Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Infrastructure topic

No spam. Unsubscribe anytime.

Committee backs bill requiring water systems to file security plans and report breaches to state cyber center

2465269 · February 28, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The committee sent House Bill 492 (first substitute) to the floor with a favorable recommendation after sponsors and the Division of Drinking Water described new cybersecurity planning and two-hour reporting to the Utah Cyber Center; the bill also protects water‑system security plans from public disclosure.

The Senate Transportation committee voted to pass House Bill 492 (first substitute) out of committee with a favorable recommendation after testimony from the sponsor and the Division of Drinking Water.

Representative Jack said the bill responds to an increasing number of cyber attacks on small water systems and would require public water systems to complete a security plan and to report breaches to the Utah Cyber Center within two hours so the state can marshal response resources. The bill also directs the Division of Drinking Water to report annually to two legislative committees and designates water‑system security plans as protected records to avoid public disclosure of sensitive information.

Nathan Lundstedt, director of the Division of Drinking Water, and Debbie Johnson of the Utah Cyber Center testified in support. Lundstedt called public water systems “high‑risk critical infrastructure” and said the bill will help protect residents; Johnson said the Cyber Center appreciated being included and supported the requirements for rapid reporting.

The committee adopted a substitute and returned the measure to the floor with a favorable recommendation. Sponsor Representative Jack said the division and the Cyber Center had been engaged throughout drafting and implementation considerations, including protections for sensitive records.