Requires certain procedures, reports, and training for municipalities, counties, and school districts in response to cybersecurity incidents.
This bill requires New Jersey municipalities, counties, and school districts to report cybersecurity incidents through a standardized online form developed by the Attorney General and the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC). Within 30 days of a report, the NJCCIC must contract an independent cybersecurity firm to audit the entity’s response and cybersecurity program, identifying vulnerabilities and recommending improvements. All relevant employees must complete annual cybersecurity training and verify completion to their governing body, with entities able to seek reimbursement for associated costs. Incident reports, audit findings, and corrective plans are exempt from public disclosure under the Open Public Records Act.
Bill status
in committee
1 of 4 stages cleared
Introduction
Mar 2024
Committee Review
Floor Vote
Governor
Introduced Mar 4, 2024
Last action Mar 4, 2024
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
1
Key actions
0
Committee
0
Mar 4, 2024
Introduced
Introduced in the Assembly, Referred to Assembly Science, Innovation and Technology Committee
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Vicky Flynn
RRepublican
Ask Maddy
·
AI policy assistant
Ask Maddy about A 3949
Scope: NJ
Hi! I can help you understand A 3949. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline