Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

NJCIC and law‑enforcement officials urge stronger incident reporting, training and state support in cybersecurity hearing

Senate committee · December 16, 2024
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

State and county cyber and law‑enforcement officials told a Senate committee that incident reporting and threat sharing are essential while urging better training for local police, centralized state communications, and attention to third‑party risk affecting hospitals and small businesses.

State cyber officials, forensic labs, prosecutors and industry representatives told a Senate committee that New Jersey faces a growing and diversified cyberthreat landscape and that improved reporting, training and state support are needed to limit harm.

Michael Garrity, director of the New Jersey Cybersecurity and Communications Integration Cell (NJCIC) and the state’s chief information security officer, described a sharp rise in observed attacks and defended the value of incident reporting. “As for cybersecurity incident reporting… the NJCIC has thus far received 493 cybersecurity incident reports,” Garrity said in his opening testimony, and he told senators that timely reports help with response, threat intelligence and preventing cascading failures.

Garrity and other witnesses identified common threat actors — nation‑state groups and transnational ransomware syndicates — and said the threat extends across government, health care, utilities and schools. He testified that phishing remains a primary vector and said routine testing and training, along with stronger technical controls, reduce risk; for executive‑branch employees Garrity cited a drop in simulated phishing click‑rates from roughly 30% to about 10%.

Lieutenant Ryan Hoppock of the New Jersey Regional Computer Forensics Laboratory and Detective William Kemna (New Jersey State Police) said consolidated forensic data and faster reporting help investigations and victim notification. “Victim notification is a big part of what we do,” Lieutenant Hoppock said, and both officials urged mandated baseline training in digital evidence handling for local patrol officers and better regional resource allocation.

Bergen County Prosecutor Mark Micella and Lieutenant Christopher Whiting called cybersecurity “a team sport,” urged continued information sharing with federal partners and recommended reporting by critical‑infrastructure partners so counties can coordinate responses. Local government representatives said procurement rules, disclosure requirements and a statutory 3% appropriation cap hamper municipal cybersecurity spending and proposed exempting cybersecurity expenses from that cap and routing state cyber communications through the NJCIC.

Hospital and health‑care representatives described growing attacks on third‑party vendors and the sector’s consequential cash‑flow disruptions. Neil Iker (NJ Hospital Association) cited the Change Healthcare incident and said claims processing and pharmacy operations were disrupted, resulting in millions of dollars in short‑term revenue problems for providers.

Business and banking witnesses urged workforce development, public‑private partnerships and funding support for small businesses. Bank representatives noted federally mandated reporting windows and the sector’s comparatively large cybersecurity budgets, and urged that mandatory reporting not be interpreted as a sign of weakness but as transparency and resiliency.

Across panels, witnesses recommended: clearer reporting expectations and follow‑up procedures; baseline and continuing cyber training for local law enforcement and municipal staff; funding or grants to help smaller entities and municipalities; careful scrutiny of third‑party vendor contracts; and stronger coordination between NJCIC, prosecutors and local police. The committee did not adopt new legislation at the hearing; members said they would consider draft bills to address training, reporting follow‑up and municipal support.

What’s next: committee members signaled interest in drafting measures that would strengthen follow‑up to incident notifications, expand training capacity for local agencies, and explore funding mechanisms for municipalities and small businesses.