SB 1859 creates a Cyber Crime and Fraud Unit within Oklahoma's State Bureau of Investigation (OSBI) to enhance investigations into cyber-enabled crimes (like ransomware and digital extortion), financial fraud (including identity theft), and digital evidence handling. The bill establishes a revolving fund with a $3 million appropriation from the General Revenue Fund for fiscal 2026, allowing the unit to operate without annual budget constraints. The unit can only investigate upon requests from local law enforcement, Governor direction, or under existing statutes - explicitly stating it does not expand OSBI's jurisdiction. It will provide technical support, training to law enforcement, and coordinate with federal and tribal partners on cybercrime cases.
SB 1716 amends Oklahoma's Security Breach Notification Act to limit class action lawsuits against private entities following cybersecurity breaches. It prohibits class action liability unless a breach results from the entity's "willful and wanton conduct or gross negligence." The bill also clarifies that private entities using reasonable safeguards and providing required breach notices cannot be held liable for civil penalties, while those failing to use reasonable safeguards face reduced penalties ($75,000) but not class actions. This directly affects businesses and organizations handling personal data in Oklahoma, shifting enforcement exclusively to the Attorney General or district attorneys for most cases.
HB 4132 creates liability protection for Oklahoma counties and municipalities if they adopt specific cybersecurity frameworks (NIST, CIS, or ISO standards) and meet compliance requirements. To qualify, local governments must annually certify compliance, maintain detailed security documentation, and undergo independent cybersecurity reviews every three years. This bill directly affects county and municipal operations by reducing legal risk from data breaches when these steps are followed. It does not change existing cybersecurity practices but provides a legal shield for entities that implement recognized standards. The law takes effect November 1, 2026.
SB 179 requires all Oklahoma state agencies to manage their own information technology and cybersecurity services starting from its effective date. It directs the transfer of all prior IT and cybersecurity data from the dissolved Information Services Division to each agency and mandates annual electronic reports to the Governor and Chief Information Officer detailing IT status, security events, and related information. The bill also dissolves the existing Information Services Division within the Office of Management and Enterprise Services and updates related statutes to align with these changes. This directly affects state agencies, shifting IT management responsibilities from a centralized division to individual departments.
HB 1983 requires Oklahoma public schools to teach media literacy and cybersecurity to students in sixth, seventh, or eighth grade starting in the 2027-2028 school year. It mandates a half-unit course covering specific topics like identifying online scams, fake news, deepfakes, password security, and protecting personal information. The State Department of Education must develop curriculum standards, guidelines, teacher training, and accessible resources to support this instruction, including accommodations for English learners and students with disabilities. The bill becomes effective November 1, 2025, with implementation beginning for incoming sixth graders in 2027.
SB 236 creates a tax credit for Oklahoma employers in the aerospace and defense sector that must meet U.S. Department of Defense cybersecurity requirements (CMMC). It allows qualifying businesses (with 5-200 employees not yet CMMC-compliant as of 2026) to claim a 50% credit on wages and expenses incurred while achieving initial CMMC compliance, capped at $50,000 total per business through 2031. The credit cannot reduce tax below zero, may be carried forward for up to five years, and is limited to $10 million annually across all businesses. This bill directly affects Oklahoma aerospace/defense employers seeking federal contracts requiring CMMC certification.
SB 488 prohibits Oklahoma state agencies and local governments from purchasing drones or unmanned aerial systems after January 1, 2028, unless the devices are cleared by the Office of Homeland Security. The Office must maintain a public list of approved drones meeting security standards, including U.S. Department of Defense clearance, compliance with federal security laws, and cybersecurity protections to prevent unauthorized data transmission. This list must be updated every six months, and all state/local procurement must prioritize devices on the approved list. The bill ensures that only drones deemed secure by state security standards can be acquired using public funds, with contracts for non-approved drones deemed void.