Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Bill mandates municipal cybersecurity reporting to state hub, aims to unlock targeted IT grants and shared services
Summary
Administration witnesses said mandated cyber incident reporting would let the Executive Office of Technology Services identify statewide vulnerabilities and target assistance to local governments.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Administration witnesses told the committee that mandatory cybersecurity reporting by municipalities would allow the Executive Office of Technology Services (EOT/EOTS) to act as a statewide hub for incident response and to direct technical assistance and grant resources where they are most needed.
"By having that reporting, we hope that we can unlock state resources for the prevention of cybersecurity incidents," Matt Gorkowitz said. Sean Cronin and other administration staff described the state as the coordination point that can provide access to a fusion center, state police investigative help and targeted grants.
Officials cited existing investments and programs: roughly $5 million for an IT grant program (covering records management, upgrades and innovation) and approximately $7 million in capital for municipal fiber (connectivity between municipal facilities) funded in the FY26 capital plan. Several municipal and regional witnesses recommended additional investment in shared IT services and intermunicipal agreements (IMAs) to spread costs for smaller towns.
Panelists said mandated reporting is intended to give the state better data to triage needs and to make grants more targeted, not to immediately impose large new operating budgets on towns. Municipal witnesses emphasized many small communities lack in‑house IT staff and welcomed state coordination and training offerings.
