← New York profile

New York

Current

General Municipal Law §995-b — Cybersecurity incident reporting

School districts and BOCES must report cybersecurity incidents and applicable ransom demands within 72 hours after reasonably believing an incident occurred.

Jurisdiction
New York · State / DC
Policy status
Effective
Implementation phase
Current
Requirement
Required
Grades
All K-12
Audience
Districts / LEAs
Learning evidence
No student-learning claim
Instrument
Statute / enacted law

Dates & implementation

Report within72 hours of reasonably believing an incident occurred; include applicable ransom demands. Current statutory revision August 1, 2025.

A legal effective date can precede school implementation. This record documents policy intent or requirements; it does not independently confirm delivery in every classroom.

Funding & support

Funding details not confirmed

Dedicated funding and current award availability are not established in this collection. This does not mean no funding exists.

Evidence & source location

GMU§995-b(1)–(3); covered municipal-corporation definition in §995-a

Coverage traced through §995-a(6) to §119-n(a), which expressly includes school districts and BOCES. Current codified law reviewed; original effective date not yet reconstructed.

Review history

Reviewed against official sources

Source availability checked Oct 4, 2026: Source reopened. This is separate from verification of the policy claim below.

Source review date recorded in database: 2026-10-04

2026-10-03 — Carried forward from the source-linked baseline; topic, grade and evidence-type inventory reviewed. Individual source was not re-opened in this update. 2026-10-04 — Substantive source review: Reviewed GMU§995-b: incidents and applicable ransom demands must be reported within72 hours of reasonably believing an incident occurred.

Record ID: NY-2025-CYBER-REPORT

Suggest a correction to this record