- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
- AdministrationU.S. House
- AgricultureU.S. House
- Agriculture, Nutrition, And ForestryU.S. House
- AppropriationsU.S. House
- Armed ServicesU.S. House
- Banking, Housing, And Urban AffairsU.S. House
- BudgetU.S. House
- Commerce, Science, And TransportationU.S. House
- Education and WorkforceU.S. House
- Energy And CommerceU.S. House
- Energy And Natural ResourcesU.S. House
- Environment And Public WorksU.S. House
- EthicsU.S. House
- FinanceU.S. House
- Financial ServicesU.S. House
- Foreign AffairsU.S. House
- Foreign RelationsU.S. House
- Health, Education, Labor, And PensionsU.S. House
- Homeland SecurityU.S. House
- Homeland Security And Governmental Affa…U.S. House
- Indian AffairsU.S. House
- Indian and Insular AffairsU.S. House
- IntelligenceU.S. House
- JudiciaryU.S. House
- Natural ResourcesU.S. House
- Oversight And Government ReformU.S. House
- Permanent Select IntelligenceU.S. House
- RulesU.S. House
- Rules And AdministrationU.S. House
- Science, Space, And TechnologyU.S. House
- Select IntelligenceU.S. Senate
- Small BusinessU.S. House
- Small Business And EntrepreneurshipU.S. House
- Subcommittee on AviationU.S. House
- Subcommittee on Border Security and Enf…U.S. House
- Subcommittee on Coast Guard and Maritim…U.S. House
- Subcommittee on Commodity Markets, Digi…U.S. House
- Subcommittee on Conservation, Research,…U.S. House
- Subcommittee on Counterterrorism and In…U.S. House
- Subcommittee on Cybersecurity and Infra…U.S. House
- Subcommittee on Disability Assistance a…U.S. House
- Subcommittee on Economic Development, P…U.S. House
- Subcommittee on Economic OpportunityU.S. House
- Subcommittee on Emergency Management an…U.S. House
- Subcommittee on Energy and Mineral Reso…U.S. House
- Subcommittee on Federal LandsU.S. House
- Subcommittee on Forestry and Horticultu…U.S. House
- Subcommittee on General Farm Commoditie…U.S. House
- Subcommittee on HealthU.S. House
- Subcommittee on Highways and TransitU.S. House
- Subcommittee on Livestock, Dairy, and P…U.S. House
- Subcommittee on Nutrition and Foreign A…U.S. House
- Subcommittee on Oversight and Investiga…U.S. House
- Subcommittee on Oversight, Investigatio…U.S. House
- Subcommittee on Railroads, Pipelines, a…U.S. House
- Subcommittee on Transportation and Mari…U.S. House
- Subcommittee on Water Resources and Env…U.S. House
- Subcommittee on Water, Wildlife and Fis…U.S. House
- Transportation And InfrastructureU.S. House
- Veterans' AffairsU.S. House
- Ways And MeansU.S. House

S 7024
Florida Senate•Passed
Summary
S 7024, “OGSR/Cybersecurity, Information Technology, and Operational Technology Information”, was introduced in the Senate on Jan 15, 2026 by Sen. Governmental Oversight and Accountability. It last saw action on Jun 12, 2026: Chapter No. 2026-120.
Record
Text
S 7024 has 4 roll calls.
