Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Incident Reporting topic

No spam. Unsubscribe anytime.

Oregon committee hears support for statewide incident notifications but small districts seek longer timelines

Joint Committee on Information Management and Technology · February 6, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Witnesses backed HB 4055’s goal of centralized cybersecurity reporting but several special districts, cities and education service districts asked the Joint Committee on Information Management and Technology to extend the bill’s 48-hour reporting and staging of follow-up reports to give small, volunteer-run entities time to respond.

House Bill 4055, which would require local governments, special districts and other public bodies to notify the state chief information officer within 48 hours of discovering an information-security or ransomware incident, drew broad agreement on purpose but sharp questions about timelines during a Feb. 6 public hearing before the Joint Committee on Information Management and Technology.

Sean McSpadden, the committee administrator, told members the bill would direct the state CIO to create a secure reporting system, maintain a public website with reporting instructions and provide an annual summary to the legislature and governor. "The measure prescribes the information a public body is required to report and directs the state chief information officer to establish a reporting system," McSpadden said in opening remarks.

Why it matters: Committee members and testifiers agreed that centralized notification could help identify widespread threats and enable coordinated assistance. But multiple witnesses emphasized that many Oregon special districts and small cities operate with minimal staff or are volunteer-run, and cannot meet tight reporting and follow-up deadlines while managing an active incident.

Hasina Wittenberg of the Special Districts Association of Oregon said the group supports the bill’s concept but asked for more time. "We're supportive of notifying a central state agency. But they require us to notify within 48 hours and we're asking that a change be made to increase that to 72 hours," she testified, adding that small districts sometimes lack the staff to know immediately whether a breach occurred and need longer to prepare mitigation reports.

League of Oregon Cities representative Greg Miller recommended a seven-day notice window for initial reporting and a stronger expectation that notifications trigger tangible support from the CIO's office for smaller municipalities. "48 hours is really quick in dealing with the cybersecurity event," Miller told the committee, and said frequent low-level incidents could otherwise generate inefficient reporting without clear benefit.

Education service districts and school-board representatives echoed those concerns, asking for a tiered schedule: an initial short notice, a seven-day interim report on actions taken and a longer (30-day) follow-up on prevention and recovery plans. Witnesses said aligning the bill’s reporting with existing breach-notification systems would reduce duplication for districts that outsource IT services.

Committee reaction and next steps: Members signaled openness to amendments that would extend initial notice to 72 hours and create staged reporting deadlines. The bill’s sponsor and committee staff said the measure aims to add practical value rather than produce records that simply "sit in a virtual shelf." The committee closed the public hearing and said co-chairs would work with staff on possible amendments.

What the bill does not do: As presented, HB 4055 would exempt submitted incident reports from disclosure under Oregon's public records laws in certain circumstances and allows the CIO to confidentially share information with specified parties. The measure declares an emergency and includes an operative date provision for preimplementation actions.

The committee took no formal vote on the measure during the hearing; members said they would consider testimony and proposed amendments before advancing the bill.