State Attorneys General Are Turning Cybersecurity Failures Into Enforcement Cases

Table of Contents

For years, many companies treated cybersecurity as primarily a technical responsibility.

Security teams maintained firewalls, monitored suspicious activity, patched vulnerabilities and responded when systems were compromised. Legal departments became involved when a breach triggered notification obligations or litigation.

That division is no longer workable.

State attorneys general are increasingly treating weak cybersecurity as a legal and regulatory violation, even when no state statute specifies the precise security technology a company was required to use.

The enforcement theory is straightforward: companies that collect personal information have a duty to protect it. When they fail to maintain reasonable safeguards, ignore known risks, misrepresent their security practices or delay notifying affected consumers, state regulators may pursue them under privacy laws, cybersecurity statutes, breach-notification requirements and longstanding consumer protection laws.

This gives state regulators a broad and increasingly sophisticated enforcement toolkit.

The result is a compliance environment in which a serious security failure can produce simultaneous exposure under multiple state laws, across multiple jurisdictions, with remediation obligations that continue long after a settlement payment is made.

State Cybersecurity Regulation Is Expanding Rapidly

State legislatures continue to add new cybersecurity requirements at a significant pace.

In 2025 alone, at least 44 states enacted more than 200 cybersecurity-related bills and adopted at least 30 related resolutions, according to legislative tracking cited by the National Conference of State Legislatures.

Many of those measures focused on protecting state and local government systems. More than two dozen, however, applied to private-sector organizations, including businesses handling financial, mortgage, educational, genetic and other sensitive information.

The legislative trend has continued so far this year and we covered how the law firms are under attack for breaches.

State comprehensive privacy laws now routinely include security obligations. Industry-specific statutes are becoming more detailed. Genetic information is receiving special protection. States are imposing new rules on critical infrastructure. Regulators are also reaching for older consumer protection laws when newer statutes do not provide the flexibility they need.

Companies therefore cannot approach state cybersecurity compliance by monitoring breach-notification laws alone.

The relevant legal framework may include:

  • Comprehensive state privacy laws
  • General data security statutes
  • Biometric and genetic privacy requirements
  • Educational technology laws
  • Financial and insurance cybersecurity regulations
  • Health data protections
  • Connected-device security laws
  • Critical infrastructure requirements
  • Unfair and deceptive practices statutes
  • State breach-notification laws

The applicable rules depend on the company’s location, customers, data, industry, technology and representations about security.

State Attorneys General Are Pursuing Major Technology Companies

Cybersecurity enforcement is not limited to small businesses with visibly outdated systems.

State attorneys general from across the political spectrum have pursued some of the largest technology and data companies in the world.

Illuminate Education and the Security of Children’s Data

In November 2025, Connecticut, California and New York announced a $5.1 million settlement with educational technology provider Illuminate Education.

Regulators alleged that the company failed to implement basic security safeguards and did not adequately monitor its platforms for suspicious activity, contributing to unauthorized access involving the personal information of millions of students.

The case was important not merely because a breach occurred. The allegations focused on whether the company maintained the security practices regulators considered reasonable for a business entrusted with children’s information.

Children’s data creates particularly high enforcement risk. Regulators are likely to examine not only the breach itself but also access controls, monitoring, retention practices, vendor oversight and the company’s response after discovering the incident.

Meta, WhatsApp and Encryption Representations

In May 2026, Texas Attorney General Ken Paxton sued Meta and WhatsApp over allegations connected to WhatsApp’s representations about end-to-end encryption.

The Texas case illustrates another major source of cybersecurity exposure: a company’s own statements.

When a business tells users that communications are encrypted, information is secure or particular technical protections are in place, regulators may treat those statements as enforceable representations.

A discrepancy between the company’s marketing and the actual operation of its systems can become the basis for a deceptive-practices claim.

Cybersecurity compliance therefore includes reviewing what the company says about security, not only what its technical systems do.

State Settlements Can Reach Enormous Amounts

The financial consequences of state privacy and security enforcement have already reached extraordinary levels.

Equifax agreed in 2019 to pay hundreds of millions of dollars through a broad settlement involving states and federal regulators following its 2017 data breach.

More recent Texas privacy settlements have been even larger.

In July 2024, Texas secured a $1.4 billion biometric privacy settlement from Meta. In 2025, the state reached a $1.375 billion settlement with Google over allegations involving geolocation, browsing and biometric information.

Those cases were centered more directly on privacy, collection, notice and consent than on conventional cybersecurity controls. Nevertheless, they show the financial scale that state enforcement can reach when regulators believe a company’s data practices affected large numbers of consumers.

A billion-dollar state cybersecurity settlement is no longer inconceivable.