s7024/enrolled.txtENROLLED2026 Legislature SB 7024, 1st Engrossed20267024er12An act relating to a review under the Open Government3Sunset Review Act; amending s. 119.0725, F.S.;4revising definitions and defining terms; providing an5exemption from public records requirements for the6cybersecurity, information technology, and operational7technology information held by an agency; providing an8exemption from public meetings requirements for any9portion of a meeting that would reveal such10information; providing for retroactive application of11the exemptions; providing for future legislative12review and repeal of the exemptions; amending ss.1315.16, 24.1051, 101.5607, 106.0706, 112.31446, 119.07,14119.071, 119.0712, 119.0713, 119.0714, and 282.318,15F.S.; conforming cross-references and provisions to16changes made by the act; repealing s. 627.352, F.S.,17relating to security of data and information18technology in the Citizens Property Insurance19Corporation; repealing s. 1004.055, F.S., relating to20security of data and information technology in state21postsecondary education institutions; providing a22statement of public necessity; providing an effective23date.2425Be It Enacted by the Legislature of the State of Florida:2627Section 1. Section 119.0725, Florida Statutes, is amended28to read:29119.0725 Agency cybersecurity information; public records30exemption; public meetings exemption.—31(1) As used in this section, the term:32(a) “Breach” means unauthorized access of data or [in]33[electronic form containing personal] information. Good faith34access of data or [personal] information by an employee or agent35of an agency does not constitute a breach, provided that the36data or information is not used for a purpose unrelated to the37business or subject to further unauthorized use.38(b) “Critical infrastructure” means existing and proposed39information technology and operational technology systems and40assets, whether physical or virtual, the incapacity or41destruction of which would negatively affect security, economic42security, public health, or public safety.43(c) “Cybersecurity” means the protection afforded to44information technology or operational technology in order to45attain the applicable objectives of preserving the46confidentiality, integrity, and availability of such47technologies, data, and information [has the same meaning as in]48[s. 282.0041].49(d) “Data” has the same meaning as in s. 282.0041.50(e) “Incident” means a violation or imminent threat of51violation, whether such violation is accidental or deliberate,52of an agency’s cybersecurity, information technology, or53operational technology [resources, security, policies, or]54[practices]. As used in this paragraph, the term “imminent threat55of violation” means a situation in which the agency has a56factual basis for believing that a specific incident is about to57occur.58(f) “Information technology” has the same meaning as in s.59282.0041.60(g) “Login credentials” means information used to61authenticate a user’s identity or otherwise authorize access62when logging into a computer, computer system, computer network,63electronic device, or online user account accessible over the64Internet through a mobile device, a website, or any other65electronic means, or for authentication or password or account66recovery.67(h) “Operational technology” means the hardware and68software that cause or detect a change through the direct69monitoring or control of physical devices, systems, processes,70or events.71(i)“Public-facing portal” means a web portal or computer72application accessible by the public over the Internet, whether73through a mobile device, website, or other electronic means.74(2) The following information held by an agency is75confidential and exempt from s. 119.07(1) and s. 24(a), Art. I76of the State Constitution:77(a) [Coverage limits and deductible or self-insurance]78[amounts of insurance or other risk mitigation coverages acquired]79[for the protection of information technology systems,]80[operational technology systems, or data of an agency.]81[(b)] Information relating to critical infrastructure.82(b)[(c)] Cybersecurity incident information reported pursuant83to s. 282.318 or s. 282.3185.84(c)[(d)] Network schematics, hardware and software85configurations, [or] encryption information, or any information86that identifies detection, investigation, or response practices87related to [for suspected or confirmed] cybersecurity incidents,88including [suspected or confirmed] breaches, if the disclosure of89such information could [would] facilitate unauthorized access to90or unauthorized modification, disclosure, or destruction of91data, information, or existing or proposed information92technology or operational technology[:]93[1. Data or information, whether physical or virtual; or]94[2. Information technology resources, which include an]95[agency’s existing or proposed information technology systems].96(d)Information relating to processes or practices designed97to protect data, information, or