Don’t do SECURITY. Do business SECURELY.

Florida bans public bodies from paying ransoms

Florida now prohibits state agencies, counties and municipalities from paying ransoms and sets tight deadlines for reporting cyber incidents.

New amendments to Florida’s State Cybersecurity Act (HB 7055) take effect today, making Florida one of the first US states to ban its public bodies from paying ransomware demands.

Key points

  • State agencies, counties and municipalities must not pay or otherwise comply with a ransom demand.
  • Ransomware incidents must be reported to the state Cybersecurity Operations Center, the Cybercrime Office and the local sheriff within 12 hours of discovery.
  • Other significant incidents (severity level 3 or above) must be reported within 48 hours.
  • Reports must cover the incident summary, backups, data affected, estimated fiscal impact and any ransom demand.
  • Local government staff must complete regular cyber security training.

Florida and North Carolina’s bans are a model for the UK’s proposed ban on ransomware payments by public-sector bodies and critical national infrastructure operators. Suppliers to UK public bodies should expect similar expectations on resilience, backups and rapid reporting.

Source: CS/HB 7055 (2022) Cybersecurity (Florida Senate)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights