a private right of action for enforcement

Legislative Description

Establishes the "secure our data act"; relates to cybersecurity protection by state entities; requires the office of information technology services to develop standards for data protection of state entity-maintained information.

Last Action

referred to governmental operations

1/7/2026

Committee Referrals

Governmental Operations2/20/2025

Full Bill Text

No bill text available