New York State Enhances Cybersecurity Measures with S.7672A/A.6769A Legislation
The new legislation, S.7672A/A.6769A, aims to improve the state's ability to address cybersecurity threats, safeguard critical infrastructure, and tackle the scourge of ransomware. The law, announced by Governor Kathy Hochul in her 2025 State of the State address, requires all municipal corporations and public authorities to report cybersecurity incidents within 72 hours and ransomware payments within 24 hours to the New York State Division of Homeland Security and Emergency Services (DHSES). This information will enhance the state's response to cybersecurity threats and keep New Yorkers safe.
Key Takeaways:
- The S.7672A/A.6769A legislation is now in effect, building on previous actions and investments to build a more resilient, safer, and secure digital environment for all New Yorkers.
- Municipal corporations and public authorities must report cybersecurity incidents, notice of ransomware payments, and justification for ransomware payments to DHSES within 72 hours and 24 hours, respectively, through a web portal or by calling the DHSES Cyber Incident Response Team hotline at 1-844-OCT-CIRT.
- Local governments, non-executive agencies, and state authorities are also required to report cybersecurity incidents to DHSES through the hotline.
- The legislation mandates annual cybersecurity awareness training for government employees across New York and sets data protection standards for State-maintained information systems.
- New York State Chief Cyber Officer Colin Ahern noted that the operationalization of this landmark legislation will enable coordinated response and information sharing, serving as a blueprint for the nation.
- State Senator Monica R. Martinez thanked Governor Hochul and her colleagues in the Legislature for recognizing the cost of inaction and advancing this important legislation.
- Assemblymember Steve Otis, Chair of the Assembly Science and Technology Committee, stated that the legislation continues the state's commitment to increasing cybersecurity assistance to local governments.
Statistics:
- The reporting of cybersecurity incidents and ransomware payments will be done within 72 hours and 24 hours, respectively.
- Municipal corporations and public authorities have a 30-day window to provide the payment amount, a justification for why it was necessary, and an explanation of the diligence performed to ensure the payment was lawful after making a ransomware payment.
- The legislation requires annual cybersecurity awareness training for government employees across New York.
- State-maintained information systems are subject to data protection standards.
Sources:
- Governor Kathy Hochul: Press Release, June 27 [no date specified]
- New York State Department of Homeland Security and Emergency Services: [no information specified]
- State Senator Monica R. Martinez: Statement, [no date specified]
- Assemblymember Steve Otis, Chair of the Assembly Science and Technology Committee: Statement, [no date specified]