Key insights
Local Florida governments are required to adopt new cybersecurity standards designed to protect data and information technology and support confidentiality and integrity.
To comply with the act, plan to implement mandatory cybersecurity training for employees, adopt stringent cybersecurity standards, establish prompt incident reporting protocols, and submit detailed reports of cybersecurity incidents.
Consider working with a professional services firm for educational resources, risk assessments, or breach resolution services.
With the advent of the Florida Local Government Cybersecurity Act, the state has laid out clear guidelines to protect sensitive digital information and maintain operational integrity. Is your local government or municipality compliant with these requirements?
Local Florida governments are required to adopt new cybersecurity standards designed to protect data and information technology and support confidentiality and integrity.
Overview of Local Government Cybersecurity Act
The Local Government Cybersecurity Act is designed to safeguard the digital resources of Florida’s local governments by setting stringent standards and protocols for cybersecurity. Review these details to learn how your organization can achieve compliance.
Cybersecurity training
All local government employees with network access are required to complete basic cybersecurity training within 30 days of employment and annually thereafter. Those in more sensitive roles must undergo advanced training. This training may be provided Florida’s Digital Service in collaboration with Florida’s Cybercrime Office, private sector entities, or other educational institutions.
Cybersecurity standards
Local governments must adopt cybersecurity standards aligning with recommended practices, such as those outlined by the National Institute of Standards and Technology Cybersecurity Framework. Compliance deadlines vary based on population size, with larger counties and municipalities required to meet standards by
Incident notification
Prompt incident reporting is crucial. Local governments must notify relevant authorities, including the Cybersecurity Operations Center and local sheriff, of any cybersecurity or ransomware incidents. The act specifies reporting timelines based on the severity of the incident, enabling a rapid response to potential threats.
After-action reports
Following a cybersecurity incident, local governments are required to submit an after-action report within one week of resolution. This report should detail the incident, the steps taken to resolve it, and any lessons learned. The Florida Digital Service provides guidelines for these reports, facilitating consistency and thoroughness.
Connect

David Scaffido
Principal