Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Senate requires third‑party forensic audits for 'massive' data breaches and gives AG access to reports
Summary
Legislation passed April 29 defining a 'massive breach' (over 100,000 affected) that triggers a third‑party forensic audit; the attorney general may request the audit and reports are protected from public disclosure and subject to privilege rules.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
The Connecticut Senate on April 29 adopted a substitute amendment to update the state's data‑breach statute and add prescriptive requirements when a 'massive' breach is suspected.
Senator Maroney, sponsor of the strike‑all amendment, said the new definition — a breach exposing personal information of more than 100,000 residents — triggers a mandatory forensic examination by a third‑party vendor and a requirement to provide a reasonable timeline to the attorney general for delivery of the detailed forensic report. The amendment clarifies that forensic reports are exempt from public disclosure and that submitting a report to the attorney general does not constitute a waiver of attorney‑client privilege or work‑product protections.
Supporters argued the measure will help the attorney general and affected companies understand root causes and improve future protections. Senator Ciccarella raised concerns about cost and burden on smaller firms; sponsors said the law requires the breached company to engage and pay the third party and that the attorney general can step in to hire an auditor if necessary, with costs billed to the company.
The amendment also narrows the earlier broad language (excluding credit card data from the massive‑breach automatic trigger, reflecting existing consumer protections) and adds a timeline requirement to give a reasonable schedule for delivery of the final forensic report.
The Senate ordered and held an immediate roll‑call vote; the substitute for SB 117 (as amended) passed. The law directs the attorney general's office and affected businesses to coordinate on forensic analyses that can support enforcement and help prevent future breaches.
What changed: the statute now defines 'massive breach' and requires forensic reporting in such cases; it clarifies privilege protections, provides a path for the AG to request audits, and includes a civil enforcement pathway for failures to comply with report/timelines.
