16 Del. C. § 10106: Cyber incident.
Where this section sits in the code
- Title 16. Health and Safety
- Emergency Services
- CHAPTER 101. 911 System Fund
- Subchapter I. Creation of Fund; Administration; Disbursements
In the event of a ransomware attack or other cybersecurity incident affecting the 911 system or related infrastructure, the affected entity must immediately implement its emergency cybersecurity response plan and notify the Board within 1 hour of discovery. The entity must take all reasonable steps to isolate affected systems, prevent further spread, and preserve system logs and evidence for forensic review. The affected entity may not engage with or make payment to the attacker without express written authorization from the Board and appropriate law-enforcement agencies. The entity must fully cooperate with this State’s cybersecurity team, law enforcement, and any designated third-party investigators during the incident response, recovery, and post-incident review. A written incident report detailing the nature of the attack, actions taken, and corrective measures must be submitted to the Board within 10 business days of system restoration. The Board may require additional reporting or security audits to ensure compliance with state cybersecurity standards.
Collected 2026-09-05T23:02:23Z. Source file · JSON