I am deeply disappointed by the failure of Florida House Bill 1147, a well-crafted and much-needed legislation addressing the growing cybersecurity threats faced by critical infrastructure systems. This bill aimed to provide clarity and support to both public and private sectors, drawing attention to incidents like the Colonial Pipeline hack and intrusions into federal agencies.
House Bill 1147 recognized the importance of standardized security capabilities, emphasizing the need for consistent definitions in control system components. By referencing respected standards such as the NIST CSF and ISA 62443 series, the bill aimed to simplify procurement processes and ensure a common language for suppliers and stakeholders.
Furthermore, this bill aimed to safeguard vital infrastructure sectors such as transportation, water and wastewater facilities, public utilities, hospitals, and financial services organizations. By implementing cybersecurity standards, House Bill 1147 intended to protect these sectors from cyber threats and guarantee the safety, security, and reliability of critical infrastructure operations.
Another crucial aspect of House Bill 1147 was its encouragement of annual risk assessments and the development of risk mitigation plans for operational technology and control systems. By taking a proactive approach, the bill aimed to identify vulnerabilities, implement necessary security measures, and minimize the potential impact of security incidents.
Moreover, House Bill 1147 sought to provide immunity from civil liability to defendants who made a good-faith effort to meet recommended cybersecurity standards. This provision would incentivize organizations to prioritize cybersecurity, fostering a culture of responsible practices and potentially reducing legal challenges following security incidents.
It is regrettable that House Bill 1147 did not pass, as it held the potential to significantly enhance the cybersecurity landscape in Florida and protect critical infrastructure from evolving threats.
We must do better