HB886: HB886 State government; prohibit state agencies and local government entities from responding to ransomware activity
Last action April 4, 2025 · House Second Readers
House Bill 886 would ban Georgia state agencies and local governments from paying ransoms or communicating with hackers during ransomware attacks, and would require them to immediately report such attacks to the Georgia Technology Authority.
In plain language
Ransomware attacks, in which hackers lock up a computer system's data and demand payment to restore access, have hit government offices around the country. This bill addresses how Georgia's state agencies and local governments must respond if it happens to them. The bill adds a new section to Georgia law (O.C.G.A. § 50-1-14) that flatly bars any state agency or local government entity, including counties, cities, school districts, sheriff's offices, and other public bodies, from paying a ransom or otherwise communicating with whoever is behind the attack. Instead, any affected agency or local government must immediately consult with the Georgia Technology Authority, which will guide and coordinate the response. Affected entities must share whatever information the authority needs to handle the situation. The bill defines key terms like 'ransomware activity,' 'state agency,' and 'local government entity' broadly to cover nearly all of Georgia's public sector.
What the bill does
- Prohibits any Georgia state agency or local government entity from paying a ransom to resolve a ransomware attack.
- Prohibits those same entities from otherwise communicating with the individuals or groups behind a ransomware attack.
- Requires state agencies and local governments hit by ransomware to immediately consult with the Georgia Technology Authority for guidance.
- Requires affected agencies to share any information the Georgia Technology Authority needs to coordinate and manage the response.
- Defines 'local government entity' broadly to include counties, cities, school districts, sheriff's offices, and other local public bodies.
Who it affects
State agencies including public universities and technical colleges, and local government entities such as counties, cities, school districts, sheriff's offices, and law enforcement agencies across Georgia. The Georgia Technology Authority, which would take on a new coordination role, is also directly affected.
Why it matters
If a ransomware attack hits a Georgia school district, county office, or state agency, officials would no longer be allowed to negotiate or pay to get their data back, and would instead have to bring in the Georgia Technology Authority right away, changing how these incidents get handled statewide.
Key provisions
- Section 1 adds new Code section O.C.G.A. § 50-1-14 defining 'local government entity,' 'ransomware activity,' and 'state agency' for purposes of the law.
- Subsection (b) bars any state agency or local government entity from paying or communicating with anyone carrying out a ransomware attack against it.
- Subsection (c) requires immediate consultation with the Georgia Technology Authority when a ransomware attack occurs, with the authority directing the response.
- Subsection (c) also requires affected agencies to turn over any information the Georgia Technology Authority needs to address the attack.
- Section 2 repeals any conflicting laws.
Status timeline
- House Second Readers (House)
- House First Readers (House)
- House Hopper (House)
Sponsors
- Stacey Evans (D, HD-057)
- Debra Bazemore (D, HD-069)
- Tanya Miller (D, HD-062)
- Kim Schofield (D, HD-063)
- Park Cannon (D, HD-058)
Topics
- cybersecurity
- ransomware
- local government
- state government technology
- data breaches