The monetary payment is also only one part of the cost.

State settlements frequently require companies to adopt extensive security reforms, submit compliance reports, undergo independent assessments, improve incident-response procedures and maintain new controls for years.

Those continuing obligations can be operationally more expensive than the settlement itself.

Reasonable Security Is Now the Baseline

At least 33 states have broadly applicable laws requiring businesses to protect personal information through reasonable security measures.

Many of these statutes do not provide a detailed checklist. Instead, they establish a flexible standard based on the circumstances.

That flexibility benefits regulators because a company cannot necessarily defend weak practices by arguing that the law failed to name the particular safeguard it lacked.

Reasonableness may be evaluated by considering:

  • The nature and sensitivity of the information
  • The volume of data being processed
  • The company’s size and resources
  • The likelihood and severity of foreseeable harm
  • The company’s industry
  • Available security practices
  • Known vulnerabilities
  • The company’s prior incidents
  • Representations made to customers
  • The access provided to vendors and employees

A small business processing ordinary contact information may not be expected to maintain the same security program as a national healthcare, financial or technology company.

Reasonable, however, does not mean optional.

Every comprehensive state privacy law adopted since 2018 includes some form of data security obligation. The Texas Data Privacy and Security Act, for example, requires controllers to establish and maintain administrative, technical and physical security practices appropriate to the volume and nature of the personal data involved.

Oklahoma, Alabama, Louisiana and Vermont added comprehensive privacy legislation in 2026, continuing the expansion of state-level privacy and security duties.

Businesses operating nationally must now assume that reasonable security is part of the baseline privacy obligation, even where the relevant state does not provide a detailed technical rulebook.

California and New York Are Moving Toward More Prescriptive Rules

Most states leave the meaning of reasonable security to enforcement decisions, industry practices and the facts of each incident.

California and New York have taken more prescriptive approaches in important areas.

New York Cybersecurity Requirements

New York’s Department of Financial Services maintains detailed cybersecurity regulations for covered financial institutions.

The requirements address cybersecurity governance, incident reporting, access controls, risk assessments and other operational safeguards.

The New York State Department of Health has also adopted detailed cybersecurity rules for hospitals, reflecting the heightened consequences of attacks against healthcare systems.

California Cybersecurity Audits

California is introducing another significant requirement: recurring cybersecurity audits for certain covered businesses.

The California Privacy Protection Agency’s regulations describe the subjects those audits must address, effectively providing regulated companies with a clearer view of the security program regulators expect.

The first audit obligations for the largest covered companies are scheduled to arrive in 2028 and will examine activities from 2027.

This is a major compliance development.

Companies subject to the California rules will need more than a written cybersecurity policy. They will need evidence demonstrating that their program has been evaluated, documented and tested.

That evidence may include:

  • Risk assessments
  • System and data inventories
  • Access-control records
  • Security policies
  • Vendor assessments
  • Incident-response testing
  • Vulnerability management records
  • Governance approvals
  • Remediation documentation
  • Independent audit findings

Organizations that wait until the audit deadline to collect this evidence may discover that years of operational records cannot be reconstructed after the fact.

Breach Notification Remains a Separate Enforcement Risk

Every state, along with the District of Columbia and several United States territories, maintains a data breach notification law.

Those laws differ in material ways.

They may use different definitions of personal information, different notice deadlines, different regulator-reporting thresholds and different requirements for the content of consumer notices.

An organization may therefore suffer two distinct compliance failures from one event.

First, regulators may allege that inadequate security contributed to the breach.

Second, they may allege that the company responded improperly after the breach occurred.

Delayed notice, incomplete descriptions, inaccurate statements or failure to notify the proper state agency can create additional exposure.

Companies should not begin researching state notification requirements after an incident has already occurred. A defensible incident-response program should include a jurisdictional notification matrix, defined escalation procedures and a method for identifying the states in which affected individuals reside.

States Are Creating Rules for Specific Industries and Data Types

The broader movement toward comprehensive privacy legislation has not replaced sector-specific cybersecurity laws.

States continue to regulate particular industries and categories of information where they perceive elevated risk.

California and Oregon, for example, maintain security requirements for connected devices.

California, Connecticut, Iowa and Vermont have cybersecurity laws aimed specifically at educational technologies used in pre-kindergarten through grade 12 environments.

California, Nevada and Washington maintain separate protections relating to medical or consumer health information.

Insurance companies face another established regulatory framework. At least 26 states, the District of Columbia and Puerto Rico have adopted versions of the National Association of Insurance Commissioners’ model cybersecurity law.

Nonbank financial companies are also facing increasing regulation. At least 12 states have adopted versions of the Conference of State Bank Supervisors’ Nonbank Model Data Security Law.