existing or proposed98information technology or operational technology if the99disclosure of such information could facilitate unauthorized100access to or unauthorized modification, disclosure, or101destruction of such data, information, or technology.102(e)Portions of risk assessments, evaluation, audits, and103other reports of an agency’s cybersecurity program if the104disclosure of such information could facilitate unauthorized105access to or unauthorized modification, disclosure, or106destruction of data, information, or existing or proposed107information technology or operational technology.108(f)Login credentials.109(g)Internet protocol addresses, geolocation data, and110other information that describes the location, computer,111computer system, or computer network from which a user accesses112a public-facing portal, and the dates and times that a user113accesses a public-facing portal.114(h)Agency-produced data processing software that is115sensitive.116(i)Insurance and self-insurance coverage limits and117deductibles, as well as any other risk mitigation coverages118acquired for the protection of information technology,119operational technology, or data of an agency.120(3) Any portion of a meeting that would reveal information121made confidential and exempt under subsection (2) is exempt from122s. 286.011 and s. 24(b), Art. I of the State Constitution. An123exempt portion of a meeting may not be off the record and must124be recorded and transcribed. The recording and transcript are125confidential and exempt from s. 119.07(1) and s. 24(a), Art. I126of the State Constitution.127(4) The public records exemptions contained in this section128apply to information held by an agency before, on, or after the129effective date of the exemptions [July 1, 2022].130(5)(a) Information made confidential and exempt pursuant to131this section shall be made available to a law enforcement132agency, the Auditor General, the Cybercrime Office of the133Department of Law Enforcement, the Florida Digital Service134within the Department of Management Services, and, for agencies135under the jurisdiction of the Governor, the Chief Inspector136General.137(b) Such confidential and exempt information may be138disclosed by an agency in the furtherance of its official duties139and responsibilities or to another agency or governmental entity140in the furtherance of the agency’s or governmental entity’s141official [its statutory] duties and responsibilities.142(6) Agencies may report information about cybersecurity143incidents in the aggregate.144(7) This section is subject to the Open Government Sunset145Review Act in accordance with s. 119.15 and shall stand repealed146on October 2, 2031 [2026], unless reviewed and saved from repeal147through reenactment by the Legislature.148Section 2. Subsection (3) of section 15.16, Florida149Statutes, is amended to read:15015.16 Reproduction of records; admissibility in evidence;151electronic receipt and transmission of records; certification;152acknowledgment.—153(3)(a) The Department of State may cause to be received154electronically any records that are required or authorized to be155filed with it pursuant to chapter 48, chapter 55, chapter 117,156chapter 118, chapter 495, chapter 605, chapter 606, chapter 607,157chapter 610, chapter 617, chapter 620, chapter 621, chapter 679,158chapter 713, or chapter 865, through facsimile or other159electronic transfers, for the purpose of filing such records.160The originals of all such electronically transmitted records161must be executed in the manner provided in paragraph (5)(b). The162receipt of such electronic transfer constitutes delivery to the163department as required by law. The department may use electronic164transmissions for purposes of notice in the administration of165chapters 48, 55, 117, 118, 495, 605, 606, 607, 610, 617, 620,166621, 679, and 713 and s. 865.09. The Department of State may167collect e-mail addresses for purposes of notice and168communication in the performance of its duties and may require169filers and registrants to furnish such e-mail addresses when170presenting documents for filing.171(b) The department may implement a password-protected172system for any record electronically received pursuant to173paragraph (a) and may require filers to produce supplemental174materials to use such system, including, but not limited to, an175original signature of the filer and verification of credentials.176The department may also implement a password-protected system177that allows entities organized under the chapters specified in178paragraph (a) to identify authorized account holders for the179purpose of electronically filing records related to the entity.180If the department implements such a system, it must send to each181e-mail address on file with the Division of Corporations on182January 1, 2024, a code to participate in a password-protected183system. The department may require verification of the identity184of an authorized account holder before the account holder is185authorized to electronically file a record with the department.186(c)1. E-mail addresses collected by the Department of State187pursuant to this subsection are exempt from s. 119.07(1) and s.18824(a), Art. I of the State Constitution. This exemption applies189to e-mail addresses held by the Department of State before, on,190or after the effective date of the exemption.1912. [Secure login credentials held by the Department of State]192[for the purpose of allowing a person to electronically file]193[records under this subsection are exempt from s. 119.07(1) and]194[s. 24(a), Art. I of the State Constitution. This exemption]195[applies to secure login credentials held by the Department of]196[State before, on, or after the effective date of the exemption.]197[For purposes of this subparagraph, the term “secure login]198[credentials” means information held by the department for]199[purposes of authenticating a user logging into a user account on]200[a computer, a computer system, a computer network, or an]201[electronic device; an online user account accessible over the]202[Internet, whether through a mobile device, a website, or any]203[other electronic means; or information used for authentication]204[or password recovery.]205[3.] This paragraph is subject to the Open Government Sunset206Review Act in accordance with s. 119.15 and shall stand repealed207on October 2, 2028, unless reviewed and saved from repeal208through reenactment by the Legislature.209Section 3. Subsection (1) of section 24.1051, Florida210Statutes, is amended to read:21124.1051 Exemptions from inspection or copying of public212records.—213(1)(a) The following information held by the department is214confidential and exempt from s. 119.07(1) and s. 24(a), Art. I215of the State Constitution:2161. Information that, if released, could harm the security217or integrity of the department, including:218a. [Information relating to the security of the department’s]219[technologies, processes, and practices designed to protect]220[networks, computers, data processing software, data, and data]221[systems from attack, damage, or unauthorized access. This sub]222[subparagraph is subject to the Open Government Sunset Review Act]223[in accordance with s. 119.15 and shall stand repealed on October]224[2, 2027, unless reviewed and saved from repeal through]225[reenactment by the Legislature.]226[b.] Security information or information that would reveal227security measures of the department, whether physical or228virtual.229b.[c.] Information about lottery games, promotions, tickets,230and ticket stock, including information concerning the231description, design, production, printing, packaging, shipping,232delivery, storage, and validation of such games, promotions,233tickets, and stock.234c.[d.] Information concerning terminals, machines, and235devices that issue tickets.2362. Information that must be maintained as confidential in237order for the department to participate in a multistate lottery238association or game.2393. Personal identifying information obtained by the240department when processing background investigations of current241or potential retailers or vendors.2424. Financial information about an entity which is not243publicly available and is provided to the department in244connection with its review of the financial responsibility of245the entity pursuant to s. 24.111 or s. 24.112, provided that the246entity marks such information as confidential. However,247financial information related to any contract or agreement, or248an addendum thereto, with the department, including the amount249of money paid, any payment structure or plan, expenditures,250incentives, bonuses, fees, and penalties, shall be public251record.252(b) This exemption is remedial in nature, and it is the253intent of the Legislature that this exemption apply to254information held by the department before, on, or after May 14,2552019.256(c) Information made confidential and exempt under this257subsection may be released to other governmental entities as258needed in connection with the performance of their duties. The259receiving governmental entity shall maintain the confidential260and exempt status of such information.261Section 4. Paragraph (d) of subsection (1) of section262101.5607, Florida Statutes, is amended to read:263101.5607 Department of State to maintain voting system264information; prepare software.—265(1)266(d) Section 119.0725(2)(h) [119.071(1)(f)] applies to all267software on file with the Department of State.268Section 5. Section 106.0706, Florida Statutes, is amended269to read:270106.0706 Electronic filing of campaign finance reports;271public records exemption.—272(1) [All user identifications and passwords held by the]273[Department of State pursuant to s. 106.0705 are confidential and]274[exempt from s. 119.07(1) and s. 24(a), Art. I of the State]275[Constitution.]276[(2)(a)] Information entered in the electronic filing system277for purposes of generating a report pursuant to s. 106.0705 is278exempt from s. 119.07(1) and s. 24(a), Art. I of the State279Constitution.280(2)[(b)] Information entered in the electronic filing system281is no longer exempt once the report is generated and filed with282the Division of Elections.283Section 6. Subsection (6) of section 112.31446, Florida284Statutes, is amended to read:285112.31446 Electronic filing system for financial286disclosure.