A 2199 New Jersey General Assembly · 2024-2025 Regular Session

Requires businesses in financial, essential infrastructure, and health care industries to report cybersecurity incidents.

This bill requires businesses in New Jersey's financial, essential infrastructure, and healthcare sectors (called "sensitive businesses") to report cybersecurity incidents to the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) promptly after discovery. It mandates reporting for incidents compromising business systems (like billing or data) or industrial control systems that disrupt infrastructure. Within 30 days of a report, the NJCCIC must arrange for an independent cybersecurity audit of the business at the business's expense, identifying vulnerabilities and requiring corrective action plans. The law creates a new reporting and audit process to improve cybersecurity resilience in critical industries.
Bill status in committee 1 of 4 stages cleared
Introduction
Jan 2024
Committee Review
Floor Vote
Governor
Introduced Jan 9, 2024 Last action Jan 9, 2024
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
1
Key actions
0
Committee
0
Jan 9, 2024
Introduced
Introduced in the Assembly, Referred to Assembly Science, Innovation and Technology Committee
lower
2 primary · 0 co-sponsors

Sponsors