HB 886: State government; prohibit state agencies and local government entities from responding to ransomware activity
Última acción: 4 de abril de 2025 · House Second Readers
House Bill 886 would bar Georgia state agencies and local governments from paying or negotiating with ransomware attackers, and instead require them to report attacks to the Georgia Technology Authority.
Los resúmenes de abajo son traducciones de resúmenes en inglés escritos por un modelo de IA (claude-sonnet-5) a partir del texto del proyecto de ley; no forman parte de él. El proyecto de ley está en inglés. Cite el texto, no el resumen. El texto almacenado es la versión Introduced, la más reciente que tiene LegiScan.
El resumen en español de este proyecto de ley se está preparando. Mientras tanto se muestra el resumen en inglés.
En lenguaje claro
Right now Georgia law does not directly address whether state agencies or local governments can pay hackers who lock up computer systems with ransomware and demand payment. This bill would add a new section to Georgia's general government code (O.C.G.A. Chapter 1 of Title 50) that flatly bans state agencies and local government entities from paying ransom or otherwise communicating with anyone carrying out a ransomware attack against them. Instead of negotiating, any affected agency or local government would have to immediately consult the Georgia Technology Authority, which would guide and coordinate the response. Affected entities would have to share whatever information the authority needs to handle the incident. The bill defines ransomware activity, state agency, and local government entity broadly, covering everything from school districts and sheriff's offices to public universities and technical colleges.
Qué hace el proyecto de ley
- Prohibits state agencies and local government entities from paying ransom to anyone carrying out a ransomware attack against them.
- Prohibits those same entities from otherwise communicating with the individuals or groups behind a ransomware attack.
- Requires any affected state agency or local government to immediately consult the Georgia Technology Authority when hit by ransomware.
- Directs the Georgia Technology Authority to provide guidance and coordinate the response to ransomware incidents.
- Requires affected entities to give the Georgia Technology Authority any information needed to address the response.
A quién afecta
State agencies including executive, legislative, and judicial branch offices, public universities, and technical colleges, plus local government entities such as counties, municipalities, school districts, authorities, and sheriff's offices and other local law enforcement agencies. The Georgia Technology Authority gains new coordination duties.
Por qué importa
If a Georgia school district, county, or state office is hit by ransomware, officials would no longer be allowed to pay or negotiate to restore access, changing how these entities can respond to an active cyberattack and shifting decision-making to the Georgia Technology Authority.
Disposiciones clave
- Adds new Code Section 50-1-14 to Chapter 1 of Title 50, defining 'local government entity,' 'ransomware activity,' and 'state agency' broadly.
- Subsection (b) bars any state agency or local government entity from submitting payment to or communicating with attackers engaged in ransomware activity against it.
- Subsection (c) requires immediate consultation with the Georgia Technology Authority, which provides guidance and coordinates the response.
- Subsection (c) also requires affected entities to supply the Georgia Technology Authority with information needed to address the response.
- Section 2 repeals any conflicting laws.
Del proyecto de ley
“No state agency or local government entity in this state shall submit payment to or otherwise communicate with an individual or organization engaging in ransomware activity against such state agency or local government entity.”
“Any state agency or local government entity experiencing ransomware activity immediately shall consult with the Georgia Technology Authority.”
Cronología del estado
- House Second Readers (Cámara de Representantes)
- House First Readers (Cámara de Representantes)
- House Hopper (Cámara de Representantes)
Patrocinadores
- Stacey Evans (D, HD-057)
- Debra Bazemore (D, HD-069)
- Tanya Miller (D, HD-062)
- Kim Schofield (D, HD-063)
- Park Cannon (D, HD-058)
Temas
- cybersecurity
- ransomware
- local government
- state agencies
- Georgia Technology Authority