S 3101 New Jersey Senate · 2024-2025 Regular Session

Requires businesses in financial, essential infrastructure, and health care industries to report cybersecurity incidents.

S 3101 requires businesses in New Jersey's financial, essential infrastructure, and healthcare sectors to report cybersecurity incidents to the state's Cybersecurity and Communications Integration Cell (NJCCIC) as soon as they become aware of them. Specifically, businesses must report incidents compromising billing, communications, data systems, or industrial control systems that cause service disruptions or infrastructure damage. Within 30 days of receiving a report, the NJCCIC must order an independent cybersecurity audit of the business's security practices at the business's expense, identifying vulnerabilities and recommending corrective actions. The bill aims to strengthen sector security through timely reporting and proactive vulnerability management, without altering existing federal reporting requirements.
Bill status in committee 1 of 4 stages cleared
Introduction
Apr 2024
Committee Review
Floor Vote
Governor
Introduced Apr 15, 2024 Last action Jun 13, 2024
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
2
Key actions
0
Committee
0
Apr 15, 2024
Introduced
Introduced in the Senate, Referred to Senate Law and Public Safety Committee
upper
2 primary · 0 co-sponsors

Sponsors