yourstate.us
N.Y. Executive Law § 711-C

Cybersecurity incident reviews

New York · New York Executive Law · Status: effective · Effective 2025-08-01

Get this as JSONEmbed this
Cite this
Citation
N.Y. Executive Law § 711-C, Cybersecurity incident reviews, New York, version 1 as recorded 2026-07-25, yourstate.us, https://yourstate.us/provision/1106299
Permanent ID
ys:prov:1106299@1
SHA-256
c8a1630bf0df1002331506b505c5fef77e9f903147026e7dc4e764e1ffd2f35e

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

§ 711-c. Cybersecurity incident reviews. 1. Definitions. As used in this section, the terms cybersecurity incident, cyber threat, cyber threat indicator, defensive measure, information system, municipal corporation, public authority, ransom payment and ransomware attack shall have the same meaning as such terms are defined in article nineteen-C of the general municipal law. 2. The commissioner, or their designees, shall review each cybersecurity incident report and notice and explanation of ransom payment submitted pursuant to sections nine hundred ninety-five-b and nine hundred ninety-five-c of the general municipal law to assess potential impacts of cybersecurity incidents and ransom payments on the health, safety, welfare or security of the state, or its residents. 3. The commissioner, or their designees, may work with appropriate state agencies, federal law enforcement, and federal homeland security agencies to provide municipal corporations and public authorities with reports of cybersecurity incidents and trends, including but not limited to, to the maximum extent practicable, related contextual information, cyber threat indicators, and defensive measures. The commissioner may coordinate and share such reported information with municipal corporations, public authorities, state agencies, and federal law enforcement and homeland security agencies to respond to and mitigate cybersecurity threats. 4. Such reports, assessments, records, reviews, documents, recommendations, guidance and any information contained or used in its preparation shall be exempt from disclosure under article six of the public officers law. 5. No later than forty-eight hours after receiving a cybersecurity incident report containing a request for advice and/or technical assistance from the division pursuant to subdivision one of section nine hundred ninety-five-b of the general municipal law, the commissioner or the commissioner's designees shall acknowledge receipt of such request. As soon as possible after receiving such a request, the commissioner or the commissioner's designees, subject to the commissioner's discretion in prioritizing the division's response to the municipal corporation's or public authority's cybersecurity incident report, shall provide advice to the requesting municipal corporation or public authority and, to the extent practicable, provide technical assistance.