A bill backed by state House leaders would ban state or local government agencies from paying ransom to hackers who take over their systems.
House Bill 813 addresses "ransomware attacks," in which a hacker breaks into a network, encrypts the data so it's no longer usable, then demands a payment to decrypt the data and restore the system.
Other WRAL Top Stories
The Colonial Pipeline hack is the latest example, but smaller attacks are becoming more common.
According to the state Department of Information Technology, 37 ransomware attacks have been reported by city, county or state agencies or public schools or community colleges since 2016, with most coming in the last two years.
Orange County's government was hit with a ransomware attack in 2019. Durham, Durham County, Rocky Mount and Chatham County all dealt with attacks in 2020.
The bill defines a ransomware attack in state law and ban state or local government agencies under such an attack from paying anything to the hackers or even communicating with them.
Sponsor Rep. Jason Saine, R-Lincoln, says the state has no record of any government entity paying any ransom in one of these attacks, although Mecklenburg County leaders reportedly weighed the option when a hacker hijacked 48 servers there in 2017.
"The public data in state systems, but also school systems, local municipalities – that's data that hackers want, and ransomware folks will target that and go after it and try to get money," Saine said. "So far we've been able to mitigate those attacks, but the issue is still gonna be there."
Saine hopes the bill will send a message to hackers.
"Part of [the purpose of] the bill is to dissuade those attacks," he told WRAL News. "If you're not giving them money, they'll go somewhere else. They're certainly still going to attack, but maybe somewhere else.
State agencies are already required to report ransomware attacks or other cybersecurity incidents to the DIT, which then takes over the management of the problem. But local government entities are not required to report attacks to the state. The bill would change that.
"Part of our problem is that we really just don't know what we don't know, because, you know, it's a little bit embarrassing if you're an agency that's been attacked. It's not something you want to hardly report," Saine explained. "But it also makes it very hard to know what we're facing."
The bill would also require DIT to work with the state Department of Public Safety on major attacks.
The bill was filed a week ago, before news of the pipeline hack broke. "It's very timely right now," joked Rep. Harry Warren, R-Rowan.
"I think you'll be hearing a lot about redundancy systems in the days and weeks to come," agreed Rep. John Torbett, R-Gaston.
The bill passed unanimously the House unanimously and moves to the Senate.