Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Cybersecurity Bill Would Set Defense Plan for Local Agencies

A new Maryland bill would ask the state’s Department of Information Technology to develop a baseline plan for localities within the state to help battle cyber attacks.

A new Maryland bill would ask the state’s Department of Information Technology to develop a baseline plan for localities within the state to help battle cyber attacks.

Senate bill 120, introduced by Sen. Susan Lee, D-Montgomery, would give the Maryland Department of Information Technology the expanded responsibility of developing a cybersecurity strategy and helping agencies within the state implement it at their discretion.

Under current law, the Department of Information Technology oversees the defense of state systems, but not that of counties, school districts and other similar entities. Having a sample plan in place could be beneficial in preventing future attacks that disrupted the likes of the city of Baltimore and Salisbury Police Department recently and cost millions in reparations.

The legislation does not mandate significant increases in expenditures by the state or local governments, but rather leaves it up to each entity to potentially implement the plan, according to Lee.

This Maryland bill follows a 2019 North Dakota law that added the same provisions and power to its state Information Technology department.

The main point of this bill is to simply draw up guidance and advice for those around the state to be able to help prepare themselves brace for potential attacks, Lee told Capital News Service.

Advertisement. Scroll to continue reading.

During a Senate Education, Health, and Environmental Affairs Committee hearing on Jan. 14, Lee compared this plan to having a fire extinguisher for protection and to prevent a possibly worse situation.

“Today we have to prepare for and respond to digital fires … upfront rather than scrambling on the back end,” Lee said during the hearing.

Senate committee members responded favorably toward the bill, but looked to generate tighter language to define the tasks this bill sets forward.

Delegate Ned Carey, D-Anne Arundel, has cross-filed this bill in the House — along with three co-sponsors — and said he believes it should receive bipartisan support due to the well-known threat that professional hackers pose.

“The bill is intended to help,” Carey said. “We’re going to work hard to make sure this bill succeeds.”

Carey’s legislation, House bill 235, was heard by the Health and Government Operations Committee on Tuesday afternoon.

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

Axonius has appointed Moshe Ben Simon as Chief Product Officer.

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.