{"data":{"id":"us-nj/n.j.-stat.-52-17b-193.3","jurisdiction":"us-nj","citation":"N.J. Stat. § 52:17B-193.3","heading":"Report, cybersecurity incidents, New Jersey Office of Homeland Security and Preparedness.","body":"2. a. Every public agency and government contractor shall report cybersecurity incidents to the New Jersey Office of Homeland Security and Preparedness.  The report shall be made within 72 hours of when the public agency or government contractor reasonably believes that a cybersecurity incident has occurred.\nb.\tThe New Jersey Office of Homeland Security and Preparedness shall receive and maintain cybersecurity incident notifications from public agencies, government contractors, and private entities in accordance with this act.\nc.\tNo later than 90 days after the effective date of this act, the Director of the New Jersey Office of Homeland Security and Preparedness shall establish cyber incident reporting capabilities to facilitate submission of timely, secure, and confidential cybersecurity incident notifications from public agencies, government contractors, and private entities to the office.\nd.\tNo later than 90 days after the effective date of this act, the New Jersey Office of Homeland Security and Preparedness shall prominently post instructions for submitting cybersecurity incident notifications on its website.  The instructions shall include, at a minimum, the types of cybersecurity incidents to be reported and any other information to be included in the notifications made through the established cyber incident reporting system.\ne.\tThe cyber incident reporting system shall permit the New Jersey Office of Homeland Security and Preparedness to:\n(1) securely accept a cybersecurity incident notification from any individual or private entity, regardless of whether the entity is a public agency or government contractor;\n(2) track and identify trends in cybersecurity incidents reported through the cyber incident reporting system; and\n(3) produce reports on the types of incidents, indicators, defensive measures, and entities reported through the cyber incident reporting system.\nf.\tAny cybersecurity incident notification submitted to the New Jersey Office of Homeland Security and Preparedness pursuant to P.L.2023, c.19 (C.52:17B-193.2 et seq.) shall be deemed confidential, non-public, and not subject to the provisions of P.L.1963, c.73 (C.47:1A-1 et seq.), commonly known as the open public records act, as amended and supplemented, may not be discoverable in any civil or criminal action, and may not be subject to subpoena, unless the subpoena is issued by the New Jersey State Legislature and is deemed necessary for the purposes of legislative oversight.\ng.\tNotwithstanding the provisions of subsection f. of this section, the New Jersey Office of Homeland Security and Preparedness may anonymize and share cyber threat indicators and relevant defensive measures to help prevent additional or future attacks and share cybersecurity incident notifications with relevant law enforcement authorities.\nh.\tInformation submitted to the New Jersey Office of Homeland Security and Preparedness through the cyber incident reporting system shall be subject to privacy and protection procedures developed and implemented by the office, which shall be based on the comparable privacy protection procedures developed for information received and shared pursuant to the federal Cyber Security Information Sharing Act of 2015 (6 U.S.C. s.1501 et seq.).\nL.2023, c.19, s.2.","path":["TITLE 52 STATE GOVERNMENT, DEPARTMENTS AND OFFICERS"],"source_url":"https://pub.njleg.state.nj.us/statutes/STATUTES-TEXT.zip","current_through":"P.L.2025, c.405, and J.R.22","vintage":"","retrieved_at":"2026-08-27T17:54:13Z","sha256":"cbd545a71081b6b33f5947b9d9488534b7f5fa84cf9d6d670e0c130a52c27360","source_id":"us-nj","stale":true,"prev":"us-nj/n.j.-stat.-52-17b-193.2","next":"us-nj/n.j.-stat.-52-17b-193.4"},"notice":"GroundRules: Original legal text. Not legal advice."}
