IC 4-13.1-2-9 — State agency reporting requirements
Chapter 2. Office of Technology
Bills amending this section
Section text
Sec. 9. (a) This section does not apply to an entity subject to IC 13-18-16.5. (b) A state agency (as defined in IC 4-1-10-2) other than a state educational institution, and a political subdivision (as defined in IC 36-1-2-13), other than a department of public utilities established under IC 8-1-11.1, shall: (1) report any cybersecurity incident using their best professional judgment to the office without unreasonable delay and not later than two (2) business days after discovery of the cybersecurity incident in a format prescribed by the chief information officer; and (2) provide the office with the name and contact information of any individual who will act as the primary reporter of a cybersecurity incident described in subdivision (1) before September 1, 2021, and before September 1 of every year thereafter. Nothing in this section shall be construed to require reporting that conflicts with federal privacy laws or is prohibited due to an ongoing law enforcement investigation.
As added by P.L.134-2021, SEC.5. Amended by P.L.137-2021, SEC.18; P.L.139-2025, SEC.1; P.L.142-2025, SEC.1; P.L.186-2025, SEC.283; P.L.23-2026, SEC.11.
Source: official publisher (2026 edition)