Iowa Joins Trend of Offering Cybersecurity Safe Harbor for Companies with Written Programs

Iowa has recently joined a gathering trend amongst states in the US to offer companies potential safe harbor through implementing and maintaining a written cybersecurity program. This move makes Iowa the fifth state to provide such an opportunity, following in the footsteps a diverse range of states that includes Connecticut, Ohio, Oregon, and Utah.

The implications of this development may be potentially significant for businesses operating in Iowa. As of July 1, 2023, corporations that have put a comprehensive written cybersecurity program in place and then subsequently suffer a security breach could have an affirmative defense in the state against tort claims for inadequate security measures.

Looking at the existing states who have adopted similar policies, Connecticut’s legislation took effect from October 1, 2021; Ohio’s has been in force since November 2, 2018; Oregon’s since January 1, 2020; and Utah’s since March 5, 2021.

What these states all have in common is an effort to incentivize businesses towards a greater focus on cybersecurity. Not only does having a well-defined written program in place protect companies from potential breaches, but it also strengthens their legal position after a breach, a critical point in an era of regular and increasingly sophisticated cybersecurity threats.

This move by Iowa represents a significant trend amongst not just U.S. states, but countries worldwide, towards incorporating cybersecurity larger into corporate legal culture. In a global environment waking up to the potential threat posed by breaches, maintaining effective cybersecurity practices for companies is rapidly becoming both a legal and pragmatic necessity.

Further reading on the topic reveals greater detail on Iowa’s approach to cybersecurity and the potential implications for businesses in the state.