HB 290 creates a refundable tax credit called the "Buy Maryland Cybersecurity Tax Credit" for Maryland businesses and nonprofits with fewer than 50 employees that purchase cybersecurity technology or services from qualifying Maryland-based cybersecurity companies. The credit covers 50% of qualifying costs, with a $50,000 annual limit per buyer and a $1 million annual cap per seller. Eligible sellers must be headquartered in Maryland, have under $10 million in annual revenue, and meet specific ownership criteria (e.g., minority-, woman-, or veteran-owned) or be located in a designated business zone. The credit expires for taxable years beginning after December 31, 2030, and is refundable if the credit exceeds the buyer's income tax liability.
SB 482 makes it a crime to intentionally access or interfere with computer systems supporting critical infrastructure (like emergency services, utilities, or public safety answering points) with the intent to disrupt operations. It prohibits unauthorized access, ransomware attacks, or sharing access codes to such systems, specifically targeting acts meant to impair public safety services. The law applies to individuals who disrupt or deny access to systems vital for public security, health, transportation, or utilities. It amends Maryland’s criminal code to clarify penalties for these specific cyber-related interferences.
SB 25 creates the "Buy Maryland Cybersecurity Tax Credit," allowing Maryland businesses to claim a 50% tax credit (up to $50,000 annually) for purchasing cybersecurity technology or services from Maryland-based cybersecurity companies meeting specific criteria. The credit is refundable (businesses can get cash if the credit exceeds taxes owed) and requires sellers to be Maryland-headquartered, small businesses (under $10 million revenue), and/or owned by minorities, women, veterans, or located in designated business zones. It limits total credits per seller to $1 million annually and ends all new credits after 2030. This directly affects Maryland businesses buying cybersecurity and qualifying Maryland cybersecurity firms.
HB 593 amends Maryland's criminal law to specifically prohibit unauthorized actions intended to disrupt critical infrastructure or public safety answering points. It makes it a crime to intentionally access, copy data from, or possess access codes for systems like power grids, emergency call centers, or transportation networks with the intent to impair their function. The bill defines "critical infrastructure" as systems vital to public security, health, safety, or utilities, and explicitly includes ransomware attacks as a prohibited act. This law directly affects individuals who interfere with these essential systems, imposing criminal penalties for intentional disruption.