—287(6)[(a) All secure login credentials held by the commission]288[for the purpose of allowing access to the electronic filing]289[system are exempt from s. 119.07(1) and s. 24(a), Art. I of the]290[State Constitution.]291[(b)] Information entered in the electronic filing system for292purposes of financial disclosure is exempt from s. 119.07(1) and293s. 24(a), Art. I of the State Constitution. Information entered294in the electronic filing system is no longer exempt once the295disclosure of financial interests or statement of financial296interests is submitted to the commission or, in the case of a297candidate, filed with a qualifying officer, whichever occurs298first.299Section 7. Paragraph (g) of subsection (1) of section300119.07, Florida Statutes, is amended to read:301119.07 Inspection and copying of records; photographing302public records; fees; exemptions.—303(1)304(g) In any civil action in which an exemption to this305section is asserted, if the exemption is alleged to exist under306or by virtue of s. 119.071(1)(d) [or (f)], (2)(d), (e), or (f), or307(4)(c), or s. 119.0725(2)(h), the public record or part thereof308in question shall be submitted to the court for an inspection in309camera. If an exemption is alleged to exist under or by virtue310of s. 119.071(2)(c), an inspection in camera is discretionary311with the court. If the court finds that the asserted exemption312is not applicable, it shall order the public record or part313thereof in question to be immediately produced for inspection or314copying as requested by the person seeking such access.315Section 8. Paragraph (f) of subsection (1) of section316119.071, Florida Statutes, is amended to read:317119.071 General exemptions from inspection or copying of318public records.—319(1) AGENCY ADMINISTRATION.—320[(f) Agency-produced data processing software that is]321[sensitive is exempt from s. 119.07(1) and s. 24(a), Art. I of]322[the State Constitution. The designation of agency-produced]323[software as sensitive does not prohibit an agency head from]324[sharing or exchanging such software with another public agency.]325Section 9. Paragraph (f) of subsection (2) of section326119.0712, Florida Statutes, is amended to read:327119.0712 Executive branch agency-specific exemptions from328inspection or copying of public records.—329(2) DEPARTMENT OF HIGHWAY SAFETY AND MOTOR VEHICLES.—330[(f)1. Secure login credentials held by the Department of]331[Highway Safety and Motor Vehicles are exempt from s. 119.07(1)]332[and s. 24(a), Art. I of the State Constitution. This exemption]333[applies to secure login credentials held by the department]334[before, on, or after the effective date of the exemption. For]335[purposes of this subparagraph, the term “secure login]336[credentials” means information held by the department for]337[purposes of authenticating a user logging into a user account on]338[a computer, a computer system, a computer network, or an]339[electronic device; an online user account accessible over the]340[Internet, whether through a mobile device, a website, or any]341[other electronic means; or information used for authentication]342[or password recovery.]343[2. Internet protocol addresses, geolocation data, and other]344[information held by the Department of Highway Safety and Motor]345[Vehicles which describes the location, computer, computer]346[system, or computer network from which a user accesses a public]347[facing portal, and the dates and times that a user accesses a]348[public-facing portal, are exempt from s. 119.07(1) and s. 24(a),]349[Art. I of the State Constitution. This exemption applies to such]350[information held by the department before, on, or after the]351[effective date of the exemption. For purposes of this]352[subparagraph, the term “public-facing portal” means a web portal]353[or computer application accessible by the public over the]354[Internet, whether through a mobile device, website, or other]355[electronic means, which is established for administering chapter]356[319, chapter 320, chapter 322, chapter 328, or any other]357[provision of law conferring duties upon the department.]358[3. This paragraph is subject to the Open Government Sunset]359[Review Act in accordance with s. 119.15 and shall stand repealed]360[on October 2, 2026, unless reviewed and saved from repeal]361[through reenactment by the Legislature.]362Section 10. Subsection (5) of section 119.0713, Florida363Statutes, is amended to read:364119.0713 Local government agency exemptions from inspection365or copying of public records.