← North Carolina profile

North Carolina

Current

G.S. 143-800 — Ransomware response

Local school administrative units may not pay or communicate with an entity encrypting their systems for ransom and must consult state IT when a ransom is requested.

Jurisdiction
North Carolina · State / DC
Policy status
Effective
Implementation phase
Current
Requirement
Required
Grades
All K-12
Audience
Districts / LEAs
Learning evidence
No student-learning claim
Instrument
Statute / enacted law

Dates & implementation

Current GS143-800 prohibits ransomware payment/communication and requires consultation with state DIT when a ransom is requested.

A legal effective date can precede school implementation. This record documents policy intent or requirements; it does not independently confirm delivery in every classroom.

Funding & support

Funding details not confirmed

Dedicated funding and current award availability are not established in this collection. This does not mean no funding exists.

Evidence & source location

GS143-800(a)–(c)(1).

Statutory definition expressly includes local school administrative units. Source cites S.L. 2021-180 §38.13(a); exact effective date not independently reconstructed. Retained despite Robert cybersecurity-floor snapshot lacking this verified school duty.

Review history

Reviewed against official sources

Source availability checked Oct 4, 2026: Source reopened. This is separate from verification of the policy claim below.

Source review date recorded in database: 2026-10-04

2026-10-03 — Carried forward from the source-linked baseline; topic, grade and evidence-type inventory reviewed. Individual source was not re-opened in this update. 2026-10-04 — Substantive source review: Current GS143-800 full text read; local school administrative units expressly included in local-government definition.

Record ID: NC-CYBER-RANSOM-001

Suggest a correction to this record