These laws can apply alongside general privacy, security and consumer protection statutes.

A company may therefore comply with a comprehensive state privacy law but still violate a more specific rule applicable to its industry, product or data.

Genetic Information Is Becoming a Cybersecurity Priority

Genetic data has emerged as a major focus of state legislation.

At least nine states enacted genetic-data cybersecurity laws during 2025 and 2026.

Some of these laws apply specifically to direct-to-consumer genetic testing companies. They require covered organizations to establish and maintain security programs designed to prevent unauthorized access, use and disclosure.

Other states have adopted broader laws addressing both cybersecurity and national security concerns.

Louisiana’s Human Genomic Security Act

Louisiana’s Human Genomic Security Act of 2025 imposes restrictions on where certain human genetic sequencing data may be stored.

Covered entities must keep protected data outside foreign-adversary countries and restrict remote access from those locations. They must also use safeguards such as encryption, access restrictions and other recognized cybersecurity practices.

The Texas Genomic Act

Texas adopted similar provisions through the Texas Genomic Act of 2025.

The law applies to certain medical facilities, research facilities, companies and nonprofit organizations storing genome sequencing data belonging to Texas residents.

Covered organizations must protect that information through reasonable encryption, access restrictions and other security practices.

They are also prohibited from storing covered genome sequencing data in designated foreign-adversary countries or permitting prohibited access from those locations.

These laws expand cybersecurity compliance into areas traditionally associated with national security and foreign investment controls.

Companies handling genetic information must now evaluate not only whether the data is encrypted, but also where it is stored, who can access it, where those people are located and whether a cloud or storage provider creates prohibited foreign access.

State Cybersecurity Rules Are Absorbing National Security Concerns

States are increasingly regulating technologies based on their perceived connection to foreign governments.

The movement became highly visible through state bans on TikTok.

Nebraska announced restrictions on TikTok use on state devices in 2020. By early 2023, approximately half the states had adopted similar measures.

The scope has since expanded.

In January 2025, the Texas governor prohibited certain artificial intelligence products associated with the People’s Republic of China or the Chinese Communist Party from government-issued devices.

In January 2026, responsibility for maintaining Texas’ list of prohibited technologies was assigned to the Texas Cyber Command.

Virginia also prohibited the use of DeepSeek AI on state devices and networks through a 2025 executive order.

Several states have separately restricted government purchases of telecommunications equipment associated with designated Chinese companies.

These rules primarily govern public systems and purchasing, but they signal a broader direction in state cybersecurity policy.

Regulators are no longer looking only at whether information is protected from conventional criminal intrusion. They are also examining supply chains, software origins, foreign access, data-hosting locations and the geopolitical risks associated with technology providers.

Private companies, especially government contractors and critical infrastructure providers, should expect these concerns to influence procurement requirements and security assessments.

Critical Infrastructure Is Receiving More State Oversight

Water and wastewater systems have become another focus of state cybersecurity legislation.

These systems often rely on operational technology that connects digital controls to physical infrastructure. A successful cyberattack may therefore disrupt water delivery, treatment processes or public health systems rather than merely expose information.

Indiana Vulnerability Assessments

Indiana enacted legislation in 2025 requiring water and wastewater systems to conduct annual cybersecurity vulnerability assessments.

Beginning in 2026, covered entities must periodically certify that they completed the assessment, addressed identified vulnerabilities or documented plans to do so, and updated their emergency response plans.

Maryland Zero-Trust Requirements

Maryland also amended its laws in 2025 to require cybersecurity standards for community water and sewage systems.

Larger covered systems must begin implementing zero-trust cybersecurity principles across on-premises and cloud services. They are also required to conduct recurring cybersecurity maturity assessments covering operational technology and information technology.

These laws reflect an important shift from general security obligations to measurable operational requirements.

Regulators are increasingly asking companies to prove that assessments occurred, vulnerabilities were tracked and remediation plans were adopted.

Consumer Protection Laws Give Attorneys General Their Broadest Authority

Some of the strongest cybersecurity enforcement authority comes from laws written decades before the modern internet.

Every state and the District of Columbia maintains a consumer protection statute prohibiting at least certain deceptive practices. Many also prohibit unfair conduct.

These statutes are often called:

  • Unfair and deceptive acts and practices laws
  • UDAP statutes
  • Mini-FTC Acts
  • Consumer fraud laws
  • Consumer protection acts

The precise language differs by state. Attorneys general, however, have repeatedly taken the position that a company’s failure to maintain reasonable security can constitute an unfair or deceptive practice.

A deception theory may arise when a company claims that information is protected, encrypted or securely stored when those statements are false or misleading.

An unfairness theory may arise when a company exposes consumers to substantial and avoidable harm through inadequate security practices, even without a specific misleading statement.

Texas demonstrated the flexibility of this authority in a September 2025 lawsuit against a cloud-services provider serving K-12 schools. Following a breach involving children and teachers, four of the state’s five counts were brought under the Texas Deceptive Trade Practices Act.

This matters because a company cannot assume that the absence of an industry-specific cybersecurity law means the attorney general lacks authority.

Consumer protection statutes can fill perceived gaps.

Software Developers May Become Enforcement Targets

State cybersecurity enforcement has traditionally focused on organizations that collect, store or control personal information.

That boundary may expand.

Litigation filed against major social media platforms has advanced the argument that software platforms and algorithmic design features should be treated as products for liability purposes.

If courts accept that theory more broadly, regulators and plaintiffs may increasingly pursue software developers whose design decisions contribute to privacy or cybersecurity harm.

That could extend potential exposure beyond the company holding the data to include:

  • Application developers
  • Software-as-a-service providers
  • Artificial intelligence system developers
  • Analytics vendors
  • Identity providers
  • Cloud infrastructure companies
  • Security technology providers
  • Developers of connected devices

The critical question may become not only who controlled the information, but who designed the system that created or amplified the risk.

Cybersecurity Compliance Must Be Documented Before an Incident

The expansion of state enforcement changes how businesses should prepare.

A written information security policy, by itself, is no longer sufficient evidence of compliance.

Regulators may examine whether the organization actually:

  • Inventoried the information it collected
  • Restricted access according to job responsibilities
  • Monitored suspicious activity
  • Assessed vendors
  • Patched known vulnerabilities
  • Encrypted sensitive information
  • Tested incident-response procedures
  • Evaluated cybersecurity risk
  • Remediated prior findings
  • Provided accurate consumer disclosures
  • Maintained evidence showing that controls operated

The company may also need to explain why its security measures were appropriate for the sensitivity and volume of the information it handled.

That explanation is much easier to defend when risk decisions were documented before the breach.

Attempting to create a compliance record after an investigation begins will not establish that the controls were operating when they were needed.

State Cybersecurity Enforcement Is Not Slowing Down

The direction of state regulation is clear.

More states are adopting comprehensive privacy laws. More industries are receiving specialized cybersecurity requirements. Attorneys general are coordinating across jurisdictions. National security concerns are entering state privacy and security legislation. Audit and assessment requirements are becoming more prescriptive.

At the same time, regulators retain the ability to use broad consumer protection statutes when a newer law does not squarely address the conduct at issue.

For businesses, the practical risk is not merely the possibility of a breach.

It is the possibility that a breach, security representation, missed assessment or delayed notice will be examined under several overlapping legal theories at once.

Captain Compliance helps organizations evaluate their privacy and cybersecurity obligations, document governance controls, review vendor risk, prepare for state privacy assessments and create defensible compliance records before regulators begin asking questions.

State attorneys general are building a larger cybersecurity enforcement toolkit.

Companies should build the evidence showing that their security program can withstand it.

Frequently Asked Questions

Can a state attorney general pursue a company for weak cybersecurity?

Yes. State attorneys general may rely on comprehensive privacy laws, state security statutes, breach-notification laws, industry-specific requirements and consumer protection statutes. The available authority depends on the state and the facts of the case.

What does reasonable security mean?

Reasonable security is generally assessed according to the circumstances, including the sensitivity and volume of the information, foreseeable risks, the company’s resources, its industry and available safeguards. The standard is flexible rather than identical for every organization.

Does a company have liability only when a data breach occurs?

Not necessarily. Regulators may also investigate misleading security representations, failure to perform required assessments, inadequate vendor oversight, prohibited data storage, noncompliance with cybersecurity regulations or delayed breach notification.

Are cybersecurity laws limited to technology companies?

No. State cybersecurity requirements apply across sectors, including education, healthcare, financial services, insurance, genetic testing, connected devices, critical infrastructure and general consumer businesses.

Why are consumer protection laws important in cybersecurity cases?

Consumer protection laws give attorneys general broad authority to challenge conduct that is allegedly unfair or deceptive. They may be used when a company misrepresents its security practices or fails to protect consumers from foreseeable harm.

What records should companies maintain?

Companies should preserve risk assessments, data inventories, access-control records, vendor reviews, incident-response tests, vulnerability remediation records, policies, training documentation, security monitoring evidence and governance approvals.

How can Captain Compliance support a cybersecurity compliance program?

Captain Compliance can help organizations identify applicable state privacy and security obligations, conduct privacy and risk assessments, evaluate vendors, document governance practices, prepare for cybersecurity audits and maintain evidence supporting a defensible compliance program.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.