—366(5)[(a)] Customer meter-derived data and billing information367in increments less than one billing cycle [The following]368[information] held by a utility owned or operated by a unit of369local government are [is] exempt from s. 119.07(1) and s. 24(a),370Art. I of the State Constitution[:]371[1. Information related to the security of the technology,]372[processes, or practices of a utility owned or operated by a unit]373[of local government that are designed to protect the utility’s]374[networks, computers, programs, and data from attack, damage, or]375[unauthorized access, which information, if disclosed, would]376[facilitate the alteration, disclosure, or destruction of such]377[data or information technology resources.]378[2. Information related to the security of existing or]379[proposed information technology systems or industrial control]380[technology systems of a utility owned or operated by a unit of]381[local government, which, if disclosed, would facilitate]382[unauthorized access to, and alteration or destruction of, such]383[systems in a manner that would adversely impact the safe and]384[reliable operation of the systems and the utility.]385[3. Customer meter-derived data and billing information in]386[increments less than one billing cycle].387(a)[(b)] This exemption applies to such data and information388held by a utility owned or operated by a unit of local389government before, on, or after the effective date of this390exemption.391(b)[(c)] This subsection is [Subparagraphs (a)1. and 2. are]392subject to the Open Government Sunset Review Act in accordance393with s. 119.15 and shall stand repealed on October 2, 2027,394unless reviewed and saved from repeal through reenactment by the395Legislature.396Section 11. Paragraph (b) of subsection (1) of section397119.0714, Florida Statutes, is amended to read:398119.0714 Court files; court records; official records.—399(1) COURT FILES.—Nothing in this chapter shall be construed400to exempt from s. 119.07(1) a public record that was made a part401of a court file and that is not specifically closed by order of402court, except:403(b) Data processing software as provided in s.404119.0725(2)(h) [s. 119.071(1)(f)].405Section 12. Paragraphs (d), (e), and (g) of subsection (4)406and subsections (5) through (9) of section 282.318, Florida407Statutes, are amended to read:408282.318 Cybersecurity.—409(4) Each state agency head shall, at a minimum:410(d) Conduct, and update every 3 years, a comprehensive risk411assessment, which may be completed by a private sector vendor,412to determine the security threats to the data, information, and413information technology resources, including mobile devices and414print environments, of the agency. The risk assessment must415comply with the risk assessment methodology developed by the416department [and is confidential and exempt from s. 119.07(1),]417[except that such information shall be available to the Auditor]418[General, the Florida Digital Service within the department, the]419[Cybercrime Office of the Department of Law Enforcement, and, for]420[state agencies under the jurisdiction of the Governor, the Chief]421[Inspector General]. If a private sector vendor is used to422complete a comprehensive risk assessment, it must attest to the423validity of the risk assessment findings.424(e) Develop, and periodically update, written internal425policies and procedures, which include procedures for reporting426cybersecurity incidents and breaches to the Cybercrime Office of427the Department of Law Enforcement and the Florida Digital428Service within the department. Such policies and procedures must429be consistent with the rules, guidelines, and processes430established by the department to ensure the security of the431data, information, and information technology resources of the432agency. [The internal policies and procedures that, if disclosed,]433[could facilitate the unauthorized modification, disclosure, or]434[destruction of data or information technology resources are]435[confidential information and exempt from s. 119.07(1), except]436[that such information shall be available to the Auditor General,]437[the Cybercrime Office of the Department of Law Enforcement, the]438[Florida Digital Service within the department, and, for state]439[agencies under the jurisdiction of the Governor, the Chief]440[Inspector General.]441(g) Ensure that periodic internal audits and evaluations of442the agency’s cybersecurity program for the data, information,443and information technology resources of the agency are444conducted. [The results of such audits and evaluations are]445[confidential information and exempt from s. 119.07(1), except]446[that such information shall be available to the Auditor General,]447[the Cybercrime Office of the Department of Law Enforcement, the]448[Florida Digital Service within the department, and, for agencies]449[under the jurisdiction of the Governor, the Chief Inspector]450[General.]451[(5) The portions of risk assessments, evaluations, external]452[audits, and other reports of a state agency’s cybersecurity]453[program for the data, information, and information technology]454[resources of the state agency which are held by a state agency]455[are confidential and exempt from s. 119.07(1) and s. 24(a), Art.]456[I of the State Constitution if the disclosure of such portions]457[of records would facilitate unauthorized access to or the]458[unauthorized modification, disclosure, or destruction of:]459[(a) Data or information, whether physical or virtual; or]460[(b) Information technology resources, which include:]461[1. Information relating to the security of the agency’s]462[technologies, processes, and practices designed to protect]463[networks, computers, data processing software, and data from]464[attack, damage, or unauthorized access; or]465[2. Security information, whether physical or virtual, which]466[relates to the agency’s existing or proposed information]467[technology systems.]468469[For purposes of this subsection, “external audit” means an audit]470[that is conducted by an entity other than the state agency that]471[is the subject of the audit.]472[(6) Those portions of a public meeting as specified in s.]473[286.011 which would reveal records which are confidential and]474[exempt under subsection (5) are exempt from s. 286.011 and s.]475[24(b), Art. I of the State Constitution. No exempt portion of an]476[exempt meeting may be off the record. All exempt portions of]477[such meeting shall be recorded and transcribed. Such recordings]478[and transcripts are confidential and exempt from disclosure]479[under s. 119.07(1) and s. 24(a), Art. I of the State]480[Constitution unless a court of competent jurisdiction, after an]481[in camera review, determines that the meeting was not restricted]482[to the discussion of data and information made confidential and]483[exempt by this section. In the event of such a judicial]484[determination, only that portion of the recording and transcript]485[which reveals nonexempt data and information may be disclosed to]486[a third party.]487[(7) The portions of records made confidential and exempt in]488[subsections (5) and (6) shall be available to the Auditor]489[General, the Cybercrime Office of the Department of Law]490[Enforcement, the Florida Digital Service within the department,]491[and, for agencies under the jurisdiction of the Governor, the]492[Chief Inspector General. Such portions of records may be made]493[available to a local government, another state agency, or a]494[federal agency for cybersecurity purposes or in furtherance of]495[the state agency’s official duties.]496[(8) The exemptions contained in subsections (5) and (6)]497[apply to records held by a state agency before, on, or after the]498[effective date of this exemption.]499[(9) Subsections (5) and (6) are subject to the Open]500[Government Sunset Review Act in accordance with s. 119.15 and]501[shall stand repealed on October 2, 2026, unless reviewed and]502[saved from repeal through reenactment by the Legislature.]503Section 13. Section 627.352, Florida Statutes, is repealed.504Section 14. Section 1004.055, Florida Statutes, is505repealed.506Section 15. (1)The Legislature finds that it is a public507necessity that the following information held by an agency be508made confidential and exempt from s. 119.07(1), Florida509Statutes, and s. 24(a), Article I of the State Constitution:510(a) Network schematics, hardware and software511configurations, encryption information, or any information that512identifies detection, investigation, or response practices513relating to cybersecurity incidents, including breaches, if the514disclosure of such information could facilitate unauthorized515access to or unauthorized modification, disclosure, or516destruction of data, information, or existing or proposed517information technology or operational technology.518(b) Information relating to processes or practices designed519to protect data, information, or existing or proposed520information technology or operational technology if the521disclosure of such information could facilitate unauthorized522access to or unauthorized modification, disclosure, or523destruction of such data, information, or technology.524(c) Portions of risk assessments, evaluations, audits, and525other reports of an agency’s cybersecurity program if the526disclosure of such information could facilitate unauthorized527access to or unauthorized modification, disclosure, or528destruction of data, information, or existing or proposed529information technology or operational technology.530(d) Login credentials.531(e) Internet protocol addresses, geolocation data, and532other information that describes the location, computer,533computer system, or computer network from which a user accesses534a public-facing portal, and the dates and times that a user535accesses a public-facing portal.536(f) Agency-produced data processing software that is537sensitive.538(g) Insurance and self-insurance coverage limits and539deductibles, as well as any other risk mitigation coverages,540acquired for the protection of information technology,541operational technology, or data of an agency.542(2)The Legislature finds that release of the information543described in subsection (1) could place an agency at greater544risk of breaches, cybersecurity incidents, and ransomware545attacks. Network schematics, hardware and software546configurations, encryption information, or any information that547identifies detection, investigation, or response practices for548cybersecurity incidents, including breaches, reveals how an549agency’s information technology and operational technology550systems are structured and defended. Disclosure of such551information could enable a malicious actor to map system552architecture, identify vulnerabilities, and bypass security553controls. Information describing processes or practices designed554to protect data, information, or existing or proposed555information technology or operational technology could similarly556be used to exploit weaknesses and predict defensive actions.557Portions of risk assessments, evaluations, audits, and other558reports of an agency’s cybersecurity program routinely include559descriptions of vulnerabilities, testing results, and560recommendations. Disclosure of such information would561substantially increase the likelihood of a successful562cyberattack. Login credentials are a foundational security563control, and disclosure of such information could allow564malicious actors to authenticate themselves in order to access565government systems, impersonate legitimate users, and access566personal identifying and other sensitive information. Internet567protocol addresses, geolocation data, and other information that568describes the location, computer, computer system, or computer569network from which a user accesses a public-facing portal, and570the dates and times that a user accesses a public-facing portal,571could be used to track usage patterns, identify remote access572points, or monitor portal vulnerabilities. Sensitive agency573produced data processing software can reveal the inner workings574of security controls, authentication mechanisms, or automated575processes that malicious actors can use to exploit weaknesses in576security measures. If information related to coverage limits and577deductibles of cybersecurity insurance were disclosed, it could578give cybercriminals an understanding of the monetary sum an579agency can afford or may be willing to pay as a result of a580ransomware attack at the expense of taxpayers. Accordingly, the581Legislature finds that the disclosure of such sensitive582cybersecurity-related information would significantly impair the583administration of vital governmental programs.584(3) The Legislature also finds that it is a public585necessity that any portion of a meeting which would reveal the586confidential and exempt information in subsection (1) be made587exempt from s. 286.011, Florida Statutes, and s. 24(b), Article588I of the State Constitution, and that any recordings and589transcripts of the closed portion of a meeting be made590confidential and exempt from s. 119.07(1), Florida Statutes, and591s. 24(a), Article I of the State Constitution. The failure to592close that portion of a meeting at which confidential and exempt593information would be revealed, and prevent the disclosure of the594recordings and transcripts of those portions of a meeting, would595defeat the purpose of the underlying public records exemption596and could result in the release of highly sensitive information597related to the cybersecurity of an agency system.598(4) For these reasons, the Legislature finds that these599public records and public meetings exemptions are of the utmost600importance and are a public necessity.601Section 16. This act shall take effect upon becoming a law.
Providing an exemption from public records requirements for the cybersecurity, information technology, and operational technology information held by an agency; providing an exemption from public meetings requirements for any portion of a meeting that would reveal such information; providing for future legislative review and repeal of the exemptions; providing a statement of public necessity, etc.
Sponsors
Sen. Governmental Oversight and Accountability sponsors S 7024 alone.
History
S 7024 has taken 28 actions since Jan 15, 2026, the latest on Jun 12, 2026.
| Chamber | Action | |||
|---|---|---|---|---|
Jun 12, 2026 | — | Chapter No. 2026-120 | ||
Jun 10, 2026 | — | Approved by Governor | ||
Jun 9, 2026 | — | Signed by Officers and presented to Governor | ||
Mar 17, 2026 | Senate | Ordered enrolled | ||
Mar 9, 2026 | House | Read 2nd time |
Votes
S 7024 went to 4 roll calls across both chambers, the latest on Mar 9, 2026 at 107–0.
| Chamber | Question | Yea | Nay | |||
|---|---|---|---|---|---|---|
Mar 9, 2026 | House | House: Third Reading RCS#727 | 107 | 0 | ||
Feb 19, 2026 | Senate | Senate: Third Reading RCS#5 | 36 | 1 | ||
Feb 3, 2026 | Senate | Senate Rules | 23 | 1 | ||
Jan 20, 2026 | Senate | Senate Governmental Oversight and Accountability | 9 | 0 |
Source: flsenate.gov · legiscan.com