A service of

State Cybersecurity Laws: Enforcers’ Growing Toolkit

State AGs are expanding their role in cybersecurity enforcement, drawing on a robust toolkit that includes a growing mix of consumer protection laws, sector-specific statutes and emerging legislation to scrutinize how companies secure personal data. For privacy and cybersecurity professionals, this creates both heightened risk and a more complex compliance landscape that they need to understand and address.

New authorities are being added every year. In 2025, according to tracking by the National Conference of State Legislators, at least 44 states enacted more than 200 bills and adopted at least 30 resolutions related to cybersecurity. Most were aimed at strengthening cybersecurity within the systems of state and local government, but more than two dozen of these new laws concerned the private sector, including ones regulating genetic data, mortgage brokers and other financial services providers.

This article examines the key authorities that states are using, highlights enforcement trends across industries and explains how the relevant laws are reshaping compliance expectations.

See “Examining Security Mandates, Including California’s Draft Audit Regulations, in State Privacy Laws” (Nov. 1, 2023).

Active Enforcement Across the Country

Across the country, in states both red and blue, state AGs have shown a willingness to take on the biggest of Big Tech across a range of issues.

Ed Tech Breach and Kids’ Data

In November 2025, Connecticut, California and New York secured a $5.1‑million settlement from educational technology company Illuminate Education for failing to protect students’ data. The states alleged that Illuminate failed to implement basic security measures, including failing to monitor for suspicious activity on its platforms, allowing attackers to access the PI of millions of students.

See “Illuminate Settlements Signal Regulator Focus on Children’s Data” (Dec. 17, 2025).

Meta and WhatsApp Failure to Encrypt

In May 2026, from the other end of the political spectrum, Texas AG Ken Paxton sued Meta and WhatsApp for failing to provide the end-to-end encryption they had promised would shield WhatsApp messages, photos and calls.

Equifax, Meta and Google Payouts

State cybersecurity enforcement actions can lead to significant monetary payouts. As long ago as 2019, Equifax agreed to pay $600 million to settle with 50 states for its 2017 breach.

But even the Equifax case was dwarfed by the eye-popping $1.4‑billion settlement that Texas secured in July 2024 in a biometric privacy case against Meta and Texas’ $1.375‑billion settlement in 2025 with Google for collecting geolocation, browsing and biometric data. While, strictly speaking, those were privacy cases centered around notice and consent, it may not be too long before there is a billion-dollar settlement in a state cybersecurity action.

On top of the direct payments to the states, the typical state cybersecurity case results in the respondent agreeing to implement and maintain multiple improvements in its cybersecurity practices, at considerable ongoing expense.

Security for Personal Data Is Expressly Mandated in a Majority of States

At least 33 states have broadly applicable laws requiring businesses to protect the PI they collect from consumers with reasonable security measures. Most say no more than that; some go into detail on what an entity must consider. A few of these laws provide a private right of action, but all are enforceable by the state AG.

Reasonable Security Measures

The number of states requiring businesses to protect the consumer information they collect has grown in part as a result of the ongoing trend toward state adoption of comprehensive consumer privacy laws. All of the comprehensive privacy laws adopted by states since 2018 (23 and counting at this writing) have a provision requiring data controllers to implement reasonable security measures. The Texas Data Security and Privacy Act is typical. It includes a provision mandating that a data controller, “for purposes of protecting the confidentiality, integrity, and accessibility of personal data, shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices that are appropriate to the volume and nature of the personal data at issue.”

The movement toward state comprehensive privacy laws, which seemed to have slowed in 2025, has picked up speed again in 2026, with Oklahoma, Alabama, Louisiana and Vermont enacting comprehensive data privacy legislation so far this year.

More Prescriptiveness in New York and California

Few states have adopted detailed regulations to spell out what “reasonable” cybersecurity means, leaving that to case-by-case enforcement. Massachusetts and New York are exceptions. In New York, however, the State Department of Financial Services has promulgated regulations for entities under its jurisdiction, and the New York State Department of Health has adopted detailed cybersecurity regulations for hospitals.

In California, which has a one-of-a-kind requirement that businesses conduct regular cybersecurity audits, the California Privacy Protection Agency has indirectly indicated what it expects of entities in a regulation defining what the audits should address. The first audits, for very large companies, are due in 2028, covering 2027.

See this two-part series “Amendment to NYDFS Cyber Regulation Brings New Mandates”: Governance Provisions (Dec. 13, 2023), and First Compliance Steps (Jan. 3, 2024).

Notice Requirements

In addition to the growing number of state laws requiring reasonable security measures for personal data, all 50 states, plus the District of Columbia, Guam, Puerto Rico and the Virgin Islands, have laws requiring notice to consumers in the case of a data breach. Delay in sending notice or failure to fully describe an incident may trigger enforcement action.

See “Establishing a Foundation for Breach-Notification Compliance in a Sea of Privacy Laws” (Jan. 29, 2020).

Sector-Specific Laws Address New and Existing Concerns

As states enact comprehensive privacy laws with cybersecurity provisions, they also adopt sector-specific laws, sometimes responding to what seems to be the issue of the day, but other times reflecting long-standing concerns.

Two states (California and Oregon) have free-standing laws that require security measures in connected devices. Four states (California, Connecticut, Iowa and Vermont) have cybersecurity laws specifically aimed at educational technology, specifically websites, online services, and online or mobile apps used primarily by – and designed and marketed for – pre‑K to 12 school purposes. California, Nevada and Washington have free-standing laws specifically requiring security protection of medical data.

At least 26 states, plus the District of Columbia and Puerto Rico, have adopted the model cybersecurity law drafted by the National Association of Insurance Commissioners. Also gaining traction is the Nonbank Model Data Security Law drafted by the Conference of State Bank Supervisors, which has been adopted by at least 12 states.

Applicable across sectors, but tailored to specific data, the Illinois Biometric Information Privacy Act requires any entity in possession of a biometric identifier or biometric information to “store, transmit and protect from disclosure all biometric identifiers and biometric information using the reasonable standard of care within the private entity’s industry.”

See “BIPA Litigation Dynamics Following Seventh Circuit Clay Decision” (May 20, 2026).

Genetic Data Becomes a Focus of Cybersecurity Laws

In 2025 and 2026, a new trend emerged, as at least nine states adopted cybersecurity laws for genetic data. Three, in ConnecticutMaryland and South Dakota, apply only to direct-to-consumer genetic testing companies and require them to develop, implement and maintain a security program to protect consumers’ genetic data against unauthorized access, use or disclosure. Six of the laws address a broader range of entities and a broader set of concerns, addressing not only cybersecurity risks in general but also the risk of processing genetic data in ways that expose it to foreign adversaries.

Typical of the class of broader laws, the Louisiana Human Genomic Security Act of 2025 provides that a medical facility, human genomic research facility or company storing human genetic sequencing data shall restrict such storage to geographic locations outside of a foreign adversary country. Remote access to data storage, other than open data, from a foreign adversary country is prohibited. Covered companies that store human genetic sequencing data, including through contracts with third-party data storage companies, also shall ensure the security of human genetic sequencing data by using reasonable encryption methods, restrictions on access and other cybersecurity best practices.

Likewise, the Texas Genomic Act of 2025 states that a medical facility, research facility, company or nonprofit organization that stores genome sequencing data of residents of the state, including storage through a contract with a third party, shall ensure the security of the data using reasonable encryption methods, restriction on access and other cybersecurity best practices. An entity subject to the act may not store any genome sequencing data of a resident of Texas at a location within the borders of a country that is a foreign adversary and must ensure genome sequencing data of Texas residents, other than open data, is inaccessible to any person located within the borders of a foreign adversary country. By cross reference to federal law, “foreign adversary” is defined as China, Cuba, Iran, North Korea, Russia and “Venezuelan politician Nicolás Maduro (Maduro Regime).”

States Address National Security Concerns

These genetic data security laws manifest one of the most remarkable developments in the evolving landscape of cybersecurity regulation, as the states address national security concerns of the type that previously had been the sole domain of the federal government. The movement began in 2020, when the governor of Nebraska announced the state would block the video sharing app TikTok on all state electronic devices, based on concerns that the People’s Republic of China could use the app to collect data on state employees. A wave of TikTok bans followed, with about half the states acting by January 2023.

In Texas and other states, the practice has expanded to cover a wide range of products and services. In January 2025, for example, the Texas governor banned the use on government-issued devices of AI products affiliated with the People’s Republic of China and the Chinese Communist Party. In January 2026, he named the Texas Cyber Command as the entity with primary responsibility for creating and maintaining a list of prohibited technologies for state employees and devices. Also, in 2025, Virginia Governor Glenn Youngkin issued an executive order banning the use of China’s DeepSeek AI on state devices and state-run networks, including state-issued cell phones, laptops or other devices capable of connecting to the internet.

States have also adopted laws banning the purchase of China-made telecommunications equipment. Louisiana adopted in 2020, and then amended in 2021, a law banning all state government agencies and publicly funded educational institutions from buying information and communications technology and services from certain Chinese companies. In 2023, Indiana banned use of public funds to purchase certain China-made communications equipment.

State Attention Expands to Critical Infrastructure

The concern with foreign adversary cyberattacks has also driven other action. It is not clear yet whether it is a broad trend, but states have begun to address the cyber vulnerability of critical infrastructure. The issue emerged in 2025 when two states adopted cybersecurity mandates for water and wastewater treatment systems. While most water and wastewater treatment systems in the U.S. are run by governmental entities, the infrastructure is highly decentralized, with many small municipal and regional entities. U.S. intelligence and cybersecurity agencies have been warning for years that the operational technology of these systems – the internet-connected digital devices that control their physical operations – have been targeted by foreign adversaries, prompting some state legislatures to act.

In 2025, Indiana enacted a law requiring water and wastewater systems to conduct a cybersecurity vulnerability assessment at least once per calendar year. Beginning in 2026, not later than December 31 of each even-numbered year, a covered entity must submit a certification to the Department of Environmental Management verifying that it completed the assessment, mitigated or has documented plans to mitigate identified vulnerabilities, and updated emergency response plans to account for vulnerabilities and mitigating procedures.

Also in 2025, Maryland amended the environmental article of the state code to add a new subtitle requiring the state Department of the Environment, in consultation with the Department of Information Technology, to update regulations governing community water and sewage systems to include comprehensive cybersecurity standards and to require covered systems to plan for disruptions of service due to cyber incidents, including ransomware attacks and other events resulting in root-level compromise. Systems that serve more than 3,300 customers must adopt a zero–trust cybersecurity approach and begin planning and implementing the zero–trust approach for on–premises services and cloud–based services. On or before July 1, 2026, and every two years thereafter, such systems shall conduct a maturity assessment of their cybersecurity program for operational technology and IT.

Prohibitions on Unfair and Deceptive Practices – the Broadest and Most Flexible Authority

Despite all the new laws coming onto the books, the most powerful tool in the state AG toolkit may be a set of laws enacted more than 50 years ago. Largely as a result of a movement that swept the country in the 1960s and 1970s, all 50 states and the District of Columbia have a consumer protection law that prohibits deceptive practices and many prohibit unfair practices, as well. These are called “mini-FTC acts,” consumer protection acts, consumer fraud acts or UDAP (unfair and deceptive acts and practices) statutes.

The state laws vary. Colorado’s, for example, does not include a broad prohibition of deceptive practices, containing instead a long list of specific practices, and has nothing on unfairness, while others – such as Delaware’s and Nevada’s – prohibit deception but do not include a broad prohibition of unfairness. Despite these differences, however, the AGs of every state have taken the position, expressly or in their litigation posture, that failure to maintain reasonable data security for PI may be considered an unfair or deceptive act.

Illustrating the utility of these laws is the September 2025 lawsuit that Texas AG Paxton filed against a provider of cloud-based services for K‑12 schools after a data breach exposed the PII and protected health information of school-aged children and teachers. The first four counts in the five-count lawsuit alleged violation of the Texas Deceptive Trade Practices Act, which prohibits “false, misleading, or deceptive acts or practices in the conduct of any trade or commerce.”

Expect More

If there is one safe bet to be made with respect to state involvement in cybersecurity regulation and enforcement, it is this: expect more enforcement actions and new state laws. Whether cooperating across jurisdictional lines or acting independently, state AGs are clearly on the lookout for cases. In particular, social media litigation filed since 2022 – including multidistrict and state AG cases against platforms such as Meta, TikTok and Snapchat – has advanced the agument that software platforms and their algorithmic design features can be treated as “products” for purposes of liability. If courts accept that framing, it could expand targets for cybersecurity enforcment beyond data custodians to include software developers.

 

Jim Dempsey is managing director of the IAPP Cybersecurity Law Center and co‑author of Cybersecurity Law Fundamentals. He is a lecturer at the UC Berkeley Law School and a former member of the U.S. Privacy and Civil Liberties Oversight Board.