New York
CurrentGeneral Municipal Law §995-b — Cybersecurity incident reporting
School districts and BOCES must report cybersecurity incidents and applicable ransom demands within 72 hours after reasonably believing an incident occurred.
- Jurisdiction
- New York · State / DC
- Policy status
- Effective
- Implementation phase
- Current
- Requirement
- Required
- Grades
- All K-12
- Audience
- Districts / LEAs
- Learning evidence
- No student-learning claim
- Instrument
- Statute / enacted law
Dates & implementation
Report within72 hours of reasonably believing an incident occurred; include applicable ransom demands. Current statutory revision August 1, 2025.
A legal effective date can precede school implementation. This record documents policy intent or requirements; it does not independently confirm delivery in every classroom.
Funding & support
Funding details not confirmed
Dedicated funding and current award availability are not established in this collection. This does not mean no funding exists.
Evidence & source location
GMU§995-b(1)–(3); covered municipal-corporation definition in §995-a
Coverage traced through §995-a(6) to §119-n(a), which expressly includes school districts and BOCES. Current codified law reviewed; original effective date not yet reconstructed.
Review history
Reviewed against official sources
Source availability checked Oct 4, 2026: Source reopened. This is separate from verification of the policy claim below.
Source review date recorded in database: 2026-10-04
2026-10-03 — Carried forward from the source-linked baseline; topic, grade and evidence-type inventory reviewed. Individual source was not re-opened in this update. 2026-10-04 — Substantive source review: Reviewed GMU§995-b: incidents and applicable ransom demands must be reported within72 hours of reasonably believing an incident occurred.
Record ID: NY-2025-CYBER-REPORT
Suggest a correction to this record