S 4427 creates a 25% tax credit for small businesses (those with fewer than 101 employees) that purchase qualified data breach insurance. This insurance must cover expenses related to data theft, loss, or unauthorized access, and businesses must comply with cybersecurity standards like the NIST framework or state-approved equivalents. The bill requires insurance premiums to be separately itemized in contracts and limits the credit to premiums paid in ordinary business operations. It applies to taxable years beginning after the law takes effect and expires after five years.
Establishes the "secure our data act"; relates to cybersecurity protection by state entities; requires the office of information technology services to develop standards for data protection of state entity-maintained information.
Creates a cyber security enhancement fund to be used for the purpose of upgrading cyber security in local governments, including but not limited to, villages, towns and cities with a population of one million or less; restricts the use of taxpayer moneys in paying ransoms in response to ransomware attacks.
Requires governmental entities to, whenever possible and feasible, consider implementing multifactor authentication for local and remote network access; requires public websites to encrypt all exchanges and to comply with privacy standards.
Senate Resolution J 73 requests Governor Hochul to issue a proclamation designating October 2025 as Cyber Security Awareness Month in New York State, aligning with the national National Cyber Security Awareness Month (NCSAM). The resolution emphasizes the importance of public and organizational awareness to strengthen online safety practices, referencing NCSAM's long-standing role in promoting cyber security education since 2004. This procedural resolution does not create new laws but seeks to formally recognize the observance through a gubernatorial proclamation.
This bill requires the state Department of Education to send annual email notifications to school district data security staff by July 1st each year. The notifications must include reminders about effective cybersecurity strategies and a copy of the National Institute of Standards and Technology's cybersecurity framework. It directly affects all public school districts in the state by mandating this yearly communication to help schools address cyber threats. The law takes effect immediately upon passage.
This bill, the Critical Infrastructure Standards and Procedures Act (CRISP Act), requires public and private entities operating critical infrastructure to follow specific cybersecurity standards. It directly affects asset owners of facilities like public transportation, water treatment plants, utilities, public buildings, hospitals, and public authorities. Key provisions mandate that these entities follow the ISA/IEC 62443 cybersecurity standards for procurement and construction of automation systems starting July 1, 2029, and for operations/maintenance starting July 1, 2027 - including annual risk assessments and mitigation plans. The law aims to strengthen cybersecurity protections for systems controlling physical infrastructure, referencing established NIST standards.