
Last year we published a blog on Florida’s House Bill 473: The Cybersecurity Incident Liability Act. Less than two weeks later, on June 26, 2024, Governor Ron DeSantis vetoed HB 473, which promised private companies as well as state and local governments a legal shield against data breach lawsuits if they “substantially complied” with an established cybersecurity framework. We were optimistic about this and similar legislation from other states. Still, we noted at the time that one potential downside was that the bill “could impact consumer rights, potentially limiting avenues for affected individuals to seek compensation or hold companies accountable for data breach incidents.” It seems that Governor DeSantis shared our concerns, citing that it may be too business-friendly and insufficiently protective of consumers.
He wrote in his veto, “As passed, the bill could result in Floridians’ data being less secure as the bill provides across-the-board protections for only substantially complying with standards. This incentivizes doing the minimum when protecting consumer data. While my Administration has prioritized policies to reduce frivolous litigation, the bill before me today may result in a consumer having inadequate recourse if a breach occurs.” You can read the full text of his veto here.
I guess we can’t say we didn’t see this coming. In our first blog, we speculated that HB 473 might lead courts to assign proportional liability to companies based on their cybersecurity efforts—a hopeful guess that courts could reward investment incrementally. However, the bill’s fine print does not support this interpretation: it was an all-or-nothing proposition. If a company achieves “substantial compliance” by the court’s interpretation, they are immune. If they don’t, they are fully liable. Governor DeSantis saw the same undesirable possibility that we did—the prospect of companies getting to skate by with “only substantially complying,” leaving consumers who have suffered damages or been exposed to risk without legal recourse.
Good legislation should set up proper incentives and be crafted with careful consideration of all competing concerns. States want to protect consumers, infrastructure, and shield businesses from frivolous or capricious lawsuits. These are all reasonable goals, but the devil is in the details, making it tricky to achieve them with a minimum of unintended and unwanted consequences. Nobody wants to reward negligence, punish positive effort, or reduce accountability without a concomitant boost in security. Compounding this difficulty is the inherent gray area in defining “negligence” in the vast world of cybersecurity, coupled with the reality that even a very tight and tidy organization can be breached through Zero-Day exploits.
Cybersecurity in today’s world is akin to workplace safety; it applies to everyone, all the time, even in what most would consider to be low risk environments. Businesses and insurers care a great deal about mitigating these risks and limiting liability. With all this in mind, we should evaluate legislation on a case-by-case basis by its stated intentions and the means by which it seeks to achieve them. The Florida bill was noteworthy as an attempt to provide safe harbor tied to compliance. This is in contrast to bills with narrower scope that only seek to impose liability limits or mandates requiring specific measures. Examples of bills implementing liability limits include Tennessee Public Chapter 151, Georgia Senate Bill 63, and Nebraska LB 241 (pending as of the time of writing). These bills provide liability limits (applicable only to class actions) except in cases of gross negligence or willful misconduct. However, these limits are not proactive or tied to cybersecurity compliance. Mandates to meet specific standards, such as New York’s DFS, are blunter instruments. Neither of these types of laws are inherently bad, but each lacks the scope and nuance of broader-based legislation that seeks to address the issue from multiple angles.
Existing legislation that is similar to Florida’s is the Ohio Cybersecurity Safe Harbor Act of 2018, Connecticut’s Act Incentivizing Cybersecurity Standards of 2021, and West Virginia’s HB 2987 (still pending as of the time of this writing). The Ohio bill is a noteworthy trailblazer, often cited as forerunning the safe harbor trend that Florida’s Fallen Act followed. This shields adopters of cybersecurity standards, such as NIST, et al., and uses similar language (“reasonably conforming”), but stipulates that the program must scale with the business, data sensitivity, and risk, with specific controls implied by their chosen standard. Florida’s Safe Harbor Act was seemingly modeled after this one, but was doomed by its all-or-none immunity based on an interpretation of “substantial compliance.” The flaws aside, this type of legislation, which attempts to strike this balance, is where the most progress can be made on the state legislative front.
Ultimately, all laws should be created in comportment with how humans operate as economic actors weighing risks, costs and benefits on the margin. Good legislation should reward incremental progress—each step a company takes to harden its defenses earning a proportionate boost in protection. Florida HB 473's Liability Act aimed for this in spirit but was stymied by its all-or-nothing shield, risking a free pass for minimal effort. LB 241 and similar bills skip effort entirely. Safe harbors like Ohio’s or Connecticut’s get closer, but they’re still binary. There is no end state for cybersecurity. Threats evolve, zero-days are a fact of life, and no program can be perfect. Laws should protect diligent companies from ruin when a breach isn’t their fault, while holding them accountable when they are negligent. The legislative environment we need incentivizes continuous progress, allocates rewards or penalties commensurate with the situation's facts, and acknowledges that businesses must be enabled to continue operating in a world where cybersecurity is an ongoing challenge.