Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Reporting topic
No spam. Unsubscribe anytime.
Committee advances bill requiring state entities to report security incidents to Legislative Audit within five days
Summary
A House bill requiring state entities to provide an initial written notice of known facts about security incidents to Legislative Audit within five days passed the Senate committee after auditors argued timely notice helps determine financial and control risks and lawmakers discussed scope, FOIA exemption and auditor judgment.
Get email alerts on the Cybersecurity Reporting topic
No spam. Unsubscribe anytime.
Senate Transportation, Technology & Legislative Affairs — The committee advanced a House bill that would require state entities to notify Legislative Audit of data-security incidents within five days of discovery and provide an initial written report of known facts.
Frank (legal counsel, Legislative Audit) told the committee the bill has two purposes: to give the General Assembly accurate, complete information about data breaches affecting public entities and to allow auditors to assess whether a breach endangers an entity’s financial viability. He said Legislative Audit would collect initial reports, maintain records, and produce annual summaries for legislative bodies; significant incidents would be reported promptly to officials who may need to respond.
David Coles (field audit supervisor, Legislative Audit) said breach reporting affects audit planning and materiality judgments. He described a recent case in which a major agency breach was not disclosed for a year and said auditors need timely notice to determine whether controls failed or whether a one-off incident occurred. Coles said auditors use judgment to triage incidents: small, isolated events are documented and monitored; major incidents (forensics, ransomware) trigger deeper audit work.
Senator Garner asked whether the bill imposes penalties if entities fail to report in five days; Frank said failure to report would generate an audit finding. Garner also asked how litigation or federal confidentiality rules that limit disclosure would be handled; auditors said they could not override federal confidentiality but that the bill’s exemption from FOIA was intended to avoid publicly flagging compromised entities and to preserve investigative confidentiality.
Representative Meeks described the bill as the first part of a broader cybersecurity package, including a proposal to create a chief cybersecurity officer for the state. After questions about scope and whether minimal incidents would trigger broad document production, auditors pointed to the bill’s initial-report requirement and to auditor judgment to limit burden.
The committee took a motion, approved the bill by voice vote and adjourned. No public testimony was recorded in the transcript.
