Florida's cyber law, handled for your town.
Florida's Local Government Cybersecurity Act (s. 282.3185, Florida Statutes) requires every county and municipality to train its workforce, adopt standards consistent with the NIST Cybersecurity Framework, and report cyber incidents to the state on tight deadlines. Most smaller local governments don't have a security team to do it. We deliver the training, the standards, and the incident response — sized for a town hall, not a federal agency.
15-minute call · senior engineer · no obligation
The pressures specific to your sector.
Mandatory workforce training
Employees with access to the local government's network must complete basic cybersecurity training within 30 days of starting and every year after. Technology staff need advanced training.
Standards consistent with NIST CSF
Counties and municipalities must adopt cybersecurity standards that align with the NIST Cybersecurity Framework, and notify the Florida Digital Service when they do.
Tight incident-reporting clocks
Ransomware must be reported to the state Cybersecurity Operations Center and the local sheriff within 12 hours of discovery; other significant incidents within 48 hours — followed by an after-action report.
Paying the ransom isn't an option
Florida law (s. 282.3186) bars local governments from paying or complying with a ransom demand. Recovery depends entirely on backups and response readiness.
Everything the statute asks of you.
- 01Basic cybersecurity training for all employees with network access — onboarding and annual
- 02Advanced training for IT and technology staff
- 03NIST Cybersecurity Framework gap assessment and written standards
- 04Incident response plan mapped to the state's 12- and 48-hour reporting requirements
- 05Incident response retainer: containment, recovery, and after-action reporting
- 06Ransomware-resilient, tested backups — the only recovery path the law allows
- 07Documentation to support Florida Local Government Cybersecurity Grant applications
From mandate to compliant.
Gap-assess against the NIST CSF and inventory who needs which training.
Roll out basic and advanced training, with completion records for every employee.
Write and adopt NIST-aligned standards your governing body can approve.
A reporting-ready incident plan, backed by a team on call around the clock.
Questions, answered.
Does s. 282.3185 apply to our municipality?+
The Act applies to Florida counties and municipalities. Deadlines to adopt standards were staggered by population, and all have now passed — so if your standards, training, or reporting procedures aren't in place, you're already behind. Special districts and other public entities should confirm their obligations with counsel; many adopt the same practices.
What training does the law require?+
Employees with access to the local government's network must complete basic cybersecurity training within 30 days of employment and annually thereafter. Technology professionals and certain leadership roles must complete advanced training. We deliver both and keep the completion records.
What do we have to report, and when?+
Ransomware incidents must be reported to the Cybersecurity Operations Center and the county sheriff within 12 hours of discovery. Other incidents at higher severity levels must be reported within 48 hours, and an after-action report is due after remediation. We build these steps into your incident plan and can make the calls with you.
Can you help us fund this?+
Florida has offered a Local Government Cybersecurity Grant program through the Florida Digital Service. Availability varies by year; we can help you document your needs and align the work with what the program funds.
Ready when you are.
Book a 15-minute introduction call. Walk away with a clear next step — whether you work with us or not.
15-minute call · senior engineer · no obligation
