Cyber breach; limit liability for certain entities.
What changed between versions
Removed specific federal law citations (like Public Law numbers) from the list of standards that entities must align with, simplifying the compliance requirements.
Updated references to NIST cybersecurity publications to emphasize 'current version' and 'most current update' rather than specific publication numbers, ensuring ongoing compliance with evolving standards.
Added a new provision stating that failure to implement cybersecurity programs is not considered evidence of negligence or negligence per se.
Added a choice of law provision ensuring the act applies to agreements designating Mississippi as governing law, regardless of where the lawsuit is filed.
Clarified burden of proof rules in lawsuits, specifying that plaintiffs must prove non-compliance with clear and convincing evidence for government entities, while defendants must prove compliance for commercial entities.
Removed page headers, footers, and session metadata from the text, cleaning up the document format.