Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Government And Regulatory Reform topic

No spam. Unsubscribe anytime.

Committee hears cybersecurity bill requiring local units to adopt state guidance, creates grant fund but no immediate funding

5839186 · March 17, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Senate Bill 472, a measure to strengthen cybersecurity practices across Indiana’s local governments and schools, was discussed at length by the House Government and Regulatory Reform Committee; the bill creates a grant fund and sets state guidance for adoption while leaving direct funding optional.

Senate Bill 472, a measure to raise cybersecurity standards for Indiana local governments and schools and to create a grant fund and a voluntary insurance mechanism, drew extended testimony and questions at the House Committee on Government and Regulatory Reform.

Author Sen. Victoria Brown said the bill grew from work of the AI and cybersecurity task force and earlier local concerns about liability costs for schools. “We created a fund,” she said in explaining the approach, “and the most important thing is to bring this to their attention” so local units adopt best practices. She said the committee extended the timeline for compliance to 2027 and clarified the fund language in an amendment distributed at the hearing.

Supporters described capacity gaps. Jeremy Miller, state president of the Special Forces Association and CEO of Lionfish Cybersecurity, told the committee that “the majority of the 92 counties lack resources, both financially and human, to adequately protect their networks and data” and urged passage to strengthen baseline protections and workforce development. Amy Krieg, who represents cities and towns for AIM (Association of Indiana Municipalities), said the bill provides “healthy accountability” and tools for members, including a grant program and a board that includes local government representation.

Utilities and critical‑infrastructure providers asked for changes to protect operational security. Bridget O’Connor, director of government affairs and regulatory policy for Citizens Energy Group, said Citizens already maintains a robust cybersecurity program and expressed concern about a proposed requirement to submit full cybersecurity plans to the Office of Technology. “We have been told we are never to give our plan to an outside entity,” she said, explaining the cybersecurity risk if a central repository were compromised. O’Connor asked the committee to permit an informational meeting in lieu of a full plan submission; the chair and sponsor indicated they would work on language and an amendment to address that point.

The committee considered two posted amendments during the hearing. Amendment No. 7, which tightened fund language relating to the Indiana Office of Technology and the grant program for school liability costs, was accepted by consent. Amendment No. 6, addressing consumer data and opt‑out concerns for reward programs, was discussed at length; sponsors and staff said they considered it unnecessary for the current bill and preferred to refer such consumer-privacy issues to the continuing task force, so the committee did not adopt the amendment that day.

Sen. Brown and witnesses said the bill does not create immediate funding; the grant fund would be used only if revenues were available, including potential fines or other receipts. Committee members asked whether assessments would be mandatory; Brown and sponsors said assessments are not required, but if a local unit performs an assessment, the bill would request the results be shared to help identify statewide gaps. Brown said the Office of Technology has already assisted many counties and schools and is available to help implement multifactor authentication and other best practices.

Committee members also asked for clarification about cyber insurance. Sponsors explained the concept as coverage that helps pay recovery costs and other expenses after a cyber incident; they emphasized the bill seeks to encourage best practices to reduce incidents and to offer a potential insurance pool or grant help for local units that choose to participate.

No final committee vote on the bill’s passage occurred during the hearing; the sponsor said she would continue to refine language and seek amendments before a later reading.