Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Legislation topic

No spam. Unsubscribe anytime.

Security professionals urge Wyoming lawmakers to update cybersecurity statutes after high loss rankings

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Volunteers and cybersecurity professionals told the Select Committee on Blockchain that Wyoming’s cybersecurity statutes are outdated and that regular statutory review and a two-tiered breach reporting regime are needed to protect businesses and residents.

Laramie, Wyo. — Cybersecurity practitioners told the Legislature’s Select Committee on Blockchain on Sept. 22 that Wyoming’s statutory framework for data breaches and cybersecurity needs systematic updating, regular review and clearer reporting thresholds.

David Horton, introduced to the committee as a member of the Wyoming Cybersecurity Action Network, said Wyoming lags other states on cyber legislation and urged lawmakers to create an ongoing process to keep cybersecurity statutes current. “In 2024, the FBI Internet Crime Complaint Center ranked Wyoming number 3 in cybersecurity losses per 100,000 citizens,” Horton said. He told the committee that, while other states enacted dozens of cybersecurity bills each year, Wyoming had enacted very few and that gaps in the law leave businesses and citizens without adequate protections and recovery support.

Patrick Wolfenbarger (presented as Patrick Wolfenbarger) told committee members that existing Wyoming breach law treats all breaches the same and that the state should adopt a two-tier reporting system distinguishing system intrusions from actual data theft. He recommended defining a clear reporting deadline — noting, by example, that the European Union’s GDPR requires a 72-hour notice — so businesses understand statutory time limits and avoid inconsistent notification burdens when a global customer base is involved.

Committee members asked follow-up questions and thanked the witnesses; there was no formal vote tied to the cybersecurity testimony. Committee members and other speakers later noted that fraud and theft remain criminal statutes and that legal remedies exist when an attacker obtains property by illegal means, but the witnesses emphasized the need for modernized statute language and for a formal periodic review process.

The committee received written illustrative examples of statutes needing updates under separate cover, according to witnesses.