Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Lawmakers debate SB403 cybersecurity standards, reporting timelines and municipal scope

Public Safety and Security Committee · March 11, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Senator Tony Hong urged the committee to adopt NIST‑based standards, reinvigorate a cyber intelligence task force, and consider 72‑hour reporting carefully; insurers asked the committee to exempt insurers already regulated under Connecticut law to avoid duplicative obligations.

State Senator Tony Hong, sponsor of legislation described as SB403, told the Public Safety and Security Committee that cybersecurity is a public‑safety issue that demands state action. "Cyber security is such a critical public safety consideration," he said, and urged adopting the National Institute of Standards and Technology (NIST) guidance as a baseline and convening the state cyber intelligence task force created in Public Act 23‑23 but never assembled.

Hong cited municipal ransomware cases (New Britain) and large disruptions elsewhere (Atlanta) to underline potential impacts on local services and infrastructure. He noted one bill provision would shorten certain private‑sector reporting to 72 hours, while municipalities currently follow a four‑day standard; that change prompted several members to ask the committee to weigh business concerns and municipal transparency needs separately.

Representative Chikarella asked whether the 72‑hour rule would sweep in private businesses and small entities; Hong said the committee should focus on municipalities and agencies that hold sensitive resident data while considering carve‑outs for private actors. Representative Pello and others pressed for clarity on whether boards of education and other quasi‑municipal bodies would be covered; Hong said boards of education and hospitals hold particularly sensitive data and should be considered.

The Insurance Association of Connecticut asked the committee to exempt insurers from SB403 because insurers are already regulated under Public Act 21‑157, which implemented the NAIC insurance data security model law and is overseen by the Connecticut Insurance Department. "Applying SB403 to insurers may create duplicative or potentially conflicting regulatory obligations," Connor (Insurance Association) said, and the group offered amendment language to preserve regulatory clarity.

Small business voices and vendors also testified in support of stronger standards. David Cook, founder of a Connecticut cybersecurity firm, urged measurable, NIST‑based benchmarks and private‑sector innovation to improve readiness.

The committee’s discussion centered on three implementation questions: which entities the bill will cover, whether the 72‑hour reporting timeline should apply uniformly, and how to minimize duplicative compliance for industries already regulated. Lawmakers asked staff to consider narrower drafting and to gather additional fiscal and implementation details for municipalities and schools.