Loading chat...

NY S01961

Bill

Status

Engrossed

5/28/2025

Primary Sponsor

Kristen Gonzalez

Click for details

Origin

Senate

2025-2026 General Assembly

AI Summary

  • Requires the Office of Information Technology Services to develop data protection standards within one year, including requirements for immutable backups, segmented storage, data validation, and annual workforce cybersecurity training

  • Mandates monthly vulnerability assessments of mission critical information systems beginning January 1, 2026, with full system-wide vulnerability testing required by December 1, 2026

  • Requires each state entity to create inventories of personal information they maintain and their information systems within one year, with inventories kept confidential and exempt from FOIL requests

  • Establishes incident response plan requirements for security breaches, with mandatory annual exercises beginning January 1, 2028 to test restoration and recovery processes

  • Applies to state boards, departments, public authorities, and other state governmental entities, but excludes the judiciary and local governments; creates no private right of action for violations

Legislative Description

Establishes the "secure our data act"; relates to cybersecurity protection by state entities; requires the office of information technology services to develop standards for data protection of state entity-maintained information.

Last Action

REPORTED AND COMMITTED TO FINANCE

2/25/2026

Committee Referrals

Finance2/25/2026
Internet and Technology1/7/2026
Governmental Operations5/28/2025
Finance2/10/2025
Internet and Technology1/14/2025

Full Bill Text

No bill text available