This bill requires public water systems in Michigan to implement security measures against cyberattacks, physical threats, and system compromises. It mandates the creation of risk-based cybersecurity programs aligned with national standards and the use of specific safety features, such as redundant cooling, manual overrides, and network segmentation. Additionally, the legislation obligates these systems to maintain incident response and disaster recovery plans that outline roles, communication procedures, and coordination with emergency responders. Violations of these new requirements are subject to civil fines of up to $25,000 per day, while other violations of the Safe Drinking Water Act remain punishable by existing misdemeanor penalties.
This bill requires data center operators in Michigan to implement security measures that protect against both cyberattacks and physical disruptions. To achieve this, facilities must adopt a risk-based cybersecurity program aligned with national standards like the NIST framework, along with specific safety features such as redundant cooling, manual overrides, and network segmentation. Operators are also mandated to create and maintain incident response and disaster recovery plans that outline communication procedures, restoration priorities, and coordination with emergency services. The legislation applies to qualified data centers as defined by state tax acts and imposes civil fines of up to $25,000 per day for violations.
This bill requires operators of large-scale solar energy facilities in Michigan, defined as those with 50 megawatts or more of capacity, to implement cybersecurity measures to protect safety-critical systems. The law mandates that these facilities follow a risk-based security program aligned with national standards and report material cyber incidents to state and local authorities within 24 to 72 hours. Operators must also maintain incident response plans for coordinating with emergency responders, while specific security details remain confidential and are exempt from public disclosure. The legislation does not regulate facility siting, create new regulatory oversight, or impose additional costs on local governments, and it allows facilities to use existing staff to meet compliance requirements.
This bill requires operators of battery energy storage facilities in Michigan to implement specific cybersecurity and physical safety measures to protect critical infrastructure. It mandates the creation of risk-based security programs aligned with national standards, along with essential safety features like automatic shutdowns, redundant cooling, and network segmentation. Additionally, operators must develop incident response and disaster recovery plans that outline roles, communication procedures, and coordination with emergency services. Facilities with a storage capacity greater than one megawatt are directly affected by these new requirements, which include a daily civil fine of up to $25,000 for violations. The legislation takes effect 90 days after it is enacted into law.
HB 5330 requires Michigan public entities (like government agencies) and their contractors to meet strict cybersecurity and data protection standards for small drones (under 55 pounds). It mandates that all collected data (including videos, photos, and personal information) must be stored within the U.S., encrypted with AES-256, and automatically deleted after 45 days unless law enforcement needs it. The bill also requires annual security audits using NIST, ISO 27001, and SOC 2 standards, plus real-time monitoring for cyber threats. The State Police will create regulations to enforce these rules, including network security controls and operator training.