Governor Hochul Announces Legislation to Strengthen Cybersecurity Across New York
Governor Kathy Hochul announced legislation (S.7672A/A.6769A) aimed at enhancing cybersecurity and resilience across New York is now in effect. The measure requires municipal corporations and public authorities to report cybersecurity incidents within 72 hours and ransomware payments within 24 hours to the New York State Division of Homeland Security and Emergency Services (DHSES). This legislation is a significant step in strengthening the state's response to cybersecurity threats, safeguarding critical infrastructure, and tackling the scourge of ransomware.
Key Takeaways:
- The legislation (S.7672A/A.6769A) requires municipal corporations and public authorities to report cybersecurity incidents within 72 hours and ransomware payments within 24 hours to the New York State Division of Homeland Security and Emergency Services (DHSES).
- Municipal corporations and public authorities must provide justification for ransomware payments within 30 days and an explanation of the diligence performed to ensure the payment was lawful.
- The web portal for reporting cybersecurity incidents and ransomware payments will enable coordinated response and information sharing, and the legislation sets data protection standards for State-maintained information systems.
- The measure also mandates annual cybersecurity awareness training for government employees across New York, under the leadership of New York State Chief Cyber Officer Colin Ahern and New York State Chief Information Officer and Director of the Office of Information Technology Services Dru Rai.
- The legislation was first announced in Governor Hochul's 2025 State of the State address and was signed into law on June 27.
- The legislation received bipartisan support, with State Senators Monica R. Martinez and Kristen Gonzalez, and Assembly Members Billy D. Jones and Steve Otis praising the measure.
Statistics:
- 72 hours: the time frame within which municipal corporations and public authorities must report cybersecurity incidents to the New York State Division of Homeland Security and Emergency Services.
- 24 hours: the time frame within which municipal corporations and public authorities must report ransomware payments to the New York State Division of Homeland Security and Emergency Services.
- 30 days: the time frame within which municipal corporations and public authorities must provide justification for ransomware payments and an explanation of the diligence performed to ensure the payment was lawful.
- 100%: the number of municipal corporations and public authorities that must provide cybersecurity awareness training for government employees across New York.
Sources:
- Governor Kathy Hochul's news release, "Governor Hochul Announces Legislation Now in Effect to Strengthen Cybersecurity Across New York"
- https://www.governor.ny.gov/news/governor-hochul-announces-legislation-now-effect-strengthen-cybersecurity-across